Skip to content
INDEPENDENT THINKING. INFORMED DECISIONS.A clearer view of SOC 2 ↗
THE BUSINESS OF TRUST,
CONSIDERED.
The Controls Report.Your first SOC 2?
Find your starting point ↗
Start here

THE CONTROLS REPORT / EXPLAINED

Choose an auditor with the right questions, not a ranking.

Look past the logo. Understand the issuing firm, engagement team, proposed scope, and what the fee includes.

THE USEFUL PART

Identify the licensed issuing firm and compare written proposals against one agreed brief. Size, brand, and platform partnerships alone do not settle fit.

Identify who will issue the report

An auditor’s brand, a consulting business, and a software platform can be different legal entities. Ask which licensed CPA firm signs the engagement and issues the opinion. Verify that entity’s license evidence through the relevant authority.

Our editorial approach separates these facts from marketing relationships. A logo in a platform’s partner directory tells you about a relationship; it does not replace a license check or explain your specific engagement.

Source context: AICPA staff — Effects of software tools on SOC 2 examinations

Discuss your actual system

Our recommendation is to describe your service before asking for a fee. Explain your cloud environment, dependencies, team, customer commitments, and intended report users. Ask how the firm would scope the work and what it needs to learn before it can commit.

  • Who will lead and perform the engagement?
  • What experience does the team have with systems like ours?
  • How will the proposed report address our intended users’ needs?
  • How do evidence requests, questions, and escalations work?

Source context: Linford — Defining SOC 2 audit scope

Get the inclusions and dates in writing

Our suggested proposal checklist includes the report type, selected criteria, system boundaries, covered dates, fieldwork approach, report review, and expected delivery. Separate any readiness or advisory services from the examination itself.

Ask what happens if scope changes or evidence is late. A proposal should let you understand your obligations as well as the provider’s deliverables. Compare exclusions alongside the headline fee.

Source context: Schellman — What does a SOC audit cost?; Schellman — How long does a SOC examination take?

Make a decision you can explain

Our selection framework is a documented fit assessment: scope, relevant experience, working process, cost, and customer requirements. Keep questions and unresolved facts visible until you have an answer.

We do not assign numerical audit-quality scores. A sourced description and a candid account of what remains unknown give you a more useful basis for your own decision.

THE EVIDENCE BEHIND THE EXPLANATION

Sources & editorial notes

Reviewed September 22, 2026. This guide draws on public criteria and practitioner explanations. Our suggested questions and planning frameworks are editorial analysis. Provider guidance is identified as such; it is not a universal requirement.

  1. AICPA staff — Effects of software tools on SOC 2 examinations

    2021 public staff FAQs; explicitly nonauthoritative. Explains management and auditor responsibilities.

  2. Linford — Defining SOC 2 audit scope

    CPA-firm explanation of system boundaries and scoping decisions.

  3. Schellman — What does a SOC audit cost?

    Supplier explanation of engagement cost drivers; not a dataset of market-wide prices.

  4. Schellman — How long does a SOC examination take?

    Supplier process guidance. Durations depend on the specific engagement.

We have not reviewed a private SOC 2 report for this guide. General editorial information, not audit, accounting, or legal advice. Our editorial approach.

Suggest a correction