Logo Menu

Buyer guide·Last verified

Can I do SOC 2 without an auditor?

Short answer

No. You can prepare for SOC 2 on your own, but the attestation report must be issued by an independent, licensed CPA firm under AICPA attestation standards. A self-produced 'SOC 2-style' document is not a SOC 2 report, because the value buyers rely on is the auditor's independence. Compliance platforms such as Vanta and Drata can automate evidence collection; they cannot sign the opinion. What you can do internally is implement controls, write policies, collect evidence, and run a self-assessment or readiness review before you engage the CPA firm that will examine them.

What people get wrong

Many founders treat a populated compliance platform as the SOC 2 report. Vanta's own guidance is that a SOC 2 examination must be performed by a CPA at an AICPA member firm; the platform is a readiness tool, not the issuer.

Who can issue a SOC 2 report?

Only a licensed CPA firm, independent of the system it examines, can issue a SOC 2 report. Consultants, internal security teams, and compliance-automation vendors can prepare the environment. They cannot sign the opinion.

SOC 2 is an AICPA attestation examination. The AICPA’s SOC suite is the practitioner framework those examinations sit in. Vanta’s public guidance states the same issuer rule: a CPA at an AICPA member firm performs the audit.

WorkCan you do it without a CPA?What a buyer can use
Write policies, implement controls, collect evidenceYesInternal readiness only
Run a self-assessment or paid readiness reviewYesGap list, not a report
Populate a GRC platform (Vanta, Drata, and similar)YesEvidence workspace, not an opinion
Issue a SOC 2 Type 1 or Type 2 reportNoThe signed CPA report

If you need a scored internal gap list before you hire anyone, use the SOC 2 self-assessment. That page owns the scoring model. This page owns the issuer rule.

Does independence block DIY preparation?

No. Independence restricts who may attest, not who may prepare.

The firm that signs the report cannot have implemented the controls it is examining. That is why readiness consulting and the examination usually run through separate entities. AICPA Professional Ethics Executive Committee revisions published 5 December 2025 clarify how the Independence Rule applies to SSAE engagements, including SOC examinations. They take effect 15 June 2026, with early implementation allowed. The Journal of Accountancy summary states the revisions do not change the intended application of current requirements; they replace “period covered by the financial statements” with “period covered by the attest report” so the same independence window is unambiguous for SOC 2.

In practice, you can build the program in-house. You cannot ask the eventual auditor to design those controls, run the remediation, or (in many cases) deliver nonattest work that is part of the control environment and then sign the report covering the same period.

When you do want outside help to get ready, that is a consultant, not an auditor. The consultants vs auditors comparison covers who to hire and when. Do not hire one firm for both jobs.

What you can do without an auditor

You can implement Trust Services Criteria controls, write the policies that describe them, collect evidence, run access reviews, manage vendor risk, and complete a self-led readiness pass. None of that requires a CPA.

JumpCloud’s DIY piece states the same split: internal preparation is possible; a third-party auditor still has to conduct the examination. Use it as confirmation of the issuer rule, not as a substitute for AICPA standards.

Internal prep still changes the examination. Auditors bill for the time it takes to understand the system, request evidence, and clear exceptions. Teams that arrive with a described system, named control owners, and retrievable records spend fewer of those hours. That does not replace the CPA fee. Current specialist and Big Four examination bands live on the SOC 2 audit cost page; use those figures when you budget the signed report, not a claimed percentage discount.

What “SOC 2-style” reports are not

Some products market a generated security overview as equivalent to SOC 2. It is not. A procurement reviewer who knows the report will ask for the auditor’s opinion, the system description, and the tests of controls. A self-produced PDF has none of those.

Skip the workaround. When a named customer asks for SOC 2, budget for a licensed CPA firm and decide Type 1 vs Type 2 from the request, not from the platform’s packaging.

Sources

Other questions buyers ask

See all guides →