Directory

SOC 2 audit firms

19 licensed audit practices that perform SOC 2 examinations, grouped by the buyer stage they fit best. Each profile links to the firm's website. We are an independent directory — not an audit firm, and these listings are not paid placements or endorsements.

Verify before you engage. SOC 2 reports can only be issued by licensed CPA firms under AICPA standards. Before signing, confirm the firm's license, ask who your engagement team will be, and get the fee in writing with scope boundaries. Our methodology explains exactly how we vet firms and label prices.

Provenance: profiles are compiled from each firm's public materials (September 2026); every price carries a source label. All 19 firm websites were load-verified September 2026 — the row-level verification log is on our methodology page.

For early-stage startups

First SOC 2, small team, price-sensitive, need speed. These firms focus on startup and small-business audits with published or low planning ranges.

FirmTypeType 2 planning rangeFieldwork window
Zero Day CPABoutique licensed CPA firm$7K–$10K (published planning range (Sept 2026))2–6 wk
ThoropassAuditor-led assurance practiceFrom $9,995 (firm-published price)2–6 wk
Prescient AssuranceAICPA-accredited SOC audit firmNot published — request a scoped quoteVaries — confirm in proposal
MJD AdvisorsSOC-focused licensed CPA firm$15K–$35K (published planning range (Sept 2026))2–6 wk
Johanson Group, LLPLicensed CPA firm focused on security compliance auditsNot published — request a scoped quoteVaries — confirm in proposal

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

For growth-stage teams

Series A through mid-market: you need a credible report for bigger customers, possibly with adjacent frameworks (ISO 27001, PCI, HITRUST) on the roadmap.

FirmTypeType 2 planning rangeFieldwork window
ThoropassAuditor-led assurance practiceFrom $9,995 (firm-published price)2–6 wk
MJD AdvisorsSOC-focused licensed CPA firm$15K–$35K (published planning range (Sept 2026))2–6 wk
Johanson Group, LLPLicensed CPA firm focused on security compliance auditsNot published — request a scoped quoteVaries — confirm in proposal
SensibaTop-75 U.S. accounting and consulting firmNot published — request a scoped quoteVaries — confirm in proposal
KirkpatrickPriceAssurance specialist$12K–$45K (published planning range (Sept 2026))3–8 wk
360 AdvancedCybersecurity and compliance audit firm$15K–$80K (published planning range (Sept 2026))3–12 wk
BARR AdvisorySecurity and compliance advisory + attest practice$15K–$50K (published planning range (Sept 2026))8–16 wk
ArmaninoNational full-service CPA firm$15K–$40K (published planning range (Sept 2026))3–12 wk
AprioNational full-service CPA and advisory firm$22K–$75K (published planning range (Sept 2026))4–10 wk
WithumNational top-ranking public accounting and advisory firmNot published — request a scoped quoteVaries — confirm in proposal
A-LIGNLicensed CPA firm$15K–$50K (published planning range (Sept 2026))3–12 wk
BDONational full-service CPA firmNot published — request a scoped quoteVaries — confirm in proposal
RSMNational CPA firm focused on the middle marketNot published — request a scoped quoteVaries — confirm in proposal
Grant ThorntonNational full-service CPA and advisory firmNot published — request a scoped quoteVaries — confirm in proposal

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

For enterprise buyers

Regulated, multi-entity, or multi-framework programs — or a stakeholder that requires a Big Four or top-tier name on the report.

FirmTypeType 2 planning rangeFieldwork window
A-LIGNLicensed CPA firm$15K–$50K (published planning range (Sept 2026))3–12 wk
BDONational full-service CPA firmNot published — request a scoped quoteVaries — confirm in proposal
RSMNational CPA firm focused on the middle marketNot published — request a scoped quoteVaries — confirm in proposal
Grant ThorntonNational full-service CPA and advisory firmNot published — request a scoped quoteVaries — confirm in proposal
SchellmanTop-50 CPA firm$20K–$100K (published planning range (Sept 2026))3–12 wk
CoalfireCybersecurity assessment and advisory firm$40K–$120K (published planning range (Sept 2026))4–12 wk
DeloitteBig Four professional-services network$60K–$400K (published planning range (Sept 2026))6–18 wk

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

All 19 auditor profiles

Auditor

Zero Day CPA

Zero Day CPA is a Michigan-based boutique accounting firm focused on SOC 1, SOC 2, and HIPAA audits for B2B SaaS and service organizations. It offers readiness assessments, gap analyses, and Type I, Type II, and combined-framework audits with on-site or remote delivery.

West Bloomfield, Michigan · Founded Not disclosed
SOC 1, SOC 2, SOC 3, HIPAA
Auditor

Thoropass

Thoropass pairs an auditor-led assurance practice with compliance technology. The SOC 2 report is issued by its licensed CPA entity, Laika Compliance, LLC (dba Thoropass Assurance), while its platform handles evidence collection — and buyers can keep Vanta, Drata, or other GRC tools they already use. It publishes package pricing starting at $9,995.

New York, New York · Founded 2019
SOC 1, SOC 2, SOC 3, ISO 27001, HIPAA, PCI DSS, HITRUST
Auditor

Prescient Assurance

Prescient Assurance, founded in 2021, positions itself as the security-testing-led SOC 2 auditor for SaaS companies, pairing audit teams with cloud-native and application-security experience. It emphasizes startup-friendly, technology-driven engagements.

New York, New York · Founded 2021
SOC 1, SOC 2, SOC 2+, CSA STAR, HIPAA/HITECH, GDPR, ISO 27001
Auditor

MJD Advisors

MJD Advisors is a CPA firm concentrated on SOC reporting rather than tax or general financial-statement audit work. Its narrow service model suits buyers who want a smaller firm centered on the attestation they actually need.

Des Moines, Iowa · Founded Not disclosed
SOC 1, SOC 2
Auditor

Johanson Group, LLP

Johanson Group, LLP is a licensed CPA firm dedicated to security and compliance audits. It publishes detailed public guidance on the SOC 2 process and offers readiness assessments, examinations, and audits aimed at making the audit cycle transparent.

United States (remote-first practice) · Founded 2015
SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS, HIPAA, GDPR, NIST 800-53 / 800-171
Auditor

Sensiba

Sensiba is a top-75 U.S. accounting and consulting firm that expanded its cybersecurity audit practice by acquiring AssuranceLab in 2025. It serves more than 2,300 startup and technology-driven clients, runs remote-first, flat-fee audits, and is a Drata alliance partner.

San Ramon, California · Founded 1977
SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, NIST CSF, CMMC, CSA STAR
Auditor

KirkpatrickPrice

KirkpatrickPrice is a Nashville-based assurance specialist with a long-running SOC practice supporting SaaS, managed services, fintech, and healthcare clients. It sits in the middle ground between a small SOC boutique and a large enterprise firm, with PCI and HITRUST coverage alongside SOC.

Nashville, Tennessee · Founded Not disclosed
SOC 1, SOC 2, PCI DSS, HITRUST, ISO 27001
Auditor

360 Advanced

360 Advanced, founded in 2004, delivers integrated audit, advisory, and testing services across SOC, ISO, HITRUST, PCI, and FedRAMP frameworks. In some states it operates under the name Hiestand, Brand, Loughran, P.A. to meet CPA licensing requirements.

St. Petersburg, Florida · Founded 2004
SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS, HIPAA, HITRUST, FedRAMP
Auditor

BARR Advisory

BARR Advisory specializes in cybersecurity consulting and compliance for companies with high-value data in cloud environments (AWS, Azure, Google Cloud). It is authorized as a CMMC C3PAO and accredited to certify against ISO 27001, 27701, and 42001.

Kansas City, Missouri · Founded 2014
SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27701, ISO 42001, PCI DSS, HITRUST, CMMC

Comparing firms? Tell us your scope once — get quotes from your shortlist. Free · 2 minutes · no obligation.

Get matched quotes
Auditor

Armanino

Armanino is a national CPA and consulting firm with a broad assurance practice covering SOC, ISO certification, healthcare, and payment-framework work. Its scale suits mid-market companies that want SOC 2 alongside adjacent frameworks from one national firm.

San Ramon, California · Founded 1969
SOC 1, SOC 2, ISO 27001, HITRUST, PCI DSS
Auditor

Aprio

Aprio is a national CPA and advisory firm with an assurance practice spanning SOC, ISO, HITRUST, PCI, CMMC, and FedRAMP. Its breadth suits mid-market teams whose compliance program is expected to widen beyond a first SOC 2.

Atlanta, Georgia · Founded 1952
SOC 1, SOC 2, ISO 27001, HITRUST, PCI DSS, CMMC, FedRAMP
Auditor

Withum

Withum is a national advisory, tax, and accounting firm founded in 1974, with more than 3,500 professionals. Its dedicated SOC services team assists with SOC 1, SOC 2, and SOC for Cybersecurity engagements for technology and emerging-growth clients.

Princeton, New Jersey · Founded 1974
SOC 1, SOC 2, SOC for Cybersecurity
Auditor

A-LIGN

A-LIGN describes itself as the number-one issuer of SOC 2 reports, trusted by more than 6,400 organizations. It pairs audit services with its A-SCEND compliance management platform and works with businesses from startups to global enterprises.

Tampa, Florida · Founded 2009
SOC 1, SOC 2, ISO 27001, FedRAMP, CMMC, PCI DSS, HITRUST
Auditor

BDO

BDO is one of the largest U.S. accounting firms, with a risk advisory practice performing SOC 1, SOC 2, and SOC 3 examinations alongside internal audit and IT risk work. Its scale suits larger and multi-entity organizations.

Chicago, Illinois · Founded 1910
SOC 1, SOC 2, SOC 3
Auditor

RSM

RSM is a national professional-services firm focused on the middle market. Its risk consulting practice performs SOC 1, SOC 2, and SOC 3 readiness and attestation engagements across industries, with dedicated systems-and-process-assurance teams.

Chicago, Illinois · Founded 1926
SOC 1, SOC 2, SOC 3
Auditor

Grant Thornton

Grant Thornton describes itself as one of the leading SOC report issuers nationwide, with a dedicated Strategic Assurance & SOC Services practice whose staff work on SOC engagements full time. Its SOC.x methodology standardizes reporting across engagements.

Chicago, Illinois · Founded 1924
SOC 1, SOC 2, SOC 3, HITRUST, SOC for Cybersecurity
Auditor

Schellman

Schellman is a top-50 CPA firm focused on IT audit and compliance. It states that it is 100% independent with no consulting agenda, does not charge by the hour, and never uses interns or contractors on engagements.

Tampa, Florida · Founded 2002
SOC 1, SOC 2, ISO 27001, PCI DSS, FedRAMP, HITRUST, CMMC, ISO 42001
Auditor

Coalfire

Coalfire is a cybersecurity assessment firm serving enterprises with SOC, FedRAMP, PCI, and HITRUST work. Its assessment-led model suits large organizations running several high-assurance programs in parallel.

Westminster, Colorado · Founded 2001
SOC 1, SOC 2, PCI DSS, FedRAMP, HITRUST, ISO 27001
Auditor

Deloitte

Deloitte is one of the Big Four global professional-services networks. Buyers choose it when a customer contract, board, investor, or multi-jurisdiction footprint explicitly requires a Big Four issuer on the report.

New York, New York · Founded 1845
SOC 1, SOC 2, ISO 27001, PCI DSS + global assurance network

Read the video transcript

Free video walkthrough

Watch: get competitive SOC 2 quotes in one brief

  • One brief goes to auditors that fit your size and scope — no five separate sales calls.
  • Compare real ballparks, timelines, and what is included before you engage anyone.
  • Free for buyers. We only introduce licensed CPA firms — listings are never pay-to-rank.

Free · No obligation · Details go only to auditors matched to your request.

How we built this directory

Read the full methodology →

Get matched with the right auditor

Answer four quick questions and receive quotes from firms that fit your size, scope, and timeline.

Get a free quote