What credentials should a SOC 2 auditor have?
Updated 4 Oct 2026
A SOC 2 report should come from a licensed CPA firm, and that firm should be enrolled in peer review. You can check both yourself, for free, in official databases. Badges, ISO accreditations and labels like "vetted auditor" do not replace those two checks.
If you’re comparing SOC 2 auditors and can’t tell who’s legitimate, you’re not alone. Here’s something most guides skip: the name on a firm’s website isn’t always the name on your report. Some firms sign through a separately licensed CPA company, which is normal. But it means the brand you’re talking to tells you less than you think.
The good news is you don’t have to take anyone’s word for it. Two checks matter more than anything on a firm’s website: is the firm that signs your report a licensed CPA firm, and is it enrolled in peer review? You can look up both yourself, for free, in official databases. Here’s how, plus what to ask and how to compare the quotes you get.
This is confusing partly because words like “auditor” and “certified” mean different things depending on who is selling. We’re a directory and we earn from listings, but we don’t do audits or sell audit services, and nothing here changes based on which firm you choose. You can read how we make money.
Who is allowed to issue a SOC 2 report?
Only a licensed CPA firm can issue a SOC 2 report. CPA stands for certified public accountant. It seems odd that an IT security report comes from accountants, but SOC 2 sits under AICPA attestation standards. Attestation means an independent professional gives an opinion on someone else’s statements, here about your controls. The AICPA is the American Institute of CPAs, the body behind those standards.
State boards of accountancy license CPA firms. The AICPA does not “certify” or “accredit” them. It sets standards and runs a quality review programme called peer review, covered below. Our SOC 2 auditors directory states the same basics: only licensed CPA firms can issue a SOC 2 report, and some firms sign through a separately licensed CPA entity.
The people who test your controls are often IT specialists. That’s normal. What matters is that the firm that signs the report is licensed.
Readiness consultants can help you prepare for an audit, but they cannot issue the report. Readiness is a separate job.
What credentials should a legitimate SOC 2 firm have?
A legitimate SOC 2 firm has an active CPA firm licence, a named signing entity and a peer review on record. The table below shows each credential, what it tells you and where to check it.
| Credential | What it tells you | Where to check |
|---|---|---|
| Active CPA firm licence | The firm is legally allowed to do this kind of work in its state | CPAverify (free, data comes from state boards), or the state board’s own lookup |
| Named signing entity | Who is actually responsible for the opinion. Sometimes a separate CPA company from the brand you hired | The opinion letter in the report. Ask before you sign the engagement letter |
| Enrolled in AICPA peer review, with a recent review | An outside firm has reviewed its quality controls | AICPA Peer Review Public File |
| Peer review result | How that review went | Often not public. Ask the firm for its latest peer review letter |
| Independence | No relationship that compromises the opinion | Ask how it separates any readiness work from the audit |
| Team skills (CISA, CISSP and similar) | The people testing your controls understand technology | Ask who will do the fieldwork. Useful, but not a legal requirement |
Peer review is an outside review of a firm’s quality controls. It checks the firm’s system, not each individual audit. Peer reviews typically run on a three-year cycle. In Louisiana, for example, CPA firms doing attest work must be peer reviewed every three years. Other places can differ.
Check the signer, not the brand. Ask which legal entity will sign your report, then look up that entity, not the brand name. Some firms sign through a separate CPA entity, and many firms in our directory don’t publish who signs.
How do you check a SOC 2 auditor yourself?
You don’t have to take anyone’s word for it. You can check a SOC 2 auditor in three steps, using free official lookups.
- Ask who signs. Ask the firm for the full legal name of the entity that will sign your report, and where it is licensed. A brand name is not enough.
- Look up the licence. Search that entity on CPAverify, a free service hosted by NASBA, the national association of state boards of accountancy. It is populated with official licensing data sent by state boards. It covers CPAs and firms, and shows enforcement and disciplinary markers. You can also use the state board’s own lookup.
- Check peer review. Search the AICPA Peer Review Public File. It shows the firm’s name, address, enrollment status and date of last peer review for every firm enrolled in the AICPA programme. If the result is not public, ask the firm for its latest peer review letter.
Be honest about what each lookup does and does not show. CPAverify tells you a firm is licensed and whether there are disciplinary markers. It does not tell you the firm is good at SOC 2. The public file shows a firm is enrolled and when it was last reviewed. Results only show for firms in certain AICPA sections or that opt in, so a missing result is a reason to ask, not proof of a problem.
If the peer review result isn’t public, ask for it. Asking for the latest peer review letter is a normal request, and a good firm will not mind.
Other credentials don’t stand in for these. An ISO accreditation shows a body can issue ISO certificates, which is a different job. The AICPA SOC logo shows a company received a SOC report. Neither shows that a firm can issue one. For how ISO certification works, see our guide to ISO 42001.
The AICPA itself urges service organisations to evaluate SOC services thoroughly. It says it will act on members found unlicensed or not enrolled in peer review, and refers unlicensed firms to state boards.
What should you ask a SOC 2 firm before you sign?
These are all normal questions, and a good firm won’t mind answering them. Ask every firm the same ones.
The basics:
- Which legal entity signs the report, and where is it licensed?
- Can you share your most recent peer review letter?
- Who will actually do the fieldwork, and what are their backgrounds? People disagree on how technical SOC 2 teams are, so it’s worth asking.
- If you also help us prepare, how do you keep the audit independent?
- What exactly will be in scope: which product, systems and locations? A report only covers what’s in scope, so make sure it covers the service your customers buy.
- If a consultant is arranging the audit, which CPA firm will sign, and can we speak to them directly?
To compare quotes fairly:
- Is this quote for Type 1, Type 2, or both? Type 1 checks your controls at a point in time. Type 2 checks them over a period.
- Which trust services criteria are included? Security is always in. Are any others?
- How long is the observation period for a Type 2?
- What costs extra, such as re-testing, extra systems or a bridge letter? A bridge letter covers the gap between your last report and the next one.
- Is the year-one price an introductory rate? What will year two and year three cost?
- Do you work with our compliance platform, if we use one?
By stage:
- Early stage, first customer asking: ask that customer which report type they’ll accept before you ask firms for quotes. It changes what you’re buying.
- Scaling: ask about year two and year three pricing, and whether the firm can cover other things you’ll need later.
- Selling to large enterprises: ask your customers whether they expect a particular kind of firm. Larger national firms make sense when customers specifically ask for them.
When your report arrives, read the auditor’s opinion, the scope (what was covered) and the exceptions (where a control didn’t work as described). Those are the parts your customers’ security teams will look at first.
Why are your SOC 2 quotes so different?
SOC 2 quotes often differ because they don’t cover the same work. Quotes can differ because of:
- Report type (Type 1 or Type 2)
- Which criteria are included
- The length of the observation period
- What is in scope (product, systems, locations, services)
- Whether readiness help is bundled in
- What counts as an extra
- Whether the price covers year one only
Line your quotes up against these and you’ll often find they aren’t quoting the same thing. For published prices and how we source them, see our SOC 2 cost page.
A cheap quote isn’t a red flag by itself. An unclear signer is. Small, specialist firms can be fully legitimate. What matters is knowing which licensed firm will sign, and our directory’s FAQ says small CPA firms can do SOC 2 if they are licensed and peer reviewed.
What about firms outside the US?
The rules for non-US firms vary, and we won’t pretend to settle them here. The AICPA’s logo terms say a SOC report can come from a licensed CPA “or a non-US equivalent”, so “US firms only” is too strong.
So ask two things. Which professional body licenses the firm that signs? And which standard is the report issued under? Then ask your own customers whether they accept it. This is a question about the signer and the licence, not about where the firm is based.
Which red flags are real, and which just look scary?
Treat every item below as “worth asking about”, never as proof that a firm is illegitimate.
Worth asking about:
- The firm can’t or won’t tell you which licensed entity signs the report.
- The signing entity doesn’t appear on CPAverify or its state board’s lookup.
- The firm isn’t in the AICPA Peer Review Public File and can’t explain why.
- The firm’s only credentials are ISO accreditations or logos, with no CPA licence for the signer.
- The firm offers “SOC 2 certification” or a “SOC 2 certificate”. SOC 2 is a report, not a certificate.
- A consultant offers to prepare you and also issue your SOC 2 report itself.
- The same team prepares you and audits you, with no clear answer on independence.
- The quote doesn’t say what will be in scope.
Looks scary, usually normal:
- The firm is small or specialist.
- The quote is lower than a big firm’s.
- The signing entity has a different name from the brand.
- The people testing your controls aren’t CPAs.
- Fieldwork happens remotely.
- The peer review result isn’t public. Ask for the letter instead.
What this does not cover
This guide is not legal or audit advice. It does not say whether a specific report will be accepted by a specific customer, or what a specific state law requires. It does not rank firms, and it names none. The rules for non-US firms are not settled here.
Want to see credentials side by side? Our SOC 2 auditors directory shows each firm’s credentials with labels for what the firm states and what a person confirmed in an official register. See our methodology for how we label facts, and our independence page for how we make money. Paid Featured slots are always labelled and never change rankings.
Comparing SOC 2 auditors? See their credentials in our directory
Tell us what you need and get 3 to 5 quotes from firms matched on fit. Free for buyers.
Get quotesQuestions
Why does an IT security report come from accountants?
SOC 2 sits under AICPA attestation standards, the same family of rules accountants use for other assurance reports. That is why the firm that signs must be a CPA firm. The people who test your controls are often IT specialists working inside that firm.
Can a small CPA firm do my SOC 2?
Yes, if it holds a current CPA firm licence and is enrolled in peer review. Size does not decide whether a report is real. Which licensed firm signs it, and what is in scope, matter far more than how big the firm is.
Is there such a thing as "SOC 2 certified"?
No. SOC 2 is an attestation report issued by a CPA firm, not a certificate. When a website says "SOC 2 certified", it usually means the company has received a SOC 2 report. Ask for the report and read the auditor's opinion.
Does a SOC 2 report cover my whole company?
Not necessarily. A report covers only what is in scope, which you agree with the auditor. Ask for the scope in writing, and make sure it covers the product or service your customers actually buy.
What does the AICPA SOC logo on a website mean?
It means the company received a SOC report. The AICPA's logo terms do not tell you which period the report covers, or anything about the firm that issued it. Treat the logo as a prompt to ask for the report, not as proof.
Can a firm outside the US issue a SOC 2?
The AICPA's logo terms refer to a licensed CPA or a non-US equivalent, and the rules vary. Ask which professional body licenses the firm that signs, and which standard the report is issued under.
Sources
- The Compliance Index, SOC 2 auditors directory (licensed CPA firms, signing entities), checked 4 Oct 2026
- AICPA, SOC for service organizations logo guidelines, checked 4 Oct 2026
- AICPA, System and Organization Controls (SOC) suite of services, checked 4 Oct 2026
- AICPA, peer review oversight and transparency, checked 4 Oct 2026
- NASBA, CPAverify: what is it and how can it help, checked 4 Oct 2026
- Louisiana Legislative Auditor, peer reviews (example of a three-year cycle), checked 4 Oct 2026
It takes about two minutes.
Get quotes