Can your SOC 2 auditor also help you get ready?
- Yes. One firm can help you get ready and then issue your opinion. It is standard practice and the AICPA writes rules for it.
- Four safeguards have to be agreed in writing before any readiness work starts, and they all sit in ET 1.295.040.
- The prohibitions are specific and they are absolute. Most founders guess the line in the wrong place.
- ET 1.295 is the rule for nonattest services. ET 1.297, effective June 2026, confirms the Independence Rule applies to SOC 2.
- You can check your own auditor in about two minutes. The engagement letter is where the answer is.
When I tell a founder that the firm helping them get ready is also the firm that will sign their report, the follow-up question comes fast. Almost nobody asks it out of curiosity. It comes from someone who read about a firm that got caught and wants to know whether they are about to sign up for the same thing.
So here is the short answer. One firm can help you get ready and then examine you. It is standard practice across the profession, from big four practices down to specialist shops, and the AICPA contemplates it explicitly and writes rules for how it works.
The part worth understanding is where the line sits, because it tends to sit somewhere people do not expect.
Two sections of the AICPA code do the work
ET 1.295 is the substance. It governs nonattest services, and a readiness assessment is a nonattest service. It is advisory work. There is no requirement that a CPA perform it at all.
ET 1.297 is the umbrella. It applies the Independence Rule to engagements performed under the attestation standards, which is what a SOC 2 examination is. It took effect June 15, 2026. The revisions were terminology and worked examples, and the committee that wrote them said they do not change the intended application of current requirements in the code. The one real addition is a defined term, "period covered by the attest report," which replaces language that assumed a financial statement audit.
Put together: 1.297 says the Independence Rule applies to your SOC 2, and 1.295 says what a firm can do alongside it.
Self-review means two opposite things
Worth separating these, because the phrase flips meaning depending on who says it.
Self-review as an independence threat is the subject of this article. A firm ends up auditing its own prior work. It is one of six threat categories the AICPA names.
Documented self-review as a control is a different thing entirely. When a company is too small to split a duty between two people, a scheduled review the founder runs on their own work is a legitimate compensating control. That one is good. It is how a one-person company satisfies a criterion written for a company of fifty.
Same words. Unrelated ideas.
Four safeguards have to be in writing first
All four have to be in place, in writing, before the readiness work starts. Plain English first, citation second.
- You keep every management decision. The firm can tell you a gap exists and describe how other companies close it. You choose what to do.
- You name someone to oversee the work. A real person at your company with enough skill and experience to judge whether the firm's guidance is any good. At a two person startup that is the founder, and that works. The problem case is nobody.
- You evaluate what the firm produced. If you cannot say why you accepted a recommendation, the safeguard did not really happen.
- You accept responsibility for the results. The controls are yours. The system is yours. The firm attests to what you built.
All four sit in ET 1.295.040. If your engagement letter does not have them in some recognizable form, that is the finding. Ask for it before you sign.
The prohibitions are specific and they are absolute
Here is where the actual limits live.
A firm may not design your specific controls, implement them, decide which ones you adopt, set your policy or strategic direction, take on project management, authorize or execute transactions for you, or monitor your controls on an ongoing basis. Those are management responsibilities under ET 1.295.030.
Two more are absolute, meaning no safeguard cures them. A firm may not design or develop an information system related to the subject matter of the attestation, and it may not configure a tool that is itself part of what gets audited. That is ET 1.295.145.
That second one is the interesting one. It is why a firm that configures your compliance tooling and then audits its output is standing somewhere different from a firm that runs a readiness assessment.
Designing a control and describing the evidence are different acts
These get confused constantly, and the difference is the whole ballgame.
Designing a control means deciding what your control is. How often the review happens, who approves it, what the threshold is, which tool it runs in. Those are your decisions.
Describing the evidence is telling you what a criterion will need to see. For an access review that means an approver, a date, the list that was reviewed, and a record of who came off it. A firm can tell you that all day. It is describing the finish line.
You can hit that finish line a dozen different ways. Picking the way has to stay yours, because a firm that picks it is examining its own choice later.
The line is easiest to hear side by side
Permitted. "To meet CC6.1, organizations typically use one of these approaches: A, B, or C. Here are examples of each."
Not permitted. "Here is your control for CC6.1. Implement this."
Same knowledge. Same criterion. The first leaves the decision with you. The second makes it for you, and then the firm is testing a control it picked.
Everything else follows from that. A firm can tell you what is missing. It can tell you what good looks like. It can answer your questions while you fix things. It cannot pick, build, or run the thing it is going to examine.
You can check your own auditor in about two minutes
- Read the engagement letter for the four safeguards. They should be in writing, before any readiness work starts.
- Ask who decides. "When you find a gap, do you tell me what to implement, or do you give me options?"
- Ask whether they configure anything you own. Especially anything that produces the evidence they will later test.
- Ask who they are registered with, and go check it. A firm's registration is public record with its state board, and enrollment in the AICPA Peer Review Program is separately verifiable at peerreview.aicpa.org.
- Ask to see the methodology. A firm that cannot show you how it decides what passes is asking you to take the conclusion on faith.
You do not have to know the rules to do any of that. You have to ask, and then go look.
Frequently asked questions
Can the same CPA firm do my SOC 2 readiness and my SOC 2 audit?
What is the self-review threat in a SOC 2 audit?
What is ET 1.297?
Does a SOC 2 readiness assessment have to be done by a CPA?
What should be in my engagement letter about independence?
Can my auditor configure my compliance tool for me?
Keep reading
Do you need an evidence collection tool?
Nothing in the standards requires one. Evidence is records your systems already produce, and the auditor should be the one collecting them.
How many controls does SOC 2 require?
None, as a number. The rulebook holds 61 criteria and no control list at all. What actually decides how many you end up writing.
How much evidence does a SOC 2 audit need?
About twenty sources, and one export often answers several criteria at once. What auditors ask for, and what does not count.
How many samples does an auditor actually test?
No standard sets a number. How often the control runs does. The table firms work from, and why which items get picked matters more.
Sources
- ET 1.295.040 sets the general requirements a member must meet before performing nonattest services for an attest client, including that the client agrees to assume all management responsibilities, oversee the service, evaluate its adequacy and results, and accept responsibility for the results.
- ET 1.295.030 lists the management responsibilities a member may not assume for an attest client, and ET 1.295.145 addresses information systems design, implementation, or integration.
- A SOC 2 is an examination engagement performed under AT-C section 205 of the AICPA attestation standards.
- Enrollment in the AICPA Peer Review Program is verifiable through the program's public file.