Independent and free for buyers. We don't do audits. We help you find and compare the firms that do.

What credentials should a SOC 2 auditor have?

Updated 4 Oct 2026

Short answer

A SOC 2 report should come from a licensed CPA firm, and that firm should be enrolled in peer review. You can check both yourself, for free, in official databases. Badges, ISO accreditations and labels like "vetted auditor" do not replace those two checks.

If you’re comparing SOC 2 auditors and can’t tell who’s legitimate, you’re not alone. Here’s something most guides skip: the name on a firm’s website isn’t always the name on your report. Some firms sign through a separately licensed CPA company, which is normal. But it means the brand you’re talking to tells you less than you think.

The good news is you don’t have to take anyone’s word for it. Two checks matter more than anything on a firm’s website: is the firm that signs your report a licensed CPA firm, and is it enrolled in peer review? You can look up both yourself, for free, in official databases. Here’s how, plus what to ask and how to compare the quotes you get.

This is confusing partly because words like “auditor” and “certified” mean different things depending on who is selling. We’re a directory and we earn from listings, but we don’t do audits or sell audit services, and nothing here changes based on which firm you choose. You can read how we make money.

Who is allowed to issue a SOC 2 report?

Only a licensed CPA firm can issue a SOC 2 report. CPA stands for certified public accountant. It seems odd that an IT security report comes from accountants, but SOC 2 sits under AICPA attestation standards. Attestation means an independent professional gives an opinion on someone else’s statements, here about your controls. The AICPA is the American Institute of CPAs, the body behind those standards.

State boards of accountancy license CPA firms. The AICPA does not “certify” or “accredit” them. It sets standards and runs a quality review programme called peer review, covered below. Our SOC 2 auditors directory states the same basics: only licensed CPA firms can issue a SOC 2 report, and some firms sign through a separately licensed CPA entity.

The people who test your controls are often IT specialists. That’s normal. What matters is that the firm that signs the report is licensed.

Readiness consultants can help you prepare for an audit, but they cannot issue the report. Readiness is a separate job.

What credentials should a legitimate SOC 2 firm have?

A legitimate SOC 2 firm has an active CPA firm licence, a named signing entity and a peer review on record. The table below shows each credential, what it tells you and where to check it.

Credential What it tells you Where to check
Active CPA firm licence The firm is legally allowed to do this kind of work in its state CPAverify (free, data comes from state boards), or the state board’s own lookup
Named signing entity Who is actually responsible for the opinion. Sometimes a separate CPA company from the brand you hired The opinion letter in the report. Ask before you sign the engagement letter
Enrolled in AICPA peer review, with a recent review An outside firm has reviewed its quality controls AICPA Peer Review Public File
Peer review result How that review went Often not public. Ask the firm for its latest peer review letter
Independence No relationship that compromises the opinion Ask how it separates any readiness work from the audit
Team skills (CISA, CISSP and similar) The people testing your controls understand technology Ask who will do the fieldwork. Useful, but not a legal requirement

Peer review is an outside review of a firm’s quality controls. It checks the firm’s system, not each individual audit. Peer reviews typically run on a three-year cycle. In Louisiana, for example, CPA firms doing attest work must be peer reviewed every three years. Other places can differ.

Check the signer, not the brand. Ask which legal entity will sign your report, then look up that entity, not the brand name. Some firms sign through a separate CPA entity, and many firms in our directory don’t publish who signs.

How do you check a SOC 2 auditor yourself?

You don’t have to take anyone’s word for it. You can check a SOC 2 auditor in three steps, using free official lookups.

Diagram: three steps to check a SOC 2 auditor: ask who signs, look up the licence, check peer review.
  1. Ask who signs. Ask the firm for the full legal name of the entity that will sign your report, and where it is licensed. A brand name is not enough.
  2. Look up the licence. Search that entity on CPAverify, a free service hosted by NASBA, the national association of state boards of accountancy. It is populated with official licensing data sent by state boards. It covers CPAs and firms, and shows enforcement and disciplinary markers. You can also use the state board’s own lookup.
  3. Check peer review. Search the AICPA Peer Review Public File. It shows the firm’s name, address, enrollment status and date of last peer review for every firm enrolled in the AICPA programme. If the result is not public, ask the firm for its latest peer review letter.

Be honest about what each lookup does and does not show. CPAverify tells you a firm is licensed and whether there are disciplinary markers. It does not tell you the firm is good at SOC 2. The public file shows a firm is enrolled and when it was last reviewed. Results only show for firms in certain AICPA sections or that opt in, so a missing result is a reason to ask, not proof of a problem.

If the peer review result isn’t public, ask for it. Asking for the latest peer review letter is a normal request, and a good firm will not mind.

Other credentials don’t stand in for these. An ISO accreditation shows a body can issue ISO certificates, which is a different job. The AICPA SOC logo shows a company received a SOC report. Neither shows that a firm can issue one. For how ISO certification works, see our guide to ISO 42001.

The AICPA itself urges service organisations to evaluate SOC services thoroughly. It says it will act on members found unlicensed or not enrolled in peer review, and refers unlicensed firms to state boards.

What should you ask a SOC 2 firm before you sign?

These are all normal questions, and a good firm won’t mind answering them. Ask every firm the same ones.

The basics:

To compare quotes fairly:

By stage:

When your report arrives, read the auditor’s opinion, the scope (what was covered) and the exceptions (where a control didn’t work as described). Those are the parts your customers’ security teams will look at first.

Why are your SOC 2 quotes so different?

SOC 2 quotes often differ because they don’t cover the same work. Quotes can differ because of:

Line your quotes up against these and you’ll often find they aren’t quoting the same thing. For published prices and how we source them, see our SOC 2 cost page.

A cheap quote isn’t a red flag by itself. An unclear signer is. Small, specialist firms can be fully legitimate. What matters is knowing which licensed firm will sign, and our directory’s FAQ says small CPA firms can do SOC 2 if they are licensed and peer reviewed.

What about firms outside the US?

The rules for non-US firms vary, and we won’t pretend to settle them here. The AICPA’s logo terms say a SOC report can come from a licensed CPA “or a non-US equivalent”, so “US firms only” is too strong.

So ask two things. Which professional body licenses the firm that signs? And which standard is the report issued under? Then ask your own customers whether they accept it. This is a question about the signer and the licence, not about where the firm is based.

Which red flags are real, and which just look scary?

Treat every item below as “worth asking about”, never as proof that a firm is illegitimate.

Worth asking about:

Looks scary, usually normal:

Comparing SOC 2 auditors? See their credentials in our directory →

What this does not cover

This guide is not legal or audit advice. It does not say whether a specific report will be accepted by a specific customer, or what a specific state law requires. It does not rank firms, and it names none. The rules for non-US firms are not settled here.

Want to see credentials side by side? Our SOC 2 auditors directory shows each firm’s credentials with labels for what the firm states and what a person confirmed in an official register. See our methodology for how we label facts, and our independence page for how we make money. Paid Featured slots are always labelled and never change rankings.

Comparing SOC 2 auditors? See their credentials in our directory

Want real quotes?

Tell us what you need and get 3 to 5 quotes from firms matched on fit. Free for buyers.

Get quotes

Questions

Why does an IT security report come from accountants?

SOC 2 sits under AICPA attestation standards, the same family of rules accountants use for other assurance reports. That is why the firm that signs must be a CPA firm. The people who test your controls are often IT specialists working inside that firm.

Can a small CPA firm do my SOC 2?

Yes, if it holds a current CPA firm licence and is enrolled in peer review. Size does not decide whether a report is real. Which licensed firm signs it, and what is in scope, matter far more than how big the firm is.

Is there such a thing as "SOC 2 certified"?

No. SOC 2 is an attestation report issued by a CPA firm, not a certificate. When a website says "SOC 2 certified", it usually means the company has received a SOC 2 report. Ask for the report and read the auditor's opinion.

Does a SOC 2 report cover my whole company?

Not necessarily. A report covers only what is in scope, which you agree with the auditor. Ask for the scope in writing, and make sure it covers the product or service your customers actually buy.

What does the AICPA SOC logo on a website mean?

It means the company received a SOC report. The AICPA's logo terms do not tell you which period the report covers, or anything about the firm that issued it. Treat the logo as a prompt to ask for the report, not as proof.

Can a firm outside the US issue a SOC 2?

The AICPA's logo terms refer to a licensed CPA or a non-US equivalent, and the rules vary. Ask which professional body licenses the firm that signs, and which standard the report is issued under.

Sources

Ready to compare?

It takes about two minutes.

Get quotes