# SOC 2 Auditor | Secureframe

> Learn what a SOC 2 auditor does, how to select a qualified CPA firm, key evaluation criteria, audit firm red flags, and what to expect from your SOC 2 audit engagement.

canonical: https://secureframe.com/glossary/soc-2-auditor

SOC 2 auditors evaluate how effective your security program is and determine whether your internal controls meet the requirements of your chosen Trust Services Criteria (TSC).

## What is a SOC 2 auditor?

[SOC 2 audits](https://secureframe.com/blog/soc-2-audit-checklist) can only be conducted by a licensed CPA firm or agency accredited by the [American Institute of Certified Public Accountants ](https://secureframe.com/glossary/aicpa)(AICPA).

A SOC 2 auditor evaluates how effective your security program is and determine whether your internal controls meet the requirements of your chosen Trust Services Criteria (TSC). 

Depending on the period of time your report covers and whether you’re pursuing a SOC 2 Type 1 or a SOC 2 Type 2 report, your auditor will spend anywhere from a few weeks to a few months working with your team before producing [a SOC 2 report](https://secureframe.com/hub/soc-2/what-is-a-soc-2-report).

This [audit report covers](https://secureframe.com/hub/soc-2/report-coverage) the auditor’s findings, including a description of the audit scope, results of testing and a list of any cybersecurity issues they uncovered during the audit, and their recommendations for improvements or remediation requirements. It also includes a management assertion, which allows your organization to make claims (or “assertions”) about your own systems and controls.
