GetSOC2

Do you need to be a CPA firm?

You need a CPA licence to sign a SOC 2 opinion and you do not need one to do most of the work. That split is the reason a readiness market exists at all, and it is enforced by independence rules rather than by preference.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

No, unless you want to issue the report. A SOC 2 examination is an attestation engagement performed under AICPA attestation standards, and the resulting opinion can only be signed by a licensed CPA firm. Everything before the opinion, which is most of the money and almost all of the hours, is open to anyone competent. Much of it is closed to the CPA firm for the opposite reason: independence.

The market has two sides that legally cannot merge. For a security consultancy, the lack of a CPA licence is not a ceiling. It decides which half you are in, and the readiness half is larger by revenue at most company sizes.

What each side can do

Who can perform which part of a SOC 2 engagement
WorkLicensed CPA firmNon-CPA consultancy
Sign the SOC 2 opinionYes, onlyNo
Perform the examination and testingYesNo
Gap assessment against the criteriaYes, but not for a client it will auditYes
Write policies and proceduresNot for an audit clientYes
Design and implement controlsNot for an audit clientYes
Select and configure a compliance platformNot for an audit clientYes
Collect and organise evidenceNot for an audit clientYes
Act as audit liaison for the clientNoYes
Penetration testingSometimes, through a separate practiceYes
Draft the system descriptionNot for an audit client. The client writes itYes, assisting the client

Read the middle column again. A CPA firm cannot do readiness for a company it will audit, so every audit firm in the country is looking at clients it must send elsewhere. That is the referral engine described on how to get SOC 2 clients, and this table is why it exists.

The Canadian licensing detail

SOC 2 is an AICPA product, and the standards are American. Canadian firms issue SOC 2 reports routinely, and the licensing that matters is provincial: CPA Ontario, CPA British Columbia, CPA Alberta and the rest grant firms a licence to practise public accounting in their province, and a firm performing assurance work must hold the appropriate registration there. CPA Canada and the provincial bodies also publish CSAE 3416, the Canadian standard for reporting on controls at a service organisation, which is the domestic analogue of SOC 1 rather than of SOC 2.

Three things follow for a firm deciding where it sits. A Canadian client asking for a SOC 2 report needs a firm licensed to perform assurance engagements, and provincial registration is checkable. A Canadian company can lawfully use a US CPA firm, and many do. And a Canadian consultancy without a licence should say on its website that it does readiness and does not issue reports. Buyers who find that out later feel misled even when nothing improper happened.

The wording that keeps you out of trouble

Provincial CPA bodies protect the terms around public accounting and assurance. A non-CPA firm describing itself as performing a SOC 2 audit, or as an auditor, is making a claim a competitor can complain about, and will. Describe what you do: readiness, gap assessment, control implementation, audit preparation, evidence support. Those are accurate, unrestricted, and what the buyer is searching for anyway.

Three paths for a non-CPA practice

Stay on the readiness side and build audit firm relationships
The default and the one that works for most firms. Larger revenue per client than the examination at small and mid sizes, recurring through the observation window and into year two, and no licensing overhead. The constraint is that you never own the client's assurance relationship.
Partner formally with one or two CPA firms
A named relationship where you take readiness and they take the examination, presented to the client as a route rather than as a referral. It closes better than either firm alone. Keep the engagements, the contracts and the fees separate, because an arrangement that looks like a joint service creates an independence question for the CPA firm.
Bring a CPA practice inside
Possible, and heavier than it looks. You would need a licensed firm structure with the required registration, quality control, and peer review, and you would then be barred from doing readiness for any client you audit. Firms that go this way generally end up running two legally separate practices, which is a business decision rather than a compliance one.

The case against staying non-CPA

The examination is the recurring, defensible revenue. It happens every year whether or not the client is happy with anyone's advice. It is priced against a requirement rather than a discretionary budget. And the relationship is stickier, because companies avoid changing auditors. Readiness revenue is largest in year one and declines sharply as the client's own team learns the work.

A readiness practice that never builds a retained evidence or year two offering finds its best clients need it less every year. That is survivable, and it is why the retainer lines on the pricing page matter more than the headline engagement fee.

Claim a listing

Listings state plainly whether a firm issues reports or prepares clients for them, because buyers ask.

List your firm
Do you need to be a CPA to do SOC 2 work?

Only to sign the report. A SOC 2 examination is an attestation engagement under AICPA standards and the opinion must come from a licensed CPA firm. Readiness, gap assessment, policy writing, control implementation, evidence collection and audit liaison are all open to a non-CPA consultancy, and most of them are closed to the audit firm by independence rules.

Can a Canadian consultancy call itself a SOC 2 auditor?

Not unless it is a licensed CPA firm performing the examination. Provincial CPA bodies protect terminology around public accounting and assurance, and a competitor will complain. Describe the work instead: readiness, audit preparation, control implementation. That is what buyers search for.

Can the firm that prepares us also audit us?

No. Independence rules stop a CPA firm from examining controls it designed, implemented or documented. A firm offering both is proposing an arrangement a sophisticated reviewer will question, and its own quality control may too. Buy readiness and the examination from different providers.

Do Canadian companies need a Canadian CPA firm for SOC 2?

No. SOC 2 is an AICPA product and a US CPA firm can issue the report for a Canadian client, which many do. A Canadian firm must hold the appropriate provincial registration to perform assurance work. Where the firm is licensed is checkable, and it is worth checking.

Is readiness or audit work more profitable?

Readiness is larger in year one at most company sizes. The examination is better long-term revenue because it recurs annually against a requirement rather than a discretionary budget. A readiness practice that wants durable revenue has to build retained evidence and year two support rather than relying on new first-year engagements.