Directory

    ISO 27001 Auditors in North America

    19 accredited ISO 27001 audit firms serving North America on Nomona. ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate. Typical timeline: Building and operating the ISMS before a first certification audit typically takes six to twelve months. Certification then runs on a three-year cycle: Stage 1 and Stage 2 audits up front, surveillance audits in years one and two, and recertification in year three.. Typical cost: Certification-body audit fees vary with organization size, number of sites, and scope, and are separate from the internal effort or consulting to build the ISMS. Larger, multi-site scopes cost materially more than a single-entity ISMS..

    IA

    Insight Assurance

    Unverified Peer ReviewedUnclaimed account
    Tampa, United States
    HITRUSTSOC 2CMMCPCI DSSISO 27001
    0.0(0)

    Big-Four rigor at startup-friendly pricing.

    SaaSFintech
    JG

    Johanson Group LLP

    Unverified Peer ReviewedUnclaimed account
    United States
    SOC 1SOC 2SOC 3ISO 27001HIPAA
    0.0(0)

    Fixed-fee SOC 2 with rapid turnaround.

    SaaSFintech
    PS

    Prescient Security

    Unverified Peer ReviewedUnclaimed account
    Nashville, United States
    SOC 2ISO 27001ISO 42001HIPAAGDPRPCI DSSCREST
    0.0(0)

    Security-first audits, built by pen testers.

    SaaSFintechGovernment
    BA

    BARR Advisory

    Unverified Peer ReviewedUnclaimed account
    Kansas City, United States
    HITRUSTSOC 2ISO 27001
    0.0(0)

    One coordinated audit across five frameworks.

    SaaSFintech
    CC

    Coalfire Certification

    UnverifiedUnclaimed account
    Westminster, United States
    ISO 27001ISO 27701
    0.0(0)
    Pricing not published

    ISO readiness assessments and certification audits only, no consulting

    SaaSGovernment
    K

    KirkpatrickPrice

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 1SOC 2ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    Multi-framework CPA and cybersecurity assessment firm

    SaaSHealthcareFintech
    SL

    Sensiba LLP

    UnverifiedUnclaimed account
    Pleasanton, United States
    SOC 1SOC 2ISO 27001ISO 27701ISO 42001HIPAA
    0.0(0)
    Pricing not published

    Top 100 US CPA firm and certified B Corp, fixed-fee SOC 2 and ISO audits

    SaaSFintech
    W

    WithumSmith+Brown

    UnverifiedUnclaimed account
    Princeton, United States
    SOC 1SOC 2ISO 27001HIPAA
    0.0(0)
    Pricing not published

    National top-25 CPA and advisory firm with a SOC audit practice

    SaaSFintechHealthcare
    A

    AARC-360

    UnverifiedUnclaimed account
    Atlanta, United States
    SOC 1SOC 2SOC 3ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    PCAOB-registered CPA firm serving small and mid-sized companies.

    SaaSFintech
    BT

    Baker Tilly

    UnverifiedUnclaimed account
    Chicago, United States
    SOC 1SOC 2SOC 2+ISO 27001
    0.0(0)
    Pricing not published

    Global Top 10 CPA firm with a large-scale SOC audit practice

    SaaSFintechHealthcareGovernment
    CL

    Consilium Labs

    UnverifiedUnclaimed account
    Sunnyvale, United States
    SOC 2ISO 27001
    0.0(0)
    Pricing not published

    All-in-one ISO 27001 + SOC 2 with proprietary tooling.

    SaaS
    T

    Thoropass

    UnverifiedUnclaimed account
    New York, United States
    SOC 2ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    GRC platform and CPA audit under a single contract

    SaaSFintechHealthcare
    A

    Aprio

    UnverifiedUnclaimed account
    Atlanta, United States
    SOC 2ISO 27001HITRUST
    0.0(0)
    Pricing not published

    Top-25 CPA & advisory firm with tech focus.

    SaaSFintechHealthcare
    A

    Armanino

    UnverifiedUnclaimed account
    San Ramon, United States
    SOC 2ISO 27001
    0.0(0)
    Pricing not published

    Top-25 CPA firm with a technology-sector focus.

    SaaSFintech
    A

    A-LIGN

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 1HITRUSTFedRAMPSOC 2PCI DSSHIPAAISO 27001
    0.0(0)
    Pricing not published

    Single-provider audits across SOC 2, ISO 27001, FedRAMP, HITRUST, and PCI DSS

    SaaSFintechHealthcareGovernment
    S&

    Schellman & Company

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 3SOC 1HITRUSTFedRAMPSOC 2CMMCPCI DSSISO 27001
    0.0(0)
    Pricing not published

    One of the largest independent SOC examination providers in the US

    SaaSFintechHealthcareGovernment
    IP

    IS Partners

    UnverifiedUnclaimed account
    Horsham, United States
    SOC 1HITRUSTSOC 2CMMCPCI DSSISO 27001NIST
    0.0(0)
    Pricing not published

    Boutique CPA firm led by former Big 4 partners.

    SaaSFintechHealthcare
    FA

    Fine Assurance

    Verified Peer Reviewed
    Pittsburgh, United States
    SOC 2SOC 1SOC 3ISO 27001ISO 42001HIPAAGDPROther: ISO 27701
    0.0(0)

    Quality-first SOC audits — not checkbox compliance.

    SaaSFintechHealthcareAIStartups
    A

    Axipro

    Readiness Partner
    London, United Kingdom
    SOC 2ISO 27001ISO 27701ISO 42001HIPAAGDPRPCI DSSNISTDORACMMCCREST
    0.0(0)
    Pricing not published

    Certification audits and compliance services — SOC 2, ISO 27001 and more — with CREST-accredited penetration testing.

    SaaSFintechOther

    Frequently asked

    How many ISO 27001 auditors serve North America?

    Nomona lists 19 independent, accredited ISO 27001 audit firms serving North America today, including firms with global coverage.

    How much does a ISO 27001 audit typically cost?

    Certification-body audit fees vary with organization size, number of sites, and scope, and are separate from the internal effort or consulting to build the ISMS. Larger, multi-site scopes cost materially more than a single-entity ISMS.