CBIZ
- Licensed CPA firm — can issue a SOC 2 report
- AICPA peer review: Pass · Accepted Oct 19, 2023 · Verify at AICPA → ·
Details
Review period: May 1, 2022–Apr 30, 2023 · Record checked: Jun 11, 2026
CBIZ is a full-service cpa SOC 2 audit firm in New York, NY, USA. Its estimated SOC 2 Type II audit price is $40,000–$100,000; fieldwork to report takes 4–9 weeks.
Independent profile, researched and maintained by this directory from public sources. CBIZ has not reviewed or verified this page. Work at CBIZ? Verify and correct it — free →
Free. Anonymous until you pick.
How Much Does CBIZ Charge for SOC 2?
CBIZ's estimated SOC 2 Type II audit price is $40,000–$100,000; fieldwork to report takes 4–9 weeks.
- Type 1 cost
- $25K–$50K
- Type 2 cost
- $40K–$100K
- Timeline
- 4–9 wk
- Team Size
- 10000-11000
- Report Delivery
- Standard cycles
- Response Time
- Dedicated teams
Type 2 cost Pricing Position
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
Timeline: The 4–9 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.
How this directory works: we are an independent directory. Firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees, and payment never changes a firm's rating or who we match a buyer with. Our methodology →
- Pricing context
- 7%
- Timeline context
- 71%
- Accreditations
- 9
of Full-service CPA firms charge more for Type II.
of Full-service CPA firms have longer minimum timelines.
itemized accreditations. Organization-group average: 2.
Source: soc2auditors.org/auditors/cbiz-marcum/ · compiled and maintained by soc2auditors.org.
Compare CBIZ with Similar Full-service CPA Firms
Side-by-side pricing, timeline, and itemized accreditation counts for the closest-priced peers in the full-service cpa organization group. Firm-reported certification totals stay outside this comparison because they are not the same measure.
| CBIZ | 360 Advanced Sponsored | Thoropass Sponsored | BDO USA | Crowe LLP | RubinBrown | |
|---|---|---|---|---|---|---|
| Type II Cost | $40K–$100K | $15K–$80K | $12K–$85K | $30K–$110K | $40K–$100K | $40K–$100K |
| Type I Cost | $25K–$50K | $15K–$60K | $8K–$15K | $20K–$62K | $25K–$50K | $25K–$80K |
| Timeline | 4–9 wk | 3–12 wk | 2–6 wk | 5–13 wk | 4–9 wk | 6–14 wk |
| Team Size | 10000-11000 | 51–200 | 200–250 | 13000–15000 | 5400–6000 | 1000–5000 |
| Itemized Accreditations | 9 | 9 | 8 | 3 | 3 | 1 |
| Founded | 1951 | 2004 | 2019 | 1910 | 1942 | 1952 |
This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose
CBIZ Industry Fit
For buyers in Technology and Healthcare, CBIZ fits the full-service cpa profile when its 4–9 weeks timeline and Type II pricing ($40K–$100K) align with the buyer's scope. Their 9 active accreditations, including PCAOB, CSA STAR, PCI DSS QSA, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Who Should Hire CBIZ?
Mid-market and enterprise organizations needing multi-location risk advisory and SOC reporting support.
What Makes CBIZ Different?
Offers a 10,000-plus-person national platform and a credentialed risk team, with attest work handled by MHM CPAs.
Is CBIZ Right for You?
- The displayed Type II price range is compatible with enterprise scope; confirm capacity and team in the proposal
- You need HITRUST + SOC 2 bundled in a single engagement
- You handle payment data and need PCI DSS + SOC 2 together
- You're in healthcare and need HIPAA-aware auditors
- You're in financial services with regulatory audit requirements
- You already use Drata, Vanta and want an auditor who integrates with it
of 6 criteria match. Get a personalized quote
Industries served
Works with these GRC platforms
Who is CBIZ?
CBIZ, Inc. (NYSE: CBZ) became the 7th-largest U.S. accounting firm when it closed the Marcum deal on 1 November 2024. SOC 2 is not issued by CBIZ, Inc.; it is issued by CBIZ CPAs, P.C.
It is performed by CBIZ CPAs, P.C., an independently owned, licensed CPA firm that is “strategically associated” with CBIZ, Inc. through what the profession calls an alternative practice structure (APS) — the same arrangement large accounting networks use to separate attest work from non-attest advisory and consulting services.
CBIZ CPAs, P.C. is the entity formerly known as Mayer Hoffman McCann P.C. (MHM), which renamed itself CBIZ CPAs in August 2024 to reduce marketplace confusion between the MHM and CBIZ names. Clients did not change auditors or contacts in the rename — MHM’s attest staff, leadership, and quality-control infrastructure carried over intact. For a buyer evaluating “CBIZ SOC 2,” the practical answer is: the report is issued by CBIZ CPAs, P.C., a CPA firm 100% owned by its CPA shareholders, not by CBIZ, Inc.
What credentials does CBIZ actually hold?
CBIZ CPAs, P.C. is a licensed CPA firm, an AICPA member, and enrolled in the AICPA Peer Review Program — the profession’s mandatory independent quality check on a firm’s audit practice. Its most recent peer review, dated October 19, 2023, covered the period May 1, 2022 through April 30, 2023 and resulted in a pass.
Buyers can verify current status directly at the AICPA Peer Review public file search.
The firm structures its independence formally, not just procedurally. Per its own site: “This structure separates CBIZ’s non-attest practice from the attest services provided by CBIZ CPAs, maintaining objectivity and integrity and ensuring freedom from conflicts of interest. In accordance with the American Institute of Certified Public Accountants (AICPA) and state board requirements, CBIZ CPAs is an independent CPA firm 100% owned by CPAs.” All professional judgments on an engagement are made by CBIZ CPAs’ own shareholders under its own quality-control policies, not by CBIZ, Inc.
CBIZ CPAs also runs a National Attest Office (NAO) inside CBIZ Financial Services — over 90 professionals dedicated to accounting and auditing subject-matter expertise, engagement quality reviews, monitoring, and IT, functioning as the firm’s internal quality-control backbone across its attest practice.
Beyond the CPA-firm accreditation, CBIZ’s broader Risk Advisory practice (the group that scopes and staffs SOC engagements alongside CBIZ CPAs) holds accreditations spanning PCAOB registration, CSA STAR, PCI DSS QSA, HITRUST Assessor, ISO 27001 Lead Auditor, FISMA Assessor, and NIST Assessor status, with staff holding CISA, CISSP, QSA, GPEN, and GWAPT credentials.
What SOC reports does CBIZ issue?
CBIZ CPAs offers the full range of SOC attestations: SOC 1 (for organizations whose services affect a client’s internal controls over financial reporting), SOC 2 (Type I and Type II, covering security, availability, confidentiality, processing integrity, and privacy), SOC 2+ (a single combined report layering additional criteria — e.g., HIPAA or ISO 27001 — onto the SOC 2 framework), and
SOC 3 (the public-facing summary version, suited for a website or RFP response). Engagements run on what CBIZ CPAs describes as a “preferred SOC engagement platform” offering real-time project status, notifications, and evidence collection, intended to reduce the client’s hands-on time during fieldwork.
For a Type II report, the audit itself is only part of the timeline — the client’s controls must first operate for an observation window, typically 3 to 12 months, before CBIZ CPAs can test and report on operating effectiveness. A Type I report, by contrast, is a point-in-time design assessment and doesn’t require that observation period.
Which industries does CBIZ actually serve?
CBIZ’s combined post-merger practice serves Technology, Healthcare, Financial Services, Manufacturing, Real Estate, Not-for-Profit, and large Enterprise clients — a breadth that reflects the firm’s general-practice roots rather than a SOC-2-only specialist’s narrower focus.
This makes CBIZ a natural fit for a company that already uses CBIZ for financial statement audits, tax, or advisory work and wants its SOC 2 handled inside the same relationship rather than adding a new vendor.
How much does a CBIZ SOC 2 audit cost?
CBIZ does not publish SOC 2 pricing. Based on the firm’s size, national-firm overhead, and the accreditation depth its Risk Advisory group carries, our estimated range for a SOC 2 Type I is $25,000–$50,000, and for a Type II, $40,000–$100,000 — directional figures from soc2auditors.org, not numbers confirmed by CBIZ.
Actual pricing depends on system scope, number of trust-services criteria, headcount, and cloud footprint; request a quote for a firm-specific ballpark.
How long does a CBIZ SOC 2 audit take?
Directory estimate for CBIZ fieldwork-to-report is 4–9 weeks, in line with a national attest practice that still runs a National Attest Office review. That window excludes the 3–12 month Type II observation period.
How does CBIZ handle auditor independence?
CBIZ’s Risk Advisory group offers cybersecurity services, including penetration testing, under the CBIZ, Inc. side of the alternative practice structure — separate from CBIZ CPAs, the entity that issues the SOC 2 report.
If your engagement scope includes both a SOC 2 report and a penetration test, confirm on the first call which CBIZ entity performs which piece, and whether the same team touches both. Under AICPA independence rules, an auditor evaluating a pen test it performed itself for the same client can create a self-review threat, since the test becomes part of the control environment the audit then assesses. CBIZ’s own APS separation is designed to address exactly this kind of conflict, but it’s worth confirming the specific staffing on your engagement rather than assuming it by default.
Which frameworks does CBIZ cover?
CBIZ CPAs is a licensed CPA firm and therefore does not itself issue certifications that require a separate accreditation body — most notably ISO 27001 and FedRAMP, where the certifying or authorizing role sits with an accredited certification body (for ISO) or an authorized 3PAO (for FedRAMP) rather than a CPA firm.
CBIZ’s Risk Advisory group can advise on and support readiness for these frameworks, but buyers should confirm which entity actually signs the certificate versus which one prepares the client for it.
Who is CBIZ a good fit for?
CBIZ fits companies that already use CBIZ for audit, tax, or advisory and want SOC 2 inside that relationship, plus a top-7 national name and NAO review. It is not the cheapest first-audit boutique.
Best fit for:
-
Companies that already use CBIZ for financial statement audit, tax, or advisory work and want SOC 2 inside the same firm relationship
-
Enterprise and mid-market companies in Technology, Healthcare, Financial Services, Manufacturing, Real Estate, or Not-for-Profit that value a top-7 national firm’s name and formal National Attest Office quality-control layer on the report
-
Buyers who need SOC 1, SOC 2, SOC 2+, or SOC 3 handled by one attest provider, or who anticipate adding PCI DSS or HITRUST scope alongside SOC 2 - Organizations for whom AICPA peer review status and a documented alternative-practice-structure independence model matter to a customer’s vendor-security or audit committee
Not a fit — look elsewhere if:
- You need the fastest, lowest-cost path to a first SOC 2 report as an early-stage startup; a boutique SOC-2-focused CPA firm will typically be faster and cheaper than a top-7 national firm’s attest practice
- You need ISO 27001 certification or a FedRAMP authorization issued directly — CBIZ CPAs is a CPA firm and does not itself act as the ISO certification body or FedRAMP 3PAO
- You want a single point of contact for both penetration testing and the SOC 2 report from the same team — CBIZ’s structure keeps those functions in separate entities by design
When should a buyer shortlist CBIZ?
CBIZ’s SOC 2 practice runs through CBIZ CPAs, P.C. — the CPA firm formerly known as Mayer Hoffman McCann (MHM), renamed in August 2024 and now strategically associated with CBIZ, Inc. (the 7th-largest U.S. accounting firm) through an alternative practice structure that keeps attest and non-attest services in legally separate entities.
The firm is AICPA peer-review enrolled (passed, October 2023) and covers SOC 1, SOC 2, SOC 2+, and SOC 3. For companies that want a top-7 national firm’s name and quality-control infrastructure behind their SOC 2 report — particularly ones already in the CBIZ or Marcum client base — that’s a real advantage. For a startup chasing its first SOC 2 fast and cheap, or a buyer who needs ISO 27001 or FedRAMP certified directly by the same entity, a specialist firm is the better match.
Contact & Links
Office Locations
Compliance Frameworks Offered
Industries, certifications, and platforms.
Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.
What Industries Does CBIZ Serve?
7 industries. Full-service CPA average: 6.
What Certifications and Accreditations Does CBIZ List?
9 accreditations. Full-service CPA average: 2.
What GRC Platforms Does CBIZ Work With?
Audit Platform
Enterprise audit methodology
Questions to Ask CBIZ Before Hiring
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
- Your team is sized at 10000-11000. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
- You quote 4–9 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
- Your Type 2 cost range is $40K–$100K. What's included at each end, and what scope changes would push pricing above the top of that range?
- You integrate with Drata, Vanta. If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
- Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
- How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
- When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
- Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
CBIZ on the verification record
CBIZ's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-06-11.
See the verification record · Is this your firm? Get your badge.
Get a quote from CBIZ
Tell us your scope. CBIZ replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? Browse All Auditors or get 3–10 quotes.
Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify CBIZ's profile →