Directory

    SOC 2 Auditors in North America

    25 accredited SOC 2 audit firms serving North America on Nomona. SOC 2 is an AICPA attestation report that shows how a company protects customer data. A licensed CPA firm tests your controls and issues an independent opinion. Typical timeline: Readiness and remediation usually take two to six months. A Type I is issued at a point in time; a Type II requires an observation window, commonly three months for a first audit and six to twelve months thereafter, before the report is issued.. Typical cost: Auditor fees: SOC 2 Type I typically $10,000 to $20,000; Type II $20,000 to $50,000 in year one, dropping to roughly 60 to 80% of that in later years. All-in first-year cost (auditor fee plus readiness tooling plus internal time) commonly $50,000 to $80,000 for an early-stage SaaS, with $20,000 to $60,000 all-in for very small scopes. See the full breakdown in our SOC 2 audit cost guide..

    IA

    Insight Assurance

    Unverified Peer ReviewedUnclaimed account
    Tampa, United States
    HITRUSTSOC 2CMMCPCI DSSISO 27001
    0.0(0)

    Big-Four rigor at startup-friendly pricing.

    SaaSFintech
    JG

    Johanson Group LLP

    Unverified Peer ReviewedUnclaimed account
    United States
    SOC 1SOC 2SOC 3ISO 27001HIPAA
    0.0(0)

    Fixed-fee SOC 2 with rapid turnaround.

    SaaSFintech
    PS

    Prescient Security

    Unverified Peer ReviewedUnclaimed account
    Nashville, United States
    SOC 2ISO 27001ISO 42001HIPAAGDPRPCI DSSCREST
    0.0(0)

    Security-first audits, built by pen testers.

    SaaSFintechGovernment
    BA

    BARR Advisory

    Unverified Peer ReviewedUnclaimed account
    Kansas City, United States
    HITRUSTSOC 2ISO 27001
    0.0(0)

    One coordinated audit across five frameworks.

    SaaSFintech
    K

    KirkpatrickPrice

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 1SOC 2ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    Multi-framework CPA and cybersecurity assessment firm

    SaaSHealthcareFintech
    L&

    Linford & Company

    UnverifiedUnclaimed account
    Denver, United States
    SOC 1SOC 2SOC 3
    0.0(0)
    Pricing not published

    CPA firm focused primarily on SOC examinations and IT attestation

    SaaSHealthcare
    SL

    Sensiba LLP

    UnverifiedUnclaimed account
    Pleasanton, United States
    SOC 1SOC 2ISO 27001ISO 27701ISO 42001HIPAA
    0.0(0)
    Pricing not published

    Top 100 US CPA firm and certified B Corp, fixed-fee SOC 2 and ISO audits

    SaaSFintech
    T

    Tevora

    UnverifiedUnclaimed account
    Irvine, United States
    SOC 3SOC 1SOC 2PCI DSS
    0.0(0)
    Pricing not published

    Cybersecurity & compliance firm with multi-framework expertise.

    SaaSFintechGovernment
    W

    WithumSmith+Brown

    UnverifiedUnclaimed account
    Princeton, United States
    SOC 1SOC 2ISO 27001HIPAA
    0.0(0)
    Pricing not published

    National top-25 CPA and advisory firm with a SOC audit practice

    SaaSFintechHealthcare
    A

    AARC-360

    UnverifiedUnclaimed account
    Atlanta, United States
    SOC 1SOC 2SOC 3ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    PCAOB-registered CPA firm serving small and mid-sized companies.

    SaaSFintech
    AB

    Anchin Block & Anchin

    UnverifiedUnclaimed account
    New York, United States
    SOC 1SOC 2HIPAA
    0.0(0)
    Pricing not published

    New York CPA firm focused on the mid-market.

    SaaSFintechRetail
    BT

    Baker Tilly

    UnverifiedUnclaimed account
    Chicago, United States
    SOC 1SOC 2SOC 2+ISO 27001
    0.0(0)
    Pricing not published

    Global Top 10 CPA firm with a large-scale SOC audit practice

    SaaSFintechHealthcareGovernment
    CL

    Consilium Labs

    UnverifiedUnclaimed account
    Sunnyvale, United States
    SOC 2ISO 27001
    0.0(0)
    Pricing not published

    All-in-one ISO 27001 + SOC 2 with proprietary tooling.

    SaaS
    T

    Thoropass

    UnverifiedUnclaimed account
    New York, United States
    SOC 2ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    GRC platform and CPA audit under a single contract

    SaaSFintechHealthcare
    ZD

    Zero Day CPA

    UnverifiedUnclaimed account
    Troy, United States
    SOC 2HIPAA
    0.0(0)
    Pricing not published

    SOC 2 and HIPAA audits with flexible delivery for smaller organizations

    SaaSHealthcare
    A

    AAFCPAs

    UnverifiedUnclaimed account
    Westborough, United States
    SOC 1SOC 2HIPAA
    0.0(0)
    Pricing not published

    IT audit services for service organizations.

    SaaSHealthcare
    A

    Aprio

    UnverifiedUnclaimed account
    Atlanta, United States
    SOC 2ISO 27001HITRUST
    0.0(0)
    Pricing not published

    Top-25 CPA & advisory firm with tech focus.

    SaaSFintechHealthcare
    A

    Armanino

    UnverifiedUnclaimed account
    San Ramon, United States
    SOC 2ISO 27001
    0.0(0)
    Pricing not published

    Top-25 CPA firm with a technology-sector focus.

    SaaSFintech
    C(

    CBIZ (Mayer Hoffman McCann CPAs)

    UnverifiedUnclaimed account
    Kansas City, United States
    SOC 1SOC 2SOC 3
    0.0(0)
    Pricing not published

    7th-largest US accounting firm, risk advisory and SOC attestation practice

    SaaSFintechHealthcare
    A

    A-LIGN

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 1HITRUSTFedRAMPSOC 2PCI DSSHIPAAISO 27001
    0.0(0)
    Pricing not published

    Single-provider audits across SOC 2, ISO 27001, FedRAMP, HITRUST, and PCI DSS

    SaaSFintechHealthcareGovernment
    S&

    Schellman & Company

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 3SOC 1HITRUSTFedRAMPSOC 2CMMCPCI DSSISO 27001
    0.0(0)
    Pricing not published

    One of the largest independent SOC examination providers in the US

    SaaSFintechHealthcareGovernment
    IP

    IS Partners

    UnverifiedUnclaimed account
    Horsham, United States
    SOC 1HITRUSTSOC 2CMMCPCI DSSISO 27001NIST
    0.0(0)
    Pricing not published

    Boutique CPA firm led by former Big 4 partners.

    SaaSFintechHealthcare
    FA

    Fine Assurance

    Verified Peer Reviewed
    Pittsburgh, United States
    SOC 2SOC 1SOC 3ISO 27001ISO 42001HIPAAGDPROther: ISO 27701
    0.0(0)

    Quality-first SOC audits — not checkbox compliance.

    SaaSFintechHealthcareAIStartups
    Axipro

    Axipro

    Readiness Partner
    London, United Kingdom
    SOC 2ISO 27001ISO 27701ISO 42001HIPAAGDPRPCI DSSNISTDORACMMCCREST
    0.0(0)
    Pricing not published

    Certification audits and compliance services — SOC 2, ISO 27001 and more — with CREST-accredited penetration testing.

    SaaSFintechOther
    MA

    Modern Assurance

    Verified Peer Reviewed
    United States
    SOC 1SOC 2SOC 3HIPAAGDPR
    0.0(0)

    Peer-reviewed CPA firm with no GRC platform partnerships.

    SaaSFintechHealthcareAIStartups

    Frequently asked

    How many SOC 2 auditors serve North America?

    Nomona lists 25 independent, accredited SOC 2 audit firms serving North America today, including firms with global coverage.

    How much does a SOC 2 audit typically cost?

    Auditor fees: SOC 2 Type I typically $10,000 to $20,000; Type II $20,000 to $50,000 in year one, dropping to roughly 60 to 80% of that in later years. All-in first-year cost (auditor fee plus readiness tooling plus internal time) commonly $50,000 to $80,000 for an early-stage SaaS, with $20,000 to $60,000 all-in for very small scopes. See the full breakdown in our SOC 2 audit cost guide.