Who can issue a SOC 2 report in the EU?

Updated 9 min read soc2pentest

This is the question European vendors ask last and should ask first. A SOC 2 report is a specific professional product with a specific author, and the market around it is full of companies whose marketing implies otherwise.

What a SOC 2 report actually is

A SOC 2 is not a certificate, a badge or a score. It is an attestation report: a professional opinion, issued after an examination, about controls at a service organization. The Journal of Accountancy, the AICPA's own publication, describes the family plainly: "Established in 2011, SOC reports are examinations performed by CPAs in accordance with the AICPA's Statements on Standards for Attestation Engagements to evaluate the controls over customer data that service organizations such as cloud providers or payroll processors have in place."

Two things in that sentence do the work. Examinations: a defined engagement type with rules about evidence, sampling and independence. Performed by CPAs: the author is a licensed professional, and the report carries the weight it does because a professional body can discipline them for signing a bad one.

The relevant standards are the AICPA's clarified attestation standards, introduced by SSAE No. 18 and identified by the AT-C prefix. SSAE No. 18 "establishes requirements for performing and reporting on examination, review, and agreed-upon procedures engagements", and for a subject-specific engagement "applicable requirements are contained in AT-C Section 105; AT-C Section 205, 210, or 215 depending on service level; and the subject-matter section". It has been effective for practitioners' reports dated on or after 1 May 2017.

Who may perform the examination

A CPA firm. That is the whole answer, and the interesting part is the corollary. The AICPA has been unusually public about enforcement recently, publishing this notice on its own SOC pages: "If auditors involved in these matters are found to have not performed audits in accordance with professional standards, not been enrolled in peer review, and/or are unlicensed, the AICPA will take action with respect to its members."

Read the three conditions in that sentence as a shopping list. The firm should be licensed, enrolled in peer review, and performing the engagement in accordance with the standards. A prospective client is entitled to ask about all three before signing, and a firm that finds the question awkward has answered it.

The tool-vendor problem

A large market of compliance-automation platforms now sits between service organizations and CPA firms. They are genuinely useful: instead of collecting dozens of screenshots, a firm can connect to a client's systems and pull evidence into one dashboard. The problem is what some of them promise on the way in.

The Journal of Accountancy is blunt about the structural issue: "Because most of the new tool providers are not CPA firms, they cannot attest that the controls in place are effective and appropriate. Instead, some tool vendors have cultivated networks of accounting firms – often smaller ones, and sometimes with overseas operations – to complete the examinations." It also notes that these vendors "may promise compliance (a term never used in SOC 2 examinations) in mere weeks – or even just hours" and that, thanks to heavy investment "especially in search-engine optimization", they now dominate the search results for SOC 2 services.

The AICPA's Professional Ethics Division has since spelled out where the ethical risk lands. Business arrangements with tool providers "may create threats to a service auditor's compliance with the Code", specifically an "undue influence threat … pressure to subordinate judgment" and a "self-interest threat … financial or other benefits tied to fee arrangements with the tool provider". Its guidance to members is to "closely evaluate any terms that shift control, professional judgment, financial dependency, promotional efforts, or access to evidence away from the member and toward the tool provider".

A peer review alert followed in May 2026, telling reviewers that "reviewing a single SOC 2 engagement file is often insufficient to address these specific risks", and quoting the AICPA's vice president for ethics and firm quality: "Some firms are leaning too heavily on third-party SOC platforms without applying the professional judgment required by our standards."

None of this makes platforms bad. It makes the identity of the signing firm, and the terms it works under, something you should look at rather than accept as part of a bundle.

Can a European firm sign one?

Yes, and many do. Nothing about the report is geographically restricted; what is restricted is who performs the examination and under which standards. In practice EU-based signers are member firms of international accounting networks, or specialist IT-audit firms whose engagement partners hold the necessary license. The Journal of Accountancy's reference to referral networks that include firms "sometimes with overseas operations" is a description of the same reality from the other direction.

The practical questions are therefore about the firm, not its address: is it licensed, is it enrolled in peer review, has it performed SOC 2 examinations in your sector, and who exactly will do the fieldwork. A firm in Dublin or Amsterdam that answers those well is a better choice than a distant firm that answers them vaguely.

The international alternative, and the mapping people get backwards

Europe has its own assurance framework, published by the International Auditing and Assurance Standards Board. Two of its standards matter here, and they are routinely confused.

SOC reports and their international counterparts
ReportStandardSubject matterDistribution
SOC 1AICPA SSAEsControls at a service organization likely relevant to user entities' internal control over financial reportingRestricted
ISAE 3402IAASBThe same subject matter: controls likely relevant to user entities' internal control as it relates to financial reportingRestricted
SOC 2AICPA SSAEsControls relevant to security and, where selected, availability, processing integrity, confidentiality or privacyRestricted to specified parties
ISAE 3000 (Revised)IAASBThe general standard for assurance engagements other than audits or reviews of historical financial information, which is where the SOC 2 subject matter fallsSet by the engagement
SOC 3AICPA SSAEsThe same subject matter as SOC 2 with far less detailGeneral use, may be freely distributed
ISAE 3402 is the SOC 1 analogue and ISAE 3000 is the SOC 2 analogue. Getting that pair the wrong way round is the most common error in European vendor documentation, and an auditor will notice it.

The entry price for issuing an ISAE report is not a registry, it is a set of professional conditions. ISAE 3000 (Revised) is premised on the engagement team being "subject to Parts A and B of the Code of Ethics for Professional Accountants issued by the International Ethics Standards Board for Accountants (IESBA Code) … or other professional requirements … that are at least as demanding", and on the practitioner being "a member of a firm that is subject to ISQC 1" – the firm-level quality control standard, since superseded by ISQM 1 – "or other professional requirements … at least as demanding". Paragraph 31(a) makes the same point as a hard requirement on the engagement partner.

The standard even anticipates outsiders: "If a competent practitioner other than a professional accountant in public practice chooses to represent compliance with this or other ISAEs, it is important to recognize that this ISAE includes requirements that reflect the premise in the preceding paragraph." In other words, it is the ethics code and the firm-wide quality system that gate the report, not a license number. In practice that means an audit or IT-audit firm.

Why a security firm can still do most of the work

Here is the part that surprises people, and it comes from the standards themselves rather than from anyone's marketing.

The AICPA publishes the trust services criteria as criteria "for use in attestation or consulting engagements to evaluate and report on controls over the security, availability, processing integrity, confidentiality, or privacy of information and systems used to provide products or services". The criteria were never reserved to the examination. Measuring yourself against them, or hiring someone to measure you against them, is an ordinary consulting engagement.

ISAE 3000 draws the same boundary from the other side. Paragraph 6 lists engagements that are expressly not assurance engagements and therefore not covered by the ISAEs at all, including "consulting (or advisory) engagements, such as management and tax consulting".

So the division of labour is not a compromise; it is the design. Readiness work, control design, evidence collection, penetration testing and remediation are consulting and testing. The examination and the opinion are assurance. One firm doing both would create exactly the independence problem the ethics guidance above is written to prevent.

There is no such thing as "SOC 2 certified"

Compliance, in the words of the AICPA's own magazine, is "a term never used in SOC 2 examinations". There is no certificate, no pass mark and no register. What exists is a report with an opinion in it, and the opinion can be unqualified, qualified, adverse or disclaimed.

This matters commercially rather than pedantically. A vendor promising to make you "SOC 2 certified" in weeks is telling you how the engagement will be run. As one member of the AICPA's SOC 2 Working Group put it about template reports: "You just know it's a template. You can compare any five of their reports, and they're all exactly the same, with a different client logo on it." Another was blunter about what happens when a business partner rejects the result: "it's not worth the paper it's on".

Restricted use, and what to hand a customer

A SOC 2 report is "restricted to specified parties with sufficient knowledge and understanding of the service organization's system and the nature of services it provides". That is why it is shared under a non-disclosure agreement and never published. If a customer, a partner or a marketing page needs something anyone can read, the answer is a SOC 3: "Like SOC 2, SOC 3 reports address controls relevant to security, availability, processing integrity, confidential and privacy. However, they do not provide the same level of detail", and they "are considered general use reports and can be freely distributed".

Many organizations commission both from the same examination. It costs little extra and it removes an argument from every future procurement conversation.

A checklist for choosing your firm

  • Licensing and peer review: ask for both, and ask what the last peer review found.
  • Who does the fieldwork, and where. A named engagement partner and a named senior beats a brand.
  • Sector experience with a system like yours. Multi-tenant SaaS, a payments flow and a data-processing bureau raise different questions.
  • Scope and sampling: how many items, over what period, and what happens when a sample fails.
  • Independence: what other services the firm sells you, and what its arrangement with any platform in the deal actually says.
  • Timeline realism. If the answer to "how fast?" is faster than your observation window, something has been left out.
  • Whether the firm will also issue a SOC 3 from the same examination.

That list is close to the one the AICPA's own working group published for clients, which is a reasonable sign it is the right list. Once you have a firm, the remaining question is what you actually have to have ready for them. That is what the readiness gap finder is for, and the testing side of it is covered in scope, timing and the report. If you have not yet settled whether SOC 2 is the right document at all, start with SOC 2 or ISO/IEC 27001 for an EU vendor.

Sources

  1. Promises of 'fast and easy' threaten SOC credibility Journal of Accountancy · 2026 SOC reports as CPA examinations under the SSAEs; tool providers that are not CPA firms cannot attest; restricted use; "compliance" is never used in SOC 2 examinations.
  2. SOC 2 – audit and assurance topic page AICPA & CIMA The AICPA notice on professional standards, peer review enrolment and licensing.
  3. SOC engagements: Ethics risks with tool providers Journal of Accountancy · 2026 Undue influence and self-interest threats, and the terms members should evaluate.
  4. AICPA guides peer reviewers to address SOC 2 risks Journal of Accountancy · 2026 The May 2026 reviewer alert and the warning about over-reliance on SOC platforms.
  5. Auditing Standards Board caps clarity project with attestation standards Journal of Accountancy · 2016 SSAE No. 18, the AT-C identifier, AT-C sections 105 and 205, and the 1 May 2017 effective date.
  6. SOC 1 and SOC 3 topic pages AICPA & CIMA SOC 1 subject matter, and SOC 3 as a general use report that can be freely distributed.
  7. ISAE 3000 (Revised), Assurance Engagements Other than Audits or Reviews of Historical Financial Information IAASB · 2013 Paragraphs 3, 6 and 31 on the IESBA Code, quality control and the exclusion of consulting engagements; the conforming amendments carry the ISAE 3402 scope.
  8. 2017 Trust Services Criteria (with revised points of focus, 2022) AICPA & CIMA · 2023 The criteria are published for use in attestation or consulting engagements.

Questions

Related questions

Can a compliance platform issue our SOC 2 report?

No. A platform that is not a CPA firm cannot attest to anything. Platforms collect evidence; a CPA firm performs the examination and signs the report. If the platform is arranging the firm for you, look closely at what the arrangement says about fees, evidence access and deadlines.

Is a SOC 2 report recognized by EU regulators?

Not as a regulatory instrument. It is a private-sector attestation, useful as evidence in a customer's due diligence and largely absent from EU legislation. The EU's NIS2 technical requirements are expressly based on ISO/IEC 27001 and ISO/IEC 27002, and name no SOC report.

Should we ask for ISAE 3000 instead?

Only if your customers ask for it. ISAE 3000 is the international equivalent and is well understood by European auditors, but a US buyer with a vendor-review checklist will be looking for the words "SOC 2". Ask the customer which document closes their review before choosing.

Can the firm that helped us prepare also do the examination?

No, and you should not want it to. Independence is the reason the report is worth anything. Keep the readiness work and the examination in separate firms and the question never arises.