Can a FedRAMP 3PAO also do my SOC 2 audit?
A FedRAMP 3PAO can run your commercial SOC 2 only when a CPA attestation arm exists in the same provider group. Verify current 3PAO status and the CPA signer, because the federal assessment and commercial report remain separate deliverables and may use different legal entities.
A Third Party Assessment Organization assesses the cloud service against the applicable FedRAMP baseline; the government, not the 3PAO, makes the authorization decision. The SOC 2 opinion still comes from a licensed CPA firm, not from the 3PAO authorization letter.
The official FedRAMP 3PAO list is the source to verify before signing. Accreditation status and scope can change. Ask the firm to name the contracting and issuing entities, target baseline, and agency path.