Back to guides
    Guide

    How to Choose a SOC 2 Auditor: An Independent Guide

    By Andreas Van NimmenPublished Jul 21, 2026Last verified Jul 21, 2026

    Short answer: a SOC 2 report can only be produced by a licensed CPA firm, so start there, then choose one with real experience in your sector and at your size, the capacity to meet your timeline, and genuine independence from your business. Decide early whether you need a Type 1 or a Type 2, and which Trust Services Criteria are in scope, because those two choices drive most of your cost and timeline. This guide walks through each, and shows you how to compare firms and get comparable quotes without emailing five of them.

    SOC 2 usually lands on your desk because a US customer or prospect sent a security questionnaire and asked for your SOC 2 report before they will buy or renew. Unlike some frameworks, SOC 2 is not a certificate you display on your website. It is an attestation report, written and signed by a CPA firm, that you share under NDA with the customers who ask for it. Who writes that report, and how independent they are, affects how much weight it carries. This guide stays neutral throughout. Nomona does not perform audits and takes no position on which firm you choose.

    What is a SOC 2 auditor?

    A SOC 2 report is an AICPA attestation, and by rule it can only be produced and signed by a licensed CPA firm. That is the first hard requirement, and it is what makes SOC 2 different from a framework like ISO 27001: there is no certificate, and there is no accreditation body handing one out. The CPA firm examines your controls against the AICPA's Trust Services Criteria and issues a report that contains a formal opinion on them. It works under the AICPA's attestation standards, SSAE 18 and specifically AT-C 205, which is the engagement type that produces a SOC 2. A consultant or a compliance platform can help you prepare and collect evidence, but only a CPA firm can sign the report, and it has to stay independent of the work it is attesting.

    One point of confusion worth clearing up early: SOC 2 is not the same as SOC 1 or SOC 3. SOC 1 covers controls relevant to a customer's financial reporting. SOC 3 is a short, public-facing summary you can post on your website. SOC 2 is the detailed security report your customers actually ask for, and the one this guide is about.

    Type 1 or Type 2? Decide this first

    SOC 2 comes in two forms, and the choice shapes everything after it.

    A Type 1 report assesses whether your controls are suitably designed at a single point in time. It is faster and cheaper, and it is often used as a first step, or when a customer needs to see something quickly.

    A Type 2 report assesses whether those controls actually operated effectively over a period of time, commonly 3 to 12 months. It is the report most enterprise customers really want, because it shows your controls work in practice, not just on paper.

    Many companies start with a Type 1 to unblock a deal, then move to a Type 2 covering the following period. If you already know a large customer will require Type 2, it is often better to plan straight for it and skip the detour.

    Which Trust Services Criteria do you need?

    SOC 2 is built on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security, known as the common criteria, is always included. The other four are optional, and you add them based on what you actually promise customers. Each criterion you add means more controls, more evidence, and more cost, so scope them to what your customers need rather than adding all five by default. A good auditor helps you set a scope that is honest and defensible.

    What to look for in a CPA firm

    Once you are talking to licensed CPA firms, fit is what separates them.

    CPA licensure and peer review. Confirm the firm is a licensed CPA firm in good standing and takes part in AICPA peer review. This is the SOC 2 equivalent of verifying accreditation, and it is the first box to tick.

    Sector and size experience. A firm that regularly audits B2B SaaS companies of your size will already understand your cloud architecture and the controls that matter for you. Ask how many reports like yours they issued in the last year.

    Capacity and timeline. Firms get booked out, and a Type 2 carries an observation window, so start early if a customer deadline is riding on the report.

    Communication and the report itself. Your customer ultimately reads the auditor's report, so its clarity and credibility matter. Ask how the firm handles exceptions, and what a finished report from them actually looks like.

    How much does a SOC 2 audit cost?

    Budget is usually the next question, so here are planning ranges to anchor it. The audit fee for a SOC 2 Type 2 commonly ranges from around $12,000 to $40,000 for small and mid-sized companies, with a Type 1 lower and large or complex scopes higher. These figures are the auditor's fee only; readiness work, a compliance platform, and your team's time are on top. And because SOC 2 is an annual report, you should budget for it every year, not once. Treat these as planning ranges, not a quote. For a number specific to your company, request comparable quotes from qualified firms rather than relying on a published range.

    The fee is driven mainly by scope: Type 1 versus Type 2, how many Trust Services Criteria you include, and your company's size and complexity. Keeping scope tight and comparing more than one firm are the two things that most move your budget.

    Timeline and the observation window

    A Type 1 can often be completed in a few weeks once you are ready. A Type 2 takes longer, because it needs an observation window during which your controls operate and evidence accrues, commonly 3 to 12 months, with a 3-month window common for a first report. So the honest timeline for a first Type 2 is your readiness period, plus the observation window, plus the audit fieldwork. Plan backward from any customer deadline, and consider a Type 1 first if the deadline is tight.

    One SOC 2 detail that catches teams out is the gap between the period your report covers and the day a customer asks to see it. When your report ends in, say, March and a prospect wants assurance in July, you can ask your CPA firm for a bridge letter, sometimes called a gap letter, stating that nothing material changed in between. It is not a substitute for the next annual report, but it keeps a deal moving while you sit inside your yearly cycle.

    The independence question most buyers skip

    Because SOC 2 is an AICPA attestation, the CPA firm that signs it must be independent of your business and of anyone with a stake in the outcome. The AICPA's rules are explicit. A firm generally cannot accept a commission or referral fee tied to a client it also audits (AICPA ET §1.520), and it must identify and manage self-interest and undue-influence threats to its objectivity (AICPA ET §1.210.010). In April 2026 the AICPA's own publication, the Journal of Accountancy, flagged exactly these risks in arrangements between SOC tool providers and the auditors their customers end up using.

    Keep this in mind when a compliance platform or consultant hands you a shortlist of auditors. A recommended firm can be an excellent choice. The point is only to check that the recommendation reflects fit, rather than a commercial arrangement you cannot see. You are allowed to ask.

    Three questions to keep your choice independent:

    • Does whoever recommended this auditor receive any compensation tied to the recommendation?
    • Who sets the audit fee and scope, the CPA firm using its own professional judgement, or a third party?
    • Am I free to choose a firm that is not on the recommended list?

    SOC 2 and ISO 27001 together

    Many companies end up needing both: SOC 2 for US customers, and ISO 27001 for European and enterprise buyers. The two overlap heavily. A large share of the underlying controls satisfy both frameworks, so one evidence set can support both, and many firms offer them together, sometimes as a combined engagement that reuses the same evidence to cut cost and effort.

    One structural detail is worth knowing. A SOC 2 report must be signed by a licensed CPA firm, while an ISO 27001 certificate must be issued by an accredited certification body. A provider that offers both usually operates both capabilities, sometimes through sister entities under one brand. If you expect to need both, ask a firm up front whether they can do both and how they combine the work, because running them together is usually cheaper and faster than two separate projects. If ISO 27001 is your more immediate need, our companion guide on choosing an ISO 27001 auditor covers that side in the same way.

    How to compare firms and get quotes

    Once you have decided Type 1 or Type 2, scoped your criteria, and confirmed CPA licensure and independence, comparison is what is left. Most companies want more than one quote before committing, and for the same scope, prices vary more than people expect. Getting there usually means hunting down qualified CPA firms, working out which ones actually fit, and emailing each separately.

    Nomona is built to take that last part off your plate. It is an independent marketplace and trust registry for security and compliance auditors. You can compare qualified firms on fit and verified reviews, then send one structured request to receive comparable quotes rather than chasing several inboxes. Nomona does not perform audits and does not take a cut for steering you toward any particular firm; results are ordered by fit.

    To start, browse SOC 2 firms in the registry, or post a single request and let matched firms come back to you with quotes.

    Frequently asked questions

    Who can perform a SOC 2 audit?
    Only a licensed CPA firm can produce and sign a SOC 2 report, because SOC 2 is an AICPA attestation. Consultants and compliance platforms can help you prepare, but they cannot issue the report.
    Is SOC 2 a certificate?
    No. SOC 2 produces an attestation report with a formal auditor opinion, not a certificate. You typically share the report with customers under an NDA rather than displaying it publicly.
    What is the difference between SOC 2 Type 1 and Type 2?
    A Type 1 assesses whether your controls are designed appropriately at a single point in time. A Type 2 assesses whether they operated effectively over a period, commonly 3 to 12 months. Most enterprise customers want a Type 2.
    How much does a SOC 2 audit cost?
    The auditor's fee for a Type 2 commonly ranges from around $12,000 to $40,000 for small and mid-sized companies, with Type 1 lower and larger scopes higher. It recurs annually, and readiness and tooling are extra. Comparing more than one quote is the most reliable way to understand your real cost.
    How long is a SOC 2 report valid?
    A Type 2 report covers a defined period, usually up to 12 months. Customers generally expect a fresh report each year, so SOC 2 is best treated as an annual cycle rather than a one-time exercise.
    Which Trust Services Criteria do I need?
    Security is mandatory. Availability, Processing Integrity, Confidentiality, and Privacy are optional and should be added only where you make related commitments to customers, since each one adds scope and cost.
    What is the difference between SOC 2 and ISO 27001?
    SOC 2 is a US-centric AICPA attestation, produced as a report with an opinion and signed by a CPA firm, and renewed on an annual cycle. ISO 27001 is an international standard, certified against your information security management system and issued as a three-year certificate by an accredited certification body. Their underlying controls overlap heavily, so many companies pursue both and reuse one evidence set.
    Can one firm do both SOC 2 and ISO 27001?
    Yes, many firms offer both, and the controls overlap enough that a combined engagement can reuse one evidence set. Note the structural difference: SOC 2 must be signed by a CPA firm and ISO 27001 issued by an accredited certification body, so a combined provider operates both capabilities.
    Do I need a Type 2, or is a Type 1 enough?
    It depends on what your customer requires. A Type 1 can unblock a deal quickly, but most enterprise buyers eventually ask for a Type 2 because it shows your controls work over time. If you know Type 2 is coming, planning straight for it can save a step.

    Ready to choose a SOC 2 auditor?

    Compare qualified CPA firms on fit, or send one structured request and receive comparable quotes.