How to choose a SOC 2 compliance consultant
- Ask nine questions. The answers separate firms far more reliably than credentials or website copy do.
- Insist on a fixed fee with itemised scope, and confirm in writing whether the auditor's fee is included.
- Find out who covers the observation period, not just the build. That is where programmes most often stall.
- Ask to see a sample policy and how it would be adapted to your architecture.
- Confirm the firm has no financial interest in which auditor or platform you choose.
What the decision turns on
Choose a SOC 2 consultant on three things: whether they will do the work rather than only advise on it, whether the fee is fixed and itemised, and whether they stay involved through the observation period. Most disappointing engagements trace back to one of those three not being settled in writing before work started.
Below are the questions worth asking, and what a useful answer sounds like.
The nine questions to ask
1. Who does the work, and who will I actually be speaking to? Ask for the name of the practitioner who will run your programme and how many hours a week they will give it. A named person with protected time is the strongest predictor of a programme that finishes.
2. How do you set scope, and what happens if it changes? Scope decides your fee, your timetable and whether the finished report answers your buyer's question. A good answer starts with your customer contracts and your buyer's requirements, not with platform configuration. Ask what triggers a change of fee.
3. Is the fee fixed, and is the auditor's fee inside it? Ask for a written, itemised fee. The auditor's fee is almost always separate. Knowing that at the proposal stage prevents an unpleasant surprise later.
4. Can you show me a sample policy, and explain how you would adapt it to our stack? Every firm has a policy library. What matters is how the library is adapted. If the answer cannot connect a policy to your deployment pipeline, your access model or your team structure, the adaptation is likely to be light.
5. Who runs the programme during the observation period? The build phase is the visible one. The observation period is where evidence stops being collected and reviews get skipped. Ask explicitly whether their engagement ends at the readiness assessment, at the start of the observation period, or at the report.
6. Which auditors do you work with, and do you receive anything for the referral? A firm with working relationships across several CPA firms can help you choose one that fits your size and sector. Ask directly whether any payment or commission passes between them, and get the answer in writing.
7. What is your position on the compliance platform we already own? If you have already bought a platform, the right answer is that they will work inside it and configure it properly. If you have not, ask what they recommend and why, and whether they have any commercial interest in that recommendation.
8. Can I speak to two clients of a similar size? Ask for references from companies at your stage and in your sector, then ask those companies one specific question: what slipped, and how was it handled?
9. What have you seen go wrong, and how did you fix it? A practitioner who has run real programmes will answer this immediately and specifically. It is the question that most reliably separates experience from presentation.
What a good proposal contains
| Element | What to look for |
|---|---|
| Scope | Named systems, named services, the criteria selected, and what is explicitly excluded |
| Deliverables | Listed individually: gap assessment, policy set, control implementation, evidence framework, audit support |
| Fee | Fixed, itemised, with the auditor's fee shown separately and clearly marked as separate |
| Timetable | Dated milestones, including the observation period start and the target examination date |
| Responsibilities | What the firm does and what your team must do, written down |
| Named practitioner | The individual who will run it |
| After the report | Whether ongoing support is included, optional or absent |
Comparing proposals fairly
If a proposal is a single page with one number on it, ask for the detail before comparing it with anything else. Two proposals cannot be compared until both state the same scope.
Comparing consultancy, platform and auditor
These three are frequently confused in sales conversations. Keeping them separate makes the buying decision much simpler.
| What it provides | What it cannot do | |
|---|---|---|
| Compliance platform | Continuous monitoring, automated evidence collection, a list of what is missing | Write the policy, change the engineering process, make the controls run |
| Consultancy | Scope, control design, policies, evidence framework, project management, audit preparation | Issue the report |
| CPA firm | The examination and the report | Prepare you for its own examination |
Where independence matters
You are buying judgement, so it is worth knowing what shapes it. Ask whether the firm takes commission from audit firms, whether it receives referral fees from platform vendors, and whether it certifies as well as advises. None of those arrangements is improper on its own, and many well-run groups operate two entities precisely so both services can be offered cleanly. What matters is that you know the arrangement before you choose, rather than after.
For our part, we are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. That is set out on our about page.
What to do next
Write down your buyer's actual requirement, your target date and your budget before you speak to anyone. Those three facts turn a vague conversation into a comparable proposal.
Then ask two or three firms the nine questions above and compare the written answers rather than the calls. If you would like a fixed-fee, requirement-by-requirement view of where you stand before you commit to a full programme, that is our readiness and gap assessment, and our SOC 2 service page sets out how the wider programme runs.
References
FAQ
What should a SOC 2 consultant cost?
Typically $15,000 to $50,000 for a full first programme at a small to mid-sized company, with the auditor's fee separate. Standalone gap assessments usually run $5,000 to $25,000. See what a SOC 2 consultant does for the full breakdown.
Should I hire a specialist or a large firm?
Both work. Large firms bring breadth and brand recognition that some boards value. Specialists usually give you more of a senior practitioner's direct time. Ask both the same nine questions and compare the answers.
Does the consultant need to be in my country?
Not usually. SOC 2 is a United States attestation standard and most fieldwork is remote, so location matters less than sector experience and time-zone overlap with your team. Location-specific guidance is in UK SOC 2 consultants and US SOC 2 consultants.
How do I check a consultant's track record?
Ask for two references at your size and in your sector, and ask those references what slipped and how it was handled. That question produces more useful information than a case study does.
What is the single biggest mistake when choosing?
Comparing fees before comparing scope. Two proposals with different scopes are not comparable at any price.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act, from first assessment to report, and maintain the position afterwards. Every engagement has a named practitioner and an agreed scope, timetable and fee. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.