On this page

In this guide, SOC service provider means an outside organization you hire to prepare for, examine, or operate controls for a SOC 2 engagement. The phrase also commonly refers to managed security operations, often sold as SOC as a Service (SOCaaS). Those are different buying decisions.

A SOC 2 report is an attestation report over selected AICPA Trust Services Criteria. A licensed CPA firm performs the examination and issues the report. Readiness consultants, MSSPs, vCISOs, penetration testers, and GRC tools can support the work, but they do not replace the service auditor.

Choose the CPA firm based on the report your customer requires. Add readiness help for control or evidence gaps, an MSSP or vCISO for operational security work, and software for evidence coordination. Confirm each provider’s legal role, scope, cost, and independence before signing.

What does “SOC service provider” mean in a SOC 2 engagement?

Within a SOC 2 program, a provider can prepare the control environment, examine it, operate security controls, or organize evidence. “SOC as a Service” usually means managed security operations. Confirm the deliverable before comparing quotes: attestation report, readiness plan, operating service, or software subscription.

If a sales page says it provides “SOC services,” ask what the buyer receives:

  • an independent SOC 2 report;
  • a readiness assessment and remediation plan;
  • security monitoring, incident response, vCISO, or penetration testing; or
  • a compliance platform that connects systems, assigns control owners, and stores evidence.

The last two categories can support a SOC 2 program without being an audit. A managed SOC provider may operate monitoring and incident-response controls. A security services firm or penetration-testing firm may produce evidence an auditor reviews. Neither service, by itself, produces the CPA firm’s opinion.

Which SOC 2 provider does each job?

The provider role determines the deliverable. The CPA firm issues the attestation; the readiness consultant prepares the organization; the operational provider runs or tests security work; and the software provider organizes records without taking management’s responsibilities.

ProviderPrimary jobTypical outputBoundary to confirm
Licensed CPA firmDefines the examination, tests selected controls, and issues the SOC 2 reportService auditor’s report, opinion, tests, and exceptionsWhich legal entity signs, which TSCs are in scope, and who is the assigned engagement partner
Readiness consultantMaps gaps, helps document controls, and stages evidence before the examinationGap analysis, remediation plan, policies, control descriptions, and evidence guidanceWhether the consultant makes decisions for management or only advises and documents them
MSSP, vCISO, or security testerOperates or tests security functions such as monitoring, incident response, access administration, or penetration testingMonitoring records, incident tickets, security reviews, or test reportsWhich service is in the system boundary, who owns the control, and what evidence the CPA firm will test
GRC or SOC 2 software providerConnects systems, maps controls, assigns tasks, and collects recordsEvidence exports, control status, audit trails, and task historyData coverage, exclusions, source-system validation, subscription terms, and any auditor or referral relationship

SOC 2 provider-role map showing CPA firm, readiness consultant, and MSSP responsibilities.

The AICPA’s SOC suite overview describes SOC services as assurance offerings that CPAs provide for service organizations. Use that source when a provider’s marketing language blurs an attestation engagement with consulting or managed security work.

Who can issue a SOC 2 report?

An independent service auditor at a licensed CPA firm issues a SOC 2 report under the applicable AICPA attestation framework. A readiness consultant, MSSP, GRC platform, or marketplace may support preparation or route a buyer, but it cannot substitute for the CPA firm named in the report.

The AICPA’s illustrative SOC 2 report shows the pieces a buyer should expect: management’s assertion, the system description, the service auditor’s report, and the auditor’s tests and results. Ask for the legal entity and report type before you discuss price.

What should you verify before signing?

  1. The legal CPA entity. Ask which firm name will appear on the report and confirm that the entity is licensed to practice accountancy in the relevant jurisdiction. A brand name, platform badge, or consultant’s CPA credential does not answer that question.
  2. Peer-review documentation. Search the AICPA Peer Review Public File using the legal firm name. Review the available enrollment and accepted-review documents, then ask the firm to explain any missing, outdated, or differently named record.
  3. The assigned engagement team. Get the engagement partner, manager, and day-to-day contact in writing. A firm’s overall client list does not prove that the team assigned to you has experience with your system boundary.
  4. A comparable report. Request a redacted report or a sample table of contents. Look for the system description, criteria, covered date or period, opinion, tests, exceptions, complementary user entity controls (CUECs), and subservice organizations.
  5. The customer requirement. Ask the customer or procurement team to state the report type, criteria, coverage period, and deadline in writing. “SOC 2” alone is not enough to scope the engagement.

Peer review is a quality signal, not a substitute for checking the license, legal entity, independence, or scope. Treat those as separate checks.

Should one firm handle readiness and attestation?

A provider group may offer readiness and attestation, but a bundled brand does not answer the independence question. The CPA firm should explain the specific services, management responsibilities, self-review risks, personnel or entity separation, and safeguards that apply to your engagement.

The practical rule is to document the specific relationship rather than rely on a blanket rule about a brand. Ask the CPA firm:

  1. Which entity and team will issue the report?
  2. What readiness, policy, configuration, penetration-testing, or remediation work did the organization perform before the examination?
  3. Which decisions remain with management, and how will management accept responsibility for them?
  4. How does the firm evaluate self-review or undue-influence risks when it also provides a tool, referral, or security service?
  5. If the firm performed a control activity or test, who evaluates that work during the SOC 2 examination?

The AICPA’s March 31, 2026 nonauthoritative FAQ on software tools used in SOC 2 examinations addresses tool use, completeness and accuracy of information, auditor responsibilities, and independence concerns. The AICPA’s SOC suite page also points to current Ethics Staff Insights on business arrangements between CPA firms and SOC 2 tool providers.

If the answer to any of those questions is vague, get a written independence explanation or use separate providers for readiness, testing, and attestation.

How should compliance software and SOCaaS fit into the provider plan?

Compliance software can collect and organize evidence, assign owners, and flag missing records. It cannot issue a SOC 2 opinion, make management decisions, or make an incomplete population complete. A managed SOC can operate monitoring and incident response; neither service replaces the CPA firm’s examination.

Use the software as an evidence system, not as the conclusion. Before signing with a platform or platform-led provider, ask:

  • Which source systems and populations does the integration cover?
  • What records are excluded, sampled, transformed, or overwritten?
  • Can the company export raw evidence with timestamps and source references?
  • Who validates that the export is complete and accurate?
  • Can the selected CPA firm use the records without treating the platform’s status label as proof?
  • Does the platform provider refer, resell, or financially benefit from the auditor relationship?

The current AICPA FAQ calls these products “SOC 2 tools” and notes that they may be hosted in the service organization’s system or delivered as SaaS. That is useful context for a 2026 buyer: the tool can improve efficiency, but the organization and auditor still own their respective responsibilities.

How do Type 1, Type 2, and scope affect provider choice?

Type 1 evaluates whether controls are suitably designed at a specified date. Type 2 evaluates that design and whether controls operated effectively throughout a specified period. Security is required for SOC 2; the other Trust Services Criteria enter when customer commitments, information flows, or risk justify them.

Scope decisionWhat to ask the provider
Type 1 or Type 2Does the requester accept a design-at-a-date report, or does it need operating-effectiveness evidence over a period?
Type 2 coverage periodWhat period will the report cover, when does it start, and how much fieldwork and report issuance time follows it?
Trust Services CriteriaIs Security sufficient, or do customer commitments require Availability, Processing Integrity, Confidentiality, or Privacy?
System boundaryWhich product, environments, locations, people, data flows, subservice organizations, and customer responsibilities are included?
Report usersWho may receive the report, and does the proposed report format meet the customer’s procurement process?

The AICPA’s SOC 2 reporting guide frames the engagement around control design and, for Type 2, operating effectiveness. It does not create a universal three-, six-, or twelve-month observation-period rule. Agree the period with the auditor and the report user.

Do not accept a fixed Type 2 promise before the provider confirms the system boundary, criteria, evidence maturity, and report period. A short observation period may not satisfy the customer; a longer period may be unnecessary for the request.

How much does a SOC 2 provider cost?

Ask for a scope-based proposal rather than treating one market range as a universal price. Total spend can include readiness, CPA examination, software, security testing or operations, internal staff time, and renewal work. Type 2 also adds calendar time and operating evidence requirements.

Cost lineWhat changes the quoteWhat to request in writing
CPA examinationType, selected criteria, system boundary, locations, subservice organizations, evidence quality, and report usersIncluded fieldwork, evidence rounds, exception handling, report issuance, and change-order rates
ReadinessGap-only review versus policy work, control design, project management, or hands-on remediation supportDeliverables, named personnel, hours or milestones, and what remains with your team
Security operations or testingMonitoring coverage, response hours, vCISO scope, penetration-test targets, and retest termsFrequency, service-level commitments, evidence format, and ownership of the control
Compliance softwareUsers, assets, integrations, implementation, support, and annual renewal termsSource coverage, export format, exclusions, data retention, and auditor handoff
Internal effortNumber of control owners, engineering changes, evidence cadence, policy approvals, and executive reviewA realistic owner-by-owner work estimate; do not hide this cost from the project plan
Renewal and scope changesAnnual report cadence, new products, new locations, new criteria, and bridge-letter needsRenewal fee, included scope, and the pricing rule for additions or acquisitions

For a more detailed pricing framework, use the SOC 2 audit cost guide. When comparing providers, send every firm the same system description, criteria, report type, target period, customer wording, and known subservice list. A lower quote is not comparable if it excludes the observation period, readiness, penetration testing, or report revisions.

How should industry and company stage change the choice?

The best provider matches the service promise, system boundary, customer requirement, and internal capability. Industry labels help narrow the search, but they do not decide the Trust Services Criteria or prove that a firm understands your controls.

SituationProvider profile to considerQuestion to ask
First SOC 2 for a small cloud-native SaaSA specialist CPA firm, plus readiness support if no one owns the control program internallyWhich AWS, Azure, or Google Cloud services and product environments has the assigned team examined?
FinTech or payment workflowAn auditor familiar with transaction processing, data integrity, and availability commitmentsDo customers also need SOC 1 because the service affects their internal control over financial reporting?
HealthTech or a product handling ePHIA CPA firm and advisors that understand the relationship between SOC 2, HIPAA, and the actual data flowsWhich requirements are covered by the SOC 2 engagement, and which HIPAA obligations need separate analysis or documentation?
MSP, MSSP, or IT service providerAn auditor familiar with RMM, PSA, backup, privileged access, shared environments, and customer-owned controlsHow will the report distinguish your own controls from controls you operate for customers? See the SOC 2 auditor directory for MSPs.
Enterprise or multi-framework programA firm with enough partner and specialist capacity for the required frameworks and locationsWhich work is performed by the named engagement team, and which parts are subcontracted or handled by another entity?

Do not assume a Big Four firm is necessary because an enterprise customer asks for “a reputable auditor.” Ask whether the customer has a named-firm requirement. If not, compare firms on legal eligibility, relevant experience, scope discipline, evidence quality, communication, and the report the customer will actually accept.

What questions should you ask on the provider call?

Use one written brief for every candidate. The goal is to make each provider answer the same questions about scope, deliverables, people, evidence, independence, and fees.

  1. Report requirement: “Will the requester accept Type 1, or does it require Type 2? Which Trust Services Criteria and coverage period must the report address?”
  2. Legal issuer: “Which licensed CPA entity will issue the report, and where can we verify the firm’s current license and peer-review record?”
  3. System boundary: “Which products, environments, locations, subservice organizations, and customer responsibilities are included?”
  4. Assigned team: “Who is the engagement partner, who performs fieldwork, and who handles evidence questions day to day?”
  5. Testing method: “How will you test access, change management, incident response, vendor management, and any criteria specific to our service?”
  6. Evidence quality: “How do you validate population completeness and accuracy when evidence comes from a GRC platform or an API export?”
  7. Exceptions: “What happens when a control fails or an exception is found during the period? What is included in the proposal?”
  8. Readiness boundary: “Which work is advisory, which decisions remain with management, and which activities will the CPA firm evaluate?”
  9. Fees and timing: “What is included, what triggers a change order, which milestones are in the calendar, and when is the report expected to be issued?”
  10. References: “Can you provide a reference from a company with a similar product, system boundary, and customer requirement?”

Ask for written answers. A sales call can show communication fit; it cannot replace a scope, independence, or fee document.

What red flags should make you pause?

Pause and investigate when a provider promises a guaranteed clean report, calls SOC 2 a certification without qualification, will not name the CPA entity, treats a dashboard status as audit proof, or quotes a Type 2 deadline before confirming the period and scope.

Other warning signs include:

  • a proposal that omits the report type, criteria, or system boundary;
  • a firm that refuses to explain tool-provider, referral, or subcontractor relationships;
  • a “fixed fee” that excludes evidence rounds, report revisions, or scope changes;
  • a readiness provider that makes control decisions for management and then proposes to evaluate them; or
  • a provider that cannot show what the customer will receive at the end of the engagement.

These problems do not prove that a provider is incapable, but they make the engagement hard to compare and harder to defend to a customer.

What should you do after selecting a provider?

After selection, put the customer requirement, system boundary, criteria, report type, covered date or period, roles, evidence owners, fee inclusions, and change-control rules in the engagement documents. The first milestone is a shared scope record that both management and the CPA firm can use.

  1. Freeze the requirement. Save the customer’s wording and identify the report users, deadline, type, criteria, and acceptable period.
  2. Describe the system. List products, environments, data flows, locations, subservice organizations, and complementary user entity controls.
  3. Assign control owners. Name the person responsible for each control and the evidence source that proves operation.
  4. Set the evidence cadence. Decide when access reviews, change approvals, incident records, vendor reviews, and other recurring evidence are produced and reviewed.
  5. Record exceptions. Document failed tests, remediation dates, management responses, and the effect on the report before the final fieldwork deadline.
  6. Plan the next cycle. Confirm renewal timing, changes to the system boundary, new customer commitments, and which evidence can be reused.

The SOC 2 auditor directory and SOC 2 readiness firms directory are useful starting points for building a shortlist. Use the same brief for every provider so the final comparison reflects scope and deliverables rather than sales language.

Which sources support this guide?

This guide uses current AICPA material for SOC provider roles, the Trust Services Criteria, SOC 2 reporting, software-tool use, and peer-review verification. Provider pricing and timelines change with scope, so no single market range is presented as universal.

Need to compare candidates? Start with the SOC 2 auditor directory and keep the same scope brief in front of every call.