Who Performs a SOC 2 Audit?
A licensed CPA firm performs every SOC 2 audit, not the compliance software. Here is what each of six platforms does instead and what the audit costs.
Some vendors pay us to be assessed or listed. Payment never changes a score, a rank or a verdict.
A licensed CPA firm performs a SOC 2 audit. The compliance software you use to prepare for the audit does not perform it, cannot issue the report and is not licensed to do so. SOC 2 is an examination defined and governed by the AICPA. The six platforms covered in our compliance software ranking automate the work that comes before and after the audit: evidence collection, policy management and continuous control monitoring. The audit itself is a separate engagement with a separate firm, with one exception in this market.
Who is qualified to perform a SOC 2 audit?
A-LIGN, a licensed assessor firm, describes a SOC 2 report as “an independent attestation that evaluates the effectiveness of a company’s controls as they relate to Security, Availability, Processing Integrity, Confidentiality, and Privacy.” The AICPA’s own SOC page states that it will take action against auditors “found to have not performed audits in accordance with professional standards, not been enrolled in peer review, and/or are unlicensed.” Peer review enrollment and licensure are the criteria the AICPA itself names.
When a buyer uses Vanta or Drata to prepare for the audit, the platform collects evidence and maps it to the Trust Services Criteria. A separate CPA firm examines that evidence and signs the report.
What compliance platforms do instead of auditing
Each of the six platforms in our compliance software comparison handles the relationship between the platform and the audit differently. Five route you to an outside auditor. One performs the audit itself.
Vanta gives customers access to its auditor network or the option to bring their own auditor. Vanta’s pricing page lists both options. The platform prepares the evidence, and a partner CPA firm reviews and attests.
Drata operates an Audit Hub described as a command center to centralize communication with your auditor. Drata’s own site does not claim to perform the audit. The model resembles Vanta’s approach: prepare inside the platform, audit with an outside firm.
Secureframe provides access to the Secureframe Audit Partner Network. Secureframe also employs more than 30 in-house compliance experts and former auditors who provide guidance through the process, but the audit engagement is with a partner firm.
Sprinto offers access to a named network of audit partners and supports a bring-your-own-auditor model. The platform includes an audit management module where auditors review evidence inside the platform, but Sprinto does not perform the audit.
Scrut provides an Audit Center where auditors share and track evidence. A named audit partner network is not listed on Scrut’s own website. The platform serves as the workspace for the audit, but the auditor is external.
Thoropass is the one vendor among the six that delivers the audit through its own firm. Thoropass describes its audit as “expert-led audits powered by Thoropass ALP” with “in-house auditor support.” The platform subscription and the audit subscription are sold together on AWS Marketplace, starting at $8,700 per year for the platform and $5,800 per year for a SOC 2 audit. This makes Thoropass the only platform in this set where you can buy the software and the audit from one company.
Type I and Type II: what the auditor examines
A SOC 2 Type I audit assesses whether controls are suitably designed at a single point in time. A SOC 2 Type II audit assesses both the design and the operating effectiveness of those controls over an observation period, typically 3 to 12 months. A-LIGN notes that “a Type II provides a greater level of trust to a customer or partner as the report provides a greater level of detail and visibility to the effectiveness of the security controls an organization has in place.”
A Type I report is a valid starting point. A Type II report covers a longer window and, as A-LIGN puts it, “provides a greater level of trust.” The compliance platforms help with both types by automating the continuous evidence collection that a Type II observation period demands. Vanta, Sprinto and Drata all describe continuous monitoring as a core feature on their product pages. That monitoring maps directly to the ongoing evidence a Type II engagement requires.
What the audit costs
A-LIGN estimates the cost of a SOC 2 audit at $20,000 to $150,000 or more. The total depends on company size, system complexity, audit scope and whether the organization is pursuing a Type I or Type II report. This is the fee paid to the CPA firm, separate from any platform subscription.
The compliance platforms have their own subscription costs, separate from the audit fee. Published starting prices range from $7,000 per year for Secureframe’s Fundamentals tier to $32,500 per year for Drata on AWS Marketplace (covering a 100-person organization plus one framework). Our pricing study tracks what each vendor lists on its own site and on AWS Marketplace.
The platform fee and the audit fee are separate line items for five of the six vendors. Thoropass is the exception: its AWS Marketplace listing bundles a platform subscription (from $8,700 per year) with an audit subscription (from $5,800 per year for SOC 2).
Why the AICPA is watching this market
The AICPA’s own SOC page currently carries a notice stating that it “is looking into allegations published anonymously about the business practices of a compliance vendor that offers Systems and Organization Control (SOC) services.” The notice adds that if auditors are “found to have not performed audits in accordance with professional standards, not been enrolled in peer review, and/or are unlicensed, the AICPA will take action.”
The Journal of Accountancy ran a piece in February 2026 titled “Promises of ‘fast and easy’ threaten SOC credibility,” warning that an ongoing push for high-volume SOC services may come at the cost of quality and objectivity. The AICPA notice does not name the vendor under investigation, and we do not speculate on it here.
These concerns reinforce the distinction between the platform and the audit. A compliance platform that automates evidence collection is doing a different job than the CPA firm that examines the evidence. The platform accelerates preparation. It does not replace the examination itself.
How to choose an auditor
Several platforms offer a shortlist of vetted auditors. Secureframe names an Audit Partner Network. Vanta and Sprinto each provide access to their own auditor networks, and Sprinto supports bring-your-own-auditor. Thoropass delivers the audit through its own CPA firm, so the auditor question is answered at purchase.
The AICPA’s notice names the criteria it will act on: professional standards, peer review enrollment and licensure. Those are the qualities to verify in whatever CPA firm you hire, whether through a platform’s network or independently.
The compliance platform prepares you. The CPA firm examines you. The two jobs are different, and the distinction is what the AICPA is reinforcing right now.
How each platform handles that handoff shapes the experience as much as the subscription price. The audit cost itself sits on top of whatever the platform charges, except at Thoropass where the two are bundled. Our rubric records how each vendor’s audit path works, whether through a partner network, bring-your-own-auditor, or an in-house CPA firm. The pricing study covers the platform side of the cost.
Platforms in this article
Frequently asked questions
-
Can compliance software perform a SOC 2 audit?
No. A SOC 2 audit is an examination that can only be performed by a licensed CPA firm. Compliance platforms automate evidence collection, policy management and control monitoring, but a CPA firm must examine the controls and issue the report.
-
What is the difference between SOC 2 Type I and Type II?
A Type I report evaluates whether controls are suitably designed at a single point in time. A Type II report evaluates both the design and the operating effectiveness of those controls over an observation period, typically 3 to 12 months. Type II provides stronger evidence of ongoing security.
-
How much does a SOC 2 audit cost?
According to A-LIGN, a licensed assessor firm, the cost typically ranges from $20,000 to $150,000 or more. The total depends on company size, system complexity, audit scope and whether the organization is pursuing a Type I or Type II report.