Many founders treat a populated compliance platform as the SOC 2 report. Vanta's own guidance is that a SOC 2 examination must be performed by a CPA at an AICPA member firm; the platform is a readiness tool, not the issuer.
Who can issue a SOC 2 report?
Only a licensed CPA firm, independent of the system it examines, can issue a SOC 2 report. Consultants, internal security teams, and compliance-automation vendors can prepare the environment. They cannot sign the opinion.
SOC 2 is an AICPA attestation examination. The AICPA’s SOC suite is the practitioner framework those examinations sit in. Vanta’s public guidance states the same issuer rule: a CPA at an AICPA member firm performs the audit.
| Work | Can you do it without a CPA? | What a buyer can use |
|---|---|---|
| Write policies, implement controls, collect evidence | Yes | Internal readiness only |
| Run a self-assessment or paid readiness review | Yes | Gap list, not a report |
| Populate a GRC platform (Vanta, Drata, and similar) | Yes | Evidence workspace, not an opinion |
| Issue a SOC 2 Type 1 or Type 2 report | No | The signed CPA report |
If you need a scored internal gap list before you hire anyone, use the SOC 2 self-assessment. That page owns the scoring model. This page owns the issuer rule.
Does independence block DIY preparation?
No. Independence restricts who may attest, not who may prepare.
The firm that signs the report cannot have implemented the controls it is examining. That is why readiness consulting and the examination usually run through separate entities. AICPA Professional Ethics Executive Committee revisions published 5 December 2025 clarify how the Independence Rule applies to SSAE engagements, including SOC examinations. They take effect 15 June 2026, with early implementation allowed. The Journal of Accountancy summary states the revisions do not change the intended application of current requirements; they replace “period covered by the financial statements” with “period covered by the attest report” so the same independence window is unambiguous for SOC 2.
In practice, you can build the program in-house. You cannot ask the eventual auditor to design those controls, run the remediation, or (in many cases) deliver nonattest work that is part of the control environment and then sign the report covering the same period.
When you do want outside help to get ready, that is a consultant, not an auditor. The consultants vs auditors comparison covers who to hire and when. Do not hire one firm for both jobs.
What you can do without an auditor
You can implement Trust Services Criteria controls, write the policies that describe them, collect evidence, run access reviews, manage vendor risk, and complete a self-led readiness pass. None of that requires a CPA.
JumpCloud’s DIY piece states the same split: internal preparation is possible; a third-party auditor still has to conduct the examination. Use it as confirmation of the issuer rule, not as a substitute for AICPA standards.
Internal prep still changes the examination. Auditors bill for the time it takes to understand the system, request evidence, and clear exceptions. Teams that arrive with a described system, named control owners, and retrievable records spend fewer of those hours. That does not replace the CPA fee. Current specialist and Big Four examination bands live on the SOC 2 audit cost page; use those figures when you budget the signed report, not a claimed percentage discount.
What “SOC 2-style” reports are not
Some products market a generated security overview as equivalent to SOC 2. It is not. A procurement reviewer who knows the report will ask for the auditor’s opinion, the system description, and the tests of controls. A self-produced PDF has none of those.
Skip the workaround. When a named customer asks for SOC 2, budget for a licensed CPA firm and decide Type 1 vs Type 2 from the request, not from the platform’s packaging.