CPA firms
Sourcing SOC 2 Auditors
Your SOC 2 auditor should be a licensed CPA (or part of a CPA firm) who comes in to review your security controls. They don’t just take your word for it; they want to see real, timestamped proof that you’re doing what you say you do. This includes evidence collection, walkthroughs, control testing, and even live demos of your infrastructure.
Depending on the type of report (Type I or Type II), the scope can cover either a point in time or several months of operations (3-12 months of observation period).
The CPA firms include
- Barr Advisory
- Johanson Group
- Prescient Assurance
- Sensiba San Filippo
- iRisk Assurance
CPA Glossary
SOC Frameworks Overview
SOC 2 Basics
SOC 2 Compliance Process
SOC 2 Compliance Process
Sprinto: Your ally for all things compliance, risk, governance