Skip to main contentChat with us

Learn · SOC Reports

Can an Indian CA
Sign a SOC 2 Report?

No — not on the strength of the ICAI Chartered Accountant qualification. A SOC 2 opinion is an AICPA attestation issued under AT-C section 205, and it must be signed in the name of a firm engaged in the practice of public accountancy: in practice a CPA firm licensed by a US state board of accountancy and subject to AICPA peer review. What any individual on the engagement happens to be qualified as is the second question, not the first.

The distinction that settles every version of this question: licensure attaches to the firm that issues the report, not to the person who does the work. A dual-qualified CA and US CPA changes nothing while they practice through an unlicensed entity — and changes everything the moment they sit inside a licensed one.

AT-C 205standard the opinion is issued under
The firmwhat must be licensed — not the individual
250+SOC 2 engagements supported by TCSA

Plain-English explainer · AT-C 105 and 205 · SSAE 21 and 23 · AICPA Code ET 1.295 · Last reviewed August 2026

No. An Indian Chartered Accountant qualification carries no authority to issue a SOC 2 report, and no combination of experience, empanelment or firm reputation in India substitutes for it. SOC 2 is an attestation engagement performed under the AICPA’s attestation standards — AT-C section 105 for the concepts common to all such engagements and AT-C section 205 for assertion-based examinations — and those standards require the opinion to be signed in the name of a firm engaged in the practice of public accountancy. In the United States that means a CPA firm holding a firm permit from a state board of accountancy and, under AICPA membership rules and most state boards’ own requirements, enrolled in the AICPA’s peer review program. The more useful version of the question is the one people mean but rarely ask: what exactly has to be licensed? The answer is the firm, not the person. An individual who holds both an ICAI membership and an active US CPA license is a genuinely valuable person to have on a SOC 2 engagement — and still cannot cause an Indian chartered accountancy firm to issue a SOC 2 report, because the license they hold is theirs and not the entity’s. Put the same person inside a licensed US CPA firm and the answer flips, not because their qualifications changed but because the name on the signature block did. Everything else on this page follows from that one distinction.

Three things people conflate

Qualification, license, and firm

Almost every argument about who can sign a SOC 2 collapses once these three are separated. They are different objects, held by different parties, granted by different authorities.

A professional qualification

What an individual earned — ICAI membership, a US CPA license, CISA, CISSP, an ISO 27001 lead auditor certificate. Qualifications describe competence. On their own they authorize nothing at the level of a report, and the AICPA’s standards never make the opinion turn on one.

A license to practice

Granted by a regulator to practice public accountancy in a jurisdiction. In the United States that is a state board of accountancy, which licenses individuals and, separately, issues firm permits. In India it is the ICAI under the Chartered Accountants Act. Neither regulator’s license operates in the other’s territory.

The firm that issues the report

The attestation standards define the practitioner as the engagement partner or, as applicable, the firm — and define a firm as an organization permitted by law or regulation, conforming to resolutions of the AICPA’s Council, that is engaged in the practice of public accounting. The report is signed in that firm’s name. This is the object that must be licensed.

Two details make this concrete. AT-C section 105 treats independence as a precondition: the practitioner must be independent to perform an attestation engagement at all, save where law or regulation compels acceptance. And AT-C section 205 requires the report to carry the signature of the practitioner’s firm and the city and state where the practitioner practices — in practice the licensed firm’s issuing office. A standard resting on a competent individual would need neither. For the general version of this question, see who can perform a SOC 2 audit; this page takes the Indian case.

Where the AT-C sections come from

The Auditing Standards Board of the AICPA issues the Statements on Standards for Attestation Engagements, and the AT-C sections are the codification those statements produce. The numbering has been re-cut recently, which is why the citations in circulation disagree with each other. SSAE No. 21 superseded AT-C sections 105 and 205 and added a section addressing direct examination engagements, effective for practitioners’ reports dated on or after 15 June 2022 — so SOC 2 collateral written before that date cites SSAE 18, and a report you were handed in 2021 is built on the earlier text. SSAE No. 23 followed with conforming amendments aligning the attestation standards with the AICPA’s quality management standards, effective as of 15 December 2025.

None of that recodification touches the analysis on this page. The requirement that the opinion be issued by a firm engaged in the practice of public accountancy survived every renumbering. If you are holding an SSAE 18-era report, you are looking at the same licensure question under an older section number, not at an obsolete one — see SSAE 18 vs SSAE 21 for what did change.

The decision matrix

Six versions of the same question

Every arrangement we are asked about reduces to one of these. Read the middle column as the answer and the right-hand column as the reason — the reasons matter more, because new arrangements keep being invented.

An ICAI-registered chartered accountancy firm in Bengaluru, with no US firm license

No

The opinion must be signed in the name of a firm engaged in the practice of public accountancy under the AICPA’s attestation standards. An ICAI firm registration number is a serious credential in its own regime and confers nothing in this one.

An individual holding both an ICAI CA and an active US CPA license, practicing through that Indian firm

No

Licensure attaches to the issuing firm, not to the person doing the work. One licensed individual does not license the entity whose name goes on the report — the single most common misreading of the rule.

The same dual-qualified individual, as engagement partner inside a US-licensed CPA firm in peer review

Yes

Here the firm signs and the firm is licensed. The partner’s Indian qualification travels well with an Indian client base, but it is not what makes the report a SOC 2.

An Indian member firm of a global network whose US member firm is a licensed CPA firm

Only the US member firm

Network membership is not a license. The report carries the licensed entity’s name and the city and state where that practitioner practices — which is why a global-network SOC 2 names a US office.

An Indian firm performs most of the testing under contract to a US CPA firm, which signs

Possible, with conditions

The standards contemplate work by an “other practitioner” outside the engagement team. What cannot be outsourced is responsibility: acceptance, direction, supervision, review and the opinion stay with the signing firm’s engagement partner.

A CERT-In empanelled auditor, or the ISO 27001 certification body that certified you

No

Different regimes. Empanelment governs security auditing for Indian regulatory purposes; ISO/IEC 27001 certificates come from accredited certification bodies. Neither is licensed to issue an AICPA attestation — and a CPA firm cannot issue an ISO certificate either.

What “licensed” actually means

A firm permit, not a certificate on the wall

American accountancy licensing is state law, not federal law, and the model the states follow is the Uniform Accountancy Act. The UAA’s definition of attest was deliberately drawn to include any examination performed under the Statements on Standards for Attestation Engagements — the family a SOC 2 belongs to. States adopt the UAA to differing degrees, so the exact boundary of regulated attest practice varies by jurisdiction; but in the states that matter for a US buyer the effect is the same. That single drafting choice is what puts SOC 2 inside the regulated practice of public accountancy rather than alongside it, and it is the reason the requirements below attach at all.

In practical terms, a firm that can issue your SOC 2 typically holds a firm permit or registration from at least one state board, is owned and controlled in accordance with that state’s ownership rules, has a licensed CPA as the engagement partner who takes responsibility for the engagement’s overall quality, and maintains a system of quality management at firm level as the standards now require. States differ on the details — permit thresholds, ownership percentages, whether a sole practitioner registers as a firm, how practice privileges work across state lines.

Two mechanisms behind that variation explain most of what a signature block looks like, and both change how you should read one. The first is firm mobility. Under the UAA model, a firm licensed in one state can generally serve clients in another without taking out a second permit there, subject to that state’s notification and registration rules. So a firm holding a single-state permit is not a red flag, and “they are only licensed in Colorado” is not an objection — it is the system working as designed. The second is that most state boards make peer review enrollment a condition of the firm permit itself. In most states, license and peer review are therefore not two independent checks but one, which is why a firm that is properly licensed and cannot produce a peer review history is an anomaly worth pressing on rather than a gap you can shrug at.

Nothing in any of this asks whether the people doing the testing are American, or where the tested system runs. It asks what the issuing firm is licensed to do.

Worth stressing to Indian founders, because the instinctive objection — “American auditors do not understand our stack” — aims at the wrong target. Engagement teams routinely mix CPAs with IT-audit specialists holding CISA or cloud credentials, and much of the testing is done by the specialists. The license governs who accepts the engagement, who directs and reviews it, and whose name goes on the opinion.

Peer review

Who audits the auditor

Licensure gets a firm through the door. Peer review is what keeps the work honest afterwards, and it is the layer sophisticated buyers actually check.

A firm performing examinations under the attestation standards is subject to a System Review under the AICPA Peer Review Program, conducted on a three-yearly cycle by reviewers from outside the firm. Firms whose attestation work is limited to reviews or agreed-upon procedures receive the lighter Engagement Review instead — which does not help you here, because a SOC 2 is an examination. Enrollment is a condition of AICPA membership for firms doing this work, and most state boards make peer review a condition of the firm permit as well, again with state-by-state variation. Within a System Review, SOC engagements are treated as “must-select”: the reviewer has to pull at least one into scope rather than sampling around them. That matters here because it means a firm cannot quietly run a SOC practice that its practice-monitoring never looks at.

The output is a peer review report with a rating — pass, pass with deficiencies, or fail — and the AICPA maintains a public file search showing a firm’s enrollment, the date its most recent review was accepted, and the period that review covered. For member firms of certain AICPA sections, and for firms that opt in, the review documents themselves are viewable. This is the closest thing SOC 2 has to the accreditation register an ISO buyer would look for, and it is public.

A three-step verification pass, in the order a security reviewer actually performs it:

Step 1

Read the signature block

The service auditor’s report — Section 1 in the usual ordering, though a meaningful share of issued reports put management’s assertion first and the auditor’s report in Section 2 — ends with the firm’s name and the city and state where the practitioner practices. Note both. If the report is signed by an individual rather than a firm, or carries no location at all, stop there.

Step 2

Verify the firm license

You are looking for a firm permit, not an individual license. NASBA’s CPAverify aggregates only participating boards and is oriented to individual licensees, so treat the relevant state board’s own firm register as the authoritative check and CPAverify as the fast first pass. Expect the name on the letterhead to differ from the registered entity — a registered DBA, an LLP that registers as a PLLC, a brand sitting over a differently named entity. That is common and usually benign, and it must be resolved rather than assumed. A firm that cannot tell you which entity holds the permit is the finding.

Step 3

Check peer review

Search the AICPA’s peer review public file for the same entity name. Confirm enrollment and look at when the most recent review was accepted and what period it covered. A firm that cannot be found at all is worth challenging — ask which program monitors its practice and when it was last reviewed.

Selecting the firm

What to ask before you sign the engagement letter

Verification tells you whether a firm that already signed something was entitled to. This is the other half: choosing the firm in the first place. Ten questions, with what a good answer sounds like beside each — the wording of the answer matters as much as its content, because a firm that has to go away and find out is telling you how routine this work is for them.

01

Which legal entity signs the report, and is that the entity on the state board register?

A specific entity name and a state, offered before you ask, with a register entry that is easy to find under that exact name. Expect the letterhead brand and the registered entity to differ; expect the firm to explain the difference without being pushed.

02

When was your most recent peer review accepted, what period did it cover, and was a SOC engagement selected in it?

A date, a period, and a straight yes. SOC engagements are must-select within a System Review, so a firm with a real SOC practice has had one looked at. “We are enrolled” answers a narrower question than the one you asked.

03

How many SOC 2 examinations does this office issue in a year?

A number and a shape — how many are Type 2, how many are first-year, what size of service organization. A firm issuing a handful a year is not disqualified, but you should know it before you are their learning curve.

04

Who is the engagement partner, are they a licensed CPA, and in which state?

A named individual you can verify on the same board register, not “a partner will be assigned at kickoff”. The engagement partner is the person the standards make responsible for the engagement’s overall quality.

05

Is any testing performed by an other practitioner or an offshore affiliate, and how does the engagement partner supervise it?

A candid yes with a supervision model attached — who reviews the workpapers, how the engagement partner satisfies themselves the work supports the opinion. Permitted arrangements get explained without hesitation. Vagueness here is the tell for license-lending.

06

What is your policy if an error is found after the report has been issued?

A described process: evaluate the effect, communicate with report users, and reissue or withdraw as the situation requires. A firm that has never had to think about this is telling you how much SOC work it does.

07

Do you work through our GRC platform’s auditor portal, or your own request list?

Either answer is fine. A firm that has done both will tell you what changes — sampling still happens on their side, and platform-collected evidence still gets tested. What you are checking is whether they have an evidence workflow rather than an inbox.

08

How long from the end of the observation period to the issued report?

A range in weeks with the drivers named — your response time on open items, how exceptions get discussed and written up. Market practice on a first Type 2 sits at roughly four to eight weeks after period end; vagueness here is the most common cause of a missed customer deadline.

09

What in your methodology triggers a qualified opinion rather than an exception described in Section 4?

A clean distinction. Individual test exceptions get described with management’s response and the opinion can stay unqualified; a criterion not met, or a description not fairly presented, moves the opinion itself. A firm that says it does not qualify reports has answered a different question.

10

Will you also sell us readiness — and if the answer is yes, why is that not an independence problem?

A firm that walks you through ET 1.295, says what it would and would not do, and shows you where it draws its own line. A firm for which the question has never come up is not the firm you want holding the pen on your opinion.

Two of those ten do most of the work. Question one, because an engagement letter signed with an entity that is not the entity on the register is the whole failure mode this page exists to describe. And question ten, because a firm that is comfortable selling you both sides has either thought hard about ET 1.295 and can show you its line, or has not thought about it at all. Both answers are informative. Only one of them is reassuring.

The dual-qualified case

Both an Indian CA and a US CPA

This is the case that deserves precision rather than a slogan, because the honest answer is “it depends on the firm, entirely”.

Start with how someone gets there. The AICPA and NASBA operate mutual recognition agreements with a handful of overseas accountancy bodies, whose members can qualify through the International Qualification Examination rather than the full US route. As of this review the recognized bodies are those of Australia and New Zealand, Canada, Hong Kong, Ireland, Mexico, Scotland and South Africa. The ICAI is not among them. An Indian CA therefore takes the ordinary path: an eligibility evaluation of their education by a US state board, the full Uniform CPA Examination, the experience requirement, and licensure by that board. Many have done it. It is a real achievement and it is not a formality.

Now the part that decides the question. That person’s license lets them practice; it does not convert the entity around them. If they are a partner in an Indian chartered accountancy firm, the firm is still an ICAI firm, still unlicensed for US attest work, and still unable to issue a SOC 2 — no matter who signs on its behalf. If they are the engagement partner at a US-licensed CPA firm, that firm issues the report, and their Indian qualification becomes exactly what it should be: an advantage in understanding an Indian client, not the source of authority.

A third configuration is common and entirely fine: a US-licensed CPA firm with an India-based delivery team, whose staff hold Indian qualifications and work Indian hours, issuing the opinion from the licensed US entity. The standards travel with the license, and the signing firm’s engagement partner remains responsible for directing, supervising and reviewing everyone who touched the work.

The other direction

What an Indian CA firm can sign

“Not a SOC 2” is not the same as “nothing”. The Indian assurance profession has its own service-organization standard, and it predates most of the SOC 2 market in India.

SAE 3402 (ICAI)

The Institute of Chartered Accountants of India’s Standard on Assurance Engagements 3402, “Assurance Reports on Controls at a Service Organisation”, effective for service auditors’ reports covering periods ending on or after 1 April 2011. It is India’s counterpart to ISAE 3402 and addresses controls relevant to user entities’ internal control over financial reporting — the SOC 1 problem, not the SOC 2 problem. Because SAE 3402, ISAE 3402 and SOC 1 address the same subject matter, a user auditor evaluating your ICFR-relevant controls may in practice be able to use an SAE 3402 report; that is a judgment for the user auditor under their own auditing framework, and not something a service organization can assert on their behalf. It does not extend to the SOC 2 subject matter, where the trust services criteria and the AT-C 205 examination have no ICAI counterpart. (The quoted title keeps the ICAI’s own spelling of “Organisation” — it is correct as quoted and should not be Americanized.)

An ISAE 3000-type assurance report against the trust services criteria

Non-US firms sometimes report on security and availability controls under a general assurance standard — internationally, ISAE 3000 (Revised) — using the AICPA’s trust services criteria as the subject matter. Such a report can be serious work and is occasionally accepted in European procurement. It is not performed under AT-C 205 and it is not a SOC 2.

ISO/IEC 27001 certification

Also outside a CA firm’s remit — certificates come from accredited certification bodies. Worth stating because the two questions arrive together: a CPA firm cannot issue your ISO certificate any more than your certification body can issue your SOC 2.

Statutory audit, internal audit, ICFR reporting and tax

The chartered accountant’s domain under Indian law, where the CA qualification is the license that matters and no American firm can substitute for it. The asymmetry runs both ways, which is the honest way to frame the whole subject.

Readiness, control design, evidence operations and advisory

No attest license is required to build the control environment, write the policies, run the gap assessment, stand up the evidence pipeline or manage the examination as a project — and that is the larger share of the total effort.

The line that must not blur: a report can be excellent and still not be the report the customer asked for. If a vendor-risk policy says “SOC 2 Type 2”, an SAE 3402 report will not satisfy it, and nor will an assurance report issued outside the AICPA system. For the comparison the other way round — and for how a user auditor is expected to think about an ICFR-relevant service organization report — see SOC 1 vs SOC 2 and AT-C 320.

When it goes wrong

A document titled SOC 2 is not a SOC 2

It happens. A company buys a “SOC 2 audit” from a firm that is not licensed to perform one, receives a professional-looking PDF with sections, criteria and an opinion paragraph, and puts it into a data room. What exists at that point is a report that looks like an attestation and is not one. The consequences land in a predictable order — and so does the recovery, which is the part nobody writes down.

What happenedWhat the buyer seesConsequenceRecovery step
You bought a “SOC 2 audit” from a firm with no US attest license and received a formatted report with an opinion paragraph.A signature block naming an entity no state board register knows, and no entry in the AICPA peer review public file.The document cannot be relied on as a SOC 2, whatever testing sits behind it. It is not one.Engage a licensed firm and treat this as a first examination. Correct the record with any customer who already holds the PDF, before their security review finds it — a self-reported correction is a procurement conversation; a discovered one is a trust event.
The report carries AICPA SOC branding.A logo whose use is restricted to licensed CPA firms and CPAs that register to use it.A branding problem stacked on a licensing one, and the fastest way for a reviewer to escalate from a question to a finding.Withdraw the document from the data room. Do not reissue the same file with the logo removed — the defect is the issuer, not the artwork.
You assumed the observation period already covered would carry over.Nothing. This one lands entirely on you.A licensed firm plans and performs its own examination rather than adopting another firm’s conclusions, so the Type 2 clock restarts from the date the new engagement is accepted.Consider a Type 1 as of a near date to hold the sales cycle open while a fresh Type 2 period runs. Ask the new firm to scope both at once so the readiness work is not repeated.
The controls, policies and evidence pipeline built during readiness already exist and are operating.A program that is real even though the report was not.The loss is the fee and the calendar, not the program. Most of the readiness build survives intact and is reusable as it stands.Have the new firm scope against what is already operating. A mature evidence pipeline usually shortens a first real examination rather than lengthening it, which is the one piece of good news in this scenario.

Two things sit outside that table. The AICPA acts against members involved in this kind of issuance and assists state boards and other regulators in relation to unlicensed firms and practitioners — that is the issuer’s problem. The commercial exposure, though, is yours: you are the party that told a customer you had a SOC 2 report, and no enforcement action against the issuer repairs that conversation for you.

Which is why the customer-communication question is worth answering plainly rather than hoping. Correct the record before the security review finds it. A self-reported correction — “the report we sent you was not issued by a licensed firm; we have engaged one and here are the dates” — is a procurement conversation with a schedule attached. The same fact discovered by a reviewer reading the signature block is a trust event, and trust events do not stay inside the security team.

The related failure mode is subtler: an entirely legitimate report described as something it is not. An SAE 3402 report called “our SOC report”. A gap assessment called “our SOC 2 readiness certificate”. A dashboard screenshot offered in place of a report. None are frauds; all fail at the same review.

Independence, precisely

Why the work has to split

Indian buyers often read the two-firm model as an upsell: a consultancy that cannot audit, selling the audit anyway. The opposite is closer to the truth. If one firm could do both without restriction the standards would say so — instead they set conditions that a full readiness build cannot realistically meet, and licensed firms respond by declining the combination.

The AICPA Code of Professional Conduct treats work a firm does for an attest client outside the attest engagement as “nonattest services”, governed by ET section 1.295, and it names the three threats such work creates: self-review, management participation, and advocacy. Two provisions decide the SOC 2 case. Under the management responsibilities interpretation (ET 1.295.030), taking on a management responsibility for an attest client impairs independence outright — no safeguard rescues it — and the interpretation lists accepting responsibility for designing, implementing or maintaining internal control among those responsibilities, alongside performing ongoing evaluations of the client’s internal control as part of its monitoring. Read the emphasis carefully: it is the acceptance of responsibility that is the management responsibility, not the design work itself.

That distinction is where the rest of the analysis lives. The general requirements interpretation (ET 1.295.040) sets the conditions under which a nonattest service is permitted at all: the client must assume all management responsibilities, designate an individual — preferably in senior management — with suitable skill, knowledge or experience to oversee the service, evaluate its adequacy and results, and accept responsibility for them. Where those conditions are met, and unless a more specific interpretation says otherwise, the threats are regarded as being at an acceptable level. Read as an operating instruction, that says your compliance program needs a real owner inside your company. A related interpretation (ET 1.295.145) governs information systems services, which is where control tooling lands.

One clarification matters if you are reading the AICPA Code alongside international rules. The AICPA framework contains no blanket prohibition on self-review. A self-review threat is identified and evaluated under the conceptual framework, and addressed with safeguards or by declining the service where it is not at an acceptable level. Some international codes are stricter, and firms that work to both apply the stricter one. So “it creates a self-review threat” is not by itself a finding under the AICPA Code — the finding is that the threat could not be reduced to an acceptable level.

None of this binds a consultancy — the Code binds the CPA firm. Two consequences follow. Accepting responsibility for designing, implementing or maintaining your internal control is out of the question for a firm that intends to examine you: no safeguard rescues it. Everything short of that — advising on a control design that management then adopts, drafting a policy management approves and owns — is a permitted nonattest service, provided the 1.295.040 conditions are met and the residual self-review threat is at an acceptable level. The practical effect is that a firm which has built the whole control environment cannot realistically clear that bar, and most licensed firms therefore decline to examine what they built rather than test the limit. That last step is market practice rather than black-letter prohibition — but it is market practice with a rule behind it, and it is why the work divides along the line below. Most disputes in a first SOC 2 start with somebody assuming the wrong column owns something.

ActivityReadiness partnerService organizationLicensed CPA firm
Scoping the system boundary and the trust services categoriesAdvises, models the options, drafts the boundaryDecides and asserts itAgrees scope in the engagement letter and evaluates whether the criteria are suitable
Writing policies and designing the control setDrafts, tailors, challengesReviews, approves, adopts and ownsMust not accept responsibility for this on an attest engagement — ET 1.295.030 lists accepting responsibility for designing, implementing or maintaining internal control as a management responsibility
Implementing tooling — identity provider, MDM, logging, vulnerability managementAdvises on configuration and sequencingOwns, operates and pays for itTests it; does not select or configure it
Gap assessment and mock auditPerforms it, writes the remediation planRemediatesRarely, and never after a full readiness build — the self-review threat has to be evaluated and safeguarded, and most firms decline rather than test the limit
Evidence collection and population extractionCoaches, quality-checks, chases ownersRuns the exports from its own systems and owns the recordsDefines what a complete population looks like and tests its completeness
Sample selectionNeverNeverAlways — the samples are the auditor’s, drawn from a population the auditor has satisfied itself is complete
Management’s assertion and the system descriptionAssists with structure and drafting against the description criteriaSigns it and stands behind itEvaluates whether the description is fairly presented
Tests of controls and the opinionNeverNeverExclusively — this is the entire point of the engagement
Bridge letter covering the gap after the period endsAdvises on wording and limitsIssues it — it is management’s letterPerforms no procedures on the gap period and does not sign it

This is the shape of every engagement we run: Tranquility Cybersecurity does readiness, control design, evidence operations and coordination; an independent licensed CPA firm performs the examination and issues the opinion. We do not certify, attest, audit or sign, and no Indian consultancy can.

Worked example

A Bengaluru platform’s first SOC 2

An illustrative composite, with the dates and the numbers carried through, because the sequencing is where the licensure question actually bites and the populations are where the split between the two firms becomes visible.

A ninety-person B2B analytics platform headquartered in Bengaluru, selling into US financial services, is asked in January 2026 for a SOC 2 Type 2 report. Its instinct is to ask the statutory auditor it has used for six years — an established chartered accountancy firm, which correctly says no. The founders then read a proposal for an “India-priced SOC 2” and notice it names no US-licensed entity anywhere.

Feb 2026

Readiness begins

Scoping workshop fixes the system boundary and the categories — Security plus Availability and Confidentiality. Gap assessment against the trust services criteria produces 31 remediation items with named owners and dates.

Feb – Apr 2026

Remediation

Policies adopted by the client, not by the consultancy. Identity provider consolidated, MFA enforced everywhere, offboarding runbook rewritten so the leaver record and the disable event share a timestamp.

Mar 2026

CPA firm selected

Three US-licensed firms quoted against the ten questions above. License checked on the state board register, peer review checked in the AICPA public file, engagement letter signed with the client — not with the consultancy.

30 Apr 2026

Type 1 as of date

Design and implementation examined at a point in time. The report goes into the sales cycle while the Type 2 clock runs.

1 May – 31 Oct 2026

Type 2 observation period

Six months. Evidence accrues continuously rather than being reconstructed; the auditor defines populations in September and selects samples itself.

Nov – Dec 2026

Fieldwork and issuance

Exceptions discussed, management responses drafted, report issued in December in the name of the CPA firm, signed with the firm’s name and the city and state where it practices.

What the September population request looked like

Five requests, five populations, five sets of samples the auditor drew itself. The client produced every population out of its own systems; the readiness team quality-checked the exports and chased owners, and touched no selection. Sample sizes are the examiner’s call, not ours, and they scale with the population — which is why eleven leavers drew a sample of eight while 1,140 deployments drew forty.

ControlPopulation producedAuditor’s sampleResult
Access removal on terminationCC6.311 leavers in the period, reconciled to the HR system rather than typed into a spreadsheet8 selected by the auditorOne exception. A leaver was disabled four days after their last working day on 12 Jul 2026 — the ticket existed, the timing did not match the control as described.
Change managementCC8.11,140 production deployments, reconciled to the deployment history40 selectedNo exceptions. Two selections had to be re-pulled because the export truncated the approver field, which is an evidence problem rather than a control problem.
Quarterly user access reviewCC6.22 in-period reviewsBoth selectedNo exceptions. The revocation tickets closed the test, not the review meeting — the control is the removal.
Backup restoration testA1.26 monthly restore tests3 selectedNo exceptions. Each log named the object restored, the person who verified it and the timestamp.
MFA enforcementCC6.1The identity-provider configuration, plus its change history for the period1 configurationNo exceptions. The change history was what proved the setting held from 1 May onward; the screenshot on its own would have proved a moment.

The outcome: an unqualified opinion, with the single termination-timing exception described in Section 4 alongside management’s response — the runbook change that had already been made in August, and the monitoring added to catch a recurrence. That is what a healthy first Type 2 looks like. An exception described and answered is not a failure; a report with no exceptions and eleven leavers in the population is a report a careful reviewer reads twice. The finished report went on to be reused across the next three enterprise deals without a further security questionnaire.

Two things about it are worth noticing. Every system it describes runs in India and everyone who collected the evidence sits in India — and the signature block names a US city, because that is where the licensed firm practices. Had they taken the cheaper route in January, the same prospect’s security team would have reached that signature block on the first read, and the company would have restarted in April with a six-month period it no longer had time for.

Evidence

What the CPA firm actually asks for

This is the part of the split that Indian teams underestimate, and it is where a readiness partner earns its fee. The examiner does not ask for “proof of your access review”. It asks for a population, satisfies itself that the population is complete, selects its own samples from it, and then tests each one against the control as described. Every step of that sequence can fail on evidence that looked fine to the person who gathered it.

A population is the complete set of times a control should have operated during the period — every leaver, every production change, every month of the backup test. Completeness is tested independently: the leaver population against the HR system, the change population against the deployment history. A hand-typed list is not a population, and an incomplete one invalidates the sample drawn from it however good the individual artifacts look. The sample sizes below are ranges commonly applied in practice — they follow from the AICPA’s sampling guidance and each firm’s methodology and risk assessment rather than a number fixed in AT-C 205, so treat them as planning assumptions and confirm with your examiner.

Control cadencePopulation requestedTypical sampleArtifact that satisfies itWhy it gets rejected
AnnualRisk assessment, policy review, DR test, penetration testThe single occurrence, with evidence of when it happened and who approved it1The approved risk register showing review date and approver; the DR test report naming participants, scenario and resultsUndated documents; approval by whoever prepared the work; a test report covering a different entity or environment
QuarterlyUser access reviews, privileged-access recertification, vendor reviewAll four occurrences in the period, with dates and reviewers2 (typical)The exact user list reviewed, the reviewer’s decisions, and the tickets showing revocations were actionedA review that ends at “reviewed” — the control is the removal, not the meeting; a list rebuilt afterwards
MonthlyBackup restoration testing, patch cycle, log review sign-offTwelve occurrences, system-generated where possible2–3 (typical)A restore log showing a file or database was actually restored and verified, with timestampsA screenshot proving the backup job succeeded — that is not a restore test; a month with an explanation instead of a record
WeeklyAlert triage review, vulnerability scan reviewThe full set of weeks in the period5–8 (typical)The week’s scan output plus the triage record showing what was accepted, deferred or fixed, and by whenScans with no evidence of what happened next; findings past their own remediation SLA with no risk acceptance on file
DailyJob monitoring, backup monitoring, security alert handlingEvery day in the period, drawn from the monitoring system rather than a spreadsheet15–25 (typical)The alert or job record for the selected date, the responder, and the resolution trailAggregated dashboards without underlying records; gaps where the tool was reconfigured mid-period and history was lost
Event-drivenOnboarding, offboarding, production changes, incidentsThe complete population of joiners, leavers, changes or incidents, reconciled to an independent source such as the HR system or the deployment history25–40 (typical)For a leaver: the HR termination record, the identity-provider disable event and the access-removal ticket, with dates that line upA hand-typed leaver list; a disable date weeks after the last working day; a change approved after it was deployed
Automated or configuration-basedMFA enforcement, encryption at rest, password policy, session timeoutThe configuration itself, tested once where the surrounding IT general controls are reliable1 configuration (typical)A screenshot showing tenant, console context, the setting and the date — plus change history proving it held all periodCropped screenshots with no context; a setting shown on the last day of the period and nowhere else

Mapped to criteria, the pattern is the one every SOC 2 follows: access provisioning against CC6.2, modification and removal against CC6.3, within the logical-access architecture CC6.1 describes; monitoring and anomaly detection against CC7.2; change management against CC8.1; vendor and business-partner risk against CC9.2; and, where Availability is in scope, backup and recovery against A1.2. The criteria come from TSP section 100, and the system description that frames them is written against the description criteria in DC section 200. Our SOC 2 controls list and trust services criteria guide go criterion by criterion.

Beyond the cadence table, the rejections we see most often across engagements:

  • Screenshots with no context — no tenant or account name, no URL or hostname, no visible date. The examiner cannot tell whose system it is or when it looked like that.
  • A configuration demonstrated on the last day of the period with nothing showing it held on the first. A Type 2 tests operation throughout the period; a snapshot proves a moment.
  • An access review with no follow-through. The reviewed list exists, the decisions exist, and the revocation tickets do not — so the control described has not been evidenced.
  • Approvals from the requester: a change approved by the engineer who wrote it, or a policy approved by its own author, fails the segregation the control describes.
  • A penetration test report addressed to a different legal entity, or covering staging while the description scopes production.
  • Populations produced by the readiness partner rather than the client. The examiner tests the service organization’s control and its records — a consultant’s tracking spreadsheet is not the system of record, and offering it invites an independence question as well as an evidence one.

Two structural items sit alongside the control evidence and catch teams out because they are not technical: complementary user entity controls — what your customers must do for your controls to work — and subservice organizations, where you choose between the inclusive and carve-out methods. Both live in the system description and both are management’s call. See CUECs and CSOCs and subservice organizations.

Where this gets contested

The edge cases that generate arguments

The rule is simple. The twenty percent of situations that do not read cleanly off it are where the real questions live.

The global network argument

An Indian firm belongs to an international network whose US member is a licensed CPA firm, and proposes to sign as “part of” that network. Networks share brands, methodologies and quality frameworks; they do not share licenses. The engagement letter, the opinion and the signature must belong to the licensed entity, and the report will name its office. If the proposal is vague about which legal entity signs, that vagueness is the answer.

Work performed by another firm

The standards recognize an “other practitioner” — an independent practitioner outside the engagement team whose work is used as evidence, possibly from a network firm or an unrelated firm. This is a real and permitted arrangement. What it is not is a license-lending scheme: the engagement partner of the signing firm remains responsible for acceptance, competence of the team, direction, supervision, review and the opinion. If nobody at the signing firm can explain how a test was performed, the arrangement has failed regardless of how it was papered.

The sole practitioner

A single licensed CPA may practice as a registered firm in many states, so “firm” is not a headcount test. The tests that matter are whether the entity issuing the report holds a permit to practice and is enrolled in peer review, and whether its quality management is real. Verify those two things rather than counting partners.

Readiness and audit under one roof, papered as two

A firm performs the readiness through an affiliate and the examination through the licensed entity, with the same people on both. The Code contemplates this: the analysis looks at the firm and its network, at management responsibilities actually assumed, and at the cumulative effect of multiple nonattest services. A separation that exists only on letterhead is not a separation, and it is the signing firm that carries the consequence.

CERT-In empanelment and Indian regulatory audits

Empanelment lets a firm perform security audits for Indian regulatory purposes. It is a meaningful credential in that context and has no relationship to AICPA attestation. The same is true in reverse: a US CPA firm is not thereby empanelled. Organizations often need both, from different providers, for different audiences.

A US-licensed firm that has never had a SOC engagement reviewed

Licensure and peer review enrollment are the floor, not the ceiling. A firm may be properly licensed and enrolled while being new to SOC work. Ask when its most recent peer review was accepted, what period it covered, and whether a SOC engagement was selected in it — SOC engagements are must-select, so a firm with a mature SOC practice will have had one looked at.

Type 1 versus Type 2

The licensure question does not move with the report type. A Type 1 examines design at a point in time and a Type 2 adds operating effectiveness over a period; both are examinations under AT-C 205 and both require the same issuing firm. A firm that cannot sign your Type 2 cannot sign your Type 1 either.

An entirely Indian system, examined from the US

Nothing in the standards ties the examination to the geography of the system. Data centers in Mumbai, staff in Hyderabad, customers in New York — the examination tests the described system wherever it runs. What does change with geography is practical: evidence in local formats, statutory records that need explaining, and a working-hours overlap that has to be planned rather than hoped for.

Objection handling

What the buyer’s security team pushes back on

Six questions, in roughly the order they arrive in a vendor review. Have the answers ready — hesitating on any of them reads as uncertainty about your own report.

Your auditor is in the United States. How did they test controls running in Bengaluru?

The same way they test controls running in Boston. A SOC 2 examination is evidence-based, not site-based. On the engagements we support that means read-only auditor accounts in the identity provider, screen-shared console walkthroughs where the auditor directs the query rather than watching a prepared demo, exports the client runs while the auditor observes the export being run, and timestamped ticket histories the auditor pulls itself. Remote fieldwork is the norm on those engagements, and no standard imposes geography on where the tested system sits.

Your consultant and your auditor are different firms. Is that a red flag?

It is the opposite. Under the AICPA Code, a firm that has accepted responsibility for designing or implementing your internal control has assumed a management responsibility, and independence is impaired with no safeguard available. A full readiness build sits squarely in that territory, which is why the licensed firms decline it. The separation you are looking at is the rule working. The sharper question to put to us is who produced the populations the auditor sampled from — the client, out of its own systems, or the consultant, out of a tracking spreadsheet. Only the first answer is acceptable.

Our statutory auditor already knows the business. Can they sign it to save time?

No — and the familiarity offered as the benefit is one of the things independence rules exist to manage. Indian statutory audit rights and AICPA attestation rights are separate systems, and holding one implies nothing about the other. In practice the statutory auditor is genuinely useful context for the readiness team, because they already know the entity structure, the finance systems and where the records live. They are no part of the examination. A statutory auditor who declines this request cleanly is telling you something good about the firm.

We already hold ISO 27001 from an Indian certification body. Is that not the same assurance?

Different regime, different output. ISO/IEC 27001 certification says an accredited certification body found a management system conforming to the standard, and the certificate itself is a page. A SOC 2 Type 2 gives a licensed firm’s opinion against the trust services criteria plus the description of the system, every test the auditor performed, every exception found and management’s response to it — typically sixty pages or more of readable detail. Many buyers accept the certificate as evidence that a program exists and still want the report, because the report is the part they can actually review.

The report names a US city, but our supplier is an Indian company. Is it genuine?

That is the expected pattern. AT-C 205 requires the report to carry the signature of the practitioner’s firm and the city and state where the practitioner practices — in practice the licensed firm’s issuing office, not the service organization’s address. An Indian company with a report issued from Denver or Tampa is entirely normal, and the engagement team may well have been sitting in Bengaluru. The pattern that deserves a second look is the reverse: a document titled SOC 2 signed by an Indian firm from an Indian city, which no state board register will recognize.

A local firm quoted us a much cheaper SOC 2. Why should we pay more?

Because there is no cheaper SOC 2 — there is a cheaper document that is not one. Ask the quote to show three line items: the name of the licensed entity that will sign, the number of controls to be tested with indicative sample sizes, and the fieldwork weeks. Cheap quotes are usually cheap because one of those three has been removed — an unlicensed signer, a control set trimmed down to whatever evidence already exists, or a week of walkthroughs sold as a Type 2. The saving is taken at quotation and repaid at the first enterprise security review.

Frequently Asked Questions

Can an Indian Chartered Accountant sign a SOC 2 report?

No. The ICAI Chartered Accountant qualification confers no authority to issue a SOC 2 opinion. A SOC 2 is an attestation engagement performed under the AICPA’s attestation standards — AT-C section 105 and AT-C section 205 — and those standards require the report to be signed in the name of a firm engaged in the practice of public accountancy, which in practice means a CPA firm licensed by a US state board and subject to peer review. The engagement team can include chartered accountants, CISAs and cloud specialists; the firm that issues the opinion is what must be licensed.

What if the CA also holds a US CPA license — can they sign then?

It depends entirely on the firm they sign for. A US CPA license lets that individual practice; it does not convert the entity around them. As a partner in an Indian chartered accountancy firm they still cannot cause that firm to issue a SOC 2, because the firm holds no US permit. As engagement partner inside a US-licensed CPA firm they can, because the firm signs. Note also that the ICAI is not party to the AICPA and NASBA mutual recognition agreements, so an Indian CA takes the full US examination route: an education evaluation by a state board, the Uniform CPA Examination, the experience requirement and licensure.

Is a SOC 2 report issued by an Indian firm valid?

If the issuing firm is not licensed to perform attestation engagements, the document is not a SOC 2 report at all — validity is the wrong question. It cannot be relied on as one, it will not survive a vendor-risk review that checks the signature block against a state board register, and the examination generally has to be performed again by a licensed firm, which restarts the observation period. The nuance worth holding: an Indian company can absolutely have a genuine SOC 2 report. What it cannot have is one issued by an unlicensed firm, wherever that firm sits.

Does the audit team have to be American?

No, and this is the most common misreading of the rule. Nothing in the attestation standards requires a nationality, or requires the team to be near the system. Engagement teams routinely combine CPAs with IT-audit specialists, and many US-licensed firms run India-based delivery teams. The license governs which entity accepts the engagement, whose engagement partner directs, supervises and reviews the work, and whose name appears on the opinion. Geography is a scheduling matter, not a licensing one.

Can our statutory auditor in India perform our SOC 2?

No. Indian statutory audit rights and AICPA attestation rights are separate systems, and holding one implies nothing about the other. Even a highly capable firm cannot issue a report under standards it is not licensed to practice under. The statutory auditor can be useful context for the readiness team — they know your entity structure, systems and finance controls — but they play no part in the examination. Asking them and getting a clear no is a good sign about the firm.

What can an Indian CA firm legitimately sign instead?

A great deal. The ICAI’s Standard on Assurance Engagements 3402, “Assurance Reports on Controls at a Service Organisation”, effective for reports covering periods ending on or after 1 April 2011, is India’s counterpart to ISAE 3402 and covers controls relevant to user entities’ internal control over financial reporting — the SOC 1 subject matter. A user auditor may in practice be able to use such a report when evaluating your ICFR-relevant controls, though that judgment is theirs, not yours to assert. Statutory audit, internal audit, ICFR reporting and tax remain the CA firm’s domain by law. And no attest license is needed for readiness, control design, evidence operations or advisory work.

Why can our compliance consultant not also perform the audit?

Because the AICPA independence rules make it unworkable in practice. Under the Code’s nonattest services provisions, accepting responsibility for designing, implementing or maintaining a client’s internal control is a management responsibility, and taking on a management responsibility for an attest client impairs independence with no available safeguard. Work short of that is a permitted nonattest service only where management assumes responsibility, designates a competent individual to oversee and evaluate the service, and accepts the results — and only where the residual self-review threat is at an acceptable level. A firm that built your whole control environment cannot realistically clear that bar, so licensed firms decline the combination rather than test it.

How do we verify the firm that signed a SOC 2 report we have been given?

Three steps, four minutes. Read the signature block at the end of the independent service auditor’s report — usually Section 1, though some reports place management’s assertion first — and note the firm name and the city and state where the practitioner practices; AT-C 205 requires both. Check that exact entity against the relevant state board of accountancy register, treating NASBA’s CPAverify as a first pass rather than the authority, since it covers only participating boards and is oriented to individuals. Then search the AICPA’s peer review public file for the same name to confirm enrollment, when the most recent review was accepted and the period it covered.

Does using a US CPA firm make a SOC 2 more expensive for an Indian company?

The attestation fee is contracted with and billed separately by the CPA firm. We do not publish a band for it, because it moves with things you control: the trust services categories in scope, the number of distinct systems and environments in the description, whether subservice organizations are carved out or included, the number of locations and legal entities, how many controls the description commits to, and whether this is a first-year examination or a repeat. Plan the calendar as well as the fee — market practice on a first Type 2 is the observation period plus roughly four to eight weeks to an issued report. The controllable share is readiness and evidence, quoted after scoping, with a fixed fee from $4,000 for early-stage startups, scaling with scope.

Is it illegal for a non-CPA firm to issue a SOC 2 report?

The precise position depends on the jurisdiction the firm operates in, and it is a question for a lawyer rather than an auditor. The professional position is clear: performing attest work without a license is unlicensed practice in US states, the AICPA acts against members involved and assists state boards and other regulators in relation to unlicensed firms and practitioners, and the AICPA’s SOC branding is restricted to licensed CPA firms that register to use it. From a buyer’s standpoint the answer is simpler — the report is not a SOC 2.

Related reading: who can perform a SOC 2 audit, attestation vs certification, how to read a SOC 2 report, opinions and exceptions, how long a SOC 2 report stays usable, SSAE 18 vs SSAE 21, and the SOC 2 hub.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: August 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations