GetSOC2

SOC 2 auditor and consultant directory

What each listing means, how the tiers differ, and what to check before you sign with any of the firms below.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Filtering happens in your browser. Nothing is sent anywhere and the order never changes.

83 firms listed on GetSOC2.

Our offerings

TrazTech Inc. VerifiedOperates this site

The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Canadian privacy, Trust center, Cloud compliance, AI-built app QA, AI security, Security questionnaires, Auditor management, Internal audit, Threat and risk assessment, Tabletop and continuity testing, Cyber insurance readiness, Technical due diligence, Outsourced privacy officer

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF, PIPEDA, PHIPA

Verified firms

Verified means the firm exists as a registered business, does the work its listing claims, and holds the credentials it states. It is normally a paid tier, though not every Verified listing was paid for. The order inside the tier is fixed either way and is not for sale. See how listings work.

Johanson Group LLP Verified

A licensed US CPA firm running SOC 1, SOC 2 and SOC 3 examinations and accredited as an ISO 27001 certification body, working mostly with early-stage technology companies.

Colorado Springs, Colorado, United States · SOC 2 audit, ISO 27001

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

MHM Professional Corporation Verified

A licensed Canadian CPA firm that performs SOC attestations and is an SCC-accredited certification body for ISO standards, including the first Canadian accreditation for ISO/IEC 42001 AI governance audits.

Calgary, Alberta · SOC 2 audit, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PIPEDA

Everyone else

Listed from public information and not yet claimed by the firm, so the details here are ours rather than theirs. If this is your firm, claim it and it becomes yours to edit.

13 Security Unclaimed

Information security consultancy that works through GRC platforms to get clients through SOC 2 Type 1 and Type 2 audits carried out by an independent auditor.

New York, New York, United States · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

360 Advanced Unclaimed

A licensed Florida CPA firm (licence AD67897, PCAOB registered) that performs SOC 2 examinations and signs the attestation opinion, alongside ISO, HIPAA, PCI DSS, NIST and FedRAMP work.

St. Petersburg, Florida, United States · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

3Tenets Consulting Unclaimed

Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.

Ontario · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, AI security

Frameworks: SOC 2, NIST CSF, PHIPA

7 River Systems Unclaimed

Runs internal audits and readiness assessments across SOC 2 and other frameworks and builds compliance programs for clients ahead of an external audit.

Maryland, United States · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

A-LIGN Unclaimed

Certification body accredited by ANAB and UKAS to audit and issue ISO/IEC 27001 certificates, and also offering ISO/IEC 42001 certification.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

AARC-360 Unclaimed

A PCAOB registered CPA firm with an AICPA peer review report that performs SOC 1, SOC 2 and SOC 3 examinations and signs the opinion.

Alpharetta, Georgia, United States · SOC 2 audit

Frameworks: SOC 2

ABM Integrated Solutions Unclaimed

IT firm whose compliance practice prepares clients for SOC 2 and ISO 27001 certification using a compliance automation platform, and does not issue certificates.

Dartmouth, Nova Scotia · SOC 2 readiness, ISO 27001, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001

Accedere Unclaimed

Offers SOC attestation reporting and ISO/IEC certification work from offices in the United States, India and the UAE; the site states no CPA firm licence, so it is listed as readiness only here.

Denver, Colorado, United States · SOC 2 readiness, Compliance advisory, Cloud compliance

Frameworks: SOC 2

Adsero Security Unclaimed

Offers SOC 2 Audit Prep covering Type I and Type II certification preparation, leaving the attestation to an independent audit firm.

Tampa, Florida, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Agency Unclaimed

US based compliance engineers who run control implementation, evidence collection and audit coordination for client SOC 2 programs; the audit is performed by others.

United States · SOC 2 readiness, vCISO, Compliance advisory

Frameworks: SOC 2

Airius Unclaimed

Implements and manages regulatory compliance frameworks including SOC 2 and provides readiness assessments and audit preparation services rather than the audit itself.

Fairfield, Connecticut, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Amomitto Security Unclaimed

Runs SOC 2, ISO 27001 and HIPAA engagements covering readiness and post-audit maintenance, coordinating the audit rather than issuing the report.

SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA

Aprio Unclaimed

Aprio LLP is a licensed independent CPA firm providing attest services, and its team reports more than 10,000 SOC reports completed including SOC 2 Type II audits.

SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Assurance Dimensions Unclaimed

A licensed independent CPA firm that provides attest services and performs SOC 1 and SOC 2 audits as well as readiness work through its IT advisory group.

SOC 2 audit, SOC 2 readiness

Frameworks: SOC 2

Atoro Unclaimed

Compliance consultancy that builds the controls and evidence behind the SOC 2 report North American buyers ask for, and runs internal audits rather than signing opinions.

Portarlington, Ireland · SOC 2 readiness, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Audit Peak Unclaimed

Performs SOC 1, SOC 2 and SOC 3 engagements and states its team members are CPAs, but the site carries no statement of firm level CPA licensure, so it is listed as readiness only here.

New York, New York, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

Auditwerx Unclaimed

Attest and audit services are provided by Auditwerx LLC and Carr Riggs & Ingram LLC as CPA firms, covering SOC 1, SOC 2 and SOC 3 examinations plus PCI DSS, HIPAA, HITRUST, NIST CSF, CMMC and ISO 27001.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

BALANCED+ Unclaimed

IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.

Mississauga, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy, Cloud compliance

Frameworks: SOC 2, ISO 27001, PIPEDA, PHIPA

BARR Advisory Unclaimed

Firm offering virtual CISO and security program management within its advisory and managed services line, oriented to compliance program delivery.

SOC 2 readiness, ISO 27001, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

Boulay Unclaimed

A CPA firm with 107 CPAs whose risk advisory group delivers SOC 1, SOC 2 and SOC 3 reporting along with ISO 27001 compliance and Microsoft SSPA attestations.

Minneapolis, Minnesota, United States · 320 · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

Bright Defense Unclaimed

Cybersecurity firm that gets clients SOC 2 ready with scoping, a control baseline and evidence workflows, then supports them through the external audit.

Culver City, California, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Certi360 Unclaimed

Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.

Laval, Quebec · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Cherry Bekaert Unclaimed

Cherry Bekaert LLP is a licensed independent CPA firm providing attest services, including SOC reporting engagements that it signs.

3000 · SOC 2 audit

Frameworks: SOC 2

CLA (CliftonLarsonAllen) Unclaimed

A licensed CPA firm that performs SOC 1, SOC 2 and SOC 2+ examinations, including a readiness assessment before the examination.

Minnesota, United States · SOC 2 audit, SOC 2 readiness

Frameworks: SOC 2

Cognisys Unclaimed

UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.

United Kingdom · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Compass IT Compliance Unclaimed

Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.

SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, HIPAA, PCI DSS, NIST CSF

Compliance Foundry Unclaimed

Compliance engineering firm in Silicon Valley that prepares clients for the SOC 2 audit through a 28 day readiness program with automated remediation of cloud controls; it is not a CPA firm and does not sign opinions.

California, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

ConstellationGRC Unclaimed

California CPA firm, ConstellationGRC CPA PC, licensed by the California Board of Accountancy, that performs SOC 2 examinations and signs the resulting report.

Seal Beach, California, United States · SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Corporate Prime Solutions Inc. Unclaimed

Consultancy providing end to end ISO 27001 advisory, assessment and training to prepare clients for external certification audits, and does not issue certificates.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

Cyber Defense Advisors Unclaimed

Cyber compliance consultancy listing SOC 2 compliance among its services, preparing clients for the audit rather than signing the opinion.

Tampa, Florida, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

CyberCrest Compliance Unclaimed

Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.

Encinitas, California, United States · SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Cycore Unclaimed

Compliance services firm that guides clients through the whole SOC 2, ISO 27001 and HIPAA process from initial assessment to certification, with the audit done by others.

SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA

Digital Fort Unclaimed

Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.

Winnipeg, Manitoba · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Doane Grant Thornton Unclaimed

Canadian accounting and business advisory LLP whose third party assurance practice issues SOC 1, SOC 2 and SOC 3 control reports, so the firm signs the attestation opinion rather than only preparing clients for the audit.

3000+ · SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Doeren Mayhew Unclaimed

A licensed independent CPA firm that performs SOC 2 Type 1 and Type 2 examinations and signs the report opinion.

SOC 2 audit

Frameworks: SOC 2

Eide Bailly Unclaimed

A licensed independent CPA firm providing attest services, including SOC 2 reports against the AICPA trust services criteria.

SOC 2 audit

Frameworks: SOC 2

Elastify Unclaimed

Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

ESKA Unclaimed

Provides end-to-end SOC 2 preparation covering gap analysis, policy development and control implementation, leaving the report itself to an independent auditor.

Ontario · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

EY Canada Unclaimed

The technology risk assurance practice of EY Canada performs SOC 1, SOC 2 and SOC 3 engagements and issues the resulting attestation reports, so the firm signs the opinion rather than only preparing clients for the audit.

SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Fine Assurance Unclaimed

Fine CPA LLC, doing business as Fine Assurance, is a licensed Pennsylvania CPA firm that performs and signs SOC 2 Type 1, Type 2, SOC 2+ and SOC 3 reports.

Pennsylvania, United States · SOC 2 audit

Frameworks: SOC 2

Framework Security Unclaimed

Firm selling virtual CISO under managed security, delivered hands-on through weekly working sessions and engineers paired with client staff.

SOC 2 readiness, vCISO, Compliance advisory, AI security

Frameworks: SOC 2, ISO 42001, PCI DSS, NIST CSF

Fusion Computing Limited Unclaimed

Toronto provider selling combined vCIO and vCISO services as strategic IT planning and security leadership, including SOC 2 readiness support.

Toronto, Ontario · SOC 2 readiness, vCISO, Compliance advisory

Frameworks: SOC 2, PIPEDA

Genius GRC Unclaimed

Develops SOC 2 controls and prepares clients to pass a cybersecurity audit conducted by an outside firm.

SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

GreenHat Security Unclaimed

Firm selling fractional and virtual CISO services positioned as security leadership that fits the company stage, with SOC 2 readiness work.

SOC 2 readiness, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, PIPEDA

GRF CPAs & Advisors Unclaimed

An independent public accounting firm that performs SOC 2 Type 1 and Type 2 audits and signs the report opinion.

North Bethesda, Maryland, United States · SOC 2 audit

Frameworks: SOC 2

Guardlii Unclaimed

Security services firm that assists clients in achieving SOC 2 compliance for supply chain and data protection requirements rather than performing the audit.

SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

GuardsArm Unclaimed

Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.

Edmonton, Alberta · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

IRM Consulting & Advisory Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

IS Partners Unclaimed

Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.

Dresher, Pennsylvania, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

Kaufman Rossin Unclaimed

A CPA and advisory firm that performs SOC 1, SOC 2 and SOC 3 examinations, including Type 1 and Type 2 testing, and signs the opinion.

Miami, Florida, United States · SOC 2 audit

Frameworks: SOC 2

KirkpatrickPrice Unclaimed

A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.

Nashville, Tennessee, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

Kobalt.io Unclaimed

Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

Lazarus Alliance Unclaimed

States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.

SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF, PIPEDA

LBMC Unclaimed

A licensed CPA firm that performs SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity examinations under SSAE 18 and signs the report opinion.

Brentwood, Tennessee, United States · SOC 2 audit

Frameworks: SOC 2

Linford & Company Unclaimed

A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.

Denver, Colorado, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

McKonly & Asbury Unclaimed

A Pennsylvania certified public accounting firm with a dedicated SOC practice that performs SOC 2 audits and signs the opinion.

Camp Hill, Pennsylvania, United States · SOC 2 audit

Frameworks: SOC 2

Mirai Security Unclaimed

Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001

Oread Risk & Advisory Unclaimed

Attestation, information security and compliance consulting firm that conducts SOC reporting engagements and IT security reviews; the site names a CPA principal but does not state firm-level CPA licensure for signing SOC 2 opinions.

Kansas, United States · SOC 2 readiness, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Pilotcore Unclaimed

Ottawa cloud and DevSecOps consultancy whose audit readiness service maps SOC 2 and customer security requirements to controls and evidence. Not a CPA firm and does not sign SOC 2 opinions.

Ottawa, Ontario · SOC 2 readiness, Compliance advisory, Cloud compliance

Frameworks: SOC 2

Render Compliance Unclaimed

Licensed CPA firm in Washington State that performs SOC 2 attestations and signs the report, and also runs gap assessments to determine readiness before fieldwork.

Seattle, Washington, United States · SOC 2 audit, SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Rhymetec Unclaimed

Provider that sets up and runs a client internal information security and data privacy program, supplying executive-level security leadership.

SOC 2 readiness, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

Richey May Unclaimed

A licensed independent CPA firm providing attest services, with a SOC audit team that performs SOC 1, SOC 2 and SOC 3 engagements.

SOC 2 audit

Frameworks: SOC 2

risk3sixty Unclaimed

GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.

Roswell, Georgia, United States · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, NIST CSF

Sage Audits Unclaimed

A Colorado licensed CPA firm (licence FRM.5000785) that performs SOC 2 examinations and signs the report opinion, working mainly with SaaS companies.

Westminster, Colorado, United States · SOC 2 audit

Frameworks: SOC 2

Sagentix Advisors Unclaimed

Ottawa advisory firm whose cyber and AI practice sells ISO 27001 and SOC 2 readiness alongside privacy and AI governance work. Not a CPA firm and does not sign SOC 2 opinions.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

SAV Associates Unclaimed

CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA

Schellman Unclaimed

Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Schneider Downs Unclaimed

A Top 60 independent CPA firm that performs SOC 2 Type 1 and Type 2 examinations and issues the opinion on the description, design and operating effectiveness of controls.

Pittsburgh, Pennsylvania, United States · SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Sikich Unclaimed

Sikich CPA LLC is a licensed CPA firm providing audit and attest services, and the cybersecurity practice performs service provider reviews covering SOC 1, SOC 2 and SOC 3 plus PCI DSS, HIPAA and penetration testing.

2500 · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA, PCI DSS

Tanner LLC Unclaimed

A CPA and consulting firm whose IT assurance practice performs SOC 1 and SOC 2 examinations and signs the report opinion.

Salt Lake City, Utah, United States · 400 · SOC 2 audit

Frameworks: SOC 2

Tempo Audits Unclaimed

A UKAS accredited assurance provider offering SOC 2 work for SaaS teams; the site does not state which CPA firm signs the report, so it is listed as readiness only here.

United Kingdom · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

The Driz Group Unclaimed

Handles SOC 2 readiness assessment and gap remediation and supports clients through to attestation, which an independent auditor issues.

SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Throughline Unclaimed

A registered CPA firm and certification body that performs SOC 1 and SOC 2 audits and signs the report, and also covers ISO 27001 and ISO 42001.

Australia · SOC 2 audit, ISO 27001, ISO 42001

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

Trava Security Unclaimed

Offers compliance readiness and audit preparation plus a managed compliance program so clients can reach SOC 2 certification through an independent auditor.

Indianapolis, Indiana, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Truvo Cyber Unclaimed

Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

URM Consulting Services Unclaimed

Provides SOC 2 gap analysis, remediation and consultancy for organizations preparing for a Type 1 or Type 2 report rather than producing the report.

Reading, United Kingdom · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

Withum Unclaimed

WithumSmith+Brown PC performs SOC 2 Type I and Type II attestations with independent reporting by AICPA licensed CPAs, and also runs SOC 1, SOC for Cybersecurity and ISO 27001 consulting.

Princeton, New Jersey, United States · 3200 · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, NIST CSF

Wolf & Company PC Unclaimed

An accounting firm whose assurance practice issues SOC 1, SOC 2 and SOC 3 reports and agreed upon procedures, with work subject to AICPA peer review and the AICPA Enhanced Oversight Program for SOC reporting.

SOC 2 audit, Compliance advisory

Frameworks: SOC 2, PCI DSS

Workstreet Unclaimed

Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.

100+ · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Trust center, Cloud compliance, Security questionnaires

Frameworks: SOC 2, ISO 27001

Zero Day CPA Unclaimed

A CPA-led audit practice that performs SOC 1, SOC 2 Type I and Type II and SOC 3 examinations and signs the report, and also offers penetration testing and HIPAA work.

West Bloomfield, Michigan, United States · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA

Browse a shorter list

The whole directory is above. These are the same firms cut down to one service or one province, which is usually the faster way in.

How do I know I can trust one of these firms?

Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.

Is a listing here a recommendation?

No. Firms are listed from public information or added by the firm itself, and a Verified badge is a tier rather than an endorsement. Nothing on this page says a firm is the right one for you. Compare at least three.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

If you run a firm rather than needing one, listing your firm sets out both tiers and what each costs, and where SOC 2 work actually comes from is the honest version of how much a directory contributes next to the channels that do not cost money. If you need quotes now rather than a list to read, the quote request form puts your scope in front of Canadian firms that do this work. If you want to understand what you are buying first, the guide to choosing a SOC 2 auditor covers independence, fees and the questions worth asking, and links to a page for each of twenty Canadian cities. The order firms appear in is explained on how we rank firms.

What this directory lists

Two categories, kept separate on purpose.

Audit firms. CPA firms that perform SOC 2 examinations and sign the opinion. In Canada that means a firm registered with a provincial CPA body and carrying the practice rights to perform assurance and attestation engagements. A listing here will record which provinces the firm is registered in, whether it performs Type 1 and Type 2 engagements, which Trust Services Criteria it covers, and whether it also audits ISO 27001 or other frameworks through an affiliated body.

Readiness consultants. Firms and independent practitioners who do the preparation work: gap assessment, policy writing, control design, remediation project management, evidence collection, and sitting beside you during fieldwork. They cannot audit you. A listing here will record what engagement models the firm offers, whether it works with a compliance platform, and what size of company it usually serves.

Listings will also carry the city or cities a firm actually serves. Most of this work is remote, so location matters less than people expect, but it still matters for on-site control testing and for firms that prefer clients in one time zone.

Auditor or consultant, and why you cannot use one firm for both

This is the distinction most companies get wrong on their first audit, and it is not a marketing nuance. The auditor has to be independent of the controls being audited. A firm that wrote your policies, designed your access review process and built your evidence collection cannot then issue an opinion on whether those controls work, because it would be auditing its own work.

What each kind of firm does on a SOC 2 engagement
QuestionAudit firmReadiness consultant
Can it issue the report?Yes, that is the whole jobNo
Must it be a licensed CPA firm?YesNo. Which work needs a licence
Can it write your policies?No, that breaks independenceYes
When you engage itOnce controls are runningBefore anything else
How it pricesFixed fee per engagement, quoted on scopeProject fee, day rate, or monthly retainer
Typical Canadian range$20,000 to $60,000 CAD for a first Type 2$6,000 to $60,000 CAD depending on how much you hand over

Some large firms sell both through separate teams and claim a wall between them. Treat that claim carefully. It can be legitimate, and the professional standards allow certain non-attest services under conditions, but the safe answer for a small company is two firms. Buyers reading your report do not know your internal governance and a reviewer who spots the same firm on both sides will ask about it. The full cost picture for both is on the SOC 2 cost page, and SOC2Prep covers the readiness work itself if you plan to do it without a consultant.

Two axes are deliberately absent. There is no rating, because we have not run these engagements and a score we cannot defend is worse than no score. And there is no sort by price, because audit fees are quoted on scope and a number attached to a firm without a scope beside it would mislead every reader who saw it. What drives an audit fee covers why.

What a listing shows

The two rows below are examples, not real firms. The names are invented to show the format and the difference between the two listing states.

Example Assurance LLP Verified

Audit firmToronto, OntarioType 1 and Type 2Security, Availability, Confidentiality

Sample entry showing a claimed and checked listing. A verified row means we confirmed the CPA firm registration and spoke to the firm about what it audits.

Request a quote

Sample Readiness Partners Unclaimed

Readiness consultantVancouver, British ColumbiaGap assessment and remediation

Sample entry showing an unclaimed listing. An unclaimed row is one nobody at the firm has confirmed or corrected yet, so the detail on it is only as good as the public record it came from.

Claim this listing

Nothing above is a firm. When real listings exist, this page will carry them in the same two states and the badge will mean what it says here.

How listings work

There are two tiers and one of them is paid. Saying which is which on the page a buyer reads, rather than only on the page a firm reads, is the point. The firm-facing page carries the full terms.

Directory tiers as a reader should understand them
TierCost to the firmWhat it means to you
Unclaimed$0Assembled from public information. Nobody at the firm has confirmed or corrected it
Claimed$0Somebody at the firm confirmed the detail is right and owns keeping it current
Verified$300 CAD/month or $3,000 CAD/yearWe checked the firm exists and is what it claims. Paid, and shown above the free tier

A claimed listing is free and stays free. Firm name, category, the provinces and cities served, a line describing the work, and a link. Claiming is done by writing to [email protected] from a company address, and nothing about it expires or converts to a trial.

Verified is the paid tier, at $300 CAD a month or $3,000 CAD a year, and it is the only badge that means we did work. For an audit firm that means we confirmed registration with a provincial CPA body and the practice rights for assurance engagements, and that a person at the firm confirmed what it audits. For a consultant it means we confirmed the business is real, spoke to somebody, and checked the firm delivers the services claimed rather than reselling somebody else's.

Two things follow from that, and a reader should hold both. Verified is a paid tier, so a firm without the badge is not worse, it is unpaid. And verification is a real check rather than a payment confirmation, so the badge is not merely a receipt. It says the firm exists and is what it says it is. It does not say the firm is good, and no badge on this site is an endorsement.

Verified listings sit above free ones. Within each tier the order is fixed and is not for sale, and nothing a firm pays changes what any guide, cost page or comparison on this site says about it.

How this site makes money

Three ways, all of them worth knowing before you read anything here as neutral. TrazTech earns a fee when a quote request turns into an engagement. Firms pay $300 CAD a month for the Verified tier, which buys the badge and placement above the free tier and buys nothing else. And where we recommend a compliance platform elsewhere on this site, some of those links are affiliate links and are labelled as such. None of the three changes what a page says about a firm or a product.

How to choose between firms

Shortlist three, not one and not eight. Give each the same scope in writing: headcount, the systems in scope, which Trust Services Criteria, whether you want Type 1 first, and the date the report has to exist by. Quotes that price different scopes cannot be compared, and most of the wild variation companies report comes from exactly that.

Ask an audit firm who signs the opinion and whether that partner has audited a company built like yours. Ask how many SOC 2 engagements the firm ran last year. Ask what renewal pricing looks like in year two and get it in writing before you sign year one, because renewals are where a cheap first-year quote gets recovered. Ask what happens if the auditor finds an exception during fieldwork and how that changes the timeline.

What readiness consulting costs and how engagements are shaped is worth reading before you talk to anyone. Ask a consultant what they will hand over at the end, whether the policies are templates or written against how you actually operate, and who does the evidence collection. A consultant who leaves you with a policy set nobody follows has made your audit harder, not easier. If the underlying problem is that nobody internally owns security, a fractional CISO is usually a better answer than a fixed-length readiness project.

Two things to walk away from: a firm that quotes a fixed price before asking what is in scope, and a firm that promises a clean opinion. Nobody can promise the outcome of an audit they have not performed, and a firm that does is either not doing the work or not planning to report what it finds.

Add your firm to the directory

Canadian audit firms and readiness consultants can claim a listing for nothing. The page for firms sets out both tiers, what Verified costs in Canadian dollars, and what it does not buy.

List your firm

Common questions

How did firms get into this directory?

Most were researched from public information: registration records, the firm's own site, and the credentials it publishes. Those listings are ours rather than the firm's until someone there claims it. A claimed listing is free and becomes the firm's to edit. Verified means we checked the firm is real and is what it says it is.

How much does it cost a firm to be listed?

A claimed listing is free and stays free. The Verified tier is paid, at $300 CAD a month or $3,000 CAD a year, and it buys the badge and placement above the free tier. Order within a tier is not for sale, and no payment changes what this site writes about a firm. The full terms are here.

Can the same firm do our readiness work and our audit?

Not safely. The auditor has to be independent of the controls it examines, so a firm that designed your controls cannot issue an opinion on them. Some large firms offer both through separated teams, but for a small company the clean answer is one consultant and one audit firm.

What does the Verified badge mean, and is it paid?

It means we confirmed the firm is real and is what it claims to be. For an audit firm that includes checking registration with a provincial CPA body and the practice rights to perform assurance engagements. It is also a paid tier at $300 CAD a month, so read it as a checked firm that chose to pay for the check, rather than as a quality rating or an endorsement.

Does the auditor need to be in our province?

No. SOC 2 is an AICPA attestation standard rather than a provincial regime, and audits are performed remotely across the country as a matter of course. What matters is that the firm holds the practice rights to perform assurance work and has audited companies with an architecture like yours. See the auditor selection guide for the city pages.

How do I get quotes before the directory fills up?

Use the quote form. Describe your headcount, cloud setup, which criteria are in scope and your deadline, and the request goes to Canadian firms that quote this work. That route does not depend on the directory having entries.