Can your SOC 2 auditor also help you get ready?

TL;DR
  • Yes. One firm can help you get ready and then issue your opinion. It is standard practice and the AICPA writes rules for it.
  • Four safeguards have to be agreed in writing before any readiness work starts, and they all sit in ET 1.295.040.
  • The prohibitions are specific and they are absolute. Most founders guess the line in the wrong place.
  • ET 1.295 is the rule for nonattest services. ET 1.297, effective June 2026, confirms the Independence Rule applies to SOC 2.
  • You can check your own auditor in about two minutes. The engagement letter is where the answer is.

When I tell a founder that the firm helping them get ready is also the firm that will sign their report, the follow-up question comes fast. Almost nobody asks it out of curiosity. It comes from someone who read about a firm that got caught and wants to know whether they are about to sign up for the same thing.

So here is the short answer. One firm can help you get ready and then examine you. It is standard practice across the profession, from big four practices down to specialist shops, and the AICPA contemplates it explicitly and writes rules for how it works.

The part worth understanding is where the line sits, because it tends to sit somewhere people do not expect.

Two sections of the AICPA code do the work

ET 1.295 is the substance. It governs nonattest services, and a readiness assessment is a nonattest service. It is advisory work. There is no requirement that a CPA perform it at all.

ET 1.297 is the umbrella. It applies the Independence Rule to engagements performed under the attestation standards, which is what a SOC 2 examination is. It took effect June 15, 2026. The revisions were terminology and worked examples, and the committee that wrote them said they do not change the intended application of current requirements in the code. The one real addition is a defined term, "period covered by the attest report," which replaces language that assumed a financial statement audit.

Put together: 1.297 says the Independence Rule applies to your SOC 2, and 1.295 says what a firm can do alongside it.

Self-review means two opposite things

Worth separating these, because the phrase flips meaning depending on who says it.

Self-review as an independence threat is the subject of this article. A firm ends up auditing its own prior work. It is one of six threat categories the AICPA names.

Documented self-review as a control is a different thing entirely. When a company is too small to split a duty between two people, a scheduled review the founder runs on their own work is a legitimate compensating control. That one is good. It is how a one-person company satisfies a criterion written for a company of fifty.

Same words. Unrelated ideas.

Four safeguards have to be in writing first

All four have to be in place, in writing, before the readiness work starts. Plain English first, citation second.

  1. You keep every management decision. The firm can tell you a gap exists and describe how other companies close it. You choose what to do.
  2. You name someone to oversee the work. A real person at your company with enough skill and experience to judge whether the firm's guidance is any good. At a two person startup that is the founder, and that works. The problem case is nobody.
  3. You evaluate what the firm produced. If you cannot say why you accepted a recommendation, the safeguard did not really happen.
  4. You accept responsibility for the results. The controls are yours. The system is yours. The firm attests to what you built.

All four sit in ET 1.295.040. If your engagement letter does not have them in some recognizable form, that is the finding. Ask for it before you sign.

The prohibitions are specific and they are absolute

Here is where the actual limits live.

A firm may not design your specific controls, implement them, decide which ones you adopt, set your policy or strategic direction, take on project management, authorize or execute transactions for you, or monitor your controls on an ongoing basis. Those are management responsibilities under ET 1.295.030.

Two more are absolute, meaning no safeguard cures them. A firm may not design or develop an information system related to the subject matter of the attestation, and it may not configure a tool that is itself part of what gets audited. That is ET 1.295.145.

That second one is the interesting one. It is why a firm that configures your compliance tooling and then audits its output is standing somewhere different from a firm that runs a readiness assessment.

Designing a control and describing the evidence are different acts

These get confused constantly, and the difference is the whole ballgame.

Designing a control means deciding what your control is. How often the review happens, who approves it, what the threshold is, which tool it runs in. Those are your decisions.

Describing the evidence is telling you what a criterion will need to see. For an access review that means an approver, a date, the list that was reviewed, and a record of who came off it. A firm can tell you that all day. It is describing the finish line.

You can hit that finish line a dozen different ways. Picking the way has to stay yours, because a firm that picks it is examining its own choice later.

The line is easiest to hear side by side

Permitted. "To meet CC6.1, organizations typically use one of these approaches: A, B, or C. Here are examples of each."

Not permitted. "Here is your control for CC6.1. Implement this."

Same knowledge. Same criterion. The first leaves the decision with you. The second makes it for you, and then the firm is testing a control it picked.

Everything else follows from that. A firm can tell you what is missing. It can tell you what good looks like. It can answer your questions while you fix things. It cannot pick, build, or run the thing it is going to examine.

You can check your own auditor in about two minutes

  1. Read the engagement letter for the four safeguards. They should be in writing, before any readiness work starts.
  2. Ask who decides. "When you find a gap, do you tell me what to implement, or do you give me options?"
  3. Ask whether they configure anything you own. Especially anything that produces the evidence they will later test.
  4. Ask who they are registered with, and go check it. A firm's registration is public record with its state board, and enrollment in the AICPA Peer Review Program is separately verifiable at peerreview.aicpa.org.
  5. Ask to see the methodology. A firm that cannot show you how it decides what passes is asking you to take the conclusion on faith.

You do not have to know the rules to do any of that. You have to ask, and then go look.

Frequently asked questions

Can the same CPA firm do my SOC 2 readiness and my SOC 2 audit?
Yes. A readiness assessment is a nonattest advisory service, and AICPA rules let the firm that will issue the opinion perform it, as long as four safeguards are agreed in writing first: you keep all management decisions, you designate someone competent to oversee the work, you evaluate the results, and you accept responsibility for them. Those safeguards are in ET 1.295.040.
What is the self-review threat in a SOC 2 audit?
It is the risk that a firm ends up auditing its own prior work. It comes up when the firm designed, selected, or implemented the controls it later examines. Telling you which criteria you were missing does not create it. Deciding for you how to close the gap does.
What is ET 1.297?
It is the section of the AICPA Code of Professional Conduct that applies independence requirements to engagements performed under the attestation standards, which includes SOC 2. It took effect June 15, 2026. The revisions clarified terminology and added examples and left the underlying requirements alone.
Does a SOC 2 readiness assessment have to be done by a CPA?
No. Readiness is advisory work and anyone can perform it, including your own team or a consultant. Only the examination itself has to be performed and signed by a licensed CPA firm.
What should be in my engagement letter about independence?
The four nonattest safeguards in recognizable form, agreed before the readiness work begins: you keep all management decisions, you designate someone with suitable skill and experience to oversee the service, you evaluate the adequacy and results of the service, and you accept responsibility for the results. If they are not there, ask for them before you sign.
Can my auditor configure my compliance tool for me?
Not if the tool is part of what gets audited. Designing or developing an information system related to the subject matter of the attestation, or configuring a tool that produces the evidence the firm will later test, is prohibited under ET 1.295.145 and no safeguard cures it.

Keep reading

Sources
  1. ET 1.295.040 sets the general requirements a member must meet before performing nonattest services for an attest client, including that the client agrees to assume all management responsibilities, oversee the service, evaluate its adequacy and results, and accept responsibility for the results.
  2. ET 1.295.030 lists the management responsibilities a member may not assume for an attest client, and ET 1.295.145 addresses information systems design, implementation, or integration.
  3. A SOC 2 is an examination engagement performed under AT-C section 205 of the AICPA attestation standards.
  4. Enrollment in the AICPA Peer Review Program is verifiable through the program's public file.