Pittsburgh CPA Firm IT: SOC 2 Readiness + Copilot Rollout
PGH Networks is a Pittsburgh-based managed services provider that helps CPA and accounting firms across the Pittsburgh metro — from the Strip District and Downtown to Wexford, Cranberry Township, Robinson, Monroeville, and Washington — reach SOC 2 readiness while rolling out Microsoft 365 Copilot safely. This case study walks through a recent engagement that captures the playbook we use for Pittsburgh CPA firm IT: SOC 2 readiness paired with a governed Copilot rollout, executed in parallel rather than as competing projects.
The pattern is now common. A managing partner gets a vendor security questionnaire from a private-equity client demanding a SOC 2 Type II report. A week later, the tax team asks why they can't "just use ChatGPT" to summarize a 200-page operating agreement. Both questions land on the same desk, and they have to be answered together.
The scenario: a 35-person Pittsburgh CPA firm
The firm — anonymized here — is a 35-person CPA practice headquartered in the North Hills with a satellite office in Washington County. Service mix is roughly 60% tax (1040, 1120-S, 1065), 30% audit and assurance, and 10% advisory for closely held manufacturers and medical practices. Their stack was typical for a Pittsburgh accounting firm of this size: CCH Axcess for tax and document, Thomson Reuters UltraTax CS for a legacy partner book, QuickBooks Online and Desktop hosted on Rightworks (formerly Right Networks), Microsoft 365 Business Premium, and a SonicWall at each office.
Two pressures arrived in the same quarter. A new PE-backed audit client required a SOC 2 Type II report within twelve months. Separately, three partners had independently signed up for consumer AI tools and were pasting client trial balances into them. The firm called PGH Networks after a peer referral through their PICPA chapter.
When a CPA firm's compliance deadline and its AI experimentation hit in the same quarter, treating them as separate projects is how client data ends up in the wrong model.

The challenge: tax stack, client data, and AI sprawl
Three problems had to be solved simultaneously. First, SOC 2 readiness — specifically the Common Criteria around logical access (CC6), system operations (CC7), and change management (CC8) — with evidence collection that would survive a Type II observation window. Second, GLBA Safeguards Rule and IRS Publication 4557 obligations, which the firm had been treating as a checklist rather than an operating model. Third, AI governance: partners wanted Microsoft 365 Copilot, but Copilot inherits the permissions of the user invoking it, and the firm's SharePoint had years of over-shared "Everyone except external users" folders containing K-1s and SSNs.
The CCH Axcess and UltraTax environments added a wrinkle. Both are cloud-hosted by the vendors, so the firm didn't own the underlying infrastructure controls — but they did own identity, endpoint, and data-exfiltration controls around the workstations and browsers touching those apps. The QuickBooks hosting on Rightworks needed similar treatment: vendor SOC 2 inheritance for the hosted layer, firm-owned controls for everything north of it.
How PGH Networks solved it
We started with a controls map, not a tool purchase. Each SOC 2 Common Criterion was mapped to a specific Microsoft 365, Defender, or Intune control, and each GLBA Safeguards element and IRS 4557 safeguard was cross-walked to the same map so the firm wasn't documenting the same control three times.
For logical access (CC6), we deployed Entra ID Conditional Access with phishing-resistant MFA, device compliance requirements through Intune, and Privileged Identity Management for the four admin accounts. Tax-season seasonal staff got time-bound access that auto-expired on April 16. For system operations (CC7), Microsoft Defender for Endpoint and Defender for Cloud Apps gave us the monitoring and alerting evidence the auditor would later sample.
The Copilot rollout was ring-fenced before a single license was assigned. This is the same Copilot readiness sequence we run for every firm: we ran SharePoint Advanced Management and Purview to find and remediate over-shared sites, then deployed Purview sensitivity labels — Public, Internal, Client-Confidential, Client-Restricted — with auto-labeling rules trained on SSN, EIN, and tax-form patterns. Purview DLP policies blocked Client-Restricted content from being summarized by Copilot in chat, pasted into consumer AI endpoints in the browser, or emailed externally without justification. Only after that ring-fence was in place did Copilot licenses go to the first pilot group of eight.
TL;DR: Copilot is safe for a CPA firm only after Purview labeling and DLP have ring-fenced client tax data — the license is the last step, not the first.
Vendor inheritance was documented for CCH Axcess, Thomson Reuters, Rightworks, and Microsoft, with their SOC 2 reports collected into a vendor management register that the firm's auditor could pull on demand.

Outcomes
Within ten months the firm completed its SOC 2 Type II observation window with zero exceptions on the controls PGH Networks owned. The auditor's sampling pulled cleanly from Defender, Entra, and Intune logs without manual evidence scrambling. The vendor security questionnaire from the PE-backed client was answered in two business days using the same evidence pack.
On the AI side, Copilot reached firm-wide deployment with no data-loss incidents detected by Purview during the first six months. Partners reported meaningful time savings on engagement-letter drafting, audit workpaper review summaries, and first-pass research against internal tax memos. Consumer-AI shadow usage dropped to near zero once a sanctioned, governed alternative existed.
Takeaway for Pittsburgh accounting firms
If you run a Pittsburgh CPA firm staring at a SOC 2 deadline and a Copilot question at the same time, the work is sequencable but not separable. The same identity, labeling, and DLP foundation that earns the SOC 2 report is what makes Copilot safe to turn on — and the same vendor-inheritance discipline that satisfies GLBA and IRS Pub 4557 is what lets you defend the CCH, Thomson Reuters, and Rightworks pieces of your stack to an auditor.
PGH Networks runs this Pittsburgh CPA firm IT playbook — SOC 2 readiness plus governed Copilot rollout — for accounting practices across Allegheny, Butler, Washington, and Westmoreland counties. If that's the quarter you're in, we should talk before the audit window starts. Call 724.888.7007 or reach us through the contact form to start scoping your engagement.
Related reading

Cyber Insurance Requirements Pittsburgh: MSP Compliance Guide
Struggling to meet cyber insurance requirements in Pittsburgh? See what carriers now demand: MFA, EDR, backups, IR plans, and how a local MSP helps you qualify.

CMMC Compliance Consultant in Pennsylvania
Pittsburgh-based CMMC compliance consultant for Pennsylvania defense contractors: step-by-step path to Level 2 readiness, SPRS scores, and DoD contract eligibility.

HIPAA Compliant MSP in Pittsburgh
A Pittsburgh case study in how a HIPAA compliant MSP hardened a 60-person specialty practice ahead of an OCR-triggered risk review. See the playbook.