SOC 2 + HIPAA Overlay Engagements: How They Work
HIPAA mapping in a SOC 2 engagement: evidence-file boundaries, bridge-letter cadence, and how auditors structure a combined SOC 2 + HIPAA report.
CBIZ (formerly Marcum LLP) is a national SOC 2 audit firm in New York, NY, USA that charges $40K–$100K for Type II audits with 4–9 month timelines. Founded in 1951, they hold 9 accreditations and specialize in Technology, Healthcare, Financial Services, and 3 more. Their pricing is in the mid-range compared to the national average of $39.3K–$100K.
Free. Anonymous until you pick.
Estimated Type 1 and Type 2 ranges, placed against the broader national peer set. Numbers are directional; final pricing depends on scope, Trust Services Criteria, evidence quality, and observation period.
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
of National firms charge more for Type II.
of National firms have longer minimum timelines.
listed certifications. Tier average: 2.
Side-by-side pricing, timeline, and certification counts for the 5 closest-priced peers in the national tier.
| CBIZ (formerly Marcum LLP) | RubinBrown | KLR (Kahn Litwin Renza) | Grassi | BDO UK | Warren Averett | |
|---|---|---|---|---|---|---|
| Type II Cost | $40K–$100K | $40K–$100K | $40K–$100K | $40K–$100K | $40K–$100K | $40K–$100K |
| Type I Cost | $25K–$50K | $25K–$80K | $25K–$80K | $25K–$80K | $25K–$80K | $25K–$80K |
| Timeline | 4–9 mo | 6–14 mo | 6–14 mo | 6–14 mo | 6–14 mo | 6–14 mo |
| Team Size | 10000-11000 | 1000–5000 | 350–5000 | 600–5000 | 8000 | 750–5000 |
| Certifications | 9 | 1 | 1 | 2 | 1 | 2 |
| Founded | 1951 | 1952 | 1975 | 1980 | 1903 | 1972 |
For buyers in Technology and Healthcare, CBIZ (formerly Marcum LLP) fits the national profile when timeline (4–9 months) and Type II pricing ($40K–$100K) align with what national firms typically deliver. Their 9 active accreditations, including CPA Firm (Licensed), PCAOB Registered, CSA STAR Certified Auditor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Mid-market to enterprise companies, organizations requiring multiple locations/subsidiaries, companies needing Big Four quality without Big Four pricing
7th-largest US accounting firm created from CBIZ acquisition of Marcum (Nov 2024) with combined $2.8B revenue and 10,000+ employees across 160+ locations. Risk Advisory practice with staff holding CISA/CISSP/QSA/GPEN/GWAPT certifications, extensive SOC 1/2/3 experience, CSA STAR certified auditor. CBIZ provides finance, advisory, insurance services; attest work handled by Mayer Hoffman McCann (MHM CPAs)
of 6 criteria match. Get a personalized quote
Visit CBIZ (formerly Marcum LLP)'s website directly, or get an anonymous quote through us. Tell us your scope, CBIZ (formerly Marcum LLP) replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.
6 industries. National average: 6.
9 certifications. National average: 2.
Enterprise audit methodology
Firm-specific answers generated from the directory record and preserved in FAQPage schema.
CBIZ (formerly Marcum LLP) SOC 2 Type I audits typically range from $25K to $50K. Type II audits range from $40K to $100K. This is in the mid-range for national firms — the national tier average is $39.265K–$100K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.
A typical SOC 2 engagement with CBIZ (formerly Marcum LLP) takes 4 to 9 months from start to report delivery.
CBIZ (formerly Marcum LLP) has deep expertise in Technology, Healthcare, Financial Services, Manufacturing, Real Estate, Not-for-Profit. They are best suited for Mid-market to enterprise companies, organizations requiring multiple locations/subsidiaries, companies needing Big Four quality without Big Four pricing
CBIZ (formerly Marcum LLP) holds 9 accreditations: AICPA, CPA Firm (Licensed), PCAOB Registered, CSA STAR Certified Auditor, PCI DSS QSA, HITRUST Assessor, ISO 27001 Assessor, FISMA Assessor, NIST Assessor. This is above average for national firms, indicating broad certification capabilities.
CBIZ (formerly Marcum LLP) uses Enterprise audit methodology for their audit engagements. Reports are delivered via Standard cycles.
CBIZ (formerly Marcum LLP) is a national SOC 2 audit firm founded in 1951 with 75 years of experience. 7th-largest US accounting firm created from CBIZ acquisition of Marcum (Nov 2024) with combined $2.8B revenue and 10,000+ employees across 160+ locations. Risk Advisory practice with staff holding CISA/CISSP/QSA/GPEN/GWAPT certifications, extensive SOC 1/2/3 experience, CSA STAR certified auditor. CBIZ provides finance, advisory, insurance services; attest work handled by Mayer Hoffman McCann (MHM CPAs) They are best suited for organizations that need technology, healthcare, financial services expertise.
CBIZ (formerly Marcum LLP) is headquartered in New York, NY, USA. They serve clients across the United States and can conduct SOC 2 audits remotely.
Compared to the 34 national firms in our directory, CBIZ (formerly Marcum LLP)'s Type II pricing ($40K–$100K) is in the mid-range (tier average: $39.265K–$100K). They hold 9 certifications vs. the tier average of 2. Their minimum timeline of 4 months is faster than the tier average.
CBIZ (formerly Marcum LLP) is best suited for Mid-market to enterprise companies, organizations requiring multiple locations/subsidiaries, companies needing Big Four quality without Big Four pricing Their key differentiator is: 7th-largest US accounting firm created from CBIZ acquisition of Marcum (Nov 2024) with combined $2.8B revenue and 10,000+ employees across 160+ locations. Risk Advisory practice with staff holding CISA/CISSP/QSA/GPEN/GWAPT certifications, extensive SOC 1/2/3 experience, CSA STAR certified auditor. CBIZ provides finance, advisory, insurance services; attest work handled by Mayer Hoffman McCann (MHM CPAs)
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
Tell us your scope. CBIZ (formerly Marcum LLP) replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? See 34 similar national firms or get 3 quotes.
HIPAA mapping in a SOC 2 engagement: evidence-file boundaries, bridge-letter cadence, and how auditors structure a combined SOC 2 + HIPAA report.
A complete 2026 guide to SOC 2 for healthcare companies. Learn how SOC 2 maps to HIPAA, prioritize Trust Services Criteria, and prepare for your audit.
The best SOC 2 compliance software for healthcare in 2026. HIPAA + SOC 2 dual coverage, BAA availability, and honest pricing for digital health companies.