Who can do the audit
A SOC 2 report must be issued by an independent, licensed CPA firm. Compliance platforms and consultants can prepare you, but they cannot issue the report.
What to look for
- Experience with companies like yours. A firm that mostly audits large enterprises may be a poor fit for a 30-person software company, and the reverse.
- Familiarity with your compliance platform. An auditor who works inside Vanta or a similar platform saves a great deal of back and forth.
- A clear process. You should know what they will ask for, when, and who your contact will be.
- Realistic timing. Ask when they can start and how long the report takes after the audit period ends.
- A name your customers will accept. If a customer's security team will read the report, the firm's reputation matters.
Questions to ask
- How many SOC 2 audits do you complete each year, and for what size of company?
- Who will actually do the testing, and will that person stay through the engagement?
- How do you select samples, and how much evidence do you typically request?
- What happens if you find an exception?
- What is included in the fee, and what would next year's audit cost?
About price
Fees vary widely with scope, report type and the size of your company. Get quotes from more than one firm on the same scope, and compare what is included. The lowest quote is not a bargain if the firm is slow or your customers question the report.
Keep the roles separate
The auditor must stay independent, so they cannot design your controls or fix your gaps. Have that work done before the audit period starts. See what to prepare before engaging an auditor.
We help you choose an audit firm, then handle all coordination and correspondence with them. See SOC 2 readiness and audit management.
