Explainer

Auditor vs. compliance platform vs. readiness firm

Three different vendors sell "SOC 2 help." Only one of them can sign your report. Here's who does what — and when to hire each.

ProviderCan sign the report?What you actually getHire when…
Licensed CPA audit firmYesThe examination and the signed attestation reportYou need the report itself — this is non-negotiable
GRC / compliance platform (Vanta, Drata, Secureframe)NoEvidence collection, control monitoring, policy templatesYou want to automate evidence and stay audit-ready year-round
Readiness / consulting firmNoGap assessment, remediation plan, evidence prepYou need hands-on help before the audit, or want the preparer separate from the auditor
Penetration testing firmNoSecurity testing (often a SOC 2 evidence input)Your auditor requires it or customers ask for it
vCISONoPart-time security leadership and program managementYou have no security lead to run the program

The independence line

Under AICPA rules, the firm that designs or implements your controls shouldn't be the one auditing them. That's why many buyers deliberately hire a readiness consultant to prepare and a separate CPA firm to attest. If one vendor offers to do both, ask exactly how independence is preserved — and get the answer in the engagement letter.

Can one vendor do audit + platform?

Yes, with care. Auditor-led models (like Thoropass, whose licensed CPA entity issues the report while its platform handles evidence) keep the assurance team as the engagement owner. The question to ask any bundled vendor: which legal entity signs my report, and is it a licensed CPA firm? If they can't name it, walk away.

A sensible buying order

  1. Decide if you need the report now. If a customer contract requires it, start with the auditor — timelines are the long pole.
  2. Add a platform if evidence is chaos. If collecting screenshots and logs already hurts, a GRC platform pays for itself before the audit starts.
  3. Add readiness help if you're far from ready. Take our 2-minute readiness quiz to find out.
  4. Keep the signer independent. Whoever prepares you shouldn't be the one issuing the opinion — unless the independence structure is explicit and documented.
Watch the marketing. If a vendor promises to "certify" you or offers SOC 2 without naming the CPA firm that signs, you're talking to a preparer. Preparers do useful work — just don't confuse their deliverable with the attestation.

Start with the signer

Get matched with licensed CPA firms that fit your scope — then layer platform and readiness help around them.

Get a free quote