Hire an auditor
How to choose a SOC 2 auditor
Sources reviewed October 1, 2026 · By Software Compliance Directory
Choose a SOC 2 auditor by the issuing CPA firm, the engagement scope, and the team's examination process. Give each shortlisted firm the same brief so you can compare deliverables, responsibilities, timing, and exclusions.
The AICPA describes SOC as assurance services provided by CPAs. A software subscription or readiness engagement is a separate purchase. Establish who performs the examination and who issues the report before evaluating a bundled offer.
Write the engagement brief
Start with the customer request. Ask the customer's security contact to confirm the report they expect and the systems it must cover. Translate that into a brief the CPA firm can assess, rather than choosing a deadline from a sales promise.
- Organization and product: the legal entity, service description, infrastructure, and relevant locations.
- Requested report: type, criteria, expected period, and customer delivery date, subject to the firm's advice.
- Current state: the controls already operating, known gaps, existing evidence, and software in use.
- Responsibilities: internal program owner, technical owners, readiness adviser, and examination firm.
- Dependencies: planned product changes, cloud migrations, staffing gaps, and buyer decisions still outstanding.
Engagement scope and the reporting period should be explicit. Confirm whether the customer needs a Type 1 or Type 2 report. A useful first meeting ends with open questions recorded and assigned. If a customer says only “SOC 2 required,” resolve what that means before ordering a package.
Separate the responsibilities
Readiness work helps your team prepare. The examination provides independent assurance. Software can organize controls and evidence. Your company still needs to operate the processes and resolve gaps.
For a combined proposal, request the names of all entities involved, the contract for each service, and a written explanation of how responsibilities and independence are handled. Ask how auditor selection works and whether you can use a different firm. The AICPA's SOC resources highlight the need to evaluate SOC services carefully.
Evaluate the firm
Ask who leads the engagement and who reviews the work. Seek experience with a comparable service boundary, not simply a familiar customer logo. A multi-tenant application, a managed service, and an organization processing sensitive customer data may raise different scoping questions.
- Which legal CPA firm issues the report, and where can its license and applicable peer-review information be checked?
- Who makes the scope and examination decisions, and who answers technical questions?
- How are evidence requests, follow-ups, exceptions, and report review handled?
- What access does the firm need to your systems or compliance platform?
- What happens if evidence is incomplete or the expected date changes?
Request a walkthrough of an anonymized evidence request and the communication process. Do not upload sensitive customer or employee records during an initial sales demo.
Compare written proposals
Build a comparison with one row per decision: scope, report and period, team, evidence process, milestones, fee, assumptions, exclusions, and change fees. Mark missing answers as “not specified” and ask for clarification. Do not score a missing detail as a zero-cost inclusion.
Separate examination fees from readiness consulting, software, testing, and internal staff time. Confirm what happens when the scope expands and whether the quoted price covers follow-up work and report delivery. Use the cost planning tool as an organizing aid, then replace assumptions with written proposals.
Prepare your shortlist
Browse the SOC 2 audit firms, select firms whose stated services match your brief, and send the same questions to each. Record the source and date for material answers. Choose the engagement your team can support and your customer can use.
Download the auditor proposal comparison. Fill in your scope and verified answers before sharing it with a provider.
Build an auditor selection brief and compare provider proposals using the same scope.
Explore directory profiles
Examples from the directory to review against your scope. These are starting points, not a quality ranking.