top of page

Elevating the Standard for SOC 1 and SOC 2 Audits.

A SOC report is only as valuable as the quality behind it. The SR Quality Certification is the industry’s premier quality signal, allowing organizations and vendor management teams to easily identify SOC 1 and SOC 2 reports backed by uncompromising audit integrity.

The Problem: The Commoditization of Compliance

Not all SOC reports are created equal. As the demand for SOC 1 and SOC 2 reports has skyrocketed, the market has been flooded with "check-the-box" audits, software-driven rubber stamps, and a race to the bottom on price and rigor. This is devaluing SOC 1 and SOC 2 reports and causing vendor management teams to no longer be able to rely on SOC reports, eliminating the key benefits of having a SOC audit performed.


The SR Quality Certification exists to cut through the noise. It provides a clear, undeniable signal to the market that a CPA firm holds itself to a high standard of quality.

What is the SR Quality Certification?

The SR Quality Certification is a powerful market signal that a SOC 1 or SOC 2 report can be trusted and relied upon.

Overseen by Fine Assurance, the SR Quality Certification acts as the ultimate gatekeeper for SOC audit quality. To award the certification, Fine Assurance performs a rigorous, two-fold review process. First, Fine Assurance validates the quality of the CPA firm that issued the SOC report, evaluating their peer review records, technical excellence, and independence from compliance software platforms. Second, Fine Assurance conducts an in-depth quality review of the issued SOC report and the CPA firm’s supporting workpapers to ensure the audit was performed in a manner that meets Fine Assurance’s quality baseline for performing a quality SOC audit.

Certified Logo Transparent_edited.png

The Power of the SR Quality
Certification Signal

For Companies Purchasing a SOC 1 or SOC 2 Audit

Don't let a low-quality audit cost you your biggest deal. When evaluating CPA firms for your next SOC 1 or SOC 2 audit, ensure their issued SOC reports will qualify for the SR Quality Certification.

  • Enterprise Acceptance: Providing a Quality Certified SOC report signals to your enterprise customers that you care about the quality of your security program and ensures your audit withstands rigorous third-party scrutiny.

  • Real Security Value: CPA firms capable of earning the certification on their SOC reports look beyond the checklist, providing genuine insights that improve your control environment rather than just pushing you across the finish line.

For Vendor Management & Procurement Teams

Trust, but verify the SOC report. You review dozens of SOC reports a year, and you know that a flawless SOC report from a low-rigor firm is a red flag.

  • A Reliable Quality Benchmark: When a vendor hands you a SR Quality Certified SOC report, you know the audit was performed with depth and precision because both the SOC report and the CPA firm’s supporting workpapers have been independently reviewed.

  • Streamlined Third-Party Risk: Reduce the time your team spends scrutinizing SOC reports. A SR Quality Certified SOC report means the auditor's work, testing procedures, and overall CPA firm quality have been thoroughly vetted and can be relied upon.

For CPA Firms

Differentiate your practice in a crowded market. If your CPA firm refuses to compromise on quality, earning the SOC Report Quality Certification for your SOC reports is your platform to prove it to the market.

  • Signal Your Quality: Display the SOC Report Quality Certification seal directly on your issued SOC 1 and SOC 2 reports to instantly communicate your commitment to audit quality to clients and the broader market

  • Become a Member of the Trusted Auditor Alliance: Stand out from low-quality CPA firms and show the market your commitment to high-quality SOC reporting. CPA firms earning the SR Quality Certification on 10 issued SOC 1 or SOC 2 reports are eligible for an invitation to the Trusted Auditor Alliance. Fine Assurance reserves full discretion to adjust this threshold, accepting fewer or requiring more reports to be SR Quality Certified based on its review of the CPA firm's overall quality and the volume of SOC Reports issued per year. Click here to learn more about the Trusted Auditor Alliance.

SOC Report Eligibility Requirements for SR Quality Certification

Peer Review Requirements

  • The CPA firm must be enrolled in the AICPA’s Peer Review Program

  • The CPA firm’s Peer Review Information must be publicly displayed on the AICPA’s Peer Review Public Search website (https://peerreview.aicpa.org/public_file_search.html).

  • The CPA firm’s Peer Review must be current. 

    • For CPA Firms with at least one completed Peer Review: The next review due date (documented in the CPA firm’s Administering Entity’s Acceptance Letter) must not be past due. If the due date has already passed, SOC reports issued by the CPA firm are not eligible for the SR Quality Certification.

    • For CPA Firms pending their first Peer Review: The due date in the Administering Entity’s Enrollment Letter must not be past due. If the due date has already passed, SOC reports issued by the CPA firm are not eligible for the SR Quality Certification.

  • The CPA firm must have received a “Pass” rating on their last Peer Review.

    • For CPA Firms that received a “Pass with Deficiencies” rating: Fine Assurance will evaluate the deficiencies. If deemed material, SOC reports issued by the CPA firm are not eligible for the SR Quality Certification. If deemed immaterial, SOC reports issued by the CPA firm will still be eligible for the SR Quality Certification.

    • For CPA Firms that received a “Fail” rating: SOC Reports issued by the CPA firm are not eligible for the SR Quality Certification.

  • The CPA firm’s current Peer Review Report must have explicitly covered SOC 1 or SOC 2 reports. If the CPA firm’s current Peer Review Report does not cover SOC 1 or SOC 2 reports, reports issued by the CPA firm are not eligible for the SR Quality Certification.

CPA Firm Engagement Partner Requirements

  • If the SOC report submitted for SR Quality Certification was a SOC 1 report, the Engagement Partner signing the SOC 1 report must possess sufficient, relevant experience in financial internal controls, information technology general controls (ITGCs), and/or SOC 1 reporting.

  • If the SOC report submitted for SR Quality Certification was a SOC 2 report, the Engagement Partner signing the SOC 2 report must possess sufficient, relevant experience in security, ITGCs, and/or SOC 2 reporting.

  • The Engagement Partner must hold an active U.S. CPA License in good standing with their state board of accountancy.

  • The Engagement Partner must reside in a country where the CPA firm holds an active CPA firm license.

 

CPA Firm Independence from the Client’s GRC Platforms

  • The CPA firm must maintain independence from their client’s GRC tool in both fact and appearance.

    • Independence in Fact: The CPA firm cannot rely financially on their client’s GRC tool for their sales pipeline. Financial reliance means that the CPA firm has a referral relationship with their client’s GRC tool and at least 10% of the CPA firm’s client base is using their client’s GRC tool.

    • Independence in Appearance: The CPA firm cannot market themselves as the CPA "arm" of their client’s GRC tool, nor use aggressive co-branding that implies an unethical relationship.

  • The CPA firm must maintain completely separate contracting and billing processes from their client’s GRC tool. The CPA firm shall not participate in bundled "Software + Audit" pricing, unified billing through their client’s GRC tool, or fee arrangement structures where the audit is sold as an add-on or inclusion within their client’s GRC tool subscription. All SOC engagements must be independently contracted and billed directly from the CPA firm to their client.

  • If the CPA firm’s client was referred to the CPA firm by their client’s GRC tool or the CPA firm has a business relationship in place with their client’s GRC tool, the CPA firm’s client’s GRC tool must not use marketing language that guarantees a favorable audit outcome or promises unrealistic timeframes for achieving “SOC 2 compliance” (e.g., claims such as "Guaranteed SOC 2 compliance," "100% audit pass rate,” or "Achieve SOC 2 in 7 days"). Such prohibited assertions also include statements that the use of the GRC tool by itself will result in the issuance of a SOC report (where such report can only be performed or delivered by a licensed CPA firm), or statements regarding the amount of time required or fees charged for an engagement to be performed, as those are independently set by third-party CPAs.

Quality Review and Fee

Quality Reviews

If the SOC report is deemed eligible for the SR Quality Certification based on the eligibility requirements, Fine Assurance will review the CPA firm’s final issued SOC report and the supporting workpapers to determine if the workpapers and SOC report meet Fine Assurance’s quality baseline for a quality SOC report. If the workpapers and SOC report meet Fine Assurance’s quality baseline for a quality SOC report, the SOC report will be SR Quality Certified and Fine Assurance will issue a certification letter to the CPA firm. The SOC report will also be included in the SR Quality Certification public database, to ensure that outside parties can verify a SR Quality Certification. If the workpapers or SOC report fail to meet Fine Assurance’s quality baseline for a quality SOC report, the SOC report will not be SR Quality Certified and Fine Assurance will communicate the reasons why the SOC report was not SR Quality Certified.

Quality Review Fee

Fine Assurance charges CPA firms a minimum $500 Quality Review Fee per SOC report submitted for SR Quality Certification. CPA firms must pay the Quality Review Fee prior to Fine Assurance performing the quality review. Once the Quality Review Fee is paid, Fine Assurance will request the supporting workpapers and final SOC report from the CPA firm. The Quality Review Fee will be communicated to the CPA firm once the CPA firm’s report is deemed eligible for the SR Quality Certification.

Apply to Determine if Your SOC Report is Eligible for SR Quality Certification

The SR Quality Certification is the industry’s premier quality signal for SOC 1 and SOC 2 reporting. SOC Reports that achieve the SR Quality Certification for their SOC reports represent the top tier of SOC Reports. These are SOC Reports issued by CPA firms that refuse to compromise on quality and are dedicated to upholding the highest standards of audit integrity.

SR Quality Certification is not purchased; it is earned through a rigorous vetting process. If your CPA firm is committed to technical excellence, robust quality control, and ethical SOC reporting, and would like to begin the process to have one of your SOC 1 or SOC 2 reports SR Quality Certified, please complete the form below. Once we receive your submitted form, we will determine if your SOC report meets all eligibility requirements.. For eligibility requirements we cannot validate, we will request additional information.

  • CPA Firm’s Legal Name:

  • CPA Firm Headquarter State

  • CPA Firm Licensure Number from Headquarter State:

  • Full Legal Name of Engagement Partner that Signed the SOC 1 or SOC 2 Report:

  • U.S. State where Engagement Partner is Licensed:

  • Engagement Partner’s U.S. CPA License Number:

  • Engagement Partner’s Email Address:

  • Your Client’s Legal Name on the SOC 1 or SOC 2 Report:

  • Type of SOC Report (SOC 1 or SOC 2):

  • Date SOC Report was Issued:

  • Your Client’s GRC Tool (NA if No GRC Tool was Used):

  • Does Your Firm have a Business Relationship with Your Client’s GRC tool (NA if No GRC Tool was Used)?

  • Does Your Firm Receive Referrals from Your Client's GRC Tool (NA if No GRC Tool was Used)? 

  • Percentage of Your Clients that use this GRC tool (0 if No GRC Tool was Used):

  • Did Your Firm have an Engagement Letter with your Client?

  • Did Your Firm bill your Client through your Client’s GRC tool?

By submitting this application, you confirm on behalf of your CPA firm that all information, answers, and supporting documentation provided are true, accurate, and complete. You understand that Fine Assurance relies on this information to determine eligibility for the SR Quality Certification. Any misrepresentation, falsification, or intentional omission of material facts will result in the immediate rejection of your application.

Fine Assurance Logo

Fine Assurance, 2025. All rights reserved.

Fine CPA LLC dba Fine Assurance is a licensed certified public accounting firm in the state of Pennsylvania.

  • LinkedIn
bottom of page