Skip to content
    July 28, 2026| Top Floor Team| 10 min read

    What to Ask a SOC 2 Auditor Before You Sign

    Before you sign a SOC 2 engagement letter, get five things in writing: the firm's most recent AICPA peer review result, the names and hours of the people who will actually perform your fieldwork, any referral arrangement the firm has with your compliance platform, the specific events that trigger a change order, and the number of SOC 2 reports the firm issued in the last twelve months. If a firm hesitates on any of these, keep shopping. Every one of them is a routine, answerable question, and the firms worth hiring answer them without flinching.

    Here's why you're reading this here instead of on an audit firm's blog. Almost every "questions to ask your SOC 2 auditor" guide on the internet was written by an audit firm, which means the questions are curated to make that firm look good. Top Floor does readiness work, not the attestation itself. We can't issue your report, we don't want to, and we make the same money whichever CPA firm you pick. That puts us in a rare position: we sit next to clients through auditor selection several times a year, we see the quotes, we see the fieldwork, and we have no reason to soften what we've learned.

    Key takeaways

    • Get five things in writing before you sign: the most recent AICPA peer review result, the names and hours of the people who will actually perform fieldwork, any referral arrangement with your compliance platform, the specific events that trigger a change order, and the number of SOC 2 reports the firm issued in the last twelve months.
    • A clean peer review means nothing if the review population never included SOC examinations. Ask which practice it covered.
    • The person on the sales call is almost never the person reading your access reviews in month four. Ask for names, certifications, and the share of hours going to staff with under two years of experience.
    • An auditor who insists your controls match a platform's template control set is optimizing for their own testing efficiency. SOC 2 does not prescribe a control set.
    • Retesting after remediation is the change-order tripwire that catches people. Confirm in writing whether it sits inside the fixed fee.

    Ask for the peer review, and actually read it

    Every CPA firm that performs attestation engagements is required to undergo an independent peer review roughly every three years under the AICPA peer review program. Another firm examines their audit files and issues a rating: pass, pass with deficiencies, or fail. This is public-adjacent information (firms enrolled in the program can share their acceptance letter, and many states require it for licensure), yet almost no buyer ever asks for it.

    Ask anyway. Specifically:

    • "Please provide your most recent peer review report and acceptance letter."
    • "Did the review cover your SOC examination practice, or only your financial statement audit practice?"

    That second question matters more than people realize. A firm can have a clean peer review that never sampled a single SOC engagement. If SOC work wasn't in the review population, the rating tells you nothing about the product you're buying. A firm that received "pass with deficiencies" and can explain exactly what the deficiency was and what changed afterward is often a safer bet than a firm that gets cagey about the whole subject.

    Ask who does the work, not who does the pitch

    The person who charms you on the sales call is almost never the person who will read your access reviews in month four. This is normal in professional services, but the gap varies wildly. We've watched engagements where the partner on the proposal never appeared again and fieldwork was run entirely by a first-year associate working from a checklist, and we've watched engagements where a director with ten years of SOC experience personally walked every control.

    Get concrete:

    • Who is the engagement partner who signs the opinion, and how many SOC 2 reports did they sign last year?
    • Who performs day-to-day fieldwork? Names, titles, and certifications (CPA, CISA, or both).
    • What share of fieldwork hours sits with staff who have less than two years of experience?
    • Is any testing performed offshore or by a subcontracted firm? If so, who reviews it, and where does your evidence physically go?

    Offshore delivery isn't automatically bad; it's how many firms keep fees reasonable. But you deserve to know before you sign, not when a request list arrives from a team you've never heard of in a time zone eleven hours away. And if your customers include defense contractors or anyone with data residency commitments, offshore evidence handling can be a genuine contractual problem, not just an aesthetic one.

    Ask about the platform referral, out loud

    If you found your auditor through your compliance automation platform's "auditor marketplace," understand the economics: many of those placements involve referral arrangements, co-marketing agreements, or volume relationships between the platform and the firm. The auditor listed at the top is not necessarily the best fit for you. Sometimes they're the best fit for the platform.

    We're not accusing anyone of misconduct. Referral arrangements are legal and common. But they create a soft conflict you should surface before signing:

    • "Do you have a referral, reseller, or marketing arrangement with our compliance platform? What are its terms?"
    • "If we switched platforms mid-engagement, would anything about our fee or your approach change?"
    • "Will you test controls as we've implemented them, or do you expect us to conform to the platform's default control set?"

    That last one is the practical danger. A platform-aligned auditor who insists your controls match the platform's templates is optimizing for their own testing efficiency, not your security program. SOC 2 doesn't prescribe a control set; the Trust Services Criteria let you define controls that fit how your company actually operates. An auditor who can't work outside the template is telling you something about their bench depth. We wrote about designing controls around your actual environment in our SOC 2 for startups guide, and the principle holds at every company size.

    Ask what triggers a change order

    Fixed-fee SOC 2 quotes are only as fixed as their assumptions. Every engagement letter has a scope paragraph, and buried in it are the tripwires: number of in-scope systems, number of trust services categories, headcount bands, single entity versus subsidiaries, one production environment versus several. Cross a tripwire and the fee reopens.

    Nobody hides this maliciously; auditors get burned by scope creep too. But you should make the tripwires explicit before signing rather than discover them in month five:

    • "What specific facts, if they change, reopen the fee? List them."
    • "We expect to add [a second product / an acquisition / Availability as a category] during the period. What does that cost?"
    • "If a control fails testing and we remediate, is retesting included or billed separately?"
    • "What's your hourly rate for out-of-scope work, and who approves it on your side before it's incurred?"

    The retest question is the one that catches people. A control exception, a remediation sprint, and a retest request is a completely ordinary sequence in a first-year Type II. If retesting is billed at $350 an hour and nobody mentioned it, your fixed fee wasn't fixed. In the engagements we've supported through audit facilitation, the difference between a calm audit and a resentful one usually traces back to whether this conversation happened before signatures.

    Ask for volume and same-industry references

    Two numbers tell you most of what you need to know about a firm's SOC practice: reports issued in the last twelve months, and reports issued to companies that look like yours.

    A firm that issued four SOC 2 reports last year is doing this as a side line to its tax practice. That can still work if the four were done well, but you're not getting a practiced machine; expect slower turnaround and more improvisation. A firm that issued three hundred is a factory, which cuts both ways: efficient process, thin partner attention. There's no single right answer, but you should know which product you're buying.

    Then ask for two references from your industry or architecture. Not logos on a website. Actual humans you can call. Ask those references three things: did the fieldwork team understand your stack without extensive education, how long from period-end to issued report, and would you rehire them. Report delivery time is a chronically underrated question. A report that lands ninety days after period-end has cost you a quarter of its sales value, because the enterprise deal that asked for it has already moved.

    The copy-pasteable RFP block

    Drop this into your auditor RFP or first call agenda as-is:

    1. Provide your most recent AICPA peer review report and acceptance letter. Did the review population include SOC examinations?

    2. Name the engagement partner and fieldwork lead for our engagement. How many SOC 2 examinations did each complete in the last 12 months?

    3. What percentage of fieldwork hours will be performed by staff with under two years of attestation experience? Is any work performed offshore or subcontracted?

    4. Do you have any referral, marketing, or commercial arrangement with our compliance platform or any platform you may recommend? Describe it.

    5. Will you test our controls as designed, or do you require conformance to a platform or firm template control set?

    6. List every assumption in your fee. Which specific changes trigger a change order, and at what rates?

    7. Is retesting of remediated exceptions included in the fixed fee?

    8. How many SOC 2 reports did your firm issue in the last 12 months? How many were Type II?

    9. Provide two references from companies in our industry or with similar architecture, with contact details.

    10. What is your median time from period-end to issued report?

    Any established firm can answer all ten in one email. The answers matter, but the willingness to answer matters almost as much.

    Where our advice runs out

    Some honesty about our own position. Because we do readiness and not attestation, there are things we can't judge for you: whether a firm's audit methodology satisfies its own quality management obligations is exactly the sort of thing the peer review process exists to check, and no consultant's opinion substitutes for it. And if you're a late-stage company selling into Fortune 100 procurement, there are cases where a Big Four or top-20 firm name genuinely reduces friction, and you should pay for the brand even though the underlying testing may be no more rigorous. We'd rather tell you that than pretend the boutique firm is always the smart buy.

    What we can tell you is that auditor selection goes better when your controls are already in order, because a well-prepared client gets the firm's B-team behaving like its A-team. That preparation, plus running the evidence process so your engineers aren't doing it, is the job we do take, either as project readiness work or as ongoing compliance operations. If you're still deciding between frameworks before you ever pick an auditor, start with our ISO 27001 versus SOC 2 comparison instead.

    Frequently asked questions

    Does the auditor's brand name matter to my customers?

    For most B2B sales below the enterprise tier, no. Security reviewers read the report contents: the opinion, the scope, the exceptions, the period covered. They rarely weight the letterhead. The exceptions are Fortune 100 procurement teams, some financial services buyers, and federal-adjacent deals, where a recognizable firm name can shorten review cycles. If your pipeline is mid-market SaaS, paying a 2x fee premium for brand is usually wasted money; if you're selling to global banks, it may be the cheapest deal accelerator you can buy.

    What does a good SOC 2 auditor cost?

    As of August 2026, in the engagements we've supported as a readiness firm (our own observation, not a survey), competent boutique and regional CPA firms typically quote first-year Type II examinations in the $20,000 to $50,000 range for a single-product SaaS company covering Security, with fees rising with additional trust services categories, multiple environments, and headcount. National and Big Four firms commonly land at two to four times that. Be suspicious below roughly $10,000 for a Type II: at that price the economics only work with minimal testing, and a thin report can fail you in a customer's security review, which is the only place it ever mattered.

    Can my readiness consultant also be my auditor?

    No, and walk away from anyone who offers. Independence rules prohibit a CPA firm from auditing controls it designed or implemented. Some large firms maintain separated advisory and attestation practices with independence safeguards, which is permissible with distance, but a small shop offering to "get you ready and then certify you" end-to-end is describing an independence violation. The clean structure is the one this article assumes: one party helps you prepare, a different, independent CPA firm examines and issues the report.

    When should I start talking to auditors?

    Earlier than feels natural: three to six months before your audit period ends, and ideally before it begins. Good firms book fieldwork one to two quarters out, and you want your observation window agreed before you're operating controls inside it. Starting early also lets you run a genuine competitive process with the ten RFP questions above instead of signing with whoever can start soonest.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.