What Are Attestation Services and When Are They Required?

Attestation services are engagements in which a CPA independently evaluates a specific claim your business has made and issues a written report that lenders, regulators, customers, or other outside parties can rely on. The claim can be almost anything measurable: the effectiveness of your cybersecurity controls, your compliance with a grant agreement, the accuracy of your carbon emissions data, the reasonableness of a financial forecast. The CPA measures the claim against defined criteria, gathers evidence, and delivers a report whose conclusion carries professional weight. Most attestation work is voluntary and driven by a contract or a customer requirement, but a handful of situations, including Sarbanes-Oxley Section 404(b) and the FDICIA rules for larger banks, require it by law.

For private companies, these engagements are governed by the Statements on Standards for Attestation Engagements (SSAEs) issued by the AICPA’s Auditing Standards Board.1AICPA & CIMA. AICPA Statement on Standards for Attestation Engagements No. 18 Public companies fall under the attestation standards adopted by the Public Company Accounting Oversight Board.2AICPA & CIMA. AICPA SSAEs – Currently Effective Every engagement involves three parties: the responsible party making the claim, the CPA evaluating it, and the intended users who will rely on the report.3American Institute of Certified Public Accountants. AT-C Section 105 – Concepts Common to All Attestation Engagements

The Three Levels of Assurance

Every attestation engagement falls into one of three categories. Each delivers a different level of confidence to the users of the report, and each costs a different amount of money. Knowing which type you have been asked for, or which one you actually need, is the first practical question.

Examination

An examination provides reasonable assurance, the highest level available. The CPA performs extensive procedures: inspecting documents, observing processes, interviewing staff, recalculating figures. The final report expresses a positive opinion, stating directly whether the subject matter conforms to the criteria in all material respects.4AICPA & CIMA. SSAE No. 21 At a Glance This is the attestation equivalent of a financial statement audit, and it carries similar weight with regulators and sophisticated counterparties. It is also the most expensive option.

Review

A review provides limited assurance. The CPA relies mostly on inquiries and analytical work, comparing data against prior periods, industry benchmarks, or expected results, rather than performing the deep testing an examination requires. The report’s conclusion is phrased in the negative: nothing came to the practitioner’s attention indicating the subject matter does not conform to the criteria.5American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements 22 – Review Engagements That wording sounds hedged because it is. The CPA is not stating the subject matter is correct; they are stating their limited procedures did not turn up problems. A review costs less than an examination and fits when stakeholders want some independent assurance but do not need full rigor.

Agreed-Upon Procedures

An agreed-upon procedures (AUP) engagement is structurally different. The CPA provides no opinion and no assurance. Instead, you and the intended users specify exactly which procedures the CPA should perform. The CPA carries them out and reports the factual findings. The users draw their own conclusions.6Public Company Accounting Oversight Board. AT Section 201 – Agreed-Upon Procedures Engagements

AUPs are common when a lender or regulator wants specific data points verified without paying for broad assurance. A grant-making agency might want a CPA to confirm that five specific cost categories on your expenditure report tie to your underlying records. The CPA tests exactly those five categories and reports what they found. Nothing more.

How Attestation Differs From an Audit

People often conflate attestation with auditing, and the confusion is understandable because an examination engagement looks a lot like an audit. The difference is scope. A financial statement audit is locked onto one subject: whether your financial statements are free from material misstatement under a recognized framework such as GAAP or IFRS. An audit follows the Statements on Auditing Standards for private companies or PCAOB standards for public ones.7AICPA & CIMA. AICPA SASs – Currently Effective

Attestation follows a separate set of standards and can address almost any subject matter against almost any suitable criteria. If you need a CPA’s opinion on whether your carbon emissions data was compiled according to the Greenhouse Gas Protocol, or whether your data center’s security controls meet the AICPA’s Trust Services Criteria, a financial statement audit cannot help you. An attestation engagement can. The professional obligations of independence, skepticism, and documentation apply to both.

When Businesses Actually Need Attestation

Most attestation engagements are triggered by a specific outside request. Here are the situations that generate the largest share of that demand.

Service Organization Controls (SOC) Reports

SOC reports are among the most commonly encountered attestation engagements, especially in technology. A SOC 1 report covers a service organization’s internal controls that are relevant to its customers’ financial reporting. If your company processes transactions on behalf of other businesses, their auditors will almost certainly ask for your SOC 1.8AICPA & CIMA. System and Organization Controls – SOC Suite of Services

A SOC 2 report addresses a broader set of controls tied to the AICPA’s Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.8AICPA & CIMA. System and Organization Controls – SOC Suite of Services Enterprise customers routinely require a SOC 2 before onboarding a cloud provider, SaaS vendor, or managed service provider. The report is a restricted-use document, typically shared under a nondisclosure agreement.

SOC 2 reports come in two versions. A Type I evaluates whether controls are suitably designed at a single point in time. A Type II tests whether those controls actually operated effectively over a period, usually three to twelve months. Type II carries more weight because it demonstrates the controls work over time, not just that they exist on paper. Many organizations start with Type I to show initial compliance and move to Type II once controls have been running long enough to observe.

A SOC 3 report covers the same Trust Services Criteria as a SOC 2 but strips out the detailed testing results and system descriptions. The result is a high-level summary designed for public distribution, often posted on a company’s website.

Compliance Attestation

Bond indentures, government grant agreements, franchise arrangements, and licensing requirements frequently include attestation provisions. A CPA can examine whether you have complied with the financial covenants in a loan agreement, properly spent grant funds on eligible expenses, or met operational benchmarks in a regulatory license. The evaluation criteria come from the agreement or regulation itself, and the report gives the counterparty confidence that your representations hold up.

ESG and Sustainability Data

Attestation over sustainability data is a growing area. Companies wanting to demonstrate the credibility of their carbon emissions figures, diversity statistics, or supply chain practices are engaging CPAs to examine or review the underlying data collection and reporting. Criteria typically come from established frameworks such as the Greenhouse Gas Protocol or the Global Reporting Initiative standards.

The SEC adopted a climate-related disclosure rule in 2024 that would have required certain public companies to obtain attestation on greenhouse gas emissions, with reasonable assurance for large accelerated filers and limited assurance for accelerated filers. The SEC stayed the rule during litigation and voted in March 2025 to end its defense of the rule.9U.S. Securities and Exchange Commission. SEC Votes to End Defense of Climate Disclosure Rules No federal ESG attestation mandate is currently in effect, though voluntary attestation remains common and some states have adopted their own disclosure requirements.

Prospective Financial Information

Forecasts and projections can be the subject of an attestation engagement. The CPA does not guarantee that projected numbers will come true. They examine the assumptions and the methodology behind the forecast, then express an opinion on whether the presentation is reasonable given those assumptions. Lenders and investors ask for this when evaluating acquisition targets, new ventures, or project finance deals where historical statements alone do not tell the story.

When Attestation Is Required by Law

Two federal regimes mandate attestation for the organizations they cover.

Sarbanes-Oxley Section 404(b)

The Sarbanes-Oxley Act requires public companies classified as accelerated filers or large accelerated filers to include an independent auditor’s attestation report on the effectiveness of internal controls over financial reporting in their annual report. This is an examination-level engagement. Smaller reporting companies with less than $100 million in annual revenue and non-accelerated filers are exempt from the auditor attestation requirement, though management must still provide its own assessment of internal controls.

FDICIA for Banks

The Federal Deposit Insurance Corporation Improvement Act imposes attestation requirements on insured depository institutions based on asset size. Effective January 1, 2026, the FDIC updated the thresholds under 12 CFR Part 363: institutions with $1 billion or more in total assets must obtain an annual independent audit, and those with $5 billion or more must include an attestation on internal controls over financial reporting.10Federal Register. Adjusting and Indexing Certain Regulatory Thresholds The thresholds are adjusted every two years based on the Consumer Price Index, with the next scheduled adjustment planned for October 2027.

How to Read the Report You Receive

An attestation report is only useful if you understand what the conclusion actually means. The specific language carries precise professional meaning.

An examination opinion falls into one of four categories. An unmodified opinion means the subject matter conforms to the criteria in all material respects; this is the clean result. A qualified opinion means the subject matter conforms except for one or more specific issues the CPA will describe, signaled by the phrase “except for” in the opinion paragraph. An adverse opinion means the subject matter does not conform to the criteria, with a separate paragraph explaining what went wrong.11Public Company Accounting Oversight Board. AS 3105 – Departures from Unqualified Opinions and Other Reporting Circumstances A disclaimer means the CPA could not gather enough evidence to form any opinion, often because access was restricted or circumstances prevented necessary testing. A disclaimer is not pass or fail; it is an inability to conclude.

When the report covers internal controls, such as a SOC report or a Sarbanes-Oxley Section 404 engagement, any problems are classified by severity. A material weakness is a control deficiency, or combination of deficiencies, creating a reasonable possibility that a material misstatement would go undetected. This is the most serious finding. A significant deficiency is less severe than a material weakness but still warrants the attention of those overseeing financial reporting.12Public Company Accounting Oversight Board. Auditing Standard No. 5 Appendix A – Definitions If you are evaluating a vendor’s SOC report or reviewing your own company’s controls, a material weakness is a serious concern. It usually triggers remediation requirements and can affect insurance pricing and financing.

What Attestation Costs

Fees vary widely based on the engagement type, the complexity of the subject matter, and the size of the organization. A narrowly scoped AUP might run a few thousand dollars. A SOC 2 Type II examination for a large technology company can cost six figures. CPA firms bill based on staff hours, with rates at most firms ranging from roughly $200 for junior staff to $500 or more for partners, and rates at large national firms running higher. The biggest single cost driver is your own readiness. Organized records and well-documented controls shrink the CPA’s time significantly. Gaps in documentation force additional procedures that push the bill up.

Before the CPA can even accept the work, they have to confirm several preconditions: independence from you, the existence of suitable criteria to evaluate against, a reasonable expectation of obtaining sufficient evidence, and the collective competence of the engagement team.3American Institute of Certified Public Accountants. AT-C Section 105 – Concepts Common to All Attestation Engagements If any of those is missing, the CPA cannot take the engagement, and the sooner you identify a shortfall (particularly on suitable criteria) the less time and money you lose on a project that would have stalled anyway.