Who is IS Partners?
IS Partners, LLC is a licensed CPA and cybersecurity firm headquartered in Dresher, Pennsylvania, founded in 2005 by Big 4 alumni and now operating a US and UK practice with a team of roughly 40 to 60 professionals.
It is a full-scope attestation and compliance shop — SOC 1, SOC 2, SOC 3, ISO 27001, HITRUST, PCI DSS, and CMMC under one roof — built for mid-market and enterprise organizations in regulated industries that need more than a single report. In November 2025 IS Partners was acquired by Axiom GRC, a UK-headquartered governance, risk, and compliance group; the firm continues to operate under its own IS Partners brand, domain, and leadership as part of that group.
A note on corporate history worth getting right: Axiom GRC separately acquired AssurancePoint in early 2026. AssurancePoint is a sibling portfolio company within the same group, not a firm that IS Partners merged with. Buyers evaluating IS Partners are engaging the IS Partners entity and its own CPA license, not a combined post-merger brand.
IS Partners serves government contractors, healthcare and revenue-cycle organizations, business process outsourcers, data centers, SaaS, energy and utilities, finance and fintech, insurance, manufacturing, and telecommunications. The through-line is regulated, audited industries where a defensible report and multi-framework coverage matter more than a rock-bottom price.
Is IS Partners a Legitimate SOC 2 Auditor?
Yes — IS Partners is a licensed CPA firm and an AICPA and PCAOB member, so it issues the SOC 2 report itself rather than subcontracting the signature to a CPA partner.
SOC 2 is an AICPA attestation engagement, and a report is only as defensible as the firm that signs it; IS Partners carries the license that makes the attestation valid.
The credentials behind the report:
- Licensed CPA firm, AICPA and PCAOB member. IS Partners issues its own SOC reports under a valid CPA license — the baseline requirement for a SOC 2 attestation to carry weight with an enterprise customer’s vendor-security team.
- AICPA Peer Review Program enrolled. IS Partners is enrolled in the AICPA Peer Review Program, the profession’s independent quality check. Its most recent review is dated January 4, 2024, covering the period April 1, 2022 through March 31, 2023. Peer review status is verifiable through the AICPA public file search.
- Deep credential bench. The firm’s practitioners hold CPA, CISA-adjacent security, CIPP, CRMA, CEH, CCSP, and HCISPP credentials, and IS Partners is a HITRUST Authorized Assessor, a PCI DSS QSA, and an authorized CMMC C3PAO.
For a company whose SOC 2 report has to satisfy a regulated enterprise buyer, the combination of a real CPA license, active peer review, and multi-framework accreditation is what makes the attestation hold up under scrutiny.
What SOC reports does IS Partners issue?
IS Partners performs the full range of SOC attestations: SOC 1 (financial-reporting controls), SOC 2 (security, availability, processing integrity, confidentiality, privacy), and SOC 3 (a public-facing summary). It also offers SOC 2 readiness assessments, SOC for Cybersecurity, and SOC for Supply Chain — a broader SOC menu than most boutiques carry.
For a first-time buyer the common path is a SOC 2 Type I (a point-in-time design review, often needed quickly to unblock a deal) followed by a SOC 2 Type II (an operating-effectiveness report over an observation window, typically three to twelve months). IS Partners runs both, and its readiness service is designed to surface and remediate control gaps before the audit period opens, so the observation window is not wasted on findings that could have been fixed up front.
Because SOC 1 sits alongside SOC 2 in the practice, organizations that process financially significant transactions on behalf of clients — payment processors, revenue-cycle managers, BPOs — can run SOC 1 and SOC 2 through the same firm on shared evidence.
Which regulated industries does IS Partners serve?
IS Partners is built for regulated industries, and healthcare is a core competency: it performs HIPAA / HITECH assessments and is a HITRUST Authorized Assessor covering the HITRUST CSF (including HITRUST’s AI assurance track). Organizations handling protected health information can run HIPAA, HITRUST, and SOC 2 through one firm rather than coordinating three engagements.
The firm’s framework coverage extends well past healthcare into the regulated stack that mid-market and enterprise buyers accumulate over time: ISO 27001 and ISO 42001 (AI management systems), PCI DSS with in-house QSA and ASV capability, CMMC as an authorized C3PAO, plus NIST 800-53, the NIST AI Risk Management Framework, DORA, FISMA, GLBA, SOX, CCPA, GDPR, CSA STAR, and Cyber Essentials. For a company that needs SOC 2 today and can see ISO, PCI, or CMMC on the horizon, that continuity means no re-onboarding with a new firm later.
Does IS Partners also sell penetration testing?
IS Partners offers penetration testing and vCISO services alongside its attestation practice. That breadth is convenient, but there is one independence point to understand before scoping a bundle.
Under AICPA independence rules, a CPA firm that performs a penetration test and then audits a control environment that includes that same test runs into a self-review consideration: the test becomes part of the controls the audit is meant to evaluate independently. Because IS Partners is both the CPA firm issuing the SOC 2 report and a provider of penetration testing, the cleanest posture is to scope the penetration test separately — either engaged as a standalone service, or performed by a different provider than the one signing the report. If you are engaging IS Partners for SOC 2, raise the separation question on the first call rather than assuming the pen test and the attestation should be delivered as one clean package. The same self-review logic applies to remediation or advisory work performed by the team that later audits it.
This is not a knock on IS Partners — it is the standard independence discipline any buyer should apply to a firm that both tests and attests.
IS Partners works with client-side GRC automation rather than pushing a proprietary compliance platform onto buyers. It names Drata as a supported compliance-automation partner, so teams already collecting evidence in Drata can run the audit against that data without a separate export.
The firm’s own audit delivery runs on FieldGuide, an audit-management platform that serves as the client-facing portal for evidence requests and engagement coordination. Buyers standardized on Vanta, Secureframe, or Sprinto should confirm the integration fit directly, since those partnerships are not currently listed among IS Partners’ named platforms.
How much does an IS Partners SOC 2 audit cost?
IS Partners does not publish a fixed rate card, and the following is our directional estimate, not a firm-confirmed quote: a SOC 2 Type I in the range of $35,000 to $100,000, and a SOC 2 Type II in the range of $50,000 to $150,000.
Actual pricing moves with scope, the number of Trust Services Criteria in scope, headcount, systems, and whether other frameworks are bundled.
These ranges sit above startup-boutique pricing by design. IS Partners skews toward mid-market and enterprise buyers in regulated industries, where engagements are larger, scopes are broader, and the multi-framework accreditation stack carries real overhead. Treat the numbers above as our estimate of where a typical IS Partners engagement lands, and request a quote for a scope-specific ballpark.
How long does an IS Partners SOC 2 audit take?
IS Partners’ fieldwork-to-report turnaround runs roughly 8 to 16 weeks depending on scope and readiness. That window covers the audit itself — fieldwork, testing, and report drafting — not the observation period.
For a SOC 2 Type II, plan for a 3-to-12-month observation window before that fieldwork window even begins: the report attests that controls operated effectively over a period, so there must be a period to observe. A Type I, being point-in-time, avoids the observation window and is the faster path when a deal deadline is looming.
Which frameworks does IS Partners cover?
IS Partners’ framework coverage is unusually wide, but one notable gap stands out: FedRAMP. The firm does not market FedRAMP authorization support, and there is no FedRAMP 3PAO offering on its site.
Organizations pursuing FedRAMP for federal cloud sales will need a separate accredited 3PAO for that scope — even though IS Partners can handle adjacent government frameworks like CMMC (as a C3PAO), NIST 800-53, and FISMA.
If your roadmap is SOC 2 plus ISO 27001, HITRUST, PCI DSS, or CMMC, IS Partners covers it under one relationship. If FedRAMP authorization is your primary near-term requirement, plan for an additional firm.
Who is IS Partners a good fit for?
IS Partners fits mid-market and enterprise buyers in healthcare, financial services, and government contracting that need a licensed CPA SOC 2. It is not the first-audit startup boutique.
Best fit for:
-
Mid-market and enterprise organizations in regulated industries — healthcare, financial services, government contracting, insurance, energy, telecom — that need a defensible SOC 2 from a licensed CPA firm.
-
Companies that need SOC 2 today and can foresee ISO 27001, HITRUST, PCI DSS, or CMMC later, and want to avoid re-onboarding a new auditor for each framework.
-
Healthcare and revenue-cycle organizations that need HIPAA, HITRUST, and SOC 2 handled by one firm on shared evidence.
-
Defense-adjacent contractors that need CMMC (C3PAO) alongside SOC 2 and NIST-based frameworks.
-
Buyers who value AICPA and PCAOB membership and a broad accreditation stack over the lowest possible price.
Not a fit — look elsewhere if you need:
- FedRAMP authorization as your primary requirement (no 3PAO offering).
- The lowest possible cost for a single, simple SOC 2 — startup-focused boutiques will come in well under IS Partners’ mid-market pricing.
- A Big Four or Top 25 firm name on the report purely for investor or SEC optics.
- A firm that only attests and never tests, if you want strict structural separation and would rather not manage the self-review question yourself.
When should a buyer shortlist IS Partners?
IS Partners is a licensed CPA and cybersecurity firm (AICPA and PCAOB member, peer-review enrolled) built for regulated mid-market and enterprise buyers who need a SOC 2 report that holds up and a single firm that can also deliver ISO 27001, HITRUST, PCI DSS, and CMMC.
Acquired by Axiom GRC in November 2025, it continues under its own brand and license. Our estimated pricing — $35k-$100k for a Type I, $50k-$150k for a Type II — reflects that mid-market, multi-framework positioning, so startup teams chasing the cheapest first SOC 2 will find better-fit boutiques elsewhere. One caveat to scope deliberately: because IS Partners both issues the SOC 2 and offers penetration testing, keep the pen test engagement separate to stay clear of the AICPA self-review consideration.