The cyber-attest practice at a modern CPA firm is a P&L unit that lives or dies on cross-framework engagement efficiency. A SOC 2 Type II examination shares 60-80% of its underlying control set with an ISO 27001 recertification and materially overlaps a PCI DSS ROC and a HITRUST r2 assessment. And yet most audit firms doing cyber attest work carry a separate tool for each framework, a separate evidence-request chain per client, a separate working-paper hierarchy, and a separate senior manager reviewing each engagement in a silo. The client sees five auditors asking for the same nine artifacts. The partner sees a realization rate that is 15-30 points below what the practice's utilization suggests it should be.
This is the operator's guide to running the modern cyber-attest practice — SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, and DORA — from one console. For the partner responsible for the practice's P&L and for the senior manager responsible for its methodology.
What the modern cyber-attest practice actually looks like in 2026
Ten years ago the cyber-attest practice at a mid-sized CPA firm was five people running SOC 2 examinations for a mixed portfolio of SaaS companies, with the occasional HIPAA-adjacent HITRUST engagement handed off from the healthcare industry group. The tooling was CaseWare or a custom spreadsheet, evidence lived in a Suralink or ShareFile folder, and the working papers were reviewed at three levels — preparer, senior manager, partner — with the review notes captured in comment threads inside the workpaper file.
The 2026 practice is different in ways that show up in the P&L before they show up in the org chart:
- Framework breadth expanded from 1-2 to 5-8 in the same practice.: SOC 2 II remains the anchor product but rarely pays the bills alone. Recurring clients now bundle ISO 27001, ISO 42001 (post-AI Act), continued PCI DSS work, HITRUST r2 for the healthtech book, DORA TLPT and ICT third-party register work for the EU financial-services book, and — for the top-of-market segment — FedRAMP 3PAO or CMMC C3PAO work. Every framework carries its own testing procedure, working-paper template, evidence taxonomy, and independence rules. A practice running seven frameworks with framework-siloed tooling is running seven practices.
- The engagement volume per practitioner doubled while the fee per engagement compressed.: The 40-engagement-per-year senior manager was a stretch role in 2018 and is baseline in 2026. Fees per engagement compressed 15-30% across the SMB and lower-mid-market segment as bundled platform vendors (Vanta, Drata, Secureframe) commoditized readiness. The margin math only works if per-engagement hours drop proportionally, which requires tooling that treats the whole book as one system.
- Client-side compliance automation shifted where the auditor's time goes.: A well-tooled auditee arrives with continuous evidence collection already running, MFA enforcement telemetry already exported, and vendor risk data already structured. The auditor's incremental value is not in re-collecting what the auditee already has — it is in the independence, the sampling, the IPE testing, the walkthrough discipline, and the report. Practices that still bill for evidence-collection hours are billing for work the client already did.
- Peer review pressure on SOC 2 examinations intensified.: The AICPA's May 2024 guidance called out SOC 2 examinations specifically as an area of elevated peer-review-deficiency risk, and 2025-2026 peer review cycles have produced findings that concentrate in three areas: IPE completeness testing, sampling justification and sample-size adequacy, and independence in appearance when the same firm carries adjacent advisory work. A practice getting a peer review finding on SOC 2 sampling loses a book of clients and pays through the nose to remediate.
- AI-native audit tooling arrived and split the market.: DataSnipper for financial audit extraction, MindBridge for full-population testing, Fieldguide for AI-native cyber-attest workflow, Thoropass for the bundled auditor-and-platform model — each addresses a different part of the practice but does not address the whole. The next-generation cyber-attest tool is the one that unifies the book across frameworks with independence architecture built in from day one.
The five failure modes eating cyber-attest margin
Every unprofitable cyber-attest engagement is unprofitable for one or more of the same five reasons. None of these are the practitioner's fault; they are structural consequences of how the tooling and the workflow are shaped.
Every one of them is a workflow problem masquerading as a methodology problem. The audit methodology is well-established — the AICPA has published trust services criteria, ISO has 27001:2022 Annex A, PCI SSC publishes the ROC template. What is missing is the tooling that makes the methodology executable across a book of 40+ concurrent multi-framework engagements without hiring proportional headcount. That is the gap the modern console solves.
What "one console" needs to do — the operator's requirements
Every audit-firm platform vendor's marketing page reads like it was written for the client; the actual buyer at the firm has a different list. Here is what matters when the partner and the senior manager sit down to evaluate.
- One book view across every framework, every client, every cycle.: Not a per-engagement dashboard federated across a portfolio. A single book where the partner can see all 40 concurrent engagements, sort by framework or by partner or by risk state, and see which engagements are in fieldwork, which are in report, and which are drifting toward the deadline. If the tool requires clicking into each engagement to answer the partner's book-view questions, it is a per-engagement tool with a portfolio wrapper, not a book-view tool.
- Cross-framework evidence deduplication with source-of-truth per artifact.: The MFA enforcement report the auditor requested for SOC 2 CC 6.1 is the same MFA enforcement report the auditor needs for ISO 27001 A.8.5 and for PCI DSS 8.4. Requesting it three times is an operational failure. The tool must recognize the same underlying artifact across frameworks and support one client-side upload that satisfies every framework's evidence requirement.
- Year-over-year control drift detection.: The tool must carry state between examination cycles for the same client. What was the sample population last cycle? What was the operating-effectiveness rate? What controls had exceptions? What was the disposition of each exception? Without state carried between cycles the drift-detection burden falls on the senior manager's memory, and the senior manager is running 40 engagements, and the drift disappears.
- IPE completeness testing as a first-class primitive, not a manual procedure.: For every IPE artifact the client produces, the tool needs to capture: the source system, the extraction query, the filter parameters, a timestamp, and — critically — a reproducible re-run of the same extraction for the auditor to verify completeness. Not a screenshot of the report. The report itself, with lineage. This is where the AICPA peer review pressure lives.
- Signed, chain-of-custody-preserving evidence storage.: Every evidence artifact captured during fieldwork should be hash-committed at capture time, timestamp-anchored, and preserved with a chain of custody that survives an inspection or a subpoena. Screenshots into a Google Drive folder do not meet this bar. Hashed evidence with signatures does.
- Independence architecture — read-only by design where independence requires it.: The audit-firm platform must not write to the auditee's own compliance state. If the platform can post evidence, remediate controls, or change the auditee's posture, an independence question arises. The AICPA independence rules for attestation engagements are explicit about non-audit-services boundaries; a platform that blurs them is a peer-review problem waiting to be found.
- Report compilation from the underlying working papers, not from a template the practitioner re-types.: The final report — the SOC 2 II opinion, the ISO 27001 audit report, the ROC — should compile from the working papers with provenance intact. Every assertion in the report should link back to the working paper section that supports it, and every finding should link to the control test that produced it. Otherwise the report becomes a re-authored document detached from the underlying work, and audit-firm risk goes up.
The cross-framework operating rhythm
A well-run cyber-attest practice does not treat SOC 2 II, ISO 27001, PCI DSS, and HITRUST as parallel workstreams. It treats them as overlapping engagements on the same underlying client posture, with the framework-specific work layered on top of a common evidence-collection cycle. Concretely, for a client running all four, the operating rhythm looks something like this:
Q1
SOC 2 II examination fieldwork for the prior calendar-year period. ISO 27001 stage 2 audit (if in the certification cycle) OR annual surveillance visit (if not). PCI DSS quarterly ASV scans reviewed. HITRUST r2 interim testing if applicable. Evidence collection window kicks off in early January; fieldwork typically wraps by mid-March.
Q2
SOC 2 II report issuance. ISO 27001 certification decision (if stage 2 occurred). PCI DSS annual ROC fieldwork if the client's assessment window aligns to Q2. Client-side board reporting on the completed cycles. Evidence-review of remediated exceptions from Q1.
Q3
SOC 2 II Type 2 walkthroughs for the current calendar-year period (July walkthroughs). ISO 27001 internal audit consultation if the client is preparing for an ISMS internal audit. PCI DSS quarterly ASV scans. HITRUST corrective action plan review if r2 remediation is in flight.
Q4
SOC 2 II sampling and testing for the H2 period. ISO 27001 pre-audit readiness for the following year's surveillance. PCI DSS annual ROC issuance if the client's window aligns to Q4. HITRUST bridge letter if the r2 certification carries into the next year. Year-end evidence integrity review and archival.
The framework-silo model asks four different tools to coordinate this rhythm across the same client — and they don't. The one-console model asks one tool to carry the client's control state, cycle-to-cycle, with the framework-specific working papers layered on top and the shared evidence collected once. That is the operational shape the modern practice needs.
Independence-by-design versus the bundled auditor-and-platform model
Two shapes of platform have emerged in this space, and they resolve the independence question in different ways. Understanding the difference is not academic — it determines whether the platform is a fit for your practice at all.
The bundled auditor-and-platform model has commercial advantages — the vendor captures both revenue streams and can price aggressively at the low end — but it creates a structural independence problem that shows up at peer review and at client escalation. The read-only-by-design model preserves the firm's independence architecture while providing the operational leverage of a modern platform. Which model fits depends on how the practice competes; firms differentiating on independence and audit quality cannot use the bundled model without giving up their differentiation.
Evidence integrity as a category the AICPA hasn't named yet
Every audit engagement produces a body of working papers — walkthroughs, test results, exception dispositions, IPE completeness assessments, sampling justifications, management representation letters — that must be defensible under peer review, under a client escalation, and (in the worst case) under a subpoena or a regulator's inquiry. The AICPA quality-control standards require workpaper retention and integrity but do not prescribe a technical mechanism. The professional norm has been a document management system with access controls, retention schedules, and change tracking.
The 2026 upgrade to this norm is cryptographic evidence integrity: every evidence artifact captured during fieldwork is hash-committed at capture time, the hash is timestamp-anchored to an external chain (RFC 3161 TSA or an equivalent), and the chain of custody survives platform migration, vendor consolidation, and multi-year archival. When a peer reviewer asks "how do you know this working paper was not modified after signoff?" — the answer is not "check the DMS access log," which is trivially forgeable. The answer is a hash comparison against a timestamp anchor issued at signoff time. That is the standard that will define the next generation of audit-firm working-paper systems, whether the AICPA names it explicitly or not.
Ask any platform vendor two questions. (1) If a partner or senior modifies a working paper after signoff, can I detect that, and how? (2) If the platform vendor is acquired and the data is migrated, do the integrity guarantees survive the migration? A serious answer includes hash commitments, external timestamp anchors, and portable integrity manifests. A weak answer includes "we have access logs" and "our DMS is SOC 2 certified." The gap between those two answers is the difference between defensible evidence integrity and the appearance of it.
The engagement-margin math
The reason to invest in a unified cyber-attest console is not "efficiency" as an abstract goal. It is the specific P&L delta that shows up when the engagement-hour distribution shifts from evidence-collection overhead to substantive testing and independent judgment. Concretely, for a typical mid-market SOC 2 II engagement running 200-300 billable hours:
The delta on a single 250-hour SOC 2 II engagement is 60-100 hours reduced — 25-40% of the engagement's total time — that flows directly to margin at the same fee, or to competitive pricing that grows the book at unchanged margin. Neither outcome is available to the framework-silo practice, which is why the practice's realization rate compresses year over year even as the practitioners get faster.
What to buy: the cyber-attest software stack decision
The market has consolidated into a small number of serious platforms, and the fit depends on the practice's shape. Full comparison is in the 2026 cyber-attest software comparison; the summary version:
CaseWare Working Papers, Wolters Kluwer CCH Axcess, TeamMate+
Legacy financial-audit workpaper platforms retrofitted for cyber-attest work. Strong at working-paper structure, weak at cyber-attest-specific evidence workflows (no PBC portal), weak at framework-specific templates (require heavy customization), weak at AI-assisted evidence review. Fit for firms that primarily do financial audit and want cyber-attest as an adjacent product line without adopting a second tool.
Suralink
Best-in-class PBC-list-plus-client-portal. Weak at working-paper structure (typically layered on top of another tool). Fit as a component of a stack, not as a standalone.
Fieldguide
AI-native cyber-attest workflow, strong at the individual-engagement layer, weak at cross-framework book-view. Fit for larger practices doing high-volume single-framework work (SOC 2 shop with 100+ engagements).
Thoropass, A-LIGN A-SCEND
Bundled auditor+platform model. Attractive commercial economics for the vendor; structural independence appearance risk for firms that differentiate on independence. Not a fit for practices where the firm is the auditor and needs an independent tool.
vCISO Lite for Auditors
Cross-framework book view, read-only-by-design architecture, cryptographic evidence integrity, free client portal. Fit for cyber-attest practices running SOC 2 alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, and DORA.
The bottom line
The modern cyber-attest practice does not compete on "we do SOC 2." It competes on the ability to carry a multi-framework client through the year without re-collecting evidence, without losing state between cycles, without exposing itself to peer review deficiency risk, and without ceding independence to a bundled platform. The tooling decision is the highest-leverage decision the practice makes in a five-year window. Get it right and the practice compounds on margin, book size, and reputation. Get it wrong and it compounds the other way.
Run the modern cyber-attest practice from one console
vCISO Lite for Auditors ships the operating substrate this pillar describes — one book across every client, every framework, every cycle; cross-framework evidence deduplication; year-over-year control drift detection; IPE completeness testing with extraction lineage; cryptographic evidence integrity with hash-chained timestamp anchors; read-only-by-design architecture that preserves the firm's independence; and free-forever client evidence portals so the auditee never pays a platform tax to submit its own evidence. Built for CPA firms, QSAs, 3PAOs, C3PAOs, HITRUST assessors, ISO 27001 lead auditors, and multi-accreditation practices carrying DORA TLPT scope running the modern cyber-attest practice at scale.
If you are evaluating the audit-firm software stack for the next cycle, or if you are building the practice from scratch, visit firm.vcisolite.com to see the console.