Why this is live right now (June 2026). In the May 2026 reviewer alert, the AICPA’s Peer Review Board told peer reviewers to treat firms running high-volume, tool-driven SOC 2 practices as elevated-risk — and warned that engagements with “identical reports, risk assessments, sample sizes, and testing procedures” across different clients can be ruled “nonconforming.” Then, beginning June 1, 2026, AICPA staff started a structured monitoring and outreach process aimed specifically at firms with SOC 2 practices. The SOC 2 standard did not change. What changed is that the profession started auditing the SOC 2 auditors.
For a few years, the dominant story in commercial compliance has been speed: a Series A SaaS company with a clean cloud stack could stand up a control program inside a compliance-automation platform, connect the integrations, and reach a SOC 2 report in months with most of the evidence collected automatically. That model is real and, for the right company, it is the right call. But it produced a quieter side effect that the AICPA has now decided to act on: a growing volume of SOC 2 reports that look the same no matter whose name is on the cover.
This is a practitioner read of what the AICPA actually did, why it matters more than a typical guidance update, and what it means depending on whether you buy SOC 2 reports, rely on them, or are a service organization that holds one.
What the AICPA actually did
Two concrete things, both in 2026, both from the body that polices CPA firm quality rather than the body that writes the SOC 2 standard.
First, the Peer Review Board (PRB) issued a reviewer alert in May 2026 addressing SOC 2 risk directly. The alert does three things. It raises awareness of the risks the AICPA is now seeing in SOC 2 engagements. It tells peer reviewers that reviewing a single SOC 2 engagement file is “often insufficient” to surface these risks — including the risk that the firm’s broader system of quality management has a problem. And it guides reviewers to obtain a deeper understanding of three specific things: the firm’s use of technology, including external SOC platforms and vendor relationships; the reasonableness of the firm’s SOC 2 engagement timelines; and whether engagements are actually tailored to each client’s specific risks and environment.
Second, the AICPA stood up a structured monitoring and outreach process that, beginning June 1, 2026, has staff identify scheduled peer reviews of firms that perform SOC 2 engagements, conduct direct outreach to the peer-review team captains early in the process, provide resource materials, and offer support on engagement selection and on the judgment of whether an engagement is nonconforming. This sits on top of the PRB’s existing enhanced oversight program, in which a subject-matter expert re-checks the peer reviewer’s own conclusions — a mechanism the AICPA has run since the mid-2010s and is now pointing at SOC 2.
The throughline, in the words of the AICPA’s VP of Ethics and Firm Quality, is that “some firms are leaning too heavily on third-party SOC platforms without applying the professional judgment required by our standards.” The point is not the tools. It is the substitution of the tool’s defaults for the CPA’s judgment.
Why this is more than a routine guidance refresh
Guidance updates land all the time and most of them change nothing about how anyone operates. This one is different for a structural reason: it changes the enforcement posture, not the standard. The Trust Services Criteria are exactly what they were. But the probability that a firm issuing thin, templated SOC 2 reports gets caught — and lands a deficiency or significant deficiency in its own peer review — went up materially as of June 1.
The mechanism is worth understanding because it is concrete. When a peer reviewer develops the deeper understanding the alert calls for and concludes that a firm’s SOC 2 timelines look unreasonable or that other risk indicators are present, the team captain is likely to determine an elevated risk exists. The response to elevated risk is specific:
- select several SOC 2 engagements — often about five — from different partners in the firm;
- compare those reports to one another and to the prior-year reports;
- review the targeted areas that require engagement-specific judgment; and
- determine whether identical risk assessments, control designs, sample sizes, or testing procedures appear across engagements.
If that comparison shows a firm is relying too heavily on compliance tooling and not complying with professional standards in all material respects, the reviewer is likely to conclude the engagements are nonconforming. A nonconforming conclusion raises the likelihood of a deficiency or significant deficiency in the firm’s peer review report, which in turn can require follow-up: revising the firm’s system of quality management, or having an outside party review completed engagements. That last remedy is the one with teeth — it means a third party re-examining work the firm already signed and delivered to clients.
The tell the AICPA is hunting for is sameness. A firm whose five sampled reports — across five different partners and five different clients — carry the same risk assessment, the same sample sizes, and the same tests is, by the AICPA’s logic, a firm that stopped doing engagement-specific work somewhere along the way. That is the cookie-cutter pattern, and it is now a named, sampled-for risk.
This is the same line we’ve been drawing
None of this should surprise anyone who has watched the “fast and easy” segment of the SOC 2 market. The AICPA’s own framing — that the goal is to “ensure that SOC 2 engagements reflect the professional judgment, rigor, and client-specific tailoring that the public expects” — is the same distinction our team has made repeatedly: tooling automates evidence collection; it does not make the architecture and judgment calls.
We wrote about where the platform-only approach breaks down in Vanta, Drata, and the limits of software-only SOC 2, and about what a report built on real, client-specific evidence looks like in SOC 2 Type II evidence patterns that pass. The AICPA’s 2026 move is the regulatory-quality counterpart to those pieces. It is also a direct vindication of the position we took in why 30-day compliance claims are misleading: a report produced fast enough to fit a “30-day SOC 2” pitch is, almost by definition, a report where the engagement-specific judgment got compressed out — which is exactly the profile the AICPA is now sampling for.
To be precise about what is not being said: a SOC 2 report produced with the help of a compliance platform is not nonconforming because a platform was involved. Platforms are legitimate tools, and a firm that uses one to collect evidence and then applies genuine engagement-specific judgment is doing exactly what the standards require. The nonconforming risk attaches to the firm that lets the tool’s defaults stand in for that judgment.
What this means for you
The right response depends on where you sit.
If you rely on vendors’ SOC 2 reports — that is, if your security or vendor-risk team reads other companies’ SOC 2 Type II reports as part of third-party risk management — the practical takeaway is that the AICPA has confirmed what experienced reviewers already suspected: not all SOC 2 reports carry the same assurance. When you read a report, look at whether the description of the system and the tests of controls actually reflect that vendor’s architecture, or whether they read like a template that could describe anyone. A report with boilerplate control descriptions, no noted exceptions, a very fast turnaround, and a high-volume issuer is now precisely the profile under scrutiny — and you are entitled to ask the vendor for specifics about scope, the controls tested, and the sampling behind a clean opinion.
If you are a service organization that holds a SOC 2 report, the question to ask is honest and internal: would your most recent report survive an auditor — or an AICPA peer reviewer — who actually looked? If your control descriptions are generic, your evidence was reconstructed rather than captured as a byproduct of operations, and your engagement moved unusually fast, you are carrying more risk than the certificate on your trust page implies. The risk is not that your report is retroactively revoked tomorrow; it is that the firm that issued it is now more likely to be reviewed, and that the next renewal will be held to a visibly higher bar. The fix is not a deadline to hit — it is design work: a control environment and evidence pipeline built around your actual architecture, so that the report describes a real program rather than a template.
If you are choosing a SOC 2 auditor or advisor, the AICPA just told you what separates the firms worth hiring: client-specific risk assessment, defensible timelines, and engagement work that is tailored rather than templated. Ask a prospective firm how they tailor the risk assessment to your environment, how they decide sample sizes, and how long the work realistically takes. A firm that cannot answer those concretely — or that quotes a turnaround that sounds too good to be true — is selling the exact product the AICPA started sampling for on June 1.
Where we sit
Our SOC 2 practice was built around the distinction the AICPA just formalized. We do not compete with the automation platforms — we use them as tools where they fit and design the parts they cannot: the scope decisions, the client-specific control environment, the evidence pipeline that produces real evidence as a byproduct of operations, and the auditor coordination that holds up when someone looks closely. That has always been the right way to do SOC 2. As of 2026, it is also the way that keeps your report on the safe side of a peer-review program that is now actively looking for the alternative.
If you are reading your own most recent SOC 2 report and quietly wondering whether it would hold up under that kind of scrutiny, that instinct is worth following. A scoping conversation will usually surface the gap quickly — whether your report describes a real program or a template, and what it would take to close the distance before your next renewal.
Related reading: When SOC 2 platforms hit their limits · SOC 2 Type II evidence patterns that pass · Why 30-day compliance claims are misleading · SOC 2 vs ISO 27001 — which first · SOC 2 framework overview