GetSOC2

SOC 2 audit firms in Canada

Firms in the GetSOC2 directory that do SOC 2 audit work, ordered by tier and then alphabetically.

37 firms.

SOC 2 audit firms in Canada

Johanson Group LLP Verified

A licensed US CPA firm running SOC 1, SOC 2 and SOC 3 examinations and accredited as an ISO 27001 certification body, working mostly with early-stage technology companies.

Colorado Springs, Colorado, United States · SOC 2 audit, ISO 27001

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

MHM Professional Corporation Verified

A licensed Canadian CPA firm that performs SOC attestations and is an SCC-accredited certification body for ISO standards, including the first Canadian accreditation for ISO/IEC 42001 AI governance audits.

Calgary, Alberta · SOC 2 audit, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PIPEDA

360 Advanced Unclaimed

A licensed Florida CPA firm (licence AD67897, PCAOB registered) that performs SOC 2 examinations and signs the attestation opinion, alongside ISO, HIPAA, PCI DSS, NIST and FedRAMP work.

St. Petersburg, Florida, United States · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

A-LIGN Unclaimed

Certification body accredited by ANAB and UKAS to audit and issue ISO/IEC 27001 certificates, and also offering ISO/IEC 42001 certification.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

AARC-360 Unclaimed

A PCAOB registered CPA firm with an AICPA peer review report that performs SOC 1, SOC 2 and SOC 3 examinations and signs the opinion.

Alpharetta, Georgia, United States · SOC 2 audit

Frameworks: SOC 2

Aprio Unclaimed

Aprio LLP is a licensed independent CPA firm providing attest services, and its team reports more than 10,000 SOC reports completed including SOC 2 Type II audits.

SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Assurance Dimensions Unclaimed

A licensed independent CPA firm that provides attest services and performs SOC 1 and SOC 2 audits as well as readiness work through its IT advisory group.

SOC 2 audit, SOC 2 readiness

Frameworks: SOC 2

Auditwerx Unclaimed

Attest and audit services are provided by Auditwerx LLC and Carr Riggs & Ingram LLC as CPA firms, covering SOC 1, SOC 2 and SOC 3 examinations plus PCI DSS, HIPAA, HITRUST, NIST CSF, CMMC and ISO 27001.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

Boulay Unclaimed

A CPA firm with 107 CPAs whose risk advisory group delivers SOC 1, SOC 2 and SOC 3 reporting along with ISO 27001 compliance and Microsoft SSPA attestations.

Minneapolis, Minnesota, United States · 320 · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

Cherry Bekaert Unclaimed

Cherry Bekaert LLP is a licensed independent CPA firm providing attest services, including SOC reporting engagements that it signs.

3000 · SOC 2 audit

Frameworks: SOC 2

CLA (CliftonLarsonAllen) Unclaimed

A licensed CPA firm that performs SOC 1, SOC 2 and SOC 2+ examinations, including a readiness assessment before the examination.

Minnesota, United States · SOC 2 audit, SOC 2 readiness

Frameworks: SOC 2

ConstellationGRC Unclaimed

California CPA firm, ConstellationGRC CPA PC, licensed by the California Board of Accountancy, that performs SOC 2 examinations and signs the resulting report.

Seal Beach, California, United States · SOC 2 audit, Compliance advisory

Frameworks: SOC 2

CyberCrest Compliance Unclaimed

Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.

Encinitas, California, United States · SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Doane Grant Thornton Unclaimed

Canadian accounting and business advisory LLP whose third party assurance practice issues SOC 1, SOC 2 and SOC 3 control reports, so the firm signs the attestation opinion rather than only preparing clients for the audit.

3000+ · SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Doeren Mayhew Unclaimed

A licensed independent CPA firm that performs SOC 2 Type 1 and Type 2 examinations and signs the report opinion.

SOC 2 audit

Frameworks: SOC 2

Eide Bailly Unclaimed

A licensed independent CPA firm providing attest services, including SOC 2 reports against the AICPA trust services criteria.

SOC 2 audit

Frameworks: SOC 2

EY Canada Unclaimed

The technology risk assurance practice of EY Canada performs SOC 1, SOC 2 and SOC 3 engagements and issues the resulting attestation reports, so the firm signs the opinion rather than only preparing clients for the audit.

SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Fine Assurance Unclaimed

Fine CPA LLC, doing business as Fine Assurance, is a licensed Pennsylvania CPA firm that performs and signs SOC 2 Type 1, Type 2, SOC 2+ and SOC 3 reports.

Pennsylvania, United States · SOC 2 audit

Frameworks: SOC 2

GRF CPAs & Advisors Unclaimed

An independent public accounting firm that performs SOC 2 Type 1 and Type 2 audits and signs the report opinion.

North Bethesda, Maryland, United States · SOC 2 audit

Frameworks: SOC 2

IS Partners Unclaimed

Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.

Dresher, Pennsylvania, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

Kaufman Rossin Unclaimed

A CPA and advisory firm that performs SOC 1, SOC 2 and SOC 3 examinations, including Type 1 and Type 2 testing, and signs the opinion.

Miami, Florida, United States · SOC 2 audit

Frameworks: SOC 2

KirkpatrickPrice Unclaimed

A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.

Nashville, Tennessee, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

Lazarus Alliance Unclaimed

States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.

SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF, PIPEDA

LBMC Unclaimed

A licensed CPA firm that performs SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity examinations under SSAE 18 and signs the report opinion.

Brentwood, Tennessee, United States · SOC 2 audit

Frameworks: SOC 2

Linford & Company Unclaimed

A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.

Denver, Colorado, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

McKonly & Asbury Unclaimed

A Pennsylvania certified public accounting firm with a dedicated SOC practice that performs SOC 2 audits and signs the opinion.

Camp Hill, Pennsylvania, United States · SOC 2 audit

Frameworks: SOC 2

Render Compliance Unclaimed

Licensed CPA firm in Washington State that performs SOC 2 attestations and signs the report, and also runs gap assessments to determine readiness before fieldwork.

Seattle, Washington, United States · SOC 2 audit, SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Richey May Unclaimed

A licensed independent CPA firm providing attest services, with a SOC audit team that performs SOC 1, SOC 2 and SOC 3 engagements.

SOC 2 audit

Frameworks: SOC 2

Sage Audits Unclaimed

A Colorado licensed CPA firm (licence FRM.5000785) that performs SOC 2 examinations and signs the report opinion, working mainly with SaaS companies.

Westminster, Colorado, United States · SOC 2 audit

Frameworks: SOC 2

Schellman Unclaimed

Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Schneider Downs Unclaimed

A Top 60 independent CPA firm that performs SOC 2 Type 1 and Type 2 examinations and issues the opinion on the description, design and operating effectiveness of controls.

Pittsburgh, Pennsylvania, United States · SOC 2 audit, Compliance advisory

Frameworks: SOC 2

Sikich Unclaimed

Sikich CPA LLC is a licensed CPA firm providing audit and attest services, and the cybersecurity practice performs service provider reviews covering SOC 1, SOC 2 and SOC 3 plus PCI DSS, HIPAA and penetration testing.

2500 · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA, PCI DSS

Tanner LLC Unclaimed

A CPA and consulting firm whose IT assurance practice performs SOC 1 and SOC 2 examinations and signs the report opinion.

Salt Lake City, Utah, United States · 400 · SOC 2 audit

Frameworks: SOC 2

Throughline Unclaimed

A registered CPA firm and certification body that performs SOC 1 and SOC 2 audits and signs the report, and also covers ISO 27001 and ISO 42001.

Australia · SOC 2 audit, ISO 27001, ISO 42001

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

Withum Unclaimed

WithumSmith+Brown PC performs SOC 2 Type I and Type II attestations with independent reporting by AICPA licensed CPAs, and also runs SOC 1, SOC for Cybersecurity and ISO 27001 consulting.

Princeton, New Jersey, United States · 3200 · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, NIST CSF

Wolf & Company PC Unclaimed

An accounting firm whose assurance practice issues SOC 1, SOC 2 and SOC 3 reports and agreed upon procedures, with work subject to AICPA peer review and the AICPA Enhanced Oversight Program for SOC reporting.

SOC 2 audit, Compliance advisory

Frameworks: SOC 2, PCI DSS

Zero Day CPA Unclaimed

A CPA-led audit practice that performs SOC 1, SOC 2 Type I and Type II and SOC 3 examinations and signs the report, and also offers penetration testing and HIPAA work.

West Bloomfield, Michigan, United States · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA

Get quotes instead of browsing

Describe what you need once and it reaches the firms on this page that match it.

Get quotes

Back to the full directory

Other ways to narrow the list

Same directory, cut a different way.

How do I know I can trust one of these firms?

Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.

How were these firms chosen?

They were listed from public information or added by the firm itself. Being listed is not a recommendation, and GetSOC2 does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

How many firms should I approach?

Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.