Hael
Book a meeting
SOC 2 · Choosing support

How to choose the right SOC 2 consultant

Hael · Published 7 August 2026 · Last reviewed 29 August 2026 · 10 min read
Key takeaways
  • Bring in help when nobody internally has protected hours, when the deadline is fixed, or when a first Type 2 has to be built from very little.
  • The consultant builds and prepares. The CPA firm examines and issues the report. Nobody may credibly do both for the same engagement.
  • Insist on implementation and project management, not advice alone. Advice without delivery is where deadlines are lost.
  • Ask how the firm works inside Vanta, Drata or Secureframe, because the platform decides how much of the evidence is automatic.
  • Compare pricing models before comparing prices. Fixed fee against a written scope is the only quotation that can be compared.

First decide whether you need one

A consultant is worth the fee in three situations. Nobody internally has several protected hours a week to own the programme. The date is fixed by a customer contract and the arithmetic is tight. Or this is a first report and the control environment has to be built rather than documented.

Outside those situations, a company with an experienced security lead, a narrow scope and a compliance platform can reach a Security-only Type 1 with no external help at all. Deciding that honestly first saves a great deal of money, and it also sharpens what you ask for if you do go to market.

Understand the two roles before you buy either

This is the distinction buyers most often get wrong, and it changes who you are allowed to hire for what.

The consultantThe CPA firm
PurposeBuilds and prepares the control environmentExamines it and issues the report
Typical workScope, gap assessment, policies, control implementation, evidence design, project management, audit preparationPlanning, testing, sampling, interviews, opinion
Who may do itAny suitably experienced firmA licensed CPA firm only
IndependenceWorks alongside your teamMust remain independent of the preparation work
DeliverableA control environment and an evidence setThe SOC 2 report

One firm may not prepare your programme and then examine it. Any provider suggesting otherwise should be removed from the shortlist immediately. Our own position is unchanged across every engagement: we prepare, an independent CPA firm examines, and we take no commission from that firm.

Where to find candidates worth speaking to

Companies one stage ahead of you are the strongest source, particularly ones at your size that finished within the last eighteen months. Your investors often keep an informal list, and your enterprise buyer's vendor security team reads a great many reports and knows whose preparation survives review.

If you have already selected the CPA firm, they can usually name consultancies they have worked alongside and found well prepared. They cannot advise you on preparing for their own examination, which is a different thing.

Platform partner directories at Vanta, Drata and Secureframe list firms that know those tools well. Ask in every case whether referral fees pass in either direction, because in partner programmes they sometimes do.

What a consultant should actually deliver

Ask for the deliverables as a list. A programme described only as a programme is not comparable to anything.

  • A written scope: systems, services, criteria selected and what is explicitly excluded
  • A gap assessment against the Trust Services Criteria you have chosen
  • Policies written from how your company genuinely works, not templates
  • Control implementation, including the configuration changes each control depends on
  • Evidence design, so operating a control leaves a dated record as a by-product
  • Project management: the schedule, the chasing and the weekly view of what is outstanding
  • Audit preparation: evidence coordination, interview briefing and remediation of findings
  • A defined end point, stated as readiness, start of the observation period, or the report

Test implementation capability, not advisory polish

Advice is cheap to give and hard to use. The question that separates the two is technical: ask how they would evidence a quarterly access review in your particular systems.

A firm that implements names the system where the review will happen and explains that it produces a dated, attributable record automatically. A firm that advises describes gathering screenshots. A Type 2 examination samples across a period, so evidence assembled afterwards is exactly what the sampling is designed to detect.

Ask the same question about change approval, joiner and leaver access, and vendor review. Three answers will tell you whether the firm has done this inside a live engineering organisation.

Test project management capability

Most SOC 2 deadlines are missed on coordination rather than on difficulty. Dozens of small tasks sit across engineering, IT, HR, legal and leadership, and they wait unless somebody owns the chasing.

Ask who runs the schedule, how often you will see the outstanding list, and what happens when an internal owner misses a date twice. If project management is excluded from the fee, assume the work still exists and that it has landed on you.

Ask about Vanta, Drata and Secureframe specifically

A compliance platform connects to your cloud accounts, identity provider and repositories, monitors configuration continuously and collects a large share of the evidence automatically. Which platform you own changes what remains manual, so platform experience is a practical question rather than a badge.

Ask which of the three the firm has worked in most recently, how they configure the control set against your chosen criteria, what the platform will not evidence in your architecture, and who works through the list of exceptions it produces. A firm that treats the platform as the programme has misunderstood the tool; a firm that ignores it will bill you for work the tool does for a subscription.

We work inside whichever platform you already own. Where there is none, the engagement runs on the Hael platform, which is included in the fee and remains yours afterwards.

Questions to ask before you engage

  • How would you scope this engagement, before we discuss fees?
  • Who is the named practitioner, and how many hours a week are committed?
  • Is the person in this meeting the person who will deliver?
  • How would you evidence a quarterly access review in our systems?
  • Which platform have you worked in most recently, and how do you configure it?
  • Does the fee include project management, and who chases our internal owners?
  • When exactly does your involvement end: readiness, observation period, or report?
  • Our deadline is [date]. Does the arithmetic work, and if not, what do you propose?
  • Do you receive commission or referral fees from CPA firms or platform vendors?
  • What is excluded from the fee, in writing?

Red flags

  • An offer to both prepare and examine, or vagueness about who issues the report
  • A guaranteed pass, or a guaranteed date given before any scoping conversation
  • A Type 2 promised inside a window shorter than the observation period allows
  • A single-page quotation with one number and no scope
  • Template policies presented as deliverables
  • Project management priced as an optional extra
  • No named practitioner, or a name that changes after signature
  • Commission arrangements that only surface when you ask twice
  • Evidence described as a collection exercise before the audit
  • An engagement that quietly ends at the readiness report while quoted as a route to a report

How engagements are priced

Three models are common, and each is legitimate for different work.

ModelSuitsWhat to watch
Fixed fee against a written scopeDefined programmes: readiness, implementation, route to a first reportConfirm the exclusions and the change mechanism, or the fixed fee is fixed only in name
Hourly or day rateGenuinely open-ended work, or short specialist inputAsk for an estimate and a cap; without one the budget is unbounded
Monthly retainerThe observation period, evidence upkeep and ongoing support after the reportConfirm what the monthly hours cover and what triggers extra fees

The CPA firm's fee is separate in every model, and should be shown separately. A quotation that folds an examination fee into an advisory fee is either an error or an independence problem.

Our engagements are fixed fee against a written scope with exclusions named. Ongoing work after the report is a separate retainer, described in continuous governance and assurance.

How to compare providers fairly

Give all three firms the same written brief: what your buyer requires, the systems you think are in scope, your real deadline and who internally is available. Proposals written against different briefs cannot be compared, and that is usually why the cheapest looks cheapest.

Then compare in this order: scope, exclusions, deliverables, responsibility split, end point, named practitioner, and only then fee. Take two references at your size and ask each what slipped and how it was handled.

What to do next

Write down the buyer requirement, the report type and the real deadline before you speak to anyone. A vague brief produces a vague scope, whoever you hire.

Our free readiness diagnostic gives a first view of where you stand. The scorecard for the selection conversation itself is in the SOC 2 consultant evaluation checklist. If you would rather we ran the programme, the SOC 2 service page sets out scope, delivery and fees.

References

FAQ

Do I actually need an SOC 2 consultant?

Not always. If someone internally has protected hours, the scope is narrow and you own a compliance platform, a first Security-only report is achievable without help. Bring in a firm when the hours do not exist, the deadline is fixed, or the control environment has to be built rather than documented.

What is the difference between an SOC 2 consultant and the auditor?

The consultant builds and prepares the control environment. A licensed CPA firm examines it and issues the report. The same firm may not do both for one engagement, because that would remove the auditor's independence.

How should an SOC 2 engagement be priced?

Defined work is best bought as a fixed fee against a written scope with exclusions named. Hourly rates suit short specialist input, and a monthly retainer suits the observation period and upkeep after the report. The CPA firm's fee is always separate.

Does platform experience matter when choosing?

Yes, practically. Vanta, Drata and Secureframe each automate a different share of evidence in a given architecture, so ask which the firm has worked in recently and who works through the exceptions the platform reports.

What is the clearest red flag?

Any firm offering to prepare the programme and also issue the report, or guaranteeing a pass or a date before scoping. Both indicate a provider you cannot rely on in front of an examiner.

About Hael

Hael is a compliance consultancy specialising in SOC 2, information security and technology assurance. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.