Logo Menu

Coalfire

Assurance specialist Verified Chicago, IL, USA
  • Licensed CPA firm — can issue a SOC 2 report
  • AICPA peer review: Pass · Accepted Aug 14, 2024 · Verify at AICPA → ·
    Details Review period: Dec 1, 2022–Nov 30, 2023 · Record checked: Sep 3, 2026

Coalfire is an assurance specialist SOC 2 audit firm in Chicago, IL, USA. Its estimated SOC 2 Type II audit price is $40,000–$120,000; fieldwork to report takes 4–12 weeks.

Coalfire fits regulated programs combining SOC 2 with FedRAMP High, CMMC, PCI, HITRUST, or ISO. Coalfire Controls signs SOC reports; Coalfire Certification handles ISO; Coalfire Federal is the FOCI-separated CMMC entity. Confirm which entity and SOW cover each workstream.

“Effectual was able to achieve SOC 2 Type 2 report within 6 months using the evidence already gathered for PCI DSS compliance and mapped in Compliance Essentials Platform. Multiple framework compliance was never easy before Compliance Essentials.”

— Jon Castaldo, Information Security Manager, Effectual

Independent profile, researched and maintained by this directory from public sources. Coalfire has not reviewed or verified this page. Work at Coalfire? Verify and correct it — free →

Type 1 cost
$25K–$60K est.
Type 2 cost
$40K–$120K est.
Timeline
4–12 weeks
Accreditations
8 listed
Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

Coalfire's estimated SOC 2 Type II audit price is $40,000–$120,000; fieldwork to report takes 4–12 weeks.

Type 1 cost
$25K–$60K
Type 2 cost
$40K–$120K
Timeline
4–12 wk
Team Size
650-1000+
Report Delivery
Type 2 observation typically at least 6 months; full advisory plus examination often 6-9 months
Response Time
Quoted per engagement; public pricing unpublished

Type 2 cost Pricing Position

$2.5K observed market span · est. $450K
Coalfire: $40K–$120K Assurance specialist avg: $19.948K–$59.705K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 4–12 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires a separate observation period, typically 3–12 months depending on scope.

Pricing context
4%

of Assurance specialist firms charge more for Type II.

Timeline context
26%

of Assurance specialist firms have longer minimum timelines.

Accreditations
8

verified accreditations. Group average: 4.

Source: soc2auditors.org/auditors/coalfire/ · compiled and maintained by soc2auditors.org.

Who is Coalfire?

Coalfire is a cybersecurity advisory and assessment firm founded in 2001, with headquarters at 330 N Wabash Ave in Chicago. Current offices also listed: Alpharetta, GA; Bellevue, WA; and Manchester, UK. Westminster, Colorado is the former HQ from the Carlyle/Chertoff era; it is no longer on the public contact page.

Public headcount signals sit around 650–1,000 (LinkedIn-class directories ~600–700; aggregators nearer 1,000). Delivery figures Coalfire publishes are more useful: 3,000 assessments a year, 500+ SOC reports a year, and 600+ framework specialists / 1 million+ assessment hours behind Compliance Essentials.

Funds advised by Apax Partners acquired Coalfire from Carlyle and The Chertoff Group; the sale closed in April 2020. That UK ownership is why Coalfire Federal had to keep operating as a structurally separate, wholly owned subsidiary with its own US leadership and board (FOCI / CFIUS), not as a fully independent company.

Three legal names matter on a contract:

  • Coalfire Controls — licensed CPA affiliate that issues SOC 1 / SOC 2 / SOC 3 reports under AICPA standards. Coalfire says it participates in the AICPA peer-review program.
  • Coalfire Certification Inc (coalfirecertification.com) — ANAB-accredited certification body. Rebranded from Coalfire ISO in December 2021. Current public scope: ISO/IEC 27001, ISO 9001, ISO/IEC 27701, ISO/IEC 42001, ISO 22301, ISO/IEC 20000-1. Dual UKAS accreditation was obtained in 2019–2021; the current CB site lists ANAB only.
  • Coalfire Federal (coalfirefederal.com) — FOCI-separated federal/CMMC entity.

What does Coalfire’s FedRAMP marketplace record actually show?

Coalfire Systems, Inc. is FedRAMP Marketplace assessor 138514: accredited 17 July 2015, High (Class D), with 128 assessments as of 17 August 2026. That large book is not proof it is the #1 3PAO, and it does not support a claim that 75% of all FedRAMP authorizations are theirs.

Schellman’s profile tracks a larger marketplace count. Coalfire’s own marketing line that 75% of all FedRAMP authorizations are theirs is not used here.

What the firm does publish on its SOC page, and that we can repeat as a firm claim: 75% of its SOC engagements are for cloud service providers, and it names Google, Amazon, IBM, and Microsoft as CSP examples.

FedRAMP work at Coalfire includes readiness (RAR), initial assessment (SAP/SAR), annual assessment, continuous monitoring, and FedRAMP-required penetration testing / red teaming. The current services page says authorization typically takes 12–18 months or longer, and that Coalfire’s FedRAMP service portfolio can target ATO in under six months. ACE here is Accelerated Cloud Engineering (pre-engineered FedRAMP-ready modules, marketed since 2020) — not “Accelerated Compliance Experience.” A Gartner Peer Insights federal reviewer credited ACE with beating a typical two-year ATO path; that is one review, not a rating.

DoD work is sold as DoD RMF and, in advisory bios, the DoD Cloud Computing SRG — not the same thing as IL6 or classified-facility work.

What is Coalfire Federal, and who does the CMMC work?

Coalfire Federal has operated independently of the commercial parent since the Apax close in April 2020, under FOCI/CFIUS rules. Bill Malone was promoted from EVP to President on 29 April 2020, when the subsidiary got its own board (first chair: Mary Griggs, FOCI/CFIUS background).

CMMC timeline, as the firm states it:

  • 23 August 2022 — among the first Cyber AB-authorized C3PAOs (CMMC 1.0-era authorization).
  • 3 January 2025 — began conducting official CMMC Level 2 assessments as an authorized C3PAO under the live program.
  • 16–18 July 2025 — triennial DIBCAC CMMC Level 2 re-certification, announced as a perfect score. DIBCAC is the body that re-assesses C3PAOs.

On 4 August 2025, Dr. Amy Williams, then VP of CMMC, was appointed Vice Chair of the Cyber AB C3PAO Advisory Council Accreditation Committee (two-year term). That appointment is not confirmation of her current operating title.

Coalfire Federal also assessed AWS’s Controlled Working Environment to CMMC Level 2 (announced June 2025). Its CMMC pages emphasize in-house assessors and say Level 2 assessments do not bundle remediation products; the same site still sells mock assessments and readiness. Ask which entity and which statement of work you are signing.

Which frameworks can Coalfire combine on one program?

Coalfire Controls issues SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain; related pages also list CSA STAR, BSI C5, Microsoft SSPA, and combined examples such as SOC + HIPAA and SOC + CSA STAR. PCI, HITRUST, and ISO sit in other legal entities, so the contract name matters.

PCI: Current services page positions Coalfire as a large QSAC with QSA and PFI capacity, and as a founding member of the PCI Global Executive Assessor Roundtable. Older 2021 accreditation sheets also listed PA-QSA, P2PE, and Secure Software/SLC; those extra designations were not re-confirmed on the 2026 PCI page.

HITRUST: Coalfire calls itself an original HITRUST External Assessment firm, with 35+ certified CSF practitioners. Services include e1 / i1 / r2, interim, rapid recertification, and bridge assessments, plus coordinated HITRUST + other-framework reporting.

ISO (Coalfire Certification): ANAB CB for the standards listed above, including ISO/IEC 42001. Coalfire also sells ISO 42001 readiness and pairs certification with model testing under AIMS+. Augment Code is a named ISO 42001 client.

Federal-adjacent (commercial Coalfire): FISMA, NIST SP 800-53, NIST SP 800-171, ITAR/EAR, DEA EPCS.

If Coalfire does both advisory and the SOC examination, its own FAQ says independence still has to be maintained — raise that on the first call.

What is Compliance Essentials, and does Coalfire use Audit AI?

Compliance Essentials is Coalfire’s current assessment product, not a GRC overlay it merely connects to. As of 5 May 2026 it includes Audit AI: MCP and open APIs so a client’s existing assistant can query live program data, plus AI policy/procedure review with page-level citations.

Coalfire’s launch claims: up to 40% less manual process work on the prior platform, up to 200% faster policy review in testing, and 70% greater accuracy than off-the-shelf chatbots for those reviews. Those are vendor test figures.

MCP sources named at launch: Jira, GitHub, Microsoft 365, and “hundreds” of other MCP-compatible systems. Audit AI policy review and the MCP server are included with a Coalfire assessment on Compliance Essentials.

The practical pattern, from Coalfire case studies: map PCI (or another framework) once, reuse evidence for SOC 2. Effectual went PCI ROC (2020) then SOC 2 Type 2 in six months (2022) on that mapping. BigCommerce used the same platform to stack PCI DSS, then ISO 27001, SOC 1/2/3, and ISO 27017/27018. AnewHealth reported cutting assessment duration by four weeks via the Continuous Compliance module.

CoalfireOne still appears on coordinated-assessment materials as the visibility portal. The 2026 product story is Compliance Essentials.

Homepage copy currently says coordinated assessments across 85+ frameworks; Compliance Essentials and Audit AI pages say 100+. The platform pages are the better figure for mapping.

Who leads Coalfire?

Brad Little became CEO on 6 January 2026, succeeding Tom McAndrew, who moved to the board as a senior advisor. Little’s last role was Global Head of Professional Services at Google Cloud, after more than two decades at Capgemini.

Immediate prior Capgemini titles include EVP and global head of application services (press release: ~58,000 people, ~$5B revenue) and head of Capgemini’s global SAP business. Career start: Ernst & Young. Tom McAndrew had been CEO for the prior 20 years.

Also on the current leadership page: Bill Malone (President, Coalfire Federal); Merri Chandler, CPA (CFO; KPMG, later Chartis Group); Vineet Seth (Chief Product & Technology Officer — BitSight VP of Product, SAP, RSA; CPO since 2021); Karen Laughton (EVP, Advisory Services); Adam Shnider (EVP, Assessment Services). Charles Henderson (EVP, DivisionHex) runs the offensive-security brand used for FedRAMP pentest and AI red-teaming.

How much does a Coalfire SOC 2 audit cost, and how long does it take?

Coalfire does not publish SOC prices. Directory figures are our estimates (Type 1 about $25k–$60k, Type 2 about $40k–$120k). There is no public Foundations / Advanced / Enterprise rate card on the current site.

Coalfire’s SOC FAQ: a Type 2 covers operating effectiveness typically at least six months. That is Coalfire’s usual window, not an AICPA-mandated floor. End-to-end advisory + readiness + examination is often 6–9 months. Fieldwork-to-report, once evidence is in, is the shorter 4–12 week band in the directory. Clients already in PCI or HITRUST can cut calendar time by reusing mapped evidence — that is the Effectual example, not a guarantee.

Positioning is premium: this is a Schellman / large-advisory comparable, not a first-SOC boutique.

Who is Coalfire a good fit for?

Coalfire is a poor fit for a first SOC 2 on a startup budget, or for anyone who wants the commercial parent and Coalfire Federal on one SOW. The shortlist case is FedRAMP High, CMMC, or stacked PCI/HITRUST/ISO; resolve the entity split during contracting.

Best fit

  • CSPs that need a 3PAO with a large High-capable book (128 marketplace assessments as of August 2026) and will ask for named assessor experience at their baseline.
  • DoD contractors wanting CMMC Level 2 from Coalfire Federal, with a clear split between mock/readiness and the official assessment.
  • Mid-market and enterprise programs stacking SOC 2 with PCI, HITRUST, and/or ISO, where one evidence library is the point of the engagement.
  • Healthcare SaaS that wants HITRUST plus a SOC 2 + HIPAA overlay from the same family of firms.
  • Buyers who already expect a specialist cyber brand in procurement, not a Top 50 CPA logo.

Poor fit

  • First SOC 2 on a startup budget. Estimated Type 2 sits well above boutique specialists.
  • Buyers who want Schellman’s CPA-firm / classified-adjacent story (Top 50 ranking, FCL, 200 marketplace CSOs) or A-LIGN’s SOC-volume / A-SCEND factory.
  • Anyone who needs the commercial parent and Coalfire Federal on one SOW without reading the FOCI split.
  • Teams that only want a portal overlay on Drata/Vanta/Secureframe. Those GRC names are not a documented Coalfire integration list; the native path is Compliance Essentials.

What changed recently at Coalfire?

Between January 2025 and May 2026 Coalfire Federal began official CMMC Level 2 assessments, the commercial firm appointed Brad Little CEO, and Compliance Essentials launched Audit AI. The dated list below is the source trail for those claims.

  • 5 May 2026: Audit AI launched inside Compliance Essentials (MCP + policy review).
  • 6 January 2026: Brad Little appointed CEO; Tom McAndrew to board/advisor.
  • 4 August 2025: Dr. Amy Williams (then VP of CMMC) named Vice Chair, Cyber AB C3PAO Advisory Council Accreditation Committee.
  • 16–18 July 2025: Coalfire Federal DIBCAC CMMC Level 2 re-certification, perfect score announced.
  • 18 June 2025: ISO/IEC 42001 ANAB accreditation / AIMS+ (model testing + certification).
  • 3 January 2025: Coalfire Federal began official CMMC Level 2 assessments.

When should a buyer shortlist Coalfire?

Coalfire is a specialist cyber assessor with a real FedRAMP marketplace book (128, High, as of August 2026), a CPA affiliate for SOC, an ANAB ISO certification body, and a FOCI-separated CMMC C3PAO. The operational advantage, when it exists, is Compliance Essentials mapping PCI, HITRUST, or ISO evidence into SOC 2.

That is not a 5.0 Gartner score built on a handful of reviews, and not an unsourced “top-three 3PAO” ranking.

If the question is FedRAMP High or CMMC Level 2 plus SOC 2 from one family of firms, Coalfire belongs on the short list. If the question is cheapest first Type 2, look elsewhere.

Client Testimonials

"We were able to achieve SOC 2 type 2 audit within 6 months using the evidence already gathered for PCI compliance and mapped in Compliance Essentials Platform."

Jon Castaldo
Information Security Manager
Effectual

"By leveraging the Continuous Compliance module in Compliance Essentials, we shortened the overall compliance assessment duration by 4 weeks."

Rachel Gardner
Information Security Compliance Program Manager
AnewHealth (formerly Tabula Rasa Healthcare)

"Coalfire is a strategic partner rather than just a third-party vendor. We were able to get to markets faster and gain a competitive advantage by achieving PCI and SOC compliance."

Michael Parks
CIO
Effectual

"Coalfire allowed us to attain Authorization to Operate (ATO) much faster than the typical 2-year process. Coalfire's ACE service enabled us to deploy a FedRAMP-compliant environment within an impressive timeframe."

Anonymous Federal Customer
Gartner Peer Insights
Compare

Which firms are closest to Coalfire on Type II price and timeline?

Closest-priced peers in the assurance specialist organization group, by Type II range, timeline, and verified accreditations. Firm-reported certification totals are left out — they are not the same measure as the badges we verify.

Coalfire 360 Advanced Sponsored Zero Day CPA Sponsored ControlCase Drummond Group IS Partners
Type II Cost $40K–$120K $15K–$80K $7K–$10K $35K–$120K $50K–$150K $50K–$150K
Type I Cost $25K–$60K $15K–$60K $5K–$7K $20K–$80K $35K–$100K $35K–$100K
Timeline 4–12 wk 3–12 wk2–6 wk4–18 wk4–16 wk8–16 wk
Team Size 650-1000+ 51–20025–30200–500500–200040–60
Itemized Accreditations 8 926613
Licensed CPA issuer Yes YesYesYesNoYes
AICPA peer review Pass PassNo public ratingNo public ratingNo public ratingNo public rating
Founded 2001 20042020200419992005

Sponsored alternatives are labeled in the table. How we make money

About

For buyers in Cloud Infrastructure and Federal/Government, Coalfire fits the assurance specialist profile when its 4–12 weeks timeline and Type II pricing ($40K–$120K) align with the buyer's scope. Their 8 active accreditations, including FedRAMP 3PAO, PCI DSS QSA, HITRUST Assessor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

What Makes Coalfire Different?

A 128-assessment FedRAMP High 3PAO for cloud companies that need SOC 2 alongside federal authorization.

Office Locations

Chicago, IL (HQ)Alpharetta, GABellevue, WAManchester, UK

Compliance Frameworks Offered

SOC 1, SOC 2, SOC 3 SOC for Cybersecurity, SOC for Supply Chain FedRAMP (3PAO since 17 July 2015; 128 marketplace assessments as of August 2026, High) DoD RMF / DoD Cloud Computing SRG CMMC Level 2 (via Coalfire Federal; official assessments from 3 January 2025) PCI DSS (QSAC; QSA and PFI) HITRUST CSF (original External Assessment firm) ISO 27001, 27701, 42001, 9001, 22301, 20000-1 (Coalfire Certification Inc, ANAB) NIST 800-53, 800-171, NIST CSF, NIST AI RMF FISMA, GDPR DEA EPCS, ITAR/EAR CSA STAR attestation, BSI C5, Microsoft SSPA

GRC Platform Compatibility

Compliance Essentials (proprietary; Audit AI and MCP as of May 2026) MCP connectors (Jira, GitHub, Microsoft 365, plus other MCP sources) CoalfireOne (coordination portal)
Expertise

Match this firm to your industry, overlapping frameworks you need alongside SOC 2, and the GRC stack you already run.

Industries

6 industries. Assurance specialist average: 6.

Cloud Infrastructure Federal/Government FinTech & Payments Healthcare Enterprise SaaS MSPs
Certifications

8 accreditations. Assurance specialist average: 4.

AICPA FedRAMP 3PAO PCI DSS QSA HITRUST Assessor CMMC C3PAO ISO 27001 Certification Body ISO 42001 CPA Firm
GRC platforms
Drata Vanta Compliance Essentials (proprietary)

Audit Platform

Compliance Essentials with Audit AI and MCP evidence connectors (as of May 2026)

Verification

Coalfire on the verification record

Coalfire's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-09-03.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from Coalfire

Tell us your scope. Coalfire replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Preparing to interview auditors? Use our checklist of questions to ask any SOC 2 auditor.

Want to compare first? Browse All Auditors or get 3–10 quotes.

We send you 3–10 quotes from firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Coalfire's profile →