Home/Readiness vs the audit

How the market works

SOC 2 readiness vs the audit

A SOC 2 involves two different engagements, and under AICPA rules they generally cannot be the same firm. Readiness is the work of getting controls in place. The examination is a licensed CPA firm forming an independent opinion about them. Understanding that split explains most of what looks confusing about the vendor landscape, including why the cheapest bundle can cost you a deal.

Updated 17 August 20267 min readVendor selection

Two engagements, two roles

ReadinessThe examination
Who does itA security engineer or consultancy. No license requiredA licensed CPA firm. Legally required, no substitutes
The jobFind gaps, fix them, document, organize evidenceTest controls independently and issue an opinion
DeliverableWorking controls, policies, an evidence repositoryThe report your customer reads
Can they touch your AWS?Yes, that is the pointNo. Doing so would destroy independence
Can they tell you how to fix something?YesOnly in general terms. Designing your control makes it theirs
Typical costFrom $10,000 fixed with us; $10,000 to $75,000 in the wider marketTypically $5,000 to $10,000 through our partner firms
Paid toThe readiness providerThe CPA firm, directly. Never through us

What independence actually means

A CPA cannot audit their own work. If a firm designs your access review process, writes your incident response plan, or configures your logging, they cannot then form an objective opinion on whether those controls are suitably designed. This is not a technicality invented to sell more engagements. It is the reason the report has value: your customer trusts it precisely because the person who says the controls work has no stake in them working.

In practice this creates a clean division of labor:

  • The readiness provider builds. They can be as hands-on as you want, up to and including deploying infrastructure and writing every policy, because they are not going to grade it.
  • The auditor examines. They will answer questions about what the criteria require. They will not tell you how to build your control, and if they do it too specifically, they have compromised themselves.
The practical benefit of the split

Because we never audit, we can do things an audit firm cannot: deploy CloudFormation into your account, write your policies, argue with your auditor on your behalf, and put a commitment in the contract about the outcome. That last one is only possible because we have no influence over the opinion. If we did, the commitment would be meaningless.

The all-in-one question

Some firms sell readiness and the examination together. It is simpler to buy, often cheaper on paper, and it works reasonably well for companies whose customers do not scrutinize the report.

The structural problem is that the same organization is both preparing the answer and grading it. Firms manage this with internal separation between advisory and attest teams, and the good ones manage it seriously. But two things follow anyway:

  • Your buyer may ask. Enterprise security reviewers increasingly check who performed readiness and who performed the examination. Discovering the answer matters during a deal is worse than choosing differently at the start.
  • Readiness stays shallow by necessity. To protect independence, the advisory side usually stops at recommendations. You still need someone to do the engineering, which means the bundle did not actually remove a vendor.

If you are considering one, ask three questions: Which team performs readiness, and which performs the attestation? What specifically will the readiness side implement versus recommend? And how do you document independence if a customer's security team asks?

Choosing an auditor

The engagement letter is between you and the CPA firm. Your readiness provider can introduce firms they have worked with, and that introduction is worth more than it sounds: knowing a firm's request-list format and expectations in advance means evidence gets organized once rather than twice.

What to verify, whoever introduces them:

  • Licensed CPA firm with peer review in good standing. Peer review is the mandatory external check on a firm's work quality, and it is a reasonable proxy for legitimacy.
  • Experience with companies your size and stack. A firm that mostly examines 500-person fintechs will run a heavier process than a 15-person AWS SaaS company needs.
  • Their request list format, before you sign. Ask for a sample. It tells you what fieldwork will feel like.
  • Availability. Good small firms book weeks out. Pick before you finish remediating, not after.
  • What their fee includes. Type 1 only, or Type 1 and Type 2 together? Are bridge letters extra?

How our commitment works, and its limits

We commit in writing: if your Type 1 opinion comes back qualified on a control we implemented, the engagement continues at no charge until it is clean. That is possible because every in-scope criterion is mapped to an implemented control with evidence before fieldwork starts, so we know what the auditor will find before they look.

The commitment carries a condition we state plainly rather than burying: it applies when the examination is performed by a firm in our partner network. We calibrate to a firm's specific expectations and request list, and we cannot underwrite an outcome from an examiner whose expectations we have never mapped. If you choose your own auditor, that is entirely reasonable and we will work with them; the quote then includes an auditor-alignment line to decode their format and remap evidence, and the clean-opinion commitment does not apply.

Frequently asked questions

Can the same firm do readiness and the audit?

Not for the same controls. AICPA independence rules prevent a CPA firm from examining controls it designed or implemented. Firms that sell both keep the readiness side advisory, which limits how much of the work they can actually take off your plate, and enterprise reviewers increasingly ask how the separation is maintained.

What does a readiness assessment include?

A gap assessment against the criteria, remediation, policy and process documentation, an evidence repository organized for the auditor, and a mock audit. The variable is how much is implemented versus recommended. Establish that before comparing prices, because two quotes with the same number can describe completely different amounts of work.

Do we need a readiness provider at all?

No. Plenty of companies do readiness in-house, particularly with a security-experienced engineer and no hard deadline. What you cannot skip is the examination, because only a licensed CPA firm can issue the report. The honest question is whether three to six months of your engineers' time is cheaper than the alternative, and whether the deal waiting on the report can afford it.

Who talks to the auditor during fieldwork?

Formally, you do. The engagement is between you and the CPA firm and it is your management assertion. In practice we handle the request list, prepare your team for walkthroughs, and take the technical questions so they do not land on your engineers mid-sprint.

One provider for the work, an independent firm for the opinion

We build, remediate, and organize the evidence, then hand you to a vetted CPA firm and support you through fieldwork. Two firms, one plan, no conflict of interest for your customer to find.

Book a 30-minute scoping call

We never perform the examination, and the audit fee is paid to the CPA firm directly.