Logo Menu

Frank, Rimerman + Co.

Mid-tier Verified Palo Alto, CA, USA
  • Licensed CPA firm — can issue (sign) a SOC 2 report
  • AICPA peer review: Pass · 2024-06-01 to 2025-05-31 · View AICPA record → (retrieved 2026-06-11)

Source: soc2auditors.org/auditors/frank-rimerman/ · compiled and maintained by soc2auditors.org.

Editorial profile, researched and maintained by this directory from public sources. Frank, Rimerman + Co. has not reviewed or verified this page. Work at Frank, Rimerman + Co.? Verify and correct it — free →

Type 1 cost
$20K–$60K est.
Type 2 cost
$30K–$80K est.
Timeline
4–12 weeks
Accreditations
3 listed

Frank, Rimerman + Co. is a mid-tier SOC 2 audit firm in Palo Alto, CA, USA that charges $30K–$80K for Type II audits with 4–12 week fieldwork-to-report timelines. Founded in 1949, they hold 3 accreditations and specialize in SaaS, Software, FinTech, and 3 more. Their pricing is in the mid-range compared to the mid-tier average of $28.9K–$76.7K.

Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

How Much Does Frank, Rimerman + Co. Charge for SOC 2?

Estimated Type 1 and Type 2 ranges, placed against the broader mid-tier peer set. Numbers are directional; final pricing depends on scope, Trust Services Criteria, evidence quality, and observation period.

Type I Cost
$20K–$60K
Type II Cost
$30K–$80K
Timeline
4–12 wk
Team Size
500-700+
Report Delivery
Standard delivery
Response Time
Unlimited partner/manager access year-round

Type II Pricing Position

$7K observed market span · est. $450K
Frank, Rimerman + Co.: $30K–$80K Mid-tier avg: $28.935K–$76.717K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 4–12 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.

How this directory works: we are an independent directory. Firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees, and payment never changes a firm's rating or who we match a buyer with. How we make money →

Pricing context
11%

of Mid-tier firms charge more for Type II.

Timeline context
72%

of Mid-tier firms have longer minimum timelines.

Certifications
3

listed certifications. Tier average: 2.

Compare

Compare Frank, Rimerman + Co. with Similar Mid-tier Firms

Side-by-side pricing, timeline, and certification counts for the closest-priced peers in the mid-tier tier.

Frank, Rimerman + Co. AAFCPAs Anders CPAs + Advisors Bennett Thrasher Dannible McKee FinAudit CPA
Type II Cost $30K–$80K $30K–$80K$30K–$80K$30K–$80K$30K–$80K$30K–$80K
Type I Cost $20K–$60K $20K–$60K$20K–$60K$20K–$60K$20K–$60K$20K–$60K
Timeline 4–12 wk 6–12 wk8–20 wk8–20 wk8–20 wk6–12 wk
Team Size 500-700+ 350–1000380–410480–510100–115100–1000
Certifications 3 31122
Founded 1949 19731965198019782010
About

Frank, Rimerman + Co. Industry Fit

For buyers in SaaS and Software, Frank, Rimerman + Co. fits the mid-tier profile when timeline (4–12 weeks) and Type II pricing ($30K–$80K) align with what mid-tier firms typically deliver. Their 3 active accreditations, including ISO 27001 Certification Body, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

Who Should Hire Frank, Rimerman + Co.?

Silicon Valley startups, VC-backed companies, and tech firms needing SOC and ISO 27001 on AWS, GCP, Azure, or Salesforce; companies wanting both SOC and ISO from one ANAB-accredited firm

What Makes Frank, Rimerman + Co. Different?

75+ years deeply embedded in the Silicon Valley tech and VC ecosystem; ANAB-accredited ISO 27001/27701 certification body; can certify both SOC and ISO in-house; unlimited partner access year-round; deep expertise in biotech, life sciences, and fintech alongside core SaaS

Fit check

Is Frank, Rimerman + Co. Right for You?

  • You're in healthcare and need HIPAA-aware auditors
  • You're a SaaS company going through SOC 2 for the first time
  • You already use Drata, Sprinto and want an auditor who integrates with it
  • You value an established firm with 77+ years of audit experience

About Frank, Rimerman’s SOC 2 Practice

Frank, Rimerman + Co. LLP is a Palo Alto-based CPA firm, founded in 1949, with roughly 500-700 people across seven California and Utah offices; its SOC and ISO examination work sits inside a dedicated Risk Advisory & Assurance practice, not as a side offering of the tax and accounting business. The firm has been embedded in Silicon Valley’s venture and technology community since the earliest days of the venture capital industry, and that client base — SaaS, software, fintech, life sciences, and venture-backed companies — is exactly who the Risk Advisory & Assurance group is built to serve.

Frank, Rimerman is also an independent member of Baker Tilly International, one of the ten largest global accountancy networks, giving it reach into 140+ territories for clients with cross-border audit or advisory needs, even though the SOC/ISO practice itself is delivered out of the US offices.

Audit Quality and Credentials

Frank, Rimerman + Co. LLP is a licensed CPA firm and AICPA member, which is the baseline requirement for issuing a SOC report — a SOC 1, SOC 2, or SOC 3 attestation is only as credible as the CPA firm behind it. The firm is enrolled in the AICPA Peer Review Program, and its most recent peer review, dated March 18, 2026, resulted in a pass rating for the engagement period June 1, 2024 through May 31, 2025. Buyers can verify this directly on the AICPA Peer Review public file search. A pass this recent is a meaningful signal — it means the firm’s SOC methodology was independently reviewed and cleared well within the current audit cycle.

SOC 1, SOC 2, and SOC 3 Examinations

Frank, Rimerman’s Risk Advisory & Assurance group performs the full SOC family: SOC 1 (internal controls over financial reporting, typically used for SOX purposes), SOC 2 (Type I and Type II, covering security, availability, confidentiality, processing integrity, and privacy), SOC 3 (the public-facing condensed summary of a SOC 2), and SOC 2+, which layers additional criteria — most commonly ISO 27001 or HIPAA — onto a standard SOC 2 examination so a client only runs one evidence-collection cycle instead of two separate audits. The practice is led by Assurance and Advisory Partners Nelly Spieler and Jason Stork, and the firm advertises unlimited partner and manager access throughout the engagement rather than gating communication to a junior staff auditor.

The ISO 27001/27701 Certification Body — Issuing Both SOC and ISO

Frank, Rimerman’s real differentiator in the SOC 2 market is that it can carry a client from a SOC 2 report through to an ISO 27001 (and ISO 27701 privacy) certification under the same firm brand — a combination most SOC 2-only shops cannot offer in-house. Get the structure right, because it matters for independence: the SOC attestation is issued by Frank, Rimerman + Co. LLP (the CPA firm), while the ISO and CSA STAR certifications are issued by Frank, Rimerman Information Security LLC, a separate legal entity that is affiliated with, but organizationally distinct from, the CPA firm. That separation is not incidental — ANAB accreditation for a certification body requires exactly this kind of structural independence from a firm’s advisory work, the same principle that keeps a CPA firm’s attest opinions clean of self-review risk.

Frank, Rimerman Information Security LLC is accredited by the ANSI-ASQ National Accreditation Board (ANAB) to certify against ISO/IEC 27001 (information security management) and ISO/IEC 27701 (the privacy extension to 27001, useful for GDPR-adjacent obligations). The firm’s marketing also references ISO 27017 (cloud security) and 27018 (PII in the cloud) as part of the “ISO family” it can assess against, but its stated ANAB accreditation covers 27001 and 27701 specifically — buyers who need a standalone 27017 or 27018 certificate should confirm current accreditation scope directly with the firm before assuming coverage. Being one of the small number of public accounting firms accredited as an ISO 27001 certification body is a genuinely uncommon capability; most SOC 2 audit firms partner out ISO work rather than issue it themselves.

CSA STAR Level 2 Certification

Frank, Rimerman Information Security LLC also holds Cloud Security Alliance (CSA) accreditation to issue CSA STAR Level 2 Certification, which combines the ISO/IEC 27001 standard with the CSA’s Cloud Controls Matrix for a cloud-specific maturity assessment, and lists the firm on the CSA STAR Certified Auditors Registry. This is pitched as a natural next step for cloud-native companies that already hold or are pursuing ISO 27001 and want a deeper, cloud-specific layer of assurance without a full separate audit cycle.

Industries Served

The Risk Advisory & Assurance practice’s client base mirrors the firm’s broader technology and life sciences focus: SaaS and software companies, fintech, healthcare and health-tech, life sciences (pharma, biotech, medical device, digital health), and venture-backed companies generally. The firm’s decades of work with Silicon Valley venture capital and growth-stage technology clients shape how its SOC and ISO teams scope and staff engagements — they are used to the pace and audit-readiness gaps typical of a company preparing for its first enterprise deal or funding round with a compliance requirement attached.

Frameworks Frank Rimerman Does Not Cover

Frank, Rimerman’s public service pages do not describe HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work as part of the Risk Advisory & Assurance offering. Buyers whose roadmap includes any of those frameworks should plan on a separate specialist firm for that scope, at least until Frank, Rimerman publishes evidence of accreditation in those areas.

Pricing

Frank, Rimerman does not publish SOC 2 pricing. Based on the firm’s mid-tier CPA positioning and Bay Area cost base, our estimated range is $20,000-$60,000 for a Type I and $30,000-$80,000 for a Type II — directional figures, not a quote from the firm, and actual pricing will move with scope, framework count (a combined SOC 2+ISO engagement costs more than either alone), headcount, and cloud footprint. Request a quote for a firm-specific number.

Timeline

Fieldwork-to-report for a SOC examination at Frank, Rimerman runs an estimated 4-12 weeks, though that window covers only the audit itself. A SOC 2 Type II additionally requires an observation period — typically 3 to 12 months of continuous control operation — before fieldwork can even begin, a constraint of the SOC 2 standard itself rather than anything specific to this firm. Combining SOC 2 with an ISO 27001 or CSA STAR certification in one coordinated engagement is the practice’s stated goal of reducing duplicate evidence requests, but it does not shorten either framework’s underlying observation-period requirements.

Who Should Choose Frank Rimerman

Best fit for:

  • SaaS, fintech, healthcare/health-tech, and life sciences companies in Frank, Rimerman’s home Silicon Valley/Bay Area market that want a recognized, 75-year-old CPA firm name on the report
  • Companies that will need both a SOC 2 report and an ISO 27001 (or 27701) certification and want that continuity handled by one affiliated firm rather than two unrelated vendors
  • Cloud-native companies already holding or pursuing ISO 27001 that want to add CSA STAR Level 2 without starting a new audit relationship
  • Venture-backed startups whose deal or funding timeline benefits from a firm fluent in the Silicon Valley investor and enterprise-buyer context
  • Buyers who value direct, unlimited partner-and-manager access over being routed to junior staff

Not a fit — look elsewhere if:

  • You need HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work; none of these appear in Frank, Rimerman’s published scope
  • You want the very lowest-cost boutique SOC 2 shop; a mid-tier regional CPA firm’s overhead puts it above the cheapest specialist auditors
  • Your business has no California/Bay Area or broader life sciences/technology footprint and gets no benefit from the firm’s regional network

Bottom Line

Frank, Rimerman’s SOC 2 practice trades on two things a lot of SOC 2 shops can’t match: a genuinely recent AICPA peer review pass (March 2026, covering mid-2024 through mid-2025) and an in-house path from SOC attestation to ISO 27001/27701 and CSA STAR Level 2 certification, delivered through an affiliated but organizationally separate entity (Frank, Rimerman Information Security LLC) as accreditation independence rules require. For a Bay Area SaaS, fintech, or life sciences company that expects to need both a SOC 2 report and an ISO certification eventually, that continuity is worth the mid-tier pricing. For HITRUST, government frameworks, or the absolute lowest-cost SOC 2, look to a specialist firm instead.

Office Locations

Palo Alto, CA (HQ)San Francisco, CASan Jose, CASacramento, CASan Diego, CASt. Helena, CALehi, UT

Compliance Frameworks Offered

SOC 1 SOC 2 (Type I & Type II) SOC 3 SOC 2+ (combined with ISO or HIPAA criteria) ISO/IEC 27001 ISO/IEC 27701 CSA STAR Level 2
Expertise

Industries, certifications, and platforms.

Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.

What Industries Does Frank, Rimerman + Co. Serve?

6 industries. Mid-tier average: 6.

SaaS Software FinTech Healthcare Life Sciences Venture-backed Companies

What Certifications Does Frank, Rimerman + Co. Hold?

3 certifications. Mid-tier average: 2.

AICPA CPA Firm ISO 27001 Certification Body

What Platforms Does Frank, Rimerman + Co. Integrate With?

Drata Sprinto

Audit Platform

Proprietary

Buyer questions

Frank, Rimerman + Co. SOC 2 Audit FAQ

Firm-specific answers generated from the directory record and preserved in FAQPage schema.

How much does a SOC 2 audit from Frank, Rimerman + Co. cost?

Frank, Rimerman + Co. SOC 2 Type I audits typically range from $20K to $60K. Type II audits range from $30K to $80K. This is in the mid-range for mid-tier firms — the mid-tier tier average is $28.935K–$76.717K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.

How long does a SOC 2 audit take with Frank, Rimerman + Co.?

The 4–12 week range is Frank, Rimerman + Co.'s audit execution and report-delivery window once evidence is available. It is the fieldwork-to-report window, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins, while a Type I is a point-in-time assessment with no observation period. Actual timelines depend on readiness, scope, and evidence availability.

What industries does Frank, Rimerman + Co. specialize in?

Frank, Rimerman + Co. has deep expertise in SaaS, Software, FinTech, Healthcare, Life Sciences, Venture-backed Companies. They are best suited for Silicon Valley startups, VC-backed companies, and tech firms needing SOC and ISO 27001 on AWS, GCP, Azure, or Salesforce; companies wanting both SOC and ISO from one ANAB-accredited firm

What accreditations does Frank, Rimerman + Co. hold?

Frank, Rimerman + Co. holds 3 accreditations: AICPA, CPA Firm, ISO 27001 Certification Body.

What audit platform does Frank, Rimerman + Co. use?

Frank, Rimerman + Co. uses Proprietary for their audit engagements. They integrate with Drata, Sprinto for evidence collection and compliance automation. Reports are delivered via Standard delivery.

Is Frank, Rimerman + Co. a good SOC 2 auditor?

Frank, Rimerman + Co. is a mid-tier SOC 2 audit firm founded in 1949 with 77 years of experience. 75+ years deeply embedded in the Silicon Valley tech and VC ecosystem; ANAB-accredited ISO 27001/27701 certification body; can certify both SOC and ISO in-house; unlimited partner access year-round; deep expertise in biotech, life sciences, and fintech alongside core SaaS They are best suited for organizations that need saas, software, fintech expertise.

Where is Frank, Rimerman + Co. located?

Frank, Rimerman + Co. is headquartered in Palo Alto, CA, USA. They also have offices in Palo Alto, CA (HQ), San Francisco, CA, San Jose, CA, Sacramento, CA, San Diego, CA, St. Helena, CA, Lehi, UT. They serve clients across the United States and can conduct SOC 2 audits remotely.

How does Frank, Rimerman + Co. compare to other mid-tier SOC 2 auditors?

Compared to the 46 mid-tier firms in our directory, Frank, Rimerman + Co.'s Type II pricing ($30K–$80K) is in the mid-range (tier average: $28.935K–$76.717K). They hold 3 certifications vs. the tier average of 2. Their minimum timeline of 4 weeks is faster than the tier average.

Who should hire Frank, Rimerman + Co. for a SOC 2 audit?

Frank, Rimerman + Co. is best suited for Silicon Valley startups, VC-backed companies, and tech firms needing SOC and ISO 27001 on AWS, GCP, Azure, or Salesforce; companies wanting both SOC and ISO from one ANAB-accredited firm Their key differentiator is: 75+ years deeply embedded in the Silicon Valley tech and VC ecosystem; ANAB-accredited ISO 27001/27701 certification body; can certify both SOC and ISO in-house; unlimited partner access year-round; deep expertise in biotech, life sciences, and fintech alongside core SaaS

Discovery call

Questions to Ask Frank, Rimerman + Co. Before Hiring

A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.

  1. Your team is sized at 500-700+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
  2. You quote 4–12 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
  3. Your Type II range is $30K–$80K. What's included at each end, and what scope changes would push pricing above the top of that range?
  4. You integrate with Drata, Sprinto. If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
  5. Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
  6. How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
  7. When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
  8. Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Verification

Frank, Rimerman + Co. on the verification record

We independently verified Frank, Rimerman + Co.'s CPA standing and peer-review record. The facts and dates are on its verification record.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from Frank, Rimerman + Co.

Tell us your scope. Frank, Rimerman + Co. replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Want to compare first? See 46 similar mid-tier firms or get 3 quotes.

We send you 3 to 5 firms that actually fit, a shortlist, not a phone book.

We email you the quotes. Auditors don't see your contact details until you choose one.

Add optional details timeline, scope, platform

Compare quotes before taking a sales call.

Read by a human. At least 3 quotes in 48 hours.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Frank, Rimerman + Co.'s profile →