What should you assess before hiring an SOC 2 consultant?
- Assess a provider on twelve procurement criteria and score each one, rather than forming an overall impression from a sales call.
- A good consultant sets scope from your customer's requirement, not from a template or a platform configuration.
- Insist that policies be written from how your company actually works. Template policies fail in the interviews.
- The strongest single mark of quality is a firm that tells you early what will not work.
- Ask for the responsibility split in writing before signing. It prevents almost every dispute that follows.
How to use this checklist
This page is a procurement instrument rather than an introduction to the market. It assumes you have already decided that external help is required and have two or three firms to assess. If you are still at the earlier decision, start with how to choose an SOC 2 consultant.
Score each criterion below out of three across every candidate, and record the evidence for the score rather than the impression. Weight scope clarity, evidence ownership and timeline realism most heavily, because those three are where programmes fail after signature rather than during selection.
The seven marks of a good consultant
| Mark | What good looks like | How to test it |
|---|---|---|
| Scoping method | Starts from your customer contract and the security review that triggered this | Ask them to walk you through how they would scope your engagement, before any fee discussion |
| Named practitioner | One person accountable, with committed weekly hours | Ask for the name and the hours in writing |
| Written responsibility split | Every workstream has one owner, yours or theirs | Ask for a responsibility table with the proposal |
| Evidence design | Controls designed so a dated record exists automatically | Ask how they would evidence a quarterly access review in your systems |
| Observation period cover | Engagement runs through the period, not to the readiness report | Ask explicitly when their involvement ends |
| Honesty about the deadline | Tells you on the first call if the arithmetic does not work | Give them a deliberately tight date and see what they say |
| Independence | No commission from accounting firms or platform vendors | Ask directly, in writing |
1. How they scope
Scope decides your fee, your timetable and whether the finished report answers your buyer's question. A good consultant starts from your customer contract and the security review that prompted this, then works out which systems and criteria that implies.
A weaker approach starts from the platform, or from a standard scope applied to every client. The result is either a report covering more than the buyer asked about, which costs more without closing the deal faster, or one drawn so narrowly that the buyer reads it and comes back with questions.
Ask a candidate to describe how they would scope your specific engagement. The answer takes two minutes and tells you a great deal.
2. The named practitioner
Ask who will run your programme, what they have done before, and how many hours a week they will give it. Then ask whether that person is the one in the room during the sales conversation.
There is nothing improper about a firm where a senior person sells and a different person delivers, provided you know which is which and the delivering practitioner is experienced. What you want to avoid is discovering the arrangement in week three.
3. The responsibility split, in writing
Ask for a table listing every workstream with one name against it. Who writes the policies. Who configures the identity provider. Who chases the evidence owners. Who books the accounting firm. Who briefs the interviewees. Who answers the buyer's follow-up questions.
Almost every dispute in these engagements traces back to an item nobody claimed. Getting it written down costs an hour and removes the argument entirely.
4. How they design evidence
This is the most technical of the seven and the most revealing.
Ask how they would evidence a quarterly access review in your particular systems. A good answer names the system where the review will happen and explains that it produces a dated, attributable record as a by-product. A weaker answer describes gathering screenshots.
The distinction matters because a Type 2 examination samples across a period. Evidence assembled afterwards is precisely what the sampling is designed to detect, and the exception appears in the report your buyer reads.
5. Whether they cover the observation period
The build phase has a deadline and gets attention. The observation period runs for three to twelve months with nothing formally due, and it is where programmes drift. Reviews get skipped in a busy quarter, evidence stops accumulating, and the auditor's sampling finds the gap months later.
Ask explicitly whether the engagement ends at the readiness assessment, at the start of the observation period, or at the report. All three are legitimate products at different prices. They are frequently quoted as though they were the same one.
Where the need continues beyond the report, that is our continuous governance and assurance service.
6. Whether they will tell you something you do not want to hear
Give a candidate a deliberately tight deadline and see what happens.
A good consultant does the arithmetic out loud. If you want a Type 2 in eight weeks and the shortest acceptable observation period is three months, they say so on the first call and offer the alternatives: a Type 1 now with a Type 2 to follow, or a conversation with your buyer about the date.
This is the single most useful signal available in a sales conversation, because the failure mode it protects against, agreeing to a date and revisiting it in month five, is expensive and common.
7. Independence
Ask three questions and get the answers in writing. Do you take commission from any accounting firm? Do you receive referral fees from platform vendors? Do you certify as well as advise?
None of these arrangements is improper on its own, and many well-run groups operate separate legal entities precisely so both services can be offered cleanly. What matters is that you know the arrangement before you choose rather than after.
Our own position is that we are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. It is set out on the about page.
8. Type 1 and Type 2 experience, separately evidenced
These are different engagements and a firm may have real depth in one and none in the other. A Type 1 assesses the design of controls at a point in time. A Type 2 assesses whether they operated across a period, which is where sampling, evidence continuity and drift become the whole problem.
Ask how many Type 2 programmes the named practitioner has taken through examination, over what observation periods, and what the most common exception was. A firm that cannot describe an exception it has had to remediate has probably not been through the period end.
9. Who owns the evidence, during and after
Evidence ownership is the criterion buyers most often leave undefined and most often regret. Establish before signature who assembles each evidence set, where it is stored, whether the store is yours or the provider's, and what you are left holding when the engagement ends.
The test is simple: ask what happens to the evidence library if you do not renew. If the answer is that the record lives in the provider's tenancy and leaves with them, price the cost of rebuilding it into the comparison. Where an engagement runs on the Hael platform, the record is the client's and remains with the client afterwards.
10. Engineering involvement, quantified
Most of the control changes behind an SOC 2 report land on engineering: identity and access configuration, branch protection and approval rules, logging, backup and restore, vulnerability handling, infrastructure change control.
Ask the provider to estimate the engineering hours their plan assumes, by workstream, and to say which changes they will make themselves against which they will specify for your team. A proposal with no engineering estimate in it has moved an unquantified cost onto your roadmap.
11. CPA independence, tested rather than assumed
The examination must be performed by a licensed CPA firm that is independent of the preparation work. A provider that prepares your controls cannot also examine them.
Ask three questions and take the answers in writing: who will perform the examination, what commercial relationship exists between the provider and that firm, and who chooses it. A provider that helps you run a fair selection and takes nothing from the outcome is behaving correctly. Hael prepares and supports; the opinion is the CPA firm's alone, and we take no commission from audit firms or platform vendors.
12. Timeline realism and pricing transparency
Test the timeline by giving each candidate your genuine deadline and asking for the arithmetic. An honest provider maps backwards from the examination date through the observation period, the remediation window and the gap assessment, and tells you on the first call if the date cannot hold.
Test pricing by requiring a fixed fee against a written scope, with exclusions named, the change mechanism stated and the CPA firm's fee shown separately. Then ask what has caused a fee change on their last three engagements. Providers who quote a single number without a scope are not cheaper; they are unpriced.
Ongoing compliance support after the report
An SOC 2 report covers a period that ends, and the next period begins immediately. Assess what each provider offers afterwards: monthly control checks, evidence upkeep, exception handling, scope changes as you add systems, and support for the following examination.
Establish whether that support is included, optional or absent, and what it costs, before you compare headline fees. Ours is a separate retainer, described in continuous governance and assurance.
Buyer checklist
Score each criterion out of three, note the evidence, and compare totals across candidates.
| Criterion | What to require | Score /3 |
|---|---|---|
| Scope clarity | Systems, services, criteria and named exclusions in writing | |
| Named practitioner | The individual who will deliver, with committed weekly hours | |
| Responsibility split | Every workstream with one named owner | |
| Type 1 experience | Design assessments taken to report | |
| Type 2 experience | Programmes taken through an observation period and examination | |
| Policy and control implementation | Written from your processes, with the configuration work included | |
| Evidence ownership | Who assembles it, where it lives, what you keep at the end | |
| Engineering involvement | Estimated hours by workstream, and who makes each change | |
| Project management | Named owner of the schedule and the chasing, included in fee | |
| Platform experience | Recent delivery in Vanta, Drata or Secureframe | |
| CPA independence | Who examines, who chooses, and what commercial links exist | |
| Timeline realism | Backward arithmetic from the examination date, on the first call | |
| Pricing transparency | Fixed fee, named exclusions, change mechanism, CPA fee separate | |
| Ongoing support | Included, optional or absent, and priced |
Warning signs during procurement
- A proposal that describes a programme but does not list deliverables
- No engineering estimate anywhere in the plan
- Evidence stored only in the provider's tenancy with no exit position
- A single fee covering both preparation and examination
- A Type 2 date that requires an observation period shorter than the criteria allow
- Project management, remediation or audit support priced as later extras
- A named practitioner who is not present in any technical conversation
- References that cannot confirm the programme reached a report
What a good proposal looks like
| Element | What to expect |
|---|---|
| Scope | Named systems and services, criteria selected, and what is explicitly excluded |
| Deliverables | Listed individually rather than described as a programme |
| Fee | Fixed and itemised, with the accounting firm's fee shown separately and marked as separate |
| Timetable | Dated milestones including observation period start and target examination date |
| Responsibilities | The table described above |
| Named practitioner | The individual, with committed hours |
| Change mechanism | What triggers a fee change and how it is agreed |
| After the report | Whether ongoing support is included, optional or absent |
Two proposals cannot be compared until both state the same scope. If one is a single page with one number on it, ask for the detail first.
What to do next
Write down three things before you speak to anyone: what your buyer requires, your real deadline, and who internally will be available. Those turn a vague conversation into comparable proposals.
Then score the checklist above across two or three firms and keep the evidence beside each score. Our readiness and gap assessment provides the detailed internal picture for a fixed fee, and the SOC 2 service page sets out how we scope, deliver and price a programme if you would rather we ran it.
References
FAQ
What should we assess before hiring an SOC 2 consultant?
Scope clarity, named practitioner, responsibility split, Type 1 and Type 2 experience, policy and control implementation, evidence ownership, engineering involvement, project management, platform experience, CPA independence, timeline realism, pricing transparency and ongoing support. Score each one and record the evidence.
Who should own the evidence produced during the engagement?
You should. Establish before signature where the evidence library lives and what you retain if the engagement ends, because rebuilding an evidence set held in a provider's tenancy is a real and avoidable cost.
How much engineering time should we budget?
Ask the provider to estimate it by workstream rather than accepting a total. Identity and access, change approval, logging, backup and restore and vulnerability handling are where the hours concentrate, and a plan without an estimate has moved that cost onto your roadmap.
Can the provider that prepares us also perform the examination?
No. The examination must be performed by a licensed CPA firm independent of the preparation work. Ask who will examine, who selects them and what commercial relationship exists with your provider.
How do we compare two very different fees?
Normalise the scope first. Require a fixed fee against a written scope with exclusions named, the change mechanism stated and the CPA fee shown separately. Fees are only comparable once both proposals describe the same work.
About Hael
Hael is a compliance consultancy specialising in SOC 2, information security and technology assurance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope with exclusions named, a responsibility table and a fixed fee. We are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.