Key Takeaways:
- Only a licensed CPA firm can legally issue a SOC attestation report under AICPA standards (SSAE 18, AT-C 105/205). A similar-looking report from an unlicensed vendor isn’t a SOC report, regardless of what it’s called.
- CPA licensure carries independence rules, mandatory peer review, and legal accountability through a state board of accountancy, which a general security vendor doesn’t carry.
- Some firms selling SOC services outsource the CPA signature to the end of the engagement instead of staffing CPA oversight throughout, which separates institutional knowledge of your environment from the professional accountability behind the opinion.
- Buyers can verify a firm’s licensure and peer review standing directly before signing an engagement letter, a check that takes minutes and changes what the report is worth later.
Ask a firm marketing “SOC audits” one question before you sign anything: are they a licensed CPA firm? A surprising number can’t answer yes.
A SOC report is an attestation, not a general assessment. Under AICPA standards (SSAE 18 and the AT-C 105/205 attestation framework), only a licensed CPA firm can issue one. A security consultancy can run the same control testing, write a similar-looking report, and call it a SOC examination, but without a CPA firm’s signature behind it, and active involvement throughout the examination, that report carries no professional standing your clients, auditors, or regulators can rely on. The word “audit” gets used loosely across this industry. The CPA license is the one thing that doesn’t bend.
A CPA LICENSE BRINGS OVERSIGHT A COMPLIANCE VENDOR CAN’T REPLICATE
Licensure carries obligations that outlast the day the credential is issued. It comes with independence rules that govern what other work a firm can do for a client without compromising its attestation opinion. It comes with mandatory peer review: a licensed CPA firm’s own attestation work gets examined by outside reviewers on a recurring cycle, with the results a matter of public record. And it comes with accountability that follows the firm past the engagement, through its state board of accountancy and through professional liability that a general security vendor doesn’t carry.
While that difference doesn’t always show up on a sales call, it’s bound to show up later, when a client’s own auditor asks who performed the SOC examination and whether that firm’s report will hold up under review.
SIGNATURES CAN BE BOLTED ON AT THE END
Determining licensure can get murky for buyers. Some firms selling SOC services hold no CPA license of their own. They run the fieldwork, the interviews, and the control testing, then contract a CPA firm at the end to review the file and sign the opinion. The people who understand your environment for months aren’t the people whose license is on the report.
That arrangement is common, and the CPAs involved may do the review carefully. But it separates the engagement’s institutional knowledge from its professional accountability, and that gap can lead to inconsistency: a signing CPA who wasn’t in the room for the fieldwork has less visibility into judgment calls made along the way, and a firm structured this way has less incentive to build long-term quality control into how it runs engagements, because the license itself was never theirs to protect.
WHAT TO ASK BEFORE YOU SIGN AN ENGAGEMENT LETTER
A prospective audit firm should be able to answer these:
- Is the firm itself a licensed CPA firm, not just staffed with individuals who happen to hold a CPA license?
- Can they produce their current AICPA peer review results without hesitation
- Does the team performing the fieldwork report to the same firm whose name goes on the opinion, or is the signature outsourced?
- In which states is the firm licensed to practice, and does that match where your clients or regulators expect the report to originate?
A firm that answers these queries affirmatively without deflection is showing you something a sales deck never will: that the license is structural, not decorative.
THE VARIABLE THAT DECIDES WHETHER THE REPORT HOLDS UP
Choosing a SOC examination firm on price or turnaround time alone skips the one variable that determines whether the report means anything once it leaves your hands. A licensed CPA firm brings independence, peer review, and legal accountability your clients are counting on, whether they know to ask about it or not.
Read more about 360 Advanced’s SOC examination and attestation services, and see the AICPA’s peer review resources for the public for how to verify a firm’s standing before you sign.