Do you need to be a CPA firm?
You need a CPA licence to sign a SOC 2 opinion and you do not need one to do most of the work. That split is the reason a readiness market exists at all, and it is enforced by independence rules rather than by preference.
No, unless you want to issue the report. A SOC 2 examination is an attestation engagement performed under AICPA attestation standards, and the resulting opinion can only be signed by a licensed CPA firm. Everything before the opinion, which is most of the money and almost all of the hours, is open to anyone competent. Much of it is closed to the CPA firm for the opposite reason: independence.
The market has two sides that legally cannot merge. For a security consultancy, the lack of a CPA licence is not a ceiling. It decides which half you are in, and the readiness half is larger by revenue at most company sizes.
What each side can do
| Work | Licensed CPA firm | Non-CPA consultancy |
|---|---|---|
| Sign the SOC 2 opinion | Yes, only | No |
| Perform the examination and testing | Yes | No |
| Gap assessment against the criteria | Yes, but not for a client it will audit | Yes |
| Write policies and procedures | Not for an audit client | Yes |
| Design and implement controls | Not for an audit client | Yes |
| Select and configure a compliance platform | Not for an audit client | Yes |
| Collect and organise evidence | Not for an audit client | Yes |
| Act as audit liaison for the client | No | Yes |
| Penetration testing | Sometimes, through a separate practice | Yes |
| Draft the system description | Not for an audit client. The client writes it | Yes, assisting the client |
Read the middle column again. A CPA firm cannot do readiness for a company it will audit, so every audit firm in the country is looking at clients it must send elsewhere. That is the referral engine described on how to get SOC 2 clients, and this table is why it exists.
The Canadian licensing detail
SOC 2 is an AICPA product, and the standards are American. Canadian firms issue SOC 2 reports routinely, and the licensing that matters is provincial: CPA Ontario, CPA British Columbia, CPA Alberta and the rest grant firms a licence to practise public accounting in their province, and a firm performing assurance work must hold the appropriate registration there. CPA Canada and the provincial bodies also publish CSAE 3416, the Canadian standard for reporting on controls at a service organisation, which is the domestic analogue of SOC 1 rather than of SOC 2.
Three things follow for a firm deciding where it sits. A Canadian client asking for a SOC 2 report needs a firm licensed to perform assurance engagements, and provincial registration is checkable. A Canadian company can lawfully use a US CPA firm, and many do. And a Canadian consultancy without a licence should say on its website that it does readiness and does not issue reports. Buyers who find that out later feel misled even when nothing improper happened.
The wording that keeps you out of trouble
Provincial CPA bodies protect the terms around public accounting and assurance. A non-CPA firm describing itself as performing a SOC 2 audit, or as an auditor, is making a claim a competitor can complain about, and will. Describe what you do: readiness, gap assessment, control implementation, audit preparation, evidence support. Those are accurate, unrestricted, and what the buyer is searching for anyway.
Three paths for a non-CPA practice
- Stay on the readiness side and build audit firm relationships
- The default and the one that works for most firms. Larger revenue per client than the examination at small and mid sizes, recurring through the observation window and into year two, and no licensing overhead. The constraint is that you never own the client's assurance relationship.
- Partner formally with one or two CPA firms
- A named relationship where you take readiness and they take the examination, presented to the client as a route rather than as a referral. It closes better than either firm alone. Keep the engagements, the contracts and the fees separate, because an arrangement that looks like a joint service creates an independence question for the CPA firm.
- Bring a CPA practice inside
- Possible, and heavier than it looks. You would need a licensed firm structure with the required registration, quality control, and peer review, and you would then be barred from doing readiness for any client you audit. Firms that go this way generally end up running two legally separate practices, which is a business decision rather than a compliance one.
The case against staying non-CPA
The examination is the recurring, defensible revenue. It happens every year whether or not the client is happy with anyone's advice. It is priced against a requirement rather than a discretionary budget. And the relationship is stickier, because companies avoid changing auditors. Readiness revenue is largest in year one and declines sharply as the client's own team learns the work.
A readiness practice that never builds a retained evidence or year two offering finds its best clients need it less every year. That is survivable, and it is why the retainer lines on the pricing page matter more than the headline engagement fee.
Claim a listing
Listings state plainly whether a firm issues reports or prepares clients for them, because buyers ask.
List your firmDo you need to be a CPA to do SOC 2 work?
Only to sign the report. A SOC 2 examination is an attestation engagement under AICPA standards and the opinion must come from a licensed CPA firm. Readiness, gap assessment, policy writing, control implementation, evidence collection and audit liaison are all open to a non-CPA consultancy, and most of them are closed to the audit firm by independence rules.
Can a Canadian consultancy call itself a SOC 2 auditor?
Not unless it is a licensed CPA firm performing the examination. Provincial CPA bodies protect terminology around public accounting and assurance, and a competitor will complain. Describe the work instead: readiness, audit preparation, control implementation. That is what buyers search for.
Can the firm that prepares us also audit us?
No. Independence rules stop a CPA firm from examining controls it designed, implemented or documented. A firm offering both is proposing an arrangement a sophisticated reviewer will question, and its own quality control may too. Buy readiness and the examination from different providers.
Do Canadian companies need a Canadian CPA firm for SOC 2?
No. SOC 2 is an AICPA product and a US CPA firm can issue the report for a Canadian client, which many do. A Canadian firm must hold the appropriate provincial registration to perform assurance work. Where the firm is licensed is checkable, and it is worth checking.
Is readiness or audit work more profitable?
Readiness is larger in year one at most company sizes. The examination is better long-term revenue because it recurs annually against a requirement rather than a discretionary budget. A readiness practice that wants durable revenue has to build retained evidence and year two support rather than relying on new first-year engagements.