How the market works
SOC 2 readiness vs the audit
A SOC 2 involves two different engagements, and under AICPA rules they generally cannot be the same firm. Readiness is the work of getting controls in place. The examination is a licensed CPA firm forming an independent opinion about them. Understanding that split explains most of what looks confusing about the vendor landscape, including why the cheapest bundle can cost you a deal.
Two engagements, two roles
| Readiness | The examination | |
|---|---|---|
| Who does it | A security engineer or consultancy. No license required | A licensed CPA firm. Legally required, no substitutes |
| The job | Find gaps, fix them, document, organize evidence | Test controls independently and issue an opinion |
| Deliverable | Working controls, policies, an evidence repository | The report your customer reads |
| Can they touch your AWS? | Yes, that is the point | No. Doing so would destroy independence |
| Can they tell you how to fix something? | Yes | Only in general terms. Designing your control makes it theirs |
| Typical cost | From $10,000 fixed with us; $10,000 to $75,000 in the wider market | Typically $5,000 to $10,000 through our partner firms |
| Paid to | The readiness provider | The CPA firm, directly. Never through us |
What independence actually means
A CPA cannot audit their own work. If a firm designs your access review process, writes your incident response plan, or configures your logging, they cannot then form an objective opinion on whether those controls are suitably designed. This is not a technicality invented to sell more engagements. It is the reason the report has value: your customer trusts it precisely because the person who says the controls work has no stake in them working.
In practice this creates a clean division of labor:
- The readiness provider builds. They can be as hands-on as you want, up to and including deploying infrastructure and writing every policy, because they are not going to grade it.
- The auditor examines. They will answer questions about what the criteria require. They will not tell you how to build your control, and if they do it too specifically, they have compromised themselves.
Because we never audit, we can do things an audit firm cannot: deploy CloudFormation into your account, write your policies, argue with your auditor on your behalf, and put a commitment in the contract about the outcome. That last one is only possible because we have no influence over the opinion. If we did, the commitment would be meaningless.
The all-in-one question
Some firms sell readiness and the examination together. It is simpler to buy, often cheaper on paper, and it works reasonably well for companies whose customers do not scrutinize the report.
The structural problem is that the same organization is both preparing the answer and grading it. Firms manage this with internal separation between advisory and attest teams, and the good ones manage it seriously. But two things follow anyway:
- Your buyer may ask. Enterprise security reviewers increasingly check who performed readiness and who performed the examination. Discovering the answer matters during a deal is worse than choosing differently at the start.
- Readiness stays shallow by necessity. To protect independence, the advisory side usually stops at recommendations. You still need someone to do the engineering, which means the bundle did not actually remove a vendor.
If you are considering one, ask three questions: Which team performs readiness, and which performs the attestation? What specifically will the readiness side implement versus recommend? And how do you document independence if a customer's security team asks?
Choosing an auditor
The engagement letter is between you and the CPA firm. Your readiness provider can introduce firms they have worked with, and that introduction is worth more than it sounds: knowing a firm's request-list format and expectations in advance means evidence gets organized once rather than twice.
What to verify, whoever introduces them:
- Licensed CPA firm with peer review in good standing. Peer review is the mandatory external check on a firm's work quality, and it is a reasonable proxy for legitimacy.
- Experience with companies your size and stack. A firm that mostly examines 500-person fintechs will run a heavier process than a 15-person AWS SaaS company needs.
- Their request list format, before you sign. Ask for a sample. It tells you what fieldwork will feel like.
- Availability. Good small firms book weeks out. Pick before you finish remediating, not after.
- What their fee includes. Type 1 only, or Type 1 and Type 2 together? Are bridge letters extra?
How our commitment works, and its limits
We commit in writing: if your Type 1 opinion comes back qualified on a control we implemented, the engagement continues at no charge until it is clean. That is possible because every in-scope criterion is mapped to an implemented control with evidence before fieldwork starts, so we know what the auditor will find before they look.
The commitment carries a condition we state plainly rather than burying: it applies when the examination is performed by a firm in our partner network. We calibrate to a firm's specific expectations and request list, and we cannot underwrite an outcome from an examiner whose expectations we have never mapped. If you choose your own auditor, that is entirely reasonable and we will work with them; the quote then includes an auditor-alignment line to decode their format and remap evidence, and the clean-opinion commitment does not apply.
Frequently asked questions
Can the same firm do readiness and the audit?
Not for the same controls. AICPA independence rules prevent a CPA firm from examining controls it designed or implemented. Firms that sell both keep the readiness side advisory, which limits how much of the work they can actually take off your plate, and enterprise reviewers increasingly ask how the separation is maintained.
What does a readiness assessment include?
A gap assessment against the criteria, remediation, policy and process documentation, an evidence repository organized for the auditor, and a mock audit. The variable is how much is implemented versus recommended. Establish that before comparing prices, because two quotes with the same number can describe completely different amounts of work.
Do we need a readiness provider at all?
No. Plenty of companies do readiness in-house, particularly with a security-experienced engineer and no hard deadline. What you cannot skip is the examination, because only a licensed CPA firm can issue the report. The honest question is whether three to six months of your engineers' time is cheaper than the alternative, and whether the deal waiting on the report can afford it.
Who talks to the auditor during fieldwork?
Formally, you do. The engagement is between you and the CPA firm and it is your management assertion. In practice we handle the request list, prepare your team for walkthroughs, and take the technical questions so they do not land on your engineers mid-sprint.
One provider for the work, an independent firm for the opinion
We build, remediate, and organize the evidence, then hand you to a vetted CPA firm and support you through fieldwork. Two firms, one plan, no conflict of interest for your customer to find.
Book a 30-minute scoping callWe never perform the examination, and the audit fee is paid to the CPA firm directly.