For Companies Outside the US
SOC 2 Audit Firm for Companies Outside the US: Get the Report Your US Customer Requires
Auditsuisse is a licensed US CPA firm with a Swiss entity. We run SOC 2 fieldwork remotely for companies in Europe, the UK, Latin America and Asia-Pacific — in English, French, German, Italian, Spanish or Portuguese — at published fixed fees in USD, and issue the report your US customer asks for by name.
What Your US Customer Means by "SOC 2 Certification"
Your customer's security questionnaire asks for "SOC 2 certification." What you will deliver is a SOC 2 report. A certification, such as ISO 27001, is issued by an accredited certification body against a standard. A SOC 2 report is an attestation: a licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report containing its opinion, a description of your system and the controls tested, with results. US buyers use both words; what they accept is the report.
Only a licensed CPA firm can issue it. SOC 2 examinations follow the AICPA's attestation standards (SSAE 18), which require a CPA license from a US state board of accountancy and enrollment in the AICPA Peer Review program. Your statutory auditor, a security consultancy or a compliance platform cannot sign a SOC 2 report. A non-US firm can report on the same controls under ISAE 3000, but that is a different report, and US procurement asks for SOC 2 by name.
Your customer can verify the issuer: the CPA license with the state board, the peer review status in the AICPA's public database. A SOC 2 report does not replace your GDPR, UK GDPR or LGPD obligations; it answers a different question — whether your security controls are suitably designed and, for a Type II, operating effectively.
How the Remote Audit Runs From Your Country
Fieldwork — evidence collection, walkthroughs and control testing — is performed remotely; on-site fieldwork is available. A senior auditor is assigned from day one. Our auditors work from Zurich and the US East Coast: Europe, the UK, the Middle East and Africa share working hours with Switzerland, Latin America with New York; for Asia-Pacific we hold walkthroughs in the overlapping hours and exchange evidence asynchronously in between.
Language. English, German, French and Italian across Europe, the Middle East and Africa; English, Spanish and Portuguese across Latin America. The report itself is written in English.
Platforms. GRC-platform agnostic: the fee is the same with Vanta, Drata, Secureframe, Sprinto or another platform — or none, in which case we work from spreadsheets and evidence exported directly from your systems.
The engagement, from kickoff to report:
- Discovery — we map your systems, identify the in-scope services and define the Trust Services Categories for your report.
- Readiness — an optional gap analysis, quoted separately, so your controls meet every applicable criterion before fieldwork.
- Fieldwork — remote testing of controls, evidence collection and walkthroughs with your engineering and security teams.
- Delivery — the final SOC 2 report, a management letter and support for your next reporting cycle.
It starts with a 30-minute scoping call that confirms scope, timeline and fee. Every engagement requires individual approval and confirmation of auditor independence before an engagement letter is issued.
SOC 2 Audit Fees in USD for Companies Outside the US
We publish our standard fees. The schedule is priced by total company headcount — not by where your company is based — for examinations scoped to the Security (Common Criteria) Trust Services Category, with no hourly billing.
| Company headcount | SOC 2 Type I | SOC 2 Type II | Type I + Type II (combined) |
|---|---|---|---|
| 1–50 employees | $3,000 | $5,000 | $7,000 |
| 51–100 employees | $5,000 | $7,500 | $10,000 |
| 101–200 employees | $7,000 | $10,000 | $15,000 |
| 201–400 employees | $9,000 | $12,000 | $18,000 |
| 401–999 employees | $10,000 | $15,000 | $20,000 |
| 1,000+ employees | Custom quote | Custom quote | Custom quote |
This schedule is base pricing for standard engagements. Fees may be higher for complex products or system descriptions, complex or multi-cloud environments, or on-premise infrastructure, and each engagement may be priced higher or lower at scoping. Additional Trust Services Categories are quoted at the scoping call; the fee is confirmed in your engagement letter. The combined engagement delivers the Type I report first, then the Type II covering your first observation period. See the full SOC 2 pricing schedule for inclusions and conditions, and our SOC 2 audit cost guide for what moves a quote.
Timeline: Type I or Type II, and What to Prepare
SOC 2 Type I evaluates the design of your controls as of a single date: about 4–8 weeks of fieldwork and reporting, roughly 3–6 months in total including readiness. SOC 2 Type II also tests operating effectiveness over an observation period of 3–12 months in which your controls must run and produce dated evidence: roughly 6–15 months in total. Readiness and the observation period set the schedule, not your location (see the SOC 2 audit timeline).
Which first? If a US contract is waiting, a Type I gives your customer an issued report while the Type II observation period runs — the combined engagement is built for this. If your controls have operated for three months or more and the customer insists on a Type II, go straight to it. Ask their security team which report they will accept before you choose (Type I vs Type II).
What to have ready for the scoping call:
- An inventory of the systems, cloud accounts and third-party services behind the product your US customer buys — the system boundary.
- Your security policies and a named owner for each control area.
- Evidence that controls operate: access reviews, change-management records, onboarding and offboarding records, monitoring alerts, incident records.
- Your vendor list and any existing certification or report, such as ISO 27001.
- The customer's deadline, and whether they asked for a Type I, a Type II or both.
Our SOC 2 readiness checklist covers the rest.
Already ISO 27001 Certified? Your Evidence Can Be Reused
Many companies outside the US hold ISO 27001 and are surprised when a US buyer still asks for SOC 2. ISO 27001 is a certification issued by an accredited certification body; US enterprise buyers ask for SOC 2 by name. Your ISO 27001 work is not wasted: the policies, risk assessments, access reviews and change-management records you maintain for it can be reused where they address a Trust Services Criterion. We map the overlap at scoping, test the controls against the criteria and issue our own opinion. More on SOC 2 for ISO 27001-certified companies.
One Fieldwork, Two Reports: SOC and ISAE 3402 for European Buyers
If you sell to US and European customers, their auditors may ask for different documents: a SOC report issued under SSAE 18 for the US buyer, and for a European or UK customer's statutory auditor an ISAE 3402 report, the IAASB standard that parallels SOC 1. Auditsuisse issues SOC 1 reports under SSAE 18 with ISAE 3402 dual reporting available, so one SOC 1 engagement can produce both; SOC 2 for the US buyer is a separate report from the same team. See SOC and ISAE 3402 dual reporting or the ISAE 3402 service page.
Why a US CPA Firm's Report Is What Your Buyer Accepts
A US customer's vendor-risk team checks who signed your report before reading it. Here is what they will find.
- Licensed US CPA firm. Auditsuisse Assurance NA PC, Kalispell, Montana, is a licensed US CPA firm enrolled in the AICPA Peer Review program — the two qualifications SSAE 18 requires of a SOC 2 issuer. Administrative offices in New York, Boston and Richmond.
- Swiss entity. Auditsuisse Assurance AG, headquartered in Zurich, is a Swiss-registered Expert Auditor (RAB/ASR).
- Dual-qualified leadership. Sébastien Ruosch, Director of Audits, is a Swiss CPA (Wirtschaftsprüfer, RAB/ASR license 114662) and a US CPA (license 034634), holds a Master's in Accounting, Control and Finance from the University of Lausanne, spent nearly five years in a Big Four audit practice and specializes in SOC 2 and cybersecurity.
- Senior auditor from day one, published fixed fees in USD and platform independence — and a report your customer can verify with a US state board of accountancy and the AICPA's public peer review database.
Read This in Your Language
The same offer, written for your market:
- Certification SOC 2 pour les entreprises en France — in French
- Certificación SOC 2 para empresas en España — in Spanish
- Certificación SOC 2 para empresas en México — in Spanish, for Mexico and Latin America
SOC 2 for International Companies FAQ
Can a company outside the US get a SOC 2 report?
Yes. Any service organization, wherever it is incorporated, can engage a licensed US CPA firm to examine its controls against the AICPA Trust Services Criteria and receive a SOC 2 report. Auditsuisse performs the fieldwork remotely for companies in Europe, the UK, Latin America and Asia-Pacific.
Who can issue a SOC 2 report?
Only a licensed CPA firm. SOC 2 examinations are performed under the AICPA's attestation standards (SSAE 18), which require a CPA license from a US state board of accountancy and enrollment in the AICPA Peer Review program. Consultancies, penetration-testing firms and compliance platforms cannot sign a SOC 2 report.
How much does a SOC 2 audit cost for an international company?
The same schedule as for a US company: fixed fees in US dollars by headcount for the Security Trust Services Category — $3,000 to $10,000 for a Type I, $5,000 to $15,000 for a Type II and $7,000 to $20,000 for a combined engagement (1–999 employees). These are base prices for standard engagements, confirmed at scoping and in the engagement letter.
How long does it take?
A SOC 2 Type I takes about 4–8 weeks of fieldwork and reporting, roughly 3–6 months in total including readiness. A Type II takes roughly 6–15 months in total, including an observation period of 3–12 months during which your controls must operate before they are tested. Your location does not change these phases.
Do we need a US auditor, or will a local firm do?
You need a licensed US CPA firm: only a CPA firm can issue a SOC 2 report under SSAE 18. A local firm that is not a US CPA firm can issue an ISAE 3000 or ISAE 3402 report, but not a SOC 2 report, and your US customer will ask for SOC 2 by name. If European customers also need ISAE 3402, a SOC 1 engagement can produce both reports; SOC 2 for the US buyer is a separate report from the same team.
We are ISO 27001 certified — is that enough for US buyers?
Usually not on its own. ISO 27001 is a certification issued by an accredited certification body; US enterprise buyers ask for a SOC 2 report by name, which only a licensed CPA firm can issue. Your ISO 27001 policies, risk assessments, access reviews and change-management records can be reused where they address a Trust Services Criterion; we map the overlap at scoping.
Is the fieldwork remote, and in which languages?
Yes. Evidence collection, walkthroughs and control testing are performed remotely, with a senior auditor assigned from day one; on-site fieldwork is available. We work in English, German, French and Italian across Europe, the Middle East and Africa, and in English, Spanish and Portuguese across Latin America. The report itself is written in English.
Should we start with Type I or Type II?
If a US contract is waiting, start with a Type I: it evaluates control design as of a single date and needs no observation period, so your customer has a report while the Type II observation period runs. If your controls have already operated for three months or more and the customer insists on a Type II, go straight to it.
Get Started
Get the SOC 2 Report Your US Customer Is Waiting For
A 30-minute scoping call confirms your scope, timeline and fixed fee — from wherever your company is based.