HomeBlog › How to Choose a SOC 2 Auditor: 9 Questions to Ask a CPA Firm Before You Sign

How to choose a SOC 2 auditor: 9 questions to ask a CPA firm before you sign

Published 2026-08-21 · 8 min read · BALTUM

In the US, a SOC 2 report can be signed only by a CPA firm holding a valid state permit, not by a consultant, a platform or an individual accountant. Yet most European buyers choose their auditor on price and a LinkedIn recommendation. Here are the questions that separate a report your customers will accept from one they will question.

1. Which state licenses your firm, and what is the permit number?

Ask for the state, the firm permit number and check it yourself in the state board register or the NASBA licence lookup. The licence sits with the firm, not the person on the sales call. A firm that hesitates here is a firm to avoid.

2. Is your latest peer review public, and did it include SOC engagements?

CPA firms undergo a peer review every three years. SOC 1 and SOC 2 are "must-select" engagements, so a firm that performs them should have at least one in the reviewed sample. Ask for the report and look for a "Pass" rating without deficiencies. A firm whose last published review is five or six years old is a warning sign, whatever the website says.

3. Have you implemented SQMS No. 1?

Since 15 December 2025, US CPA firms must operate a quality management system under SQMS No. 1, with the first annual evaluation due by 15 December 2026. Firms that cannot explain how outsourced staff, automation platforms and engagement acceptance fit into that system are behind the standard.

4. How many SOC 2 reports does each signing partner issue per year?

Two hundred reports a year across forty professionals is healthy. Two hundred reports across three people is not. Since 2026 AICPA peer reviewers have been told to look for unrealistic timelines and near-identical reports across clients. A firm that promises "Type 2 in three weeks" is taking a risk that eventually lands on its clients.

5. Who sets the audit fee, and is it fixed?

Under AICPA ethics rules the CPA firm sets its own fee. If a consultant or platform quotes you "the audit" as part of a bundle they price and mark up, something is wrong with the structure. You should receive an engagement letter directly from the CPA firm with a fixed fee for the defined scope.

6. Does any platform or partner have rights over your scope, timing or opinion?

Ask whether any agreement with a compliance-automation vendor or referral partner gives that third party influence over scope, evidence, fees or marketing, or contains a non-disparagement clause. Any "yes" is an independence problem that AICPA called out explicitly in 2026.

7. Can you work with a European company?

Practical points: time zones for walkthroughs, willingness to sign a data processing agreement, experience with EU cloud regions and GDPR, and whether the firm can map SOC 2 to ISAE 3000 if your European customers ask for it. Firms with a presence in Ireland or the UK make this easier.

8. What does the timeline look like, realistically?

Expect 4–8 weeks from the end of the observation period to the final report. Ask how fieldwork is scheduled, how long the draft review takes and what happens if exceptions are found. A firm that refuses an unrealistic deadline is showing you its quality system working.

9. What insurance and what references?

Professional liability cover appropriate to your customer base, and two references from companies of your size. A short call with a past client tells you more than any brochure.

How BALTUM fits in

BALTUM does not issue SOC 2 reports and is not a CPA firm. We prepare your controls and evidence, run the internal readiness audit and introduce you to independent, licensed US CPA firms that we have checked against exactly these questions. You contract with the CPA firm directly, the firm sets its own fee, and we never receive a share of it. One role per client, never both. If you already have an auditor in mind, we are happy to work alongside them.