The independence firewall
Firms and software platforms may pay for a clearly labeled placement after qualifying for a page. Payment does not determine coverage or change review findings, comparison facts, or fit scores.
- Sponsorship buys
- Clearly labeled placement on a page where the company already qualifies to appear.
- Sponsorship does not buy
- Eligibility for a list, a higher rating, an earned badge, softer criticism, removal of a weakness, a favorable verdict, a higher fit score, or priority over a better-fit firm in quote matching.
If a paid placement appears to affect an editorial conclusion, email us. We will review it and correct the page.
What we cover
We review 192+ SOC 2 audit firms and 32 compliance automation platforms.
Adjacent frameworks (ISO 27001, HIPAA, PCI DSS, and seven more) appear only where they affect SOC 2 scope, cost, readiness, evidence collection, or auditor selection. Reference explainers live in our frameworks hub; recurring buyer questions live in the SOC 2 buyer guides. General-purpose GRC tools that are not built for SOC 2 buyers are out of scope.
How we evaluate auditors
We start by checking active CPA and AICPA standing and, for US firms, the AICPA peer-review record. Profiles show the public result: Pass, Pass with Deficiencies, Fail, result not public, or review not shown. A missing public result does not mean Fail; AICPA publishes ratings only for specified members and firms that opt in. When we cannot confirm a record, the firm stays listed with a caveat badge and ranks below firms that clear the bar.
The ranked best SOC 2 auditors shortlist has a narrower rule. A US firm qualifies only if its latest accepted AICPA peer-review rating is Pass. We verify that result in the public file or from the report and acceptance letter supplied to our research team. Enrollment without a verified Pass does not qualify. Pass with Deficiencies and Fail do not qualify. A firm can return after a newer accepted review records a Pass.
CPA licensing and peer review determine whether a firm can issue a report. The assigned team's cloud, SaaS, security, and platform experience helps show whether the firm is a fit for that buyer.
How we compare firms
Profiles show where a firm works, what it can audit or certify, how long the work takes, and what it costs. These details help you decide which firms to contact.
| On the profile | What we show | What it does not mean |
|---|---|---|
| Price | A range marked firm-confirmed or estimated. Prices buyers report paying carry more weight than published rates. | A lower fee is not a better fit. |
| Location | We use the headquarters as the default. Other countries appear only when the record shows the firm serves buyers there. | The headquarters is not the service area. |
| Company size | The company sizes the firm works with. A 200-person fintech and a 12-person startup often need different firms. | Serving larger companies does not make the firm a better choice. |
| Specialty | Reports or certifications the firm can issue, and the industries it serves. | Having implemented ISO 27001 is not the right to issue the certificate. |
| Timeline | Kickoff-to-report estimates draw on firms' engagement descriptions and buyer reports where available. Vendor marketing timelines do not count. | A shorter marketing timeline is not a better fit. |
| Platforms | GRC platforms the firm has a record of working with. | A listed platform does not imply a partnership or mean you need that platform to get a report. |
Quote matching checks service geography, company size, audit or readiness needs, framework and report requirements, and deadline. Price does not affect fit.
Fit score comes first. Featured status can break a tie between equally fit audit firms, after eligibility and peer-review checks. It cannot change a firm's fit score or move a worse-fit firm ahead.
Profiles may also show documented industry, cloud, and platform experience. These details help you assess a team but are not automatic match inputs. Request quotes to see the matching process in action.
How we evaluate software
Four rules govern software reviews.
Our reviews draw on our own testing, buyer interviews where available, and primary-source research. We source every claim. Each published platform fact has an evidence state, source URL, and retrieval date. We check claims against vendor documentation, marketplace listings, and independent reviews.
Our testing includes checking published claims, tracing documented workflows, and identifying what a buyer should verify in a tenant. Testing depth and direct product access vary by review. When we operate a product first-hand, we describe the task and observed result beside the finding.
We compare published prices with buyer-reported quotes where available and show a range instead of a single number. Marketing-site prices remain starting points until buyer quotes corroborate them.
Each review includes a section on product limitations. We publish those findings when our research supports them.
Ratings and recommendations
We do not assign star ratings to audit firms or software platforms. The software comparison shows G2 ratings and review counts as third-party data. Its default order puts eligible Featured listings first, then orders the remaining platforms by G2 review count, rating, and name. Readers can switch to G2 review-count or alphabetical order.
G2 scores are third-party review signals, not our fit verdict. Our recommendations explain which firm or platform fits a buyer's needs and why; auditor profiles also report official AICPA peer-review outcomes.
How we weigh evidence
We use four evidence tiers. When sources disagree, the higher tier takes precedence.
- Tier 1: regulatory and licensing text
- AICPA peer-review records, board-of-accountancy CPA-license rosters, FedRAMP marketplace listings, CREST registry entries, and AICPA Trust Services Criteria. We cite the public registry directly where possible.
- Tier 2: vendor-published primary documents
- A firm's service descriptions, a platform's pricing page, or an audit report shared by a buyer under NDA. This is the next-highest tier after Tier 1. We source and date each entry.
- Tier 3: live briefs and quotes
- Anonymized buyer briefs, RFPs, and quotes from firms or software vendors show the scopes buyers ask for, the prices vendors propose, and recurring buyer concerns. We publish ranges, never individual submissions, and cross-check them against Tier 1 and Tier 2 sources.
- Tier 4: signal data
- Hiring patterns on LinkedIn, review patterns on G2 and Trustpilot, and public earnings commentary. We use these signals only to cross-check Tiers 1โ3.
Buyer briefs and supplier quotes help us set planning ranges and assess fit. One quote never becomes a published range. Per-figure sources for audit-cost ranges are on the cost sources page.
Each price is marked as our estimate or firm-confirmed. Auditor profiles also show a last-verified date, so you can see when we checked the record.
What "last verified" means on an auditor profile
Every verified auditor profile carries a Last verified date. That stamp asserts three things on that date: the firm is still operating under the listed name, the AICPA peer-review record we link to is current, and the public-website pricing or scope signals still match what the firm publishes.
It does not assert that the firm's quoted pricing is current to the dollar. Audit fees move with scope, headcount, and timeline. The verified date is for structural facts, not the quote a firm would write today.
We aim to re-check every profile quarterly, and sooner when reliable new information suggests a material fact may have changed.
A firm can request an off-cycle re-check by emailing hello@soc2auditors.org. Buyers can flag a stale stamp the same way.
Verification cadence triggers
These four events trigger an off-schedule review:
- Peer-review status change. The directory's source of truth for a CPA firm's standing is the AICPA peer-review database. A change there triggers a profile review.
- Leadership departure. Named partners and methodology leads are part of a firm's fit profile. A departure surfaced by a reader, a vendor announcement, or a public filing triggers a re-check.
- Pricing change documented in writing. A recent quote, buyer-side RFP, or published pricing update can trigger a review of the firm's range.
- Material business event. An acquisition, merger, regional expansion, or reported security incident can change the facts a buyer needs to know.
When we update
We update a page when a material fact changes, such as pricing, supported frameworks, leadership, a security incident, or a product feature. We do not reset dates to make a page look fresh. Each article shows when it was last updated and what changed.
How we make money
Audit firms, service firms, and software platforms can pay for advertising or sponsored placement. We do not take a commission, referral fee, or share of a buyer's contract. Buyers do not pay to use the directory or request quotes.
A qualified company can pay for labeled advertising or placement, which may change the company's position or presentation. Payment cannot buy eligibility, alter review findings or comparison facts, create an earned badge, suppress a correction, or change quote-match fit scores. Featured status breaks ties between equally fit audit firms only after eligibility and peer-review checks.
Corrections
Send corrections about pricing, license status, other facts, or a disputed quote to hello@soc2auditors.org. Screenshots help with pricing disputes; a recent quote for comparable scope carries more weight than an aggregated range.
We review factual corrections against the strongest available source. Material corrections receive a dated note on the affected page so readers can see what changed and when.
You can also challenge judgment calls, such as which platform fits a scenario or how we describe a weakness. We may revise them when the evidence warrants it. Email us with your reasoning.
Peter Korpak, founder.
Questions about a specific review, a partnership, or a pricing submission: hello@soc2auditors.org.