The independence firewall
Some firms and software platforms pay for clearly labeled placement on this site. Those commercial relationships do not determine which companies we cover, what we say about them, or which options fit a buyer.
Paid placement must be visible, limited to companies that already meet the page's editorial criteria, and separate from our factual findings and recommendations.
- Sponsorship buys
- Clearly labeled placement on a page where the company already qualifies to appear.
- Sponsorship does not buy
- Inclusion, a higher rating, an earned badge, softer criticism, removal of a weakness, a favorable verdict, or priority over a better-fit firm.
If a paid placement appears to affect an editorial conclusion, email us. We will review it and correct the page.
What we cover
174+ SOC 2 audit firms and 26 compliance automation platforms. Nothing else.
Adjacent frameworks (ISO 27001, HIPAA, PCI DSS, and seven more) show up only where they intersect with a SOC 2 decision. Reference explainers live in our frameworks hub; recurring buyer questions live in the SOC 2 buyer guides. General-purpose GRC tools that are not built for SOC 2 buyers are not here.
The scope stays narrow because broad directories are useless to anyone with a real decision to make. If a tool or firm does not affect SOC 2 scope, cost, readiness, evidence collection, or auditor selection, it does not belong in the core review set.
How we evaluate auditors
The license first. We check active CPA and AICPA standing and, for US firms, the AICPA peer-review record. Directory and profile pages show the exact public result β Pass, Pass with Deficiencies, Fail, result not public, or review not shown β rather than collapsing anything short of Pass into Enrolled. A missing public result is not a Fail: AICPA publishes ratings only for specified members or firms that opt in. Where we cannot confirm a record, the firm stays listed with a caveat badge and ranks below firms that clear the bar. We flag what we cannot verify, we do not hide it.
The ranked best SOC 2 auditors shortlist has a narrower admission rule. A US firm qualifies only when its latest accepted AICPA peer-review rating is Pass, verified in the public file or from the peer-review report and acceptance letter supplied to our research team. Enrollment without a verified rating does not qualify. Neither Pass with Deficiencies nor Fail clears the shortlist; a firm can return after a newer accepted review records a Pass.
Then pricing: a mix of figures firms confirm to us, public sources, and our own estimates, refreshed periodically. We prefer what clients actually pay (direct submissions, shared RFPs, and post-engagement reports) over published rates, and surface ranges rather than point estimates. Where a number is our estimate rather than firm-confirmed, the entry says so.
Then timelines: our estimate of kickoff-to-report duration, drawn from each firm's published engagement descriptions and refined from client interviews where we have them. Vendor marketing estimates do not count.
Then fit. Industries served, company sizes, tech stacks, and co-sourcing partners. A firm that is right for a 200-person fintech is often wrong for a 12-person AI startup. We say which is which.
We also separate what a firm can sign from what it can support. CPA licensing and peer review determine whether a firm can issue a report; the assigned team's cloud, SaaS, security, and platform experience determines whether the engagement will be smooth for a specific buyer.
How we evaluate software
Three rules govern software reviews.
We source every claim. Every platform in our directory carries an evidence state, a source URL, and a retrieval date for each renderable fact. Claims are checked against vendor docs, marketplace listings, and independent write-ups.
We cross-check pricing. We check published pricing against buyer-reported quotes where we have them and surface a range rather than a single number. Marketing-site figures are placeholders until real quotes back them.
We find what is broken. Every review has a section on what does not work. If we cannot write one, we have not looked hard enough, and the review is not ready to publish.
How we rate
We do not.
We do not use 5-star scores or 4.3-out-of-5 averages. Star ratings compress too much. A platform that is excellent for your situation remains excellent even if its average score is middling, and a mediocre fit stays mediocre even at 4.8.
Every platform on the software hub is matched to the scenarios it actually fits. Every auditor in the directory has a fit profile: industries, company sizes, strengths, and known gaps. The recommendation is always "this one, for this buyer, for this reason."
Source-class tiers: how much each kind of evidence counts
Four classes of evidence are ranked by weight. Where two sources disagree, the higher tier wins. Cost ranges with their per-entry sources live at /soc-2-audit-cost/sources/.
- Tier 1: regulatory and licensing text
- AICPA peer-review records, board-of-accountancy CPA-license rosters, FedRAMP marketplace listings, CREST registry entries, and AICPA Trust Services Criteria. Treated as fact and cited directly with a permalink to the public registry where possible.
- Tier 2: vendor-published primary documents
- A firm's own service descriptions, a platform's own pricing page, or an audit report shared with us by a buyer under NDA. Heaviest weight after Tier 1. Sourced and dated on the entry.
- Tier 3: live briefs and quotes
- Anonymized buyer briefs, RFPs, and quotes from firms or software vendors. We use these to understand real scope, pricing, and buyer concerns. We publish ranges rather than individual submissions and cross-check them against Tier 1 and Tier 2 sources.
- Tier 4: signal data
- LinkedIn hiring patterns for enterprise traction reads, G2 and Trustpilot clusters for consistency, and public earnings commentary. Never used on its own, only as a cross-reference to Tier 1, Tier 2, or Tier 3 evidence.
Every price carries a source marker (our estimate versus firm-confirmed), and auditor profiles carry a last-verified date, so you can see how old a number is and where it came from.
What "last verified" means on an auditor profile
Every verified auditor profile carries a Last verified date. That stamp asserts three things on that date: the firm is still operating under the listed name, the AICPA peer-review record we link to is current, and the public-website pricing or scope signals still match what the firm publishes.
It does not assert that the firm's quoted pricing is current to the dollar. Audit fees move with scope, headcount, and timeline. The verified date is for structural facts, not the quote a firm would write today.
We aim to re-check every profile quarterly and sooner when reliable new information indicates that a material fact may have changed.
A firm can request an off-cycle re-check by emailing hello@soc2auditors.org. Buyers can flag a stale stamp the same way.
Verification cadence triggers
We aim to re-check every profile quarterly. Four events pull a profile out of that cadence and into an off-schedule re-check.
- Peer-review status change. The directory's source of truth for a CPA firm's standing is the AICPA peer-review database. A change there triggers a profile review.
- Leadership departure. Named partners and methodology leads are part of a firm's fit profile. A departure surfaced by a reader, a vendor announcement, or a public filing triggers a re-check.
- Pricing change documented in writing. A recent quote, buyer-side RFP, or published pricing update can trigger a review of the firm's range.
- Material business event. An acquisition, merger, regional expansion, or reported security incident can change the facts a buyer needs to know.
When we update
We update when something real changes: a pricing shift, a new framework supported, a leadership departure, a security incident, or a feature added or removed. We do not update to hit a publishing calendar.
If nothing meaningful changed in six months, the page keeps its date. Every article carries the date it was last touched and what changed.
How we make money
Audit firms, service firms, and software platforms can pay for advertising or sponsored placement. We do not take a commission, referral fee, or share of a buyer's contract. Buyers do not pay to use the directory or request quotes.
Payment can affect the position or presentation of an eligible company only where the placement is clearly labeled. It cannot determine inclusion, change a review or comparison, create an earned badge, suppress a correction, or give a company priority over a better fit.
Corrections
Wrong price, stale license status, factual error, disputed quote? Email hello@soc2auditors.org. Screenshots help for pricing disputes; a recent quote beats our aggregated range every time.
We review factual corrections against the strongest available source. Material corrections receive a dated note on the affected page so readers can see what changed and when.
Disagreements on judgment calls, including which platform fits which scenario or how we read a weakness, are fair game to argue, and sometimes we revise. Email the argument.
Peter Korpak, founder.
Questions about a specific review, a partnership, or a pricing submission: hello@soc2auditors.org.