SOC 2 Type I audit (licensed, AICPA peer-reviewed CPA firm only) for a B2B SaaS platform

via Freelancer ·

Budget / Salary$250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
We are looking for a licensed CPA firm to perform a SOC 2 Type I examination (AICPA SSAE 18, AT-C 205) of our SaaS platform, with an option to continue into a Type II examination.

About us

B2B SaaS: application lifecycle management for regulated industries (medical device, pharma, aerospace)
Hosted entirely on AWS (ECS, Aurora PostgreSQL, CloudWatch); source control and CI/CD on GitHub
Small team: 3 people
Existing controls: role-based access, SSO/SAML, MFA, a tamper-evident audit trail, automated CI security gates, a documented incident response plan, and backup/DR runbooks

Scope

Trust Services Criteria: Security (required) and Availability
Type I as of a point-in-time date to be agreed (target: [month 2026/2027])
Please quote Type I alone and a Type I + Type II bundle (3–6 month observation window)

Requirements (bids that don't meet these will not be considered)

A licensed CPA firm. The report must be signed by the firm, not by an individual consultant.
Enrolled in the AICPA Peer Review Program, with a recent peer review result of "Pass"
Has issued SOC 2 reports for SaaS companies before. Please send a redacted sample or references.
Independent: you will audit only. Readiness work is handled internally.

Please include in your bid

Firm legal name, state(s) of CPA licensure, and license number
Peer review details (date and result)
Fixed price for Type I, and for the Type I + Type II bundle
Timeline from engagement to report
Whether you work with Vanta, Drata or Secureframe, or accept evidence directly

Not looking for: consultants, "SOC 2 certificates", readiness-only services, or firms that can't issue the report themselves.

Licensed CPA firm. The SOC 2 report must be issued and signed by the firm, not by an individual. Provide the firm's legal name, state(s) of licensure and license number.
AICPA Peer Review (mandatory).
The firm must be enrolled in the AICPA Peer Review Program
Its most recent review must be a System Review with a rating of "Pass"
The review must cover attestation engagements under SSAE (SOC examinations), not only tax, bookkeeping or compilations
Provide the peer review date, the reviewing firm, and a copy of the peer review report or a link to it in the AICPA public file
SOC 2 experience. You have issued SOC 2 reports for SaaS companies before. Provide a redacted sample report or two client references.
Independence. You will perform the audit only. Readiness work is handled internally.
accounting audit compliance risk management continuous integration cloud security financial consulting saas cpa services
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.