SOC 2 audit firms
Firms in the ISO27K directory that do soc 2 audit work, ordered by tier and then alphabetically.
14 firms.
Johanson Group LLP Verified
A licensed US CPA firm running SOC 1, SOC 2 and SOC 3 examinations and accredited as an ISO 27001 certification body, working mostly with early-stage technology companies.
MHM Professional Corporation Verified
A licensed Canadian CPA firm that performs SOC attestations and is an SCC-accredited certification body for ISO standards, including the first Canadian accreditation for ISO/IEC 42001 AI governance audits.
360 Advanced Unclaimed
A licensed Florida CPA firm (licence AD67897, PCAOB registered) that performs SOC 2 examinations and signs the attestation opinion, alongside ISO, HIPAA, PCI DSS, NIST and FedRAMP work.
A-LIGN Unclaimed
Certification body accredited by ANAB and UKAS to audit and issue ISO/IEC 27001 certificates, and also offering ISO/IEC 42001 certification.
Auditwerx Unclaimed
Attest and audit services are provided by Auditwerx LLC and Carr Riggs & Ingram LLC as CPA firms, covering SOC 1, SOC 2 and SOC 3 examinations plus PCI DSS, HIPAA, HITRUST, NIST CSF, CMMC and ISO 27001.
Boulay Unclaimed
A CPA firm with 107 CPAs whose risk advisory group delivers SOC 1, SOC 2 and SOC 3 reporting along with ISO 27001 compliance and Microsoft SSPA attestations.
CyberCrest Compliance Unclaimed
Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.
IS Partners Unclaimed
Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.
KirkpatrickPrice Unclaimed
A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.
Lazarus Alliance Unclaimed
States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.
Linford & Company Unclaimed
A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.
Schellman Unclaimed
Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.
Throughline Unclaimed
A registered CPA firm and certification body that performs SOC 1 and SOC 2 audits and signs the report, and also covers ISO 27001 and ISO 42001.
Withum Unclaimed
WithumSmith+Brown PC performs SOC 2 Type I and Type II attestations with independent reporting by AICPA licensed CPAs, and also runs SOC 1, SOC for Cybersecurity and ISO 27001 consulting.
Get quotes instead of browsing
Describe what you need once and it reaches the firms on this page that match it.
Get quotesHow were these firms chosen?
They were listed from public information or added by the firm itself. Being listed is not a recommendation, and ISO27K does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
How many firms should I approach?
Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.