What is a SOC 2 auditor?
A SOC 2 auditor is a licensed CPA (Certified Public Accountant) firm whose practitioners are qualified to examine a service organization’s controls against the AICPA’s Trust Service Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). Unlike PCI QSA, there’s no centralized certification — any licensed CPA firm can in theory issue a SOC 2 report, but the market has concentrated around firms with dedicated SOC 2 practices. The deliverable is a SOC 2 Type 2 report, which covers a period (typically 3–12 months) and includes the auditor’s opinion on whether the controls were operating effectively.