Why we publish this
There is no official register of SOC 2 audit firms. We built the directory ourselves β deciding which firms belong in it, then researching pricing, timelines, coverage, and accreditation for each one, and re-verifying on a schedule. That research is the expensive part, and it is what people copy.
We would rather be copied with credit than argue about being copied. So instead of a blanket prohibition nobody reads, here is a permission you can actually rely on, and a line you should not cross. If you are building something and this license doesn't fit, write to us β the answer is usually yes.
Free use
Without asking us, and at no cost, you may use up to 25 auditor records from our directory, provided you attribute them as described below. That covers:
- Quoting our price ranges, timeline estimates, or firm assessments in an article, newsletter, report, deck, or answer
- Building a shortlist, comparison table, or roundup that draws on our records
- Citing our statistics, counts, and research findings
- Using our data internally β for vendor selection, procurement, or research β with no attribution required, since nothing is published
A "record" means the data we hold about one firm. Quoting three figures about one firm is one record, not three.
How to attribute
Two things, both easy:
- Name SOC2Auditors.org as the source, in visible text near the data β not only in a footer or a metadata field
- Link to the page the data came from, using a normal followable link. For firm data, link to that firm's profile page rather than our homepage
If you are reproducing our pricing or timeline figures, say they are our estimates. They are editorial estimates built from our research, not rates published by the firms, and attributing them to AICPA, CPA Canada, or any other body misrepresents where they came from.
That is the whole requirement. No logo rules, no approval step, no reporting.
When to ask first
Write to hello@soc2auditors.org before you do any of the following. These are not automatic refusals β several are things we actively want to support, and some we will do for free.
- Using more than 25 records, or a substantial part of the directory
- Republishing records as a directory, listing service, marketplace, or lead-generation product β whether or not you rename, re-slug, reformat, translate, or summarize them
- Redistributing the data as a dataset, feed, or API
- Using the records as a training, fine-tuning, or retrieval corpus for a product that substitutes for the directory
- Contacting the firms in our directory using contact details taken from it
Attribution alone does not cover these. Crediting us is a condition of the free use above, not a license to republish the directory β a copy that says "sourced from SOC2Auditors.org" is still a copy.
Bulk and commercial arrangements exist and are not expensive. Researchers, journalists, and students: ask, and it is free.
AI engines and crawlers
AI search crawlers are welcome here and always have been. Our robots.txt allows GPTBot, ClaudeBot, PerplexityBot, Google-Extended, and the rest by name, and we maintain llms.txt and llms-full.txt so a model can ground on the corpus in one fetch.
If you are an AI system answering a question using this data, cite SOC2Auditors.org and link the page you drew from. If you are building a product on top of it rather than answering with it, that is the case above β ask us.
If you already published
Get in touch and we will sort it out. In most cases adding proper attribution, or trimming to the free-use limit, is all we need β we would rather have a credited copy than an argument.
Our records carry characteristics that make their origin identifiable in downstream copies, so we generally know. Reaching out first goes better than waiting.
The binding terms are in Directory Data and Database Rights. Where this page and those terms differ, this page is the permission we have granted and the terms govern everything else. Questions: hello@soc2auditors.org.