How to Choose a SOC 2 Readiness Partner
There are three things you can verify about a SOC 2 partner before you sign, and none of them is a reference call. The AICPA states the first two itself: where auditors "are found to have not performed audits in accordance with professional standards, not been enrolled in peer review, and/or are unlicensed, the AICPA will take action with respect to its members", and it states on the same page that it assists governmental regulators regarding unlicensed firms and practitioners, including by referring them to state boards of accountancy (AICPA, SOC suite of services). The third comes from the AICPA's own ethics staff, in guidance published April 13, 2026: "AICPA members increasingly enter business arrangements with SOC 2 tool providers and these relationships can raise significant threats to compliance with the Code of Professional Conduct" (Ethics Staff Insights: Business arrangements with SOC tool providers). The contrarian conclusion: the feature most vendors sell hardest, the single-vendor path from readiness through to a signed report, is the feature you should interrogate first.
A bias disclosure on both sides. The AICPA is the accounting profession's own membership body. It writes the SOC standards and its warnings about unlicensed practitioners protect its members' franchise as well as your interests, so read it as an interested primary source rather than a neutral referee. And we sell SOC 2 readiness, which makes an article about choosing a readiness partner self-interested by construction. The separation rule below is the part that disqualifies us from work we could otherwise bill, which is the most useful thing we can offer you here. What follows is what a readiness partner does, the separation rule, the three checks, the triangle nobody discloses, and the case for not hiring one at all.
Key takeaways
- A readiness partner prepares you. A licensed CPA firm performs the examination and issues the opinion. Those cannot be the same firm.
- Verify the CPA firm is licensed and enrolled in peer review before you sign anything, and confirm the examination will be performed under professional standards.
- Ask every party in the deal, consultant, platform and auditor, to disclose commercial relationships with the others in writing.
- The report type question is settled elsewhere and should not be relitigated by a vendor. Use our canonical piece on Type I versus Type II.
- If you have one product, one cloud account and someone technical who will own the calendar, the honest answer may be that you do not need a readiness firm.
What a readiness partner actually does, and what it cannot do
Readiness is the work between "we have decided to do this" and "the examination can start". Concretely: mapping your current controls to the criteria in scope, producing the remediation backlog, writing and arguing over the policies, building the evidence collection so it survives an auditor's sample, and managing the auditor relationship through fieldwork. If you want the shape of that evidence burden before you scope anything, the auditor request list is the concrete version.
What a readiness partner cannot do is produce the outcome. A SOC 2 report is an attestation performed by an independent licensed CPA firm, which reaches its own conclusions and issues its own opinion. No consultant controls that. Any firm that offers a guaranteed clean report is either claiming influence over an independent opinion, which would be a serious problem for the opinion, or making a promise it intends to renegotiate later. We have written the wider version of that pattern in red flags when hiring a security consulting firm, and this article deliberately does not repeat those seven.
One more thing readiness cannot fix: exceptions come overwhelmingly from calendar-driven human tasks like access reviews and offboarding, not from missing tooling. A partner who spends the engagement on documents and none of it on who owns the recurring tickets has left the actual risk in place. How exceptions arise is the longer treatment.
The separation rule, and why it is the first question
Ask this before anything else: who signs the opinion, and are they independent of you and of us?
The reason this is question one rather than question five is that it is the only one where the wrong answer devalues the report you are buying. Independence requirements exist because a firm cannot objectively examine controls that it designed and implemented itself. If the same firm builds your control environment and then attests to it, the resulting report carries a conflict that a sophisticated buyer's security team can identify from the cover page, and the value of the report to your sales process is the entire reason you are spending the money.
The practical arrangement is straightforward and you should insist on it: you engage the CPA firm directly, the engagement letter is between you and them, and the readiness partner coordinates around it. Top Floor performs readiness and advisory work only. We do not conduct examinations, we do not issue opinions, and we cannot influence the conclusion of one, including a conclusion we would rather it did not reach.
A related and slightly harder version of the question: is your readiness partner introducing the auditor? An introduction is normal and often useful. A referral fee changes the picture, and you should know which one you are getting.
The three checks you can run before signing
None of these needs a reference call, and all three are answerable in writing.
One: is the firm that will issue the opinion a licensed CPA firm? The AICPA describes the SOC suite as "a suite of service offerings CPAs may provide in connection with system-level controls of a service organization", and it explicitly assists regulators with referrals to state boards of accountancy regarding unlicensed firms and practitioners. Licensing is verifiable through the relevant state board. If the answer arrives as a brand name rather than a firm name and a license, keep asking.
Two: is the firm enrolled in peer review? The AICPA names peer review enrollment alongside licensing and adherence to professional standards as the markers it will act on when they are missing. This is a yes or no question with a documentary answer, and a firm that treats it as an odd thing to ask has told you something.
Three: will the examination be performed in accordance with professional standards, and what does the engagement letter say about scope? The AICPA's own framing is that "SOC services should be thoroughly evaluated by service organizations and CPA firms". Thorough evaluation means reading the engagement letter for what testing is actually performed, not accepting an assurance that it will be rigorous.
Run these three against the CPA firm even when a platform or a consultancy is the one presenting it to you. The party you are buying from is not necessarily the party whose name goes on the opinion.
The triangle nobody volunteers: consultant, platform, auditor
Compliance automation platforms are genuinely useful and we recommend them in most engagements. That is not in tension with the following.
The AICPA's ethics staff published guidance on April 13, 2026 addressing exactly this structure, opening with the observation that members "increasingly enter business arrangements with SOC 2 tool providers and these relationships can raise significant threats to compliance with the Code of Professional Conduct", and describing the installment as walking through "common arrangements, potential threats to independence and objectivity, and how to apply the conceptual framework when the code doesn't address the issue directly."
Two things follow. This is not a competitor's talking point; it is the profession's own ethics staff writing about arrangements common enough to need guidance. And the concern named is independence and objectivity, which is precisely the property you are paying for.
So make the disclosure explicit and put it in writing. Ask the consultancy whether it receives any compensation from the platform or the audit firm. Ask the platform which audit firms it has commercial arrangements with, and whether bundled audit pricing reflects one. Ask the audit firm whether it has a business arrangement with the platform whose evidence it will be testing. None of these questions accuses anyone of anything. All three answers change how you read the price. The related decision of whether you need a consultant at all alongside a platform is covered in Vanta, Drata, and whether you need a consultant.
There is a separate live example of why buyers should ask. The AICPA has publicly stated that it "is looking into allegations published anonymously about the business practices of a compliance vendor that offers Systems and Organization Control (SOC) services". We are not naming the vendor, and neither does the AICPA. The point is not the specific matter. The point is that the profession's own body considers the business practices around SOC services worth an inquiry, which is a good reason to ask your own questions rather than assume the market has been vetted for you.
What to ask about delivery, without repeating the generic checklist
Two questions specific to SOC 2 readiness that the generic consultant checklists do not cover.
"Which criteria do you recommend we include, and what is your reasoning?" Security is always in scope. Availability, confidentiality, processing integrity and privacy are elective, and each one you add expands evidence, testing and fee. A partner who recommends adding categories without tying each to a named customer requirement is selling scope. A partner who says start with Security alone and add later when a customer actually demands it is giving you the answer that shrinks their own engagement.
"Who owns the compliance calendar after you leave?" Access reviews, offboarding checks, vendor reviews and the evidence they produce are recurring obligations that outlive the project, and year two arrives before year one is amortized. A partner who has no answer beyond "we can stay on" has designed a dependency rather than a program. What year two looks like is the honest picture.
For the broader vetting checklist that applies to any consultancy, staffing, statement of work, change orders and escalation, use twelve questions to ask a compliance consultant rather than expecting this article to restate it. And when you are choosing the auditor rather than the readiness partner, the counterparty and the questions are different: what to ask a SOC 2 auditor before you sign covers that side, and whether the auditor's brand matters covers the question buyers spend the most money getting wrong.
Where this advice cuts against us
A readiness partner is not always the right purchase, and the cases where it is not are easy to describe.
If you have one product, one cloud account, a technical founder or engineer willing to own the compliance calendar, and identity and device hygiene already in decent shape, a compliance platform plus a boutique CPA firm is a legitimate path and you probably do not need a consultancy for year one. The cost profile of that path, and where the money actually goes, is in what SOC 2 actually costs, all in. We would rather you read that first than hire us and discover it afterward.
The inverse is also true and worth stating so the advice is not merely modest. Readiness help earns its fee when scope multiplies across products, clouds or frameworks, when nobody internal can absorb the evidence work without the roadmap bleeding, or when a customer contract has already committed you to a date. Those are the conditions, and if none of them describe you, the honest recommendation is to spend the money on controls instead.
One caveat about this article itself: everything above is verifiable process, not outcome prediction, and we are not going to tell you which firms are good, because ranking a market we compete in is not a service.
Where Top Floor fits
Our SOC 2 work is readiness and advisory: scoping the criteria, closing the gaps, building evidence that survives sampling, and running the process around an examination we do not perform. You engage the CPA firm directly and the engagement letter stays between you and them, which is the separation that makes the report worth having.
Where the program spans several frameworks at once, compliance as a service is the model that keeps one evidence set feeding all of them instead of running parallel projects. And our audit and readiness practice is where the auditor relationship is managed, from evidence requests through to the final report, without ever crossing the line into issuing the opinion.
How to decide this week
Send one email to every firm on your shortlist, with four questions and a request for written answers.
Who will issue the opinion, are they a licensed CPA firm, and are they enrolled in peer review? Do you receive any compensation from the audit firm or the compliance platform involved in this deal? Which trust services categories are you recommending, and which named customer requirement drives each one beyond Security? Who owns the compliance calendar twelve months after your engagement ends?
Then do one thing that costs nothing. Pull the security requirement from your largest open deal and read what it actually asks for. A surprising share of SOC 2 projects are scoped against a requirement nobody has read, and the report type question in particular gets decided by vendors rather than by the buyer's own contract. Settle it with our canonical piece on Type I versus Type II and bring the answer to the shortlist rather than asking them to supply it.
Frequently asked questions
Can the firm that does our readiness work also perform the SOC 2 examination?
No, and you should not want it to. Independence requirements exist because a firm cannot objectively examine controls it designed and implemented itself, and the value of the report to your sales process depends on that separation being intact. The workable arrangement is that you engage a licensed CPA firm directly, the engagement letter stays between you and them, and the readiness partner coordinates around the examination without influencing its conclusion.
How do we verify a SOC 2 audit firm is legitimate?
Ask for the firm name and its license, verify the license with the relevant state board of accountancy, and ask whether the firm is enrolled in peer review. The AICPA names licensing, peer review enrollment and performing engagements in accordance with professional standards as the markers it will act on when they are absent, and it assists regulators with referrals regarding unlicensed firms and practitioners. All three are answerable in writing before you sign.
Should we worry that our consultant, platform and auditor all know each other?
Not automatically, but you should ask for disclosure in writing. AICPA ethics staff guidance published in April 2026 addresses business arrangements between members and SOC 2 tool providers, noting such relationships can raise significant threats to compliance with the Code of Professional Conduct, and covering threats to independence and objectivity. Ask each party what compensation flows between them. The answers change how you read a bundled price, whatever they turn out to be.
Do we need a readiness partner at all?
Often not. A company with one product, one cloud account, decent identity and device hygiene, and someone technical willing to own the recurring compliance calendar can reasonably run year one with a compliance platform and a boutique CPA firm. Readiness help earns its fee when scope multiplies across products or frameworks, when nobody internal can absorb the evidence work, or when a customer contract has already committed you to a date.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.