Who is Coalfire?
Coalfire is a cybersecurity advisory and assessment firm founded in 2001, with headquarters at 330 N Wabash Ave in Chicago. Current offices also listed: Alpharetta, GA; Bellevue, WA; and Manchester, UK. Westminster, Colorado is the former HQ from the Carlyle/Chertoff era; it is no longer on the public contact page.
Public headcount signals sit around 650–1,000 (LinkedIn-class directories ~600–700; aggregators nearer 1,000). Delivery figures Coalfire publishes are more useful: 3,000 assessments a year, 500+ SOC reports a year, and 600+ framework specialists / 1 million+ assessment hours behind Compliance Essentials.
Funds advised by Apax Partners acquired Coalfire from Carlyle and The Chertoff Group; the sale closed in April 2020. That UK ownership is why Coalfire Federal had to keep operating as a structurally separate, wholly owned subsidiary with its own US leadership and board (FOCI / CFIUS), not as a fully independent company.
Three legal names matter on a contract:
- Coalfire Controls — licensed CPA affiliate that issues SOC 1 / SOC 2 / SOC 3 reports under AICPA standards. Coalfire says it participates in the AICPA peer-review program.
- Coalfire Certification Inc (coalfirecertification.com) — ANAB-accredited certification body. Rebranded from Coalfire ISO in December 2021. Current public scope: ISO/IEC 27001, ISO 9001, ISO/IEC 27701, ISO/IEC 42001, ISO 22301, ISO/IEC 20000-1. Dual UKAS accreditation was obtained in 2019–2021; the current CB site lists ANAB only.
- Coalfire Federal (coalfirefederal.com) — FOCI-separated federal/CMMC entity.
What does Coalfire’s FedRAMP marketplace record actually show?
Coalfire Systems, Inc. is FedRAMP Marketplace assessor 138514: accredited 17 July 2015, High (Class D), with 128 assessments as of 17 August 2026. That large book is not proof it is the #1 3PAO, and it does not support a claim that 75% of all FedRAMP authorizations are theirs.
Schellman’s profile tracks a larger marketplace count. Coalfire’s own marketing line that 75% of all FedRAMP authorizations are theirs is not used here.
What the firm does publish on its SOC page, and that we can repeat as a firm claim: 75% of its SOC engagements are for cloud service providers, and it names Google, Amazon, IBM, and Microsoft as CSP examples.
FedRAMP work at Coalfire includes readiness (RAR), initial assessment (SAP/SAR), annual assessment, continuous monitoring, and FedRAMP-required penetration testing / red teaming. The current services page says authorization typically takes 12–18 months or longer, and that Coalfire’s FedRAMP service portfolio can target ATO in under six months. ACE here is Accelerated Cloud Engineering (pre-engineered FedRAMP-ready modules, marketed since 2020) — not “Accelerated Compliance Experience.” A Gartner Peer Insights federal reviewer credited ACE with beating a typical two-year ATO path; that is one review, not a rating.
DoD work is sold as DoD RMF and, in advisory bios, the DoD Cloud Computing SRG — not the same thing as IL6 or classified-facility work.
What is Coalfire Federal, and who does the CMMC work?
Coalfire Federal has operated independently of the commercial parent since the Apax close in April 2020, under FOCI/CFIUS rules. Bill Malone was promoted from EVP to President on 29 April 2020, when the subsidiary got its own board (first chair: Mary Griggs, FOCI/CFIUS background).
CMMC timeline, as the firm states it:
- 23 August 2022 — among the first Cyber AB-authorized C3PAOs (CMMC 1.0-era authorization).
- 3 January 2025 — began conducting official CMMC Level 2 assessments as an authorized C3PAO under the live program.
- 16–18 July 2025 — triennial DIBCAC CMMC Level 2 re-certification, announced as a perfect score. DIBCAC is the body that re-assesses C3PAOs.
On 4 August 2025, Dr. Amy Williams, then VP of CMMC, was appointed Vice Chair of the Cyber AB C3PAO Advisory Council Accreditation Committee (two-year term). That appointment is not confirmation of her current operating title.
Coalfire Federal also assessed AWS’s Controlled Working Environment to CMMC Level 2 (announced June 2025). Its CMMC pages emphasize in-house assessors and say Level 2 assessments do not bundle remediation products; the same site still sells mock assessments and readiness. Ask which entity and which statement of work you are signing.
Which frameworks can Coalfire combine on one program?
Coalfire Controls issues SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain; related pages also list CSA STAR, BSI C5, Microsoft SSPA, and combined examples such as SOC + HIPAA and SOC + CSA STAR. PCI, HITRUST, and ISO sit in other legal entities, so the contract name matters.
PCI: Current services page positions Coalfire as a large QSAC with QSA and PFI capacity, and as a founding member of the PCI Global Executive Assessor Roundtable. Older 2021 accreditation sheets also listed PA-QSA, P2PE, and Secure Software/SLC; those extra designations were not re-confirmed on the 2026 PCI page.
HITRUST: Coalfire calls itself an original HITRUST External Assessment firm, with 35+ certified CSF practitioners. Services include e1 / i1 / r2, interim, rapid recertification, and bridge assessments, plus coordinated HITRUST + other-framework reporting.
ISO (Coalfire Certification): ANAB CB for the standards listed above, including ISO/IEC 42001. Coalfire also sells ISO 42001 readiness and pairs certification with model testing under AIMS+. Augment Code is a named ISO 42001 client.
Federal-adjacent (commercial Coalfire): FISMA, NIST SP 800-53, NIST SP 800-171, ITAR/EAR, DEA EPCS.
If Coalfire does both advisory and the SOC examination, its own FAQ says independence still has to be maintained — raise that on the first call.
What is Compliance Essentials, and does Coalfire use Audit AI?
Compliance Essentials is Coalfire’s current assessment product, not a GRC overlay it merely connects to. As of 5 May 2026 it includes Audit AI: MCP and open APIs so a client’s existing assistant can query live program data, plus AI policy/procedure review with page-level citations.
Coalfire’s launch claims: up to 40% less manual process work on the prior platform, up to 200% faster policy review in testing, and 70% greater accuracy than off-the-shelf chatbots for those reviews. Those are vendor test figures.
MCP sources named at launch: Jira, GitHub, Microsoft 365, and “hundreds” of other MCP-compatible systems. Audit AI policy review and the MCP server are included with a Coalfire assessment on Compliance Essentials.
The practical pattern, from Coalfire case studies: map PCI (or another framework) once, reuse evidence for SOC 2. Effectual went PCI ROC (2020) then SOC 2 Type 2 in six months (2022) on that mapping. BigCommerce used the same platform to stack PCI DSS, then ISO 27001, SOC 1/2/3, and ISO 27017/27018. AnewHealth reported cutting assessment duration by four weeks via the Continuous Compliance module.
CoalfireOne still appears on coordinated-assessment materials as the visibility portal. The 2026 product story is Compliance Essentials.
Homepage copy currently says coordinated assessments across 85+ frameworks; Compliance Essentials and Audit AI pages say 100+. The platform pages are the better figure for mapping.
Who leads Coalfire?
Brad Little became CEO on 6 January 2026, succeeding Tom McAndrew, who moved to the board as a senior advisor. Little’s last role was Global Head of Professional Services at Google Cloud, after more than two decades at Capgemini.
Immediate prior Capgemini titles include EVP and global head of application services (press release: ~58,000 people, ~$5B revenue) and head of Capgemini’s global SAP business. Career start: Ernst & Young. Tom McAndrew had been CEO for the prior 20 years.
Also on the current leadership page: Bill Malone (President, Coalfire Federal); Merri Chandler, CPA (CFO; KPMG, later Chartis Group); Vineet Seth (Chief Product & Technology Officer — BitSight VP of Product, SAP, RSA; CPO since 2021); Karen Laughton (EVP, Advisory Services); Adam Shnider (EVP, Assessment Services). Charles Henderson (EVP, DivisionHex) runs the offensive-security brand used for FedRAMP pentest and AI red-teaming.
How much does a Coalfire SOC 2 audit cost, and how long does it take?
Coalfire does not publish SOC prices. Directory figures are our estimates (Type 1 about $25k–$60k, Type 2 about $40k–$120k). There is no public Foundations / Advanced / Enterprise rate card on the current site.
Coalfire’s SOC FAQ: a Type 2 covers operating effectiveness typically at least six months. That is Coalfire’s usual window, not an AICPA-mandated floor. End-to-end advisory + readiness + examination is often 6–9 months. Fieldwork-to-report, once evidence is in, is the shorter 4–12 week band in the directory. Clients already in PCI or HITRUST can cut calendar time by reusing mapped evidence — that is the Effectual example, not a guarantee.
Positioning is premium: this is a Schellman / large-advisory comparable, not a first-SOC boutique.
Who is Coalfire a good fit for?
Coalfire is a poor fit for a first SOC 2 on a startup budget, or for anyone who wants the commercial parent and Coalfire Federal on one SOW. The shortlist case is FedRAMP High, CMMC, or stacked PCI/HITRUST/ISO; resolve the entity split during contracting.
Best fit
- CSPs that need a 3PAO with a large High-capable book (128 marketplace assessments as of August 2026) and will ask for named assessor experience at their baseline.
- DoD contractors wanting CMMC Level 2 from Coalfire Federal, with a clear split between mock/readiness and the official assessment.
- Mid-market and enterprise programs stacking SOC 2 with PCI, HITRUST, and/or ISO, where one evidence library is the point of the engagement.
- Healthcare SaaS that wants HITRUST plus a SOC 2 + HIPAA overlay from the same family of firms.
- Buyers who already expect a specialist cyber brand in procurement, not a Top 50 CPA logo.
Poor fit
- First SOC 2 on a startup budget. Estimated Type 2 sits well above boutique specialists.
- Buyers who want Schellman’s CPA-firm / classified-adjacent story (Top 50 ranking, FCL, 200 marketplace CSOs) or A-LIGN’s SOC-volume / A-SCEND factory.
- Anyone who needs the commercial parent and Coalfire Federal on one SOW without reading the FOCI split.
- Teams that only want a portal overlay on Drata/Vanta/Secureframe. Those GRC names are not a documented Coalfire integration list; the native path is Compliance Essentials.
What changed recently at Coalfire?
Between January 2025 and May 2026 Coalfire Federal began official CMMC Level 2 assessments, the commercial firm appointed Brad Little CEO, and Compliance Essentials launched Audit AI. The dated list below is the source trail for those claims.
- 5 May 2026: Audit AI launched inside Compliance Essentials (MCP + policy review).
- 6 January 2026: Brad Little appointed CEO; Tom McAndrew to board/advisor.
- 4 August 2025: Dr. Amy Williams (then VP of CMMC) named Vice Chair, Cyber AB C3PAO Advisory Council Accreditation Committee.
- 16–18 July 2025: Coalfire Federal DIBCAC CMMC Level 2 re-certification, perfect score announced.
- 18 June 2025: ISO/IEC 42001 ANAB accreditation / AIMS+ (model testing + certification).
- 3 January 2025: Coalfire Federal began official CMMC Level 2 assessments.
When should a buyer shortlist Coalfire?
Coalfire is a specialist cyber assessor with a real FedRAMP marketplace book (128, High, as of August 2026), a CPA affiliate for SOC, an ANAB ISO certification body, and a FOCI-separated CMMC C3PAO. The operational advantage, when it exists, is Compliance Essentials mapping PCI, HITRUST, or ISO evidence into SOC 2.
That is not a 5.0 Gartner score built on a handful of reviews, and not an unsourced “top-three 3PAO” ranking.
If the question is FedRAMP High or CMMC Level 2 plus SOC 2 from one family of firms, Coalfire belongs on the short list. If the question is cheapest first Type 2, look elsewhere.