Compliance audit questions, answered straight
100 plain-English answers about SOC 2 and compliance audits — pricing, process, reports, and choosing an auditor. Every answer is dated, sourced, and kept current.
Pricing & Fees
Can I negotiate a SOC 2 audit price?
Yes. SOC 2 audit fees are quotes, not fixed prices, so scope, timing, and multi-year commitments are all negotiable. The biggest lever is narrowing scope; bundling readiness or future audits and comparing firms also moves the number.
Do SOC 2 auditors charge for a readiness assessment?
Usually yes — a readiness assessment is a separate, billed engagement, priced below the audit itself. Some firms bundle or credit it toward the audit; others quote it standalone. Independence rules limit how much remediation the same auditor can do.
Do SOC 2 audits have hidden fees?
Sometimes. The audit fee itself is usually fixed, but total SOC 2 cost can include readiness assessments, GRC tooling, penetration testing, remediation, extra Trust Services Criteria, and bridge letters — get an itemized quote to avoid surprises.
Do auditors discount multi-year SOC 2 contracts?
Often yes. Because SOC 2 is an annual attestation, many firms offer a discount or locked rate for a two- or three-year commitment in exchange for recurring revenue. There is no standard discount; terms are negotiated firm by firm.
Does company size change the price of a SOC 2 audit?
Yes, but scope drives price more than headcount. Bigger companies usually have more systems, locations, and controls to test, which raises fees. A small startup with tight scope can pay far less than a large firm with sprawling infrastructure.
Does using a GRC platform lower my SOC 2 audit fee?
Sometimes, modestly. A GRC platform like Vanta, Drata, or Secureframe mainly cuts your prep time and internal effort, not the auditor's base fee. Fees drop most when your auditor has a confirmed integration and pulls evidence directly.
How do auditors price additional Trust Services Criteria?
Auditors price extra Trust Services Criteria by the added testing hours involved. Security is always included; adding Availability, Confidentiality, Processing Integrity, or Privacy means more controls to test, so the fee rises with scope, not a flat per-criterion charge.
Is SOC 2 cheaper the second year?
Usually no. The audit fee itself rarely drops in year two — most auditors charge a similar or slightly higher rate. Your total spend often falls because readiness, first-time remediation, and tooling setup are one-time costs.
Is a SOC 2 audit worth it for a small startup?
Usually yes, if enterprise prospects are asking for it. A SOC 2 Type 2 unblocks security reviews and larger deals. If no customer requires it yet, a readiness assessment or Type 1 first can be enough.
What happens if I cancel a SOC 2 audit mid-engagement?
You typically owe for work already performed and lose any prepaid deposit, per your engagement letter — there is no standard cancellation fee. Terms vary by firm, so the contract, not an industry rule, decides what you pay.
What is included in a SOC 2 audit fee?
The audit fee covers the CPA firm's work: planning the engagement, testing your controls against the Trust Services Criteria, and issuing the signed attestation report under SSAE No. 18. Readiness, tooling, and remediation are usually separate costs.
Who pays for a SOC 2 audit — the vendor or the customer?
The vendor pays. The company being audited hires and pays the CPA firm to produce its SOC 2 report, then shares it with customers under NDA. Buyers do not pay for their vendors' audits.
Why are Big 4 SOC 2 audits more expensive?
Big 4 firms charge premium rates for brand recognition, higher overhead, senior staffing, and rigorous internal review — not because their SOC 2 report is a different document. Smaller licensed CPA firms issue the same attestation under SSAE No. 18.
Why do SOC 2 audit quotes vary so much between firms?
Quotes vary because scope drives cost: the number of Trust Services Criteria, systems, and locations in scope, Type 1 versus Type 2, your prep readiness, and each CPA firm's rate card all differ. Same logo, very different engagements.
Process & Timeline
Can I speed up a SOC 2 audit?
Yes, partly. You can compress readiness and fieldwork with a GRC platform, a Type 1 or 3-month Type 2 first, and fast evidence responses — but a Type 2 observation window still has to run its full length.
Can a SOC 2 Type 2 observation period be 3 months?
Yes. Three months is the shortest observation window most auditors will accept for a SOC 2 Type 2, so a 3-month period is valid and common for a first report. Longer windows give buyers more assurance.
Do SOC 2 audits happen on-site or remotely?
Almost always remotely. Most SOC 2 audits are conducted entirely over video calls, screen shares, and secure evidence uploads, since the evidence is digital. On-site visits are rare and usually only relevant if you run your own physical data centers.
How long does a SOC 2 audit take?
A SOC 2 Type 1 usually takes one to three months end to end, while a Type 2 adds an observation window of three to twelve months. Readiness prep, not the audit itself, is often the longest phase.
How long does the SOC 2 report take after fieldwork ends?
Most SOC 2 reports are drafted and delivered within a few weeks of fieldwork ending, though timing varies by firm and how quickly you clear any open evidence items. There is no AICPA-set deadline for delivery.
How many internal hours does a SOC 2 audit take my team?
There is no official figure. Most internal effort is front-loaded during readiness, not the audit itself. Expect a designated owner to spend meaningful part-time hours over the prep window, plus lighter time answering auditor questions during fieldwork.
How often do I need a SOC 2 audit?
Once a year in practice. No AICPA rule sets a frequency, but buyers treat a SOC 2 report as current for twelve months from its period end, so most companies renew annually with a rolling Type 2 to avoid gaps.
What happens after I sign a SOC 2 engagement letter?
After signing, the auditor kicks off the engagement: scoping confirmation, a kickoff call, and an evidence request list. For a Type 1 they move toward testing at a point in time; for a Type 2 the observation window then begins.
What happens during SOC 2 fieldwork?
During SOC 2 fieldwork, your CPA auditor examines the evidence for your controls — sampling access reviews, tickets, logs, and configurations — interviews your team, and tests whether each control operated as described before drafting the report.
What happens if my SOC 2 audit finds exceptions?
The audit still finishes and you still get a report. Exceptions — instances where a control did not operate as described — are documented in the report with your management response; they do not automatically make the report a fail.
What is a SOC 2 kickoff call?
A SOC 2 kickoff call is the first meeting with your auditor, where you confirm scope, trust criteria, the report type and observation window, timeline, evidence expectations, and how you'll share information — setting the plan before fieldwork begins.
What is a SOC 2 observation period?
A SOC 2 observation period is the span of time — usually three to twelve months for a Type 2 report — over which your auditor tests whether your controls operated effectively. A Type 1 report has no observation period.
What is evidence sampling in a SOC 2 audit?
Sampling is how a SOC 2 auditor tests a control without checking every instance. For a Type 2, they inspect a representative subset of occurrences across the observation window — like several access reviews — as evidence it operated consistently.
When should a startup start its first SOC 2 audit?
Start when a customer or investor asks — or just before, once you expect enterprise deals. Begin readiness first, then a Type 1 to prove design quickly; Type 2 follows over a three-to-twelve-month observation window.
Reports & Opinions
Are SOC 2 reports public?
No. A SOC 2 report is confidential and shared only under NDA with customers, prospects, and auditors. If you want a freely shareable version, the public summary is a SOC 3 report.
Can I share my SOC 2 report with prospects?
Yes, but almost always under an NDA. SOC 2 reports are confidential, so companies share them with prospects and customers after a signed non-disclosure agreement. For a freely shareable version, use a SOC 3.
Can buyers verify my SOC 2 report is real?
Yes. Buyers verify a SOC 2 by confirming the signing CPA firm is licensed, checking the report period and opinion, and often contacting the firm directly. A real report names a licensed firm and follows AICPA formatting.
Can one SOC 2 report cover multiple products?
Yes. One SOC 2 report can cover multiple products or systems as long as they share the same control environment and you define that scope clearly in the system description. Many companies audit their whole platform in a single report.
How long is a SOC 2 report valid?
There is no formal expiry — the AICPA sets none. In practice, buyers treat a SOC 2 report as current for about twelve months from its period end date, then expect a fresh Type 2.
What are complementary user entity controls (CUECs)?
Complementary user entity controls, or CUECs, are controls the service organization assumes its customers will operate for the overall controls to work. They are listed in the SOC 2 report, and the auditor does not test them.
What is a SOC 2 bridge letter?
A SOC 2 bridge letter is a short statement from your management confirming that nothing material changed between your report's period end and a customer's review date. It is written by you, not your auditor.
What is a SOC 2 exception?
A SOC 2 exception is an instance where a control did not operate as described during the audit — a test that failed. Exceptions appear in Type 2 reports and do not automatically mean you failed the audit.
What is a SOC 3 report and do I need one?
A SOC 3 is the public, general-use summary of a SOC 2 Type 2 audit. You likely do not need one unless you want a shareable trust document; most B2B buyers still ask for the full SOC 2.
What is a carve-out vs inclusive SOC 2 report?
Carve-out and inclusive describe how a SOC 2 handles your subservice providers. A carve-out excludes their controls and just names them; an inclusive report folds their controls into your audit and tests them. Carve-out is far more common.
What is a qualified opinion in a SOC 2 report?
A qualified opinion means the auditor found one or more controls that were not suitably designed or did not operate effectively. The report is still valid, but it flags specific problems rather than giving a clean pass.
What is in a SOC 2 report?
A SOC 2 report has five standard parts: the auditor's opinion, management's assertion, a system description, the trust services criteria with controls, and — in a Type 2 — the auditor's tests and results.
What is the management assertion in a SOC 2 report?
The management assertion is the company's written statement, signed by its own leadership, claiming the system description is accurate and controls were suitably designed (and, for Type 2, operating effectively) throughout the report period.
Who can issue a SOC 2 report?
Only a licensed CPA firm can issue a SOC 2 report. SOC 2 is an AICPA attestation performed under SSAE No. 18, so GRC platforms, consultants, and internal teams can help you prepare but cannot sign the opinion.
Choosing an Auditor
Are cheap SOC 2 audits legit?
Sometimes. A low price is legitimate only if a licensed CPA firm issues the report under SSAE No. 18. Suspiciously cheap 'audits' that skip fieldwork, use non-CPA reviewers, or auto-generate reports are not real SOC 2 attestations.
Can my SOC 2 auditor also do my penetration test?
Usually no. Under AICPA independence rules, the CPA firm that audits your controls cannot design or operate them, and a penetration test it then relies on can compromise that independence. Use a separate provider for the pentest.
Can my SOC 2 auditor help me remediate issues they find?
Not directly. Under AICPA independence rules your attestation firm cannot design or operate the controls it audits, so it cannot fix your gaps. It can flag deficiencies, but remediation must come from you or a separate advisor.
Do I need a local SOC 2 auditor?
No. SOC 2 audits run remotely, so your auditor's location rarely matters. What matters is that a licensed CPA firm signs the report under SSAE No. 18. Time-zone overlap and industry experience help more than being in your city.
Does my SOC 2 auditor need to be a CPA firm?
Yes. A SOC 2 report is an AICPA attestation issued under SSAE No. 18, so it must be signed by a licensed CPA firm. Readiness prep can come from anyone, but only a CPA firm can issue the report.
Does the auditor's brand name matter to enterprise buyers?
Less than founders expect. Most enterprise buyers accept any SOC 2 report signed by a licensed CPA firm; they check the scope, opinion, and exceptions, not the auditor's logo. A recognizable name can smooth procurement but seldom decides it.
How do I choose a SOC 2 auditor?
Choose a licensed CPA firm (SOC 2 is a CPA attestation), check its current AICPA peer review, confirm experience with your industry and stack, and compare fixed quotes. AuditNex network audits start at $2,500 and average about $5,000.
How do I verify a SOC 2 auditor's credentials?
Confirm the firm holds an active CPA license in a US state and that a licensed CPA will sign the report under SSAE No. 18. Then check its peer-review status, SOC 2 experience, and client references before you engage.
Should I use a Big 4 firm for SOC 2?
Usually not necessary. Any licensed CPA firm can issue a SOC 2 report, and Big 4 fees sit at the top of the market. Choose a Big 4 firm only if a large customer specifically requires that brand.
What is AICPA peer review and does my auditor need it?
AICPA peer review is an independent quality check of a CPA firm's audit and attestation work, done roughly every three years. Firms issuing SOC 2 attestations under SSAE No. 18 are subject to it, so yes, your auditor needs it.
What questions should I ask a SOC 2 auditor before hiring?
Ask whether it is a licensed CPA firm, when it last passed AICPA peer review, its experience with your stack, whether it integrates with your GRC platform, the fixed price and scope, the timeline, and re-test costs.
What red flags should I watch for in SOC 2 audit proposals?
Watch for anything that undercuts a real attestation: no licensed CPA firm named, a guaranteed clean opinion, no scoping conversation, prices far below the market band, unclear who signs, and pressure to skip a readiness assessment or fieldwork.
Switching Auditors
Can I switch SOC 2 auditors mid-cycle?
Yes. No AICPA rule locks you to one auditor. It is cleanest to switch between report periods, but you can change mid-cycle if your current engagement has not started fieldwork or has stalled.
Can I use a different auditor for Type 1 and Type 2?
Yes. Type 1 and Type 2 are separate engagements, so you can use different CPA firms for each. Many companies do, though keeping one firm can streamline the Type 2 since it already knows your controls.
Do I lose my SOC 2 history if I change auditors?
No. You keep every SOC 2 report you have already received, and your control and evidence history stays yours. A new auditor builds on that record; changing firms does not erase your prior reports.
Does a new auditor accept my old SOC 2 evidence?
Often yes, but they must re-test it themselves. A new auditor can review evidence and prior reports you provide, yet independence rules mean they form their own conclusions rather than relying on the previous firm's work.
How do I switch SOC 2 auditors?
Wait until your current report is issued, gather your scope and prior reports, request quotes from new firms, sign an engagement letter, and hand over your system description and evidence. No AICPA approval or transfer process is required.
How much can I save by switching SOC 2 auditors?
Potentially thousands, depending on scope. US SOC 2 audits range from $5,000 to $60,000-plus, while audits booked through the AuditNex network start at $2,500 and average about $5,000, so overpaying firms leave real room to save.
When is the best time to switch SOC 2 auditors?
Right after your current report is issued and before your next observation period begins. That timing avoids splitting a Type 2 window, keeps coverage continuous, and gives the new firm a clean period to plan.
Will switching SOC 2 auditors raise questions with customers?
Usually no. Customers care that a licensed CPA firm issued your report and that it covers a continuous period, not which firm signed it. Keep periods continuous and provide a bridge letter for any gap.
Getting Ready
Can a two-person startup get SOC 2?
Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.
Do I need a penetration test for SOC 2?
Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.
Does SOC 2 cover remote work and BYOD?
Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.
Does SOC 2 require MFA?
Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.
Does SOC 2 require a vendor management program?
Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.
Does SOC 2 require annual security training?
Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.
Does SOC 2 require background checks?
Not by name. SOC 2's Trust Services Criteria expect you to hire and retain trustworthy personnel but never mandate background checks specifically; auditors treat pre-employment screening as the standard way to evidence that control, so most companies run them.
Does SOC 2 require encryption at rest?
Not by a specific rule, but in practice yes. SOC 2's Security criteria expect you to protect stored data, and encryption at rest is the standard control auditors look for. Documenting a justified alternative is possible but uncommon.
How do I prepare for my first SOC 2 audit?
Start by choosing your report type and scope, defining the Trust Services Criteria you will cover, writing core security policies, enabling controls like MFA and logging, then collecting evidence through a GRC platform before your auditor begins fieldwork.
How do I respond to a security questionnaire without a SOC 2?
Answer honestly, describe the controls you already have, and share supporting documents like a security policy or pentest summary. State that a SOC 2 is planned or in progress with a target date if true.
What evidence do SOC 2 auditors ask for?
SOC 2 auditors ask for evidence that your controls actually operated: access and MFA settings, onboarding and offboarding records, access reviews, change-management tickets, vulnerability scans, backup and incident logs, vendor reviews, and signed policies covering the period.
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment is a pre-audit gap analysis that maps your current controls against the AICPA's Trust Services Criteria, flags missing evidence or policies, and gives you a remediation plan before the real attestation begins.
What is continuous monitoring in SOC 2?
Continuous monitoring means automatically and regularly checking that your security controls are operating — not just at audit time. It matters most for SOC 2 Type 2, which tests controls across an observation window rather than a single date.
What policies do I need for SOC 2?
SOC 2 has no fixed policy checklist, but auditors expect a core set: information security, access control, change management, risk assessment, incident response, business continuity, vendor management, data classification, acceptable use, and HR security policies.
Which Trust Services Criteria should I include in my SOC 2?
Security, also called the Common Criteria, is mandatory in every SOC 2. The other four — Availability, Confidentiality, Processing Integrity, and Privacy — are optional. Add only those your customers contractually require.
GRC Platforms
Can I pass SOC 2 with spreadsheets instead of a GRC platform?
Yes. A GRC platform is not required to pass a SOC 2 audit; the AICPA standards mandate no specific tool. Spreadsheets and manual evidence work, but they add prep and audit hours as your control count grows.
Can I switch GRC platforms mid-SOC 2 audit?
Yes, but time it carefully. You can move between GRC platforms during a SOC 2 engagement because the audit is a CPA attestation, not tied to any tool. Switching mid-observation risks evidence gaps, so plan it with your auditor.
Can any auditor work with Vanta?
Usually yes. Any licensed CPA firm can audit a company that uses Vanta, but only auditors with a confirmed Vanta integration pull evidence directly from the platform. Others still work from exported reports, which adds some manual effort.
Do I need a GRC platform for SOC 2?
No, a GRC platform is not required for SOC 2. The audit is a CPA attestation under AICPA rules, not a software purchase. Platforms like Vanta or Drata speed evidence collection but are optional, especially for small scopes.
Do auditors charge less if I use Drata?
Usually not directly. Drata doesn't lower the auditor's fee itself, but by automating evidence collection it cuts the auditor's fieldwork hours, and some auditors pass part of that time savings along in their quote.
Does Drata include the SOC 2 audit?
No. Drata is a compliance automation platform, not a CPA firm, so it does not perform or issue the SOC 2 audit. You engage a licensed auditor separately, and that attestation fee is not part of your Drata plan.
Does Secureframe work with any auditor?
Mostly yes, but not automatically. Secureframe partners with a network of auditors and works best when your CPA firm has a confirmed integration that pulls evidence directly. Any independent auditor can accept Secureframe evidence, though non-integrated firms review it manually.
Does Vanta include the SOC 2 audit?
No. Vanta is compliance software that automates evidence and readiness; it does not perform or issue the SOC 2 audit. A separate licensed CPA firm conducts the attestation, and that audit fee is billed separately from your Vanta subscription.
What does audit ready mean in Vanta or Drata?
Audit ready is a platform's internal status meaning your controls are mapped and evidence collected, not an official pass. It signals Vanta or Drata thinks you are prepared; only a CPA firm tests controls and issues the SOC 2 report.
Who picks the auditor when I use a GRC platform?
You do. A GRC platform like Vanta, Drata, or Secureframe suggests firms from its partner network, but you choose and contract the auditor directly. The platform never assigns one, and you can bring an outside CPA firm instead.
Frameworks & Standards
Can one audit firm do SOC 2 and ISO 27001 together?
Often yes, if the firm holds both a CPA license for SOC 2 and ISO 27001 accreditation, or partners with an accredited certification body. Many providers now run a combined audit that shares evidence and fieldwork to save time.
Do I need both SOC 2 and ISO 27001?
Usually not at first. Most US startups start with SOC 2 to close deals; ISO 27001 matters more for international or enterprise buyers. Many companies eventually hold both because auditors can reuse overlapping evidence.
Do government buyers accept SOC 2?
Sometimes. State and local agencies and government contractors often accept a SOC 2 Type 2, but most federal cloud work requires FedRAMP, and defense contracts increasingly require CMMC. SOC 2 helps, yet rarely replaces those government-specific programs.
Does PCI DSS overlap with SOC 2?
Yes, they share many technical controls — access management, encryption, logging, and vulnerability management — but they don't substitute for each other. PCI DSS is a prescriptive, mandatory standard for handling cardholder data; SOC 2 is a flexible CPA attestation.
Does SOC 2 cover AI and LLM features?
Yes, indirectly. SOC 2 has no AI-specific criteria, but its technology-neutral Trust Services Criteria cover any system in your defined scope — including AI and LLM features — for security, availability, confidentiality, processing integrity, and privacy.
Does SOC 2 help with GDPR?
Partly. SOC 2 is not a GDPR certification, but a report with the confidentiality and privacy criteria demonstrates many security safeguards the GDPR expects. You still need GDPR-specific steps like lawful basis, data subject rights, and processing agreements.
Does SOC 2 satisfy HIPAA?
No. SOC 2 is a voluntary AICPA attestation; HIPAA is US federal law for protected health information. A SOC 2 report can show strong security controls, but it does not prove HIPAA compliance or replace a HIPAA risk assessment.
Is SOC 2 enough to sell to banks?
Usually not on its own. Banks and their vendor-risk teams typically accept a SOC 2 Type 2 as a strong baseline, but large financial institutions often layer on their own questionnaires, contract clauses, and sometimes extra frameworks.
Is SOC 2 required by law?
No. No US law requires SOC 2; it is a voluntary AICPA attestation. Customers, not regulators, drive it: enterprise buyers routinely demand a SOC 2 Type 2 in security reviews before they will sign a contract.
Is there a SOC 2 equivalent in Europe?
Not a single one-to-one match. Europe's closest widely used equivalent is ISO 27001 certification. Auditors also use the ISAE 3000/3402 attestation standards, and country schemes like Germany's BSI C5 serve a similar "trust the cloud provider" purpose.
What is CSA STAR and how does it relate to SOC 2?
CSA STAR is the Cloud Security Alliance's cloud-specific assurance program, built on its Cloud Controls Matrix. It complements SOC 2 rather than replacing it; STAR Level 2 can accompany a SOC 2 exam from the same CPA firm.
What is HITRUST and do I need it instead of SOC 2?
HITRUST is a certifiable healthcare-focused security framework built around the HITRUST CSF, not an AICPA product. Most companies need it in addition to, not instead of, SOC 2 — and only when a healthcare customer specifically requires it.
What is a SOC 1 report and do I need one?
A SOC 1 is an AICPA attestation on controls that affect your customers' financial reporting. You need one only if your service touches clients' financials, like payroll or billing. Most SaaS companies need SOC 2 instead.
Skip the research — get matched
Tell us your scope once and compare transparent quotes from vetted audit firms.
Get instant pricing →