Logo Menu

Barnes Dennig

Full-service CPA Verified Cincinnati, OH, USA
  • Licensed CPA firm — can issue a SOC 2 report
  • AICPA peer review: Pass · Accepted Mar 5, 2025 · Verify at AICPA → ·
    Details Review period: Jul 1, 2023–Jun 30, 2024 · Record checked: Sep 3, 2026

Barnes Dennig is a full-service cpa SOC 2 audit firm in Cincinnati, OH, USA. Its estimated SOC 2 Type II audit price is $15,000–$40,000; fieldwork to report takes 3–9 weeks.

Independent profile, researched and maintained by this directory from public sources. Barnes Dennig has not reviewed or verified this page. Work at Barnes Dennig? Verify and correct it — free →

Type 1 cost
$10K–$25K est.
Type 2 cost
$15K–$40K est.
Timeline
3–9 weeks
Accreditations
5 listed
Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

Barnes Dennig's estimated SOC 2 Type II audit price is $15,000–$40,000; fieldwork to report takes 3–9 weeks.

Type 1 cost
$10K–$25K
Type 2 cost
$15K–$40K
Timeline
3–9 wk
Team Size
225
Report Delivery
4-6 weeks
Response Time
24-48 hours

Type 2 cost Pricing Position

$2.5K observed market span · est. $450K
Barnes Dennig: $15K–$40K Full-service CPA avg: $31.187K–$82.355K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 3–9 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires a separate observation period, typically 3–12 months depending on scope.

Pricing context
98%

of Full-service CPA firms charge more for Type II.

Timeline context
97%

of Full-service CPA firms have longer minimum timelines.

Accreditations
5

verified accreditations. Group average: 2.

Source: soc2auditors.org/auditors/barnes-dennig/ · compiled and maintained by soc2auditors.org.

Who is Barnes Dennig?

Barnes Dennig is an independent, employee-owned U.S.-based CPA and advisory firm founded in 1965 by Bob Barnes and Al Dennig, headquartered in Cincinnati, Ohio. Being employee-owned means no outside investor or parent firm sits behind the audit opinion, which the firm points to as part of the objective, stakeholder-focused stance it brings to every engagement.

Effective January 1, 2025, the firm merged with Indianapolis-based Greenwalt CPAs (founded 1945), creating one combined firm operating under the Barnes Dennig name. The combined firm now has roughly 225 employees across five offices in three states — Cincinnati and Dayton (Ohio), Crestview Hills (Kentucky), and two locations in Indianapolis (Indiana).

The firm celebrated its 60th anniversary in 2025 and is recognized as a Top 200 Inside Public Accounting “Best of the Best” firm. Jay Rammes has served as Managing Director since 2018 and continues to lead the combined firm post-merger.

For SOC-specific work, approximately 20 people focus exclusively on SOC reports — readiness, fieldwork, audit, and report issuance handled entirely in-house, with no portion of the engagement outsourced. The SOC team is distributed across six time zones, allowing them to serve clients ranging from two-person startups to large multinationals. Their public materials confirm SOC clients in the United States as well as New Zealand, Europe, and the Philippines.

The firm is in good standing with the AICPA Peer Review Program, the independent CPA-firm-on-CPA-firm review of compliance with professional standards. Buyers running third-party risk reviews or vendor due diligence can use peer review status as part of the trust signal.

Who leads the Barnes Dennig SOC practice?

Robert J. Ramsay (CPA, CISA, CITP) leads Barnes Dennig’s Risk Management and SOC Reporting practice. He is an AICPA-designated SOC specialist and an instructor for the AICPA SOC School.

Robert J. Ramsay (CPA, CISA, CITP) leads the Risk Management and SOC Reporting practice. Robert is:

  • An AICPA-designated SOC specialist — a credential that allows him to serve as a quality control inspector for other firms’ SOC reports nationally
  • An instructor for the AICPA’s SOC School, training other firms on planning, executing, and reporting on SOC engagements
  • A Certified Common Security Framework (CSF) Practitioner through the HITRUST Academy
  • The author of the first HMIS attestation guide
  • 22+ years of experience in technology audits and SOC reporting; 15+ years of helping organizations strengthen internal controls
  • Former president of the Cincinnati ISACA chapter; frequent presenter for AICPA and ISACA

That AICPA SOC School and quality-control-inspector credential is unusual — most firms send their staff to SOC School. Barnes Dennig sends an instructor.

Other named members of the SOC team include:

  • Bryan Gayhart (CPA, CISA, HITRUST CCSFP) — Director, SOC Reporting
  • Morgan Ryle (CPA) — Director, SOC Reporting
  • Cheryl Ganim — SOC Reporting team
  • Myles Wallace — SOC Reporting (author of public SOC 2 Plus guidance)

How does a Barnes Dennig engagement work?

Barnes Dennig positions itself away from transactional, checkbox-style audits. The emphasis is on quality of work and long-term client relationships — clients who stay with them across multiple report cycles, framework expansions, and growth stages, rather than one-off engagements driven purely by procurement.

This shows up operationally in two specific ways the partner team called out:

  1. No outsourcing. The full scope of every SOC engagement — readiness through report issuance — is handled by Barnes Dennig employees. No subcontractors, no white-labeled deliverables.
  2. Same-team continuity. Public client testimonials repeatedly name the same auditors (Ramsay, Gayhart, Ryle, Ganim) over multi-year engagements — a signal that staffing is stable rather than rotating juniors through accounts.

What should buyers know about Multi-Framework Coverage and SOC 2 Plus?

SOC 2 is the core of the practice, but the same team handles a broad set of adjacent frameworks — including SOC 2+ reports that bundle multiple framework attestations into a single AICPA-backed deliverable.

SOC reports

  • SOC 1 Type I and Type II (financial reporting controls / SSAE 18)
  • SOC 2 Type I and Type II (Security, Availability, Confidentiality, Processing Integrity, Privacy)
  • SOC 3 (public-facing summary report)

SOC 2+ extended frameworks

A single SOC 2+ report can include any of the following alongside the AICPA Trust Services Criteria:

  • ISO/IEC 27001 (Information Security Management)
  • ISO 42001 (AI management systems)
  • HITRUST CSF (mapped to HIPAA)
  • NIST 800-53 and NIST CSF
  • HIPAA
  • GDPR
  • PCI DSS
  • CSA Cloud Controls Matrix
  • ISACA Blockchain Framework
  • Germany’s C5 (Cloud Computing Compliance Controls Catalog)
  • ISAE 3000 / ISAE 3402 (international assurance standards for non-US customer requirements)

AI compliance: SOC 2 + ISO 42001

Barnes Dennig has built a productized SOC 2 + ISO 42001 offering for organizations whose products or services touch AI. ISO 42001 is the world’s first international standard for managing AI — covering ethics, transparency, accountability, and risk management across the AI lifecycle. Most CPA-side SOC firms have not yet built this capability; Barnes Dennig has it as a named service line on their website.

For multi-framework buyers, the practical value of the SOC 2+ approach is consolidating multiple attestations into one audit, one fieldwork window, and one report — rather than running parallel SOC 2 and ISO 27001 engagements with two separate firms.

Which industries does Barnes Dennig actually serve?

The SOC practice focuses on healthcare, financial services, and technology companies that need a regional CPA with HITRUST fluency. National buyers should still confirm bench depth for their scope.

Industries the SOC practice specifically focuses on:

  • Healthcare (including HITRUST and HIPAA)
  • FinTech and financial services
  • Banking
  • Revenue management and collections (TPAs)
  • Workers’ compensation and self-insured entities
  • Cloud-based software vendors / SaaS
  • Data centers
  • AI / emerging technology (via ISO 42001)

The Barnes Dennig website lists roughly 12–15 industries — all reflecting actual client work the SOC team has delivered, not aspirational verticals.

How much does a Barnes Dennig SOC 2 audit cost?

SOC engagements typically fall in the $15,000 to $40,000 range, quoted as a fixed fee rather than billed hourly, so the number is known before fieldwork begins. Final pricing is influenced by:

  • Risk profile of the entity being audited
  • Complexity of the control environment
  • Size of the environment in scope
  • Adherence to timeline — clients who keep evidence flowing on schedule reduce overall cost

This positions Barnes Dennig in the standard regional-CPA range for SOC 2 — below Big Four and Top 25 firm pricing, but with the structural quality benefits of a peer-reviewed CPA firm with an AICPA SOC School instructor leading the practice.

How fast can Barnes Dennig start a SOC 2?

A specific operational differentiator: Barnes Dennig is able to start engagements immediately, where many comparable CPA and SOC firms quote multi-month waitlists before fieldwork begins. For companies with an external deadline driven by enterprise sales, vendor reviews, funding, or a customer contract clause, this responsiveness can be the deciding factor between firms that otherwise look similar on paper.

What trust signals does Barnes Dennig publish?

Check AICPA peer-review standing, Ramsay’s AICPA SOC School instructor role, and Inside Public Accounting Top 200 placement before you treat them as current. Those are public signals, not a substitute for the engagement letter.

  • AICPA Peer Review Program — good standing. Standard CPA-on-CPA quality review.

  • AICPA SOC School instructor (Robert Ramsay). Trains other firms; serves as quality control inspector for other firms’ SOC reports.

  • Top 200 Inside Public Accounting firm; recognized as “Best of the Best.”

  • 60+ year operating history (founded 1965; 60th anniversary in 2025).

  • HITRUST Academy participation — including the CSF Practitioner credential.

  • AICPA and ISACA active membership and presenting.

Who is Barnes Dennig a good fit for?

Barnes Dennig fits companies that want SOC 2 plus ISO, HITRUST, HIPAA, or PCI from one regional CPA team, including AI products adding ISO 42001. Immediate start dates are the operational differentiator versus waitlisted specialists.

  • Companies pursuing SOC 2 alongside one or more additional frameworks — ISO 27001, ISO 42001, HITRUST, NIST, HIPAA, PCI — who want a single audit team consolidating the work into a SOC 2+ report rather than running parallel engagements.

  • AI-touching products that need both standard security attestation (SOC 2) and credible AI governance attestation (ISO 42001) — a combination most regional CPA firms cannot yet offer.

  • Healthcare, FinTech, financial services, TPA / collections, and self-insured / workers’ comp organizations where the SOC team has direct vertical experience.

  • Companies on a tight external deadline that need an auditor who can start immediately rather than after a multi-month queue.

  • Buyers who want a long-term audit relationship — same partners, same team, multi-year continuity — rather than a transactional, one-off checkbox engagement.

  • International companies needing US SOC reports plus ISAE 3000 / 3402 or C5 to satisfy non-US customer requirements.

When is Barnes Dennig not the right fit?

Skip Barnes Dennig if you need FedRAMP 3PAO or CMMC C3PAO, a Big Four name, or the cheapest single-framework boutique price. Those are outside the current mix or the regional-CPA cost band.

  • Defense / classified work requiring FedRAMP 3PAO authorization or CMMC C3PAO assessment status — not part of the current service mix.

  • Pure boutique pricing at the lowest end of the market — Barnes Dennig is competitive within the regional-CPA tier, but a single-framework SOC 2 engagement at a tech-only specialist may price lower.

  • Big Four brand requirement — if a board, investor, or enterprise customer specifically mandates a Big Four audit firm, Barnes Dennig is a regional CPA firm rather than a Big Four.

Client Testimonials

"Robert Ramsay and Cheryl Ganim consistently inspire trust and confidence. They support our team and we feel like they are always working in our best interest. It's a pleasure to work with them!"

Client
Barnes Dennig SOC Reporting client

"We have worked with Robert Ramsay and Bryan Gayhart at Barnes Dennig for several years now and are very happy with their service! I highly recommend their firm to any company in need of SOC services."

Client
Barnes Dennig SOC Reporting client

"The audit team at Barnes Dennig, headed by Bryan Gayhart and Morgan Ryle, is always a pleasure to work with."

Client
Barnes Dennig SOC 2+ client
Compare

Which firms are closest to Barnes Dennig on Type II price and timeline?

Closest-priced peers in the full-service cpa organization group, by Type II range, timeline, and verified accreditations. Firm-reported certification totals are left out — they are not the same measure as the badges we verify.

Barnes Dennig 360 Advanced Sponsored Thoropass Sponsored Armanino LLP Sensiba LLP Boulay Group
Type II Cost $15K–$40K $15K–$80K $12K–$85K $15K–$40K $20K–$50K $25K–$50K
Type I Cost $10K–$25K $15K–$60K $8K–$15K $10K–$20K $15K–$35K $15K–$30K
Timeline 3–9 wk 3–12 wk2–6 wk3–12 wk4–10 wk3–6 wk
Team Size 225 51–200200–2502000–3000400–500250–350
Itemized Accreditations 5 98753
Licensed CPA issuer Yes YesYesYesYesYes
AICPA peer review Pass PassPassPassPassPass
Founded 1965 20042019196919771934

This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose

About

For buyers in SaaS and Healthcare, Barnes Dennig fits the full-service cpa profile when its 3–9 weeks timeline and Type II pricing ($15K–$40K) align with the buyer's scope. Their 5 active accreditations, including SOC 2, ISO 27001, ISO 42001, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

What Makes Barnes Dennig Different?

Keeps readiness, audit, and report issuance in-house with a dedicated SOC team spanning multiple compliance frameworks.

Office Locations

Cincinnati, OH (HQ)Dayton, OHCrestview Hills, KYIndianapolis, IN (two offices)Distributed SOC team across six time zones

Compliance Frameworks Offered

SOC 1 (Type I and Type II) SOC 2 (Type I and Type II) SOC 3 SOC 2+ (multi-framework reports) ISO/IEC 27001 ISO 42001 (AI management systems) HITRUST CSF NIST 800-53 NIST CSF HIPAA GDPR PCI DSS CSA Cloud Controls Matrix ISAE 3000 / ISAE 3402
Expertise

Match this firm to your industry, overlapping frameworks you need alongside SOC 2, and the GRC stack you already run.

Industries

8 industries. Full-service CPA average: 6.

SaaS Healthcare FinTech Financial Services Revenue Management & Collections Workers' Compensation Self-Insured Entities AI / Emerging Tech
Certifications

5 accreditations. Full-service CPA average: 2.

AICPA Peer Review SOC 2 ISO 27001 ISO 42001 NIST

Audit Platform

Secure client portal

Verification

Barnes Dennig on the verification record

Barnes Dennig's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-09-03.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from Barnes Dennig

Tell us your scope. Barnes Dennig replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Preparing to interview auditors? Use our checklist of questions to ask any SOC 2 auditor.

Want to compare first? Browse All Auditors or get 3–10 quotes.

We send you 3–10 quotes from firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Barnes Dennig's profile →