SOC2Prep

Can one firm do readiness and the audit?

No, and a firm that offers both for the same engagement is telling you something about how it reads the independence rules. What the rule actually says, how the split works in practice, and the two questions that settle it before you sign.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

The short answer

No. The firm that helps you build your SOC 2 control environment cannot also be the firm that examines it and signs the report. That is not a scheduling problem, a pricing problem, or a matter of firm policy that a persuasive buyer can negotiate around. It is a condition of the engagement existing at all. A SOC 2 report signed by a practitioner who designed and implemented the controls under examination is not a defective report. It is not a report.

Most buyers hit this question for a practical reason. One vendor, one point of contact, one invoice stream would obviously be easier. The easier path is closed, and the reasoning explains a lot about what a SOC 2 report is actually for and what your customer is buying when they ask you for one.

What independence actually means in an attestation engagement

A SOC 2 report is an attestation engagement. A licensed CPA firm examines a description of a service organization's system and the suitability of the design of controls, and in a Type II report their operating effectiveness over a period, and issues an opinion. The value of that opinion rests entirely on the idea that the person giving it has no stake in the answer.

Independence in the professional standards has two halves, usually described as independence of mind and independence in appearance. Independence of mind is the practitioner's actual ability to reach a conclusion without being compromised. Independence in appearance is whether a reasonable and informed third party, knowing the relevant facts, would conclude that the practitioner's objectivity was at risk. The second half is where the readiness question lands. Even if a practitioner believed they could objectively test a policy they wrote six months earlier, a reader of the report could not be expected to believe it, and the reader is the entire audience.

The professional frameworks name the specific hazards. A self-review threat arises when a practitioner has to evaluate the results of their own previous work. A management participation threat arises when a practitioner takes on a role that properly belongs to the client's management, such as deciding which risks are acceptable, authorising transactions, or accepting responsibility for the design of internal controls. Designing and implementing a client's control environment and then testing it triggers both at once, and no safeguard brings the threat back to an acceptable level.

In Canada, CPAs are bound by the CPA Code of Professional Conduct in their province, with the independence provisions administered through the provincial bodies and the CPA Canada standards, and by the assurance and related services standards in the CPA Canada Handbook. SOC 2 itself is an AICPA product, performed under the AICPA attestation standards and reported against the AICPA Trust Services Criteria. Canadian practitioners commonly issue SOC 2 reports under those attestation standards, and the AICPA Code of Professional Conduct carries a detailed set of rules on non-attest services which say the same thing in more detail: a firm may provide certain advisory services to an attest client only if it does not perform management functions, and only if the client designates someone with suitable skill, knowledge and experience to oversee the service and take responsibility for it.

Two rulebooks, one answer. The firm that built it does not bless it.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Why the profession draws the line exactly there

Think about who the report is for. You are not commissioning a SOC 2 for yourself. You are commissioning it because a customer, a prospect, a partner or a regulator has asked for evidence that your controls work and cannot come and look for themselves. The report is a substitute for their own inspection.

A substitute for inspection only works if the inspector was disinterested. If the inspector also sold you the thing being inspected, the substitution fails and the customer is back where they started. Every dollar you spent has bought nothing, because the assurance it was supposed to transfer never made the trip. The rule is not there to make professional services more expensive. It is there because a report without independence has no economic function.

The practical split: two contracts, two firms, one program

Here is what the work looks like when it is done properly.

The readiness partner handles everything up to the audit and everything supporting it during the audit: the gap assessment that establishes scope and produces a findings register, control design, policy drafting, standing up the processes that generate evidence in the first place, collecting and organising that evidence, running the remediation program, and coordinating with the auditor once fieldwork begins.

The licensed CPA firm plans the examination, selects samples, tests controls, evaluates whether the description is fairly presented, and signs the opinion.

Two contracts. Two firms. One program, in the sense that there is a single timeline and a single set of controls at the centre of it. The split is contractual and professional, not operational chaos. A readiness engagement run well makes the audit faster and quieter, because the auditor's requests land on a client who already has the answers organised.

At TrazTech the readiness side runs in two phases, and the phasing exists for a reason that is closely related to independence. Phase 1 is a gap assessment that sets scope and produces a findings register. Phase 2 is remediation, scoped and priced from those findings. Remediation cannot be honestly priced before Phase 1, because nobody yet knows what the gaps are. A fixed remediation price quoted before anyone has looked at your environment is a guess dressed as a quote.

Why this is good for the buyer, not an inconvenience

Turn the question around. The reason your SOC 2 report is worth something to your customer is precisely that the person who signed it did not build the thing.

When a prospect's security team reads your report, they are reading a document whose author had no reason to be generous. If a control was not operating for part of the period, the report says so. If the description overstates what the system does, the examination is supposed to catch it. The auditor's professional licence is on the line in a way that a consultant's reputation is not.

That is what you are paying for, and it is the only part of the exercise you cannot produce internally. You can write your own policies. You can build your own access review process. You cannot issue your own opinion, and neither can anyone you hired to help you build it.

There is a second benefit buyers notice later. Two parties in the room creates a real check. The readiness partner's view of whether a control is adequate gets tested against the auditor's view before the report is signed, rather than after a customer's security team finds the gap.

What to watch for when you are shopping

Ask directly. The question is not rude and any honest party will answer it in one sentence.

Are the readiness firm and the audit firm related by ownership, in whole or in part? Affiliated entities are the structure worth the most scrutiny. A consulting arm and an attest arm under common ownership or common control raise the same independence questions as a single firm, and the professional rules look at the network, not just the legal entity that signed your contract. If the two names in front of you share owners, partners, offices, staff or a parent, you need the audit firm's own written confirmation that they are independent with respect to your engagement.

Does a single offering cover both readiness and the audit? A package promising to take you from nothing to a signed report under one contract, one brand and one price is describing something that either is not what it sounds like, or involves a second party nobody has named yet. Ask who signs the report, which firm they work for, and what their licence is.

Is there a commercial relationship between the two firms? Referral fees, revenue sharing, reseller arrangements and volume commitments all create an interest that a reader of the report would want to know about. A readiness partner who refers you to an auditor and receives a payment for doing so has a financial stake in that auditor continuing to be pleasant to work with.

If there is a relationship, is it disclosed before you ask? This is the part that tells you the most. Disclosure that has to be extracted was never intended to be given.

Who chose the auditor? A readiness partner who will only work with one audit firm, and will not explain why, is describing a constraint that serves them rather than you.

How to choose the auditor

The choice should be yours, and you should treat it as a procurement exercise rather than a formality.

Ask each candidate audit firm: who is the practitioner who will sign the opinion, and in which jurisdiction are they licensed. What is the firm's experience with service organizations of your size, in your sector, with your technology stack. How do they handle a subservice organization and the carve-out or inclusive method. When do you get the evidence request list. What is the fieldwork window and the turnaround to draft report. Can you speak to a client who went through a first-year examination with them.

Ask for the fee structure in writing, and ask what changes it. Scope creep in an attestation engagement usually comes from criteria you did not know applied or a subservice arrangement nobody mapped.

A readiness partner who has worked with a given audit firm before is useful to you, and this is not in tension with independence. Familiarity means they know that firm's evidence format, their sampling habits, the questions they always ask, the things they always push back on. The engagement is smoother because the preparation is aimed correctly. What familiarity must not become is a closed loop. Your readiness partner can tell you which firms they have worked with, what each was like to work with, and where each is strong. You make the call, you sign the contract with the audit firm directly, and you can pick a firm your readiness partner has never met.

Two TrazTech case studies are worth reading before you run the process: one where a documented readiness position took $11,000 off an audit quote, at /blog/auditor-vetting-readiness-case-study, and one on how widely auditor pricing varies for the same scope, at /blog/auditor-price-differences-prep-firm-case-study.

What a readiness partner can legitimately do during fieldwork

Once the audit starts, the readiness partner does not disappear. They can:

  • Prepare and organise evidence against the auditor's request list, so that what gets submitted is complete and in the format the auditor expects
  • Project manage the evidence request cycle, track what is outstanding, chase internal owners and keep the timeline honest
  • Answer the auditor's questions about how a control was designed and why, and explain the rationale behind a policy they helped draft
  • Respond to follow-up requests and prepare material for a second round
  • Help the client understand what a proposed exception means and what the options are
  • Attend walkthroughs alongside the client's control owners

In the Ontario medtech SOC 2 Type I engagement at /blog/soc-2-type-i-medtech-ai-case-study, the auditor's evidence request ran to 84 items. Eighty-four items land very differently on a client who has someone tracking them than on a client meeting them for the first time.

What a readiness partner must never do

The line is about who owns the answer.

  • Answer as the client. The readiness partner can help the client prepare an answer. The client gives it. Management's representations are management's, and an auditor relying on a consultant's assertion about the client's environment has a problem.
  • Select the sample. Sampling is the auditor's judgment and the auditor's alone. A readiness partner who influences which items get tested has compromised the test.
  • Test its own controls and present the result as assurance. A readiness partner can and should check its own work internally before fieldwork. That is quality control. It is not testing, it produces no opinion, and it must never be described to the auditor or to a customer as though it were.
  • Make management decisions. Accepting a risk, approving a policy, deciding what is in scope, assigning control ownership: these are the client's to decide. A readiness partner advises. Somebody at the client with the authority to do so decides.
  • Sit between the client and the auditor as a gatekeeper. The auditor must be able to reach the client's control owners directly, and the client must be able to reach the auditor without an intermediary.

If you are told your readiness partner will handle the auditor so you do not have to, ask what that means. The good version is project management. The bad version is a filter.

The same logic applies to ISO 27001

The structure is different, the principle is identical.

An ISO 27001 certificate is issued by a certification body that has itself been accredited, and the accreditation requirements for bodies certifying management systems prohibit them from providing management system consultancy to organizations they certify. A consultant who helped you build your ISMS, write your Statement of Applicability, run your risk assessment and prepare for the Stage 1 and Stage 2 audits cannot also be the body that audits and certifies it. Same reason, same result.

Running SOC 2 and ISO 27001 together leaves you with three parties: the readiness partner, the CPA firm for the SOC 2 examination, and the accredited certification body for ISO 27001. That is less overhead than it sounds, because the underlying control work overlaps heavily. TrazTech ran both in parallel for a Waterloo data centre operator across three physical sites, written up at /blog/soc-2-iso-27001-parallel-case-study.

What to do next

If you are early, the first thing to buy is not the audit. It is a gap assessment that tells you what scope you are looking at and what has to change before an auditor is worth engaging. SOC 2 and ISO 27001 readiness at TrazTech starts at $3,000 for that gap assessment, with remediation scoped and priced from the findings rather than guessed at beforehand.

If you already have a readiness partner and you are choosing an auditor, put the questions above in your RFP, in writing, and keep the answers.

If you have been offered a single arrangement covering both, ask the one question that settles it: who signs the report, which firm do they work for, and is there any ownership, referral or revenue relationship between that firm and the firm that prepared us. You are entitled to a clear answer before you sign anything.

soc2prep.ca is a neutral Canadian directory for SOC 2 readiness. For readiness work, the two-phase model and pricing, see traztech.ca.

Common questions

What can a readiness partner do during fieldwork?

Prepare and organise evidence, answer the auditor's process questions, project manage the request list and keep the schedule moving. What it must not do is answer as the client, select the sample, or test controls it built.

Does the same rule apply to ISO 27001?

Yes, and it is enforced through accreditation. A certification body cannot provide management system consultancy to an organization it certifies. The consultant who builds your ISMS cannot be the body that certifies it.

Is a referral from my readiness partner to an auditor a problem?

Not on its own, and it is often useful, because a partner who has worked with that firm knows what it asks for. What matters is that the choice stays yours and that any commercial relationship between the two is disclosed when you ask.

Get readiness and the audit from the right places

Independence rules mean the firm that builds your controls cannot also issue your opinion. Tell us your scope and we will put it to firms on the correct side of that line.

Get matched