# Who Performs a SOC 2 Audit?

**URL:** https://theauditrail.com/blog/who-performs-a-soc-2-audit/
**Published:** 2026-09-24
**Modified:** 2026-09-24
**Author:** The Audit Trail editorial desk

> A licensed CPA firm performs every SOC 2 audit, not the compliance software. Here is what each of six platforms does instead and what the audit costs.

---

Blog

# Who Performs a SOC 2 Audit?

A licensed CPA firm performs every SOC 2 audit, not the compliance software. Here is what each of six platforms does instead and what the audit costs.

The Audit Trail editorial desk

Published Sep 24, 2026

[Some vendors pay us to be assessed or listed. Payment never changes a score, a rank or a verdict.](https://theauditrail.com/how-we-make-money/)

In brief

-   A licensed CPA firm performs every SOC 2 audit.
-   Compliance platforms automate evidence, not the audit.
-   Five of six platforms route you to an outside auditor.
-   Thoropass delivers the audit through its own CPA firm.
-   Audit fees range from $20,000 to $150,000 or more.

A licensed CPA firm performs a SOC 2 audit. The compliance software you use to prepare for the audit does not perform it, cannot issue the report and is not licensed to do so. [SOC 2](https://theauditrail.com/frameworks/soc-2/) is an examination defined and governed by the AICPA. The six platforms covered in our [compliance software ranking](https://theauditrail.com/best-soc-2-compliance-software/) automate the work that comes before and after the audit: evidence collection, policy management and continuous control monitoring. The audit itself is a separate engagement with a separate firm, with one exception in this market.

## Who is qualified to perform a SOC 2 audit?

A-LIGN, a licensed assessor firm, describes a SOC 2 report as “an independent attestation that evaluates the effectiveness of a company’s controls as they relate to Security, Availability, Processing Integrity, Confidentiality, and Privacy.” The AICPA’s own SOC page states that it will take action against auditors “found to have not performed audits in accordance with professional standards, not been enrolled in peer review, and/or are unlicensed.” Peer review enrollment and licensure are the criteria the AICPA itself names.

When a buyer uses [Vanta](https://theauditrail.com/vendors/vanta/) or [Drata](https://theauditrail.com/vendors/drata/) to prepare for the audit, the platform collects evidence and maps it to the Trust Services Criteria. A separate CPA firm examines that evidence and signs the report.

## What compliance platforms do instead of auditing

Each of the six platforms in our [compliance software comparison](https://theauditrail.com/best-soc-2-compliance-software/) handles the relationship between the platform and the audit differently. Five route you to an outside auditor. One performs the audit itself.

**Vanta** gives customers access to its auditor network or the option to bring their own auditor. Vanta’s [pricing page](https://www.vanta.com/pricing) lists both options. The platform prepares the evidence, and a partner CPA firm reviews and attests.

**Drata** operates an Audit Hub described as a command center to centralize communication with your auditor. Drata’s own site does not claim to perform the audit. The model resembles [Vanta’s approach](https://theauditrail.com/compare/vanta-vs-drata/): prepare inside the platform, audit with an outside firm.

**Secureframe** provides access to the [Secureframe Audit Partner Network](https://theauditrail.com/vendors/secureframe/). Secureframe also employs more than 30 in-house compliance experts and former auditors who provide guidance through the process, but the audit engagement is with a partner firm.

**Sprinto** offers access to a named [network of audit partners](https://theauditrail.com/vendors/sprinto/) and supports a bring-your-own-auditor model. The platform includes an audit management module where auditors review evidence inside the platform, but Sprinto does not perform the audit.

**Scrut** provides an [Audit Center](https://theauditrail.com/vendors/scrut/) where auditors share and track evidence. A named audit partner network is not listed on Scrut’s own website. The platform serves as the workspace for the audit, but the auditor is external.

![Thoropass logo](https://theauditrail.com/logos/thoropass.png)

Thoropass

47/100 Limited

[Scorecard](https://theauditrail.com/vendors/thoropass/) [Thoropass site](https://www.thoropass.com)

**Thoropass** is the one vendor among the six that delivers the audit through its own firm. Thoropass describes its audit as “expert-led audits powered by Thoropass ALP” with “in-house auditor support.” The platform subscription and the audit subscription are sold together on [AWS Marketplace](https://theauditrail.com/research/compliance-software-pricing-2026/), starting at $8,700 per year for the platform and $5,800 per year for a SOC 2 audit. This makes Thoropass the only platform in this set where you can buy the software and the audit from one company.

## Type I and Type II: what the auditor examines

A SOC 2 Type I audit assesses whether controls are suitably designed at a single point in time. A SOC 2 Type II audit assesses both the design and the operating effectiveness of those controls over an observation period, typically 3 to 12 months. A-LIGN notes that “a Type II provides a greater level of trust to a customer or partner as the report provides a greater level of detail and visibility to the effectiveness of the security controls an organization has in place.”

A Type I report is a valid starting point. A Type II report covers a longer window and, as A-LIGN puts it, “provides a greater level of trust.” The compliance platforms help with both types by automating the continuous evidence collection that a Type II observation period demands. [Vanta](https://theauditrail.com/vendors/vanta/), [Sprinto](https://theauditrail.com/vendors/sprinto/) and [Drata](https://theauditrail.com/vendors/drata/) all describe continuous monitoring as a core feature on their product pages. That monitoring maps directly to the ongoing evidence a Type II engagement requires.

## What the audit costs

A-LIGN estimates the cost of a SOC 2 audit at $20,000 to $150,000 or more. The total depends on company size, system complexity, audit scope and whether the organization is pursuing a Type I or Type II report. This is the fee paid to the CPA firm, separate from any platform subscription.

The compliance platforms have their own subscription costs, separate from the audit fee. Published starting prices range from $7,000 per year for [Secureframe’s](https://theauditrail.com/vendors/secureframe/) Fundamentals tier to $32,500 per year for [Drata](https://theauditrail.com/vendors/drata/) on AWS Marketplace (covering a 100-person organization plus one framework). Our [pricing study](https://theauditrail.com/research/compliance-software-pricing-2026/) tracks what each vendor lists on its own site and on AWS Marketplace.

The platform fee and the audit fee are separate line items for five of the six vendors. Thoropass is the exception: its [AWS Marketplace listing](https://theauditrail.com/vendors/thoropass/) bundles a platform subscription (from $8,700 per year) with an audit subscription (from $5,800 per year for SOC 2).

## Why the AICPA is watching this market

The AICPA’s own SOC page currently carries a notice stating that it “is looking into allegations published anonymously about the business practices of a compliance vendor that offers Systems and Organization Control (SOC) services.” The notice adds that if auditors are “found to have not performed audits in accordance with professional standards, not been enrolled in peer review, and/or are unlicensed, the AICPA will take action.”

The Journal of Accountancy ran a piece in February 2026 titled “Promises of ‘fast and easy’ threaten SOC credibility,” warning that an ongoing push for high-volume SOC services may come at the cost of quality and objectivity. The AICPA notice does not name the vendor under investigation, and we do not speculate on it here.

These concerns reinforce the distinction between the platform and the audit. A compliance platform that automates evidence collection is doing a different job than the CPA firm that examines the evidence. The platform accelerates preparation. It does not replace the examination itself.

## How to choose an auditor

Several platforms offer a shortlist of vetted auditors. [Secureframe](https://theauditrail.com/vendors/secureframe/) names an Audit Partner Network. Vanta and [Sprinto](https://theauditrail.com/vendors/sprinto/) each provide access to their own auditor networks, and Sprinto supports bring-your-own-auditor. [Thoropass](https://theauditrail.com/vendors/thoropass/) delivers the audit through its own CPA firm, so the auditor question is answered at purchase.

The AICPA’s notice names the criteria it will act on: professional standards, peer review enrollment and licensure. Those are the qualities to verify in whatever CPA firm you hire, whether through a platform’s network or independently.

The compliance platform prepares you. The CPA firm examines you. The two jobs are different, and the distinction is what the AICPA is reinforcing right now.

How each [platform handles that handoff](https://theauditrail.com/best-vanta-alternatives/) shapes the experience as much as the subscription price. The audit cost itself sits on top of whatever the platform charges, except at Thoropass where the two are bundled. Our [rubric](https://theauditrail.com/rubric/) records how each vendor’s audit path works, whether through a partner network, bring-your-own-auditor, or an in-house CPA firm. The [pricing study](https://theauditrail.com/research/compliance-software-pricing-2026/) covers the platform side of the cost.

Platforms in this article

 [![Sprinto logo](https://theauditrail.com/logos/sprinto.png)Sprinto (82/100)](/vendors/sprinto/)[ ![Vanta logo](https://theauditrail.com/logos/vanta.png)Vanta (75/100) ](/vendors/vanta/)[ ![Drata logo](https://theauditrail.com/logos/drata.png)Drata (73/100) ](/vendors/drata/)[ ![Secureframe logo](https://theauditrail.com/logos/secureframe.png)Secureframe (73/100) ](/vendors/secureframe/)[ ![Scrut logo](https://theauditrail.com/logos/scrut.png)Scrut (63/100) ](/vendors/scrut/)[ ![Thoropass logo](https://theauditrail.com/logos/thoropass.png)Thoropass (47/100)](/vendors/thoropass/)

## Frequently asked questions

-   Can compliance software perform a SOC 2 audit?
    
    No. A SOC 2 audit is an examination that can only be performed by a licensed CPA firm. Compliance platforms automate evidence collection, policy management and control monitoring, but a CPA firm must examine the controls and issue the report.
    
-   What is the difference between SOC 2 Type I and Type II?
    
    A Type I report evaluates whether controls are suitably designed at a single point in time. A Type II report evaluates both the design and the operating effectiveness of those controls over an observation period, typically 3 to 12 months. Type II provides stronger evidence of ongoing security.
    
-   How much does a SOC 2 audit cost?
    
    According to A-LIGN, a licensed assessor firm, the cost typically ranges from $20,000 to $150,000 or more. The total depends on company size, system complexity, audit scope and whether the organization is pursuing a Type I or Type II report.