Johanson Group
- Licensed CPA firm — can issue a SOC 2 report
- AICPA peer review: No public rating · Accepted Apr 30, 2025 · Verify at AICPA → ·
Details
Review period: Aug 1, 2023–Jul 31, 2024 · Record checked: Aug 17, 2026
Johanson Group is an assurance specialist SOC 2 audit firm in Colorado Springs, CO, USA. Its estimated SOC 2 Type II audit price is $15,000–$30,000; fieldwork to report takes 4–8 weeks.
Johanson Group can issue both a CPA-signed SOC 2 and an IAS-accredited ISO 27001 certificate through Johanson Group LLP. ISO 42001 is advertised but is not on its IAS scope. The published 4–8 weeks excludes the Type 2 observation window.
Independent profile, researched and maintained by this directory from public sources. Johanson Group has not reviewed or verified this page. Work at Johanson Group? Verify and correct it — free →
“The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group.”
— Björn Schwenzer, COO, WunderGraph
Free. Anonymous until you pick.
How Much Does Johanson Group Charge for SOC 2?
Johanson Group's estimated SOC 2 Type II audit price is $15,000–$30,000; fieldwork to report takes 4–8 weeks.
- Type 1 cost
- $10K–$18K
- Type 2 cost
- $15K–$30K
- Timeline
- 4–8 wk
- Team Size
- 50-60
- Report Delivery
- Type 1 listed at 4-6 weeks; sitewide planning range 4-8 weeks (approximate)
- Response Time
- Dedicated Customer Success Manager plus audit project lead on every engagement
Type 2 cost Pricing Position
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
Timeline: The 4–8 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires a separate observation period, typically 3–12 months depending on scope.
How this directory works: firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees. Our methodology →
- Pricing context
- 90%
- Timeline context
- 26%
- Accreditations
- 4
of Assurance specialist firms charge more for Type II.
of Assurance specialist firms have longer minimum timelines.
verified accreditations. Group average: 4.
Source: soc2auditors.org/auditors/johanson-group/ · compiled and maintained by soc2auditors.org.
Compare Johanson Group with Similar Assurance specialist Firms
Closest-priced peers in the assurance specialist organization group, by Type II range, timeline, and verified accreditations. Firm-reported certification totals are left out — they are not the same measure as the badges we verify.
| Johanson Group | 360 Advanced Sponsored | Zero Day CPA Sponsored | Modern Assurance | Decrypt Compliance | MJD Advisors | |
|---|---|---|---|---|---|---|
| Type II Cost | $15K–$30K | $15K–$80K | $7K–$10K | $7K–$42K | $10K–$40K | $15K–$35K |
| Type I Cost | $10K–$18K | $15K–$60K | $5K–$7K | $5K–$24K | $8K–$15K | $8K–$20K |
| Timeline | 4–8 wk | 3–12 wk | 2–6 wk | 1–7 wk | 4–8 wk | 2–6 wk |
| Team Size | 50-60 | 51–200 | 25–30 | 2–10 | 10–100 | 5–10 |
| Itemized Accreditations | 4 | 9 | 2 | 3 | 5 | 2 |
| Founded | 2012 | 2004 | 2020 | 2022 | 2023 | 2021 |
This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose
Johanson Group Industry Fit
For buyers in B2B SaaS and Startups (Pre-Series A through Series B), Johanson Group fits the assurance specialist profile when its 4–8 weeks timeline and Type II pricing ($15K–$30K) align with the buyer's scope. Their 4 active accreditations, including ISO 27001 Certification Body, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Who Should Hire Johanson Group?
SaaS, fintech, healthtech, and crypto companies that want a CPA-issued SOC 2 plus IAS-accredited ISO 27001 from one firm.
What Makes Johanson Group Different?
A CPA firm of 50-plus people with a dedicated CSM: the same LLP signs SOC 2 and issues ISO 27001 as an IAS-accredited certification body.
Is Johanson Group Right for You?
- You need an affordable first SOC 2 audit (starting from $15K)
- You're a SaaS company going through SOC 2 for the first time
- You already use Drata, Vanta, Secureframe, Sprinto and want an auditor who integrates with it
- You want a firm whose practice centers on SOC 2 and information assurance
of 4 criteria match. Get a personalized quote
Industries served
Works with these GRC platforms
Who is Johanson Group LLP?
Johanson Group LLP is a licensed CPA firm and an IAS-accredited ISO 27001 certification body (MSCB-314). Its About page, reviewed 17 August 2026, dates the firm to 2012, lists a Colorado Springs headquarters, and names 50-plus people on the public roster.
The same page lists 6547 North Academy Boulevard #105, says the firm serves clients in the US, Latin America, Europe, and APAC, and assigns a Customer Success Manager to every engagement.
That combination — CPA-signed SOC reports plus an accredited ISO certificate from the same legal entity — is the reason to shortlist Johanson. It is no longer accurate to describe the firm as a 12-to-20-person startup boutique. The public roster now includes co-founders, an ISO practice (Managing Director Stewart Riley; Quality Director John Miller), a PCI director who is a QSA, a sizable audit bench, and a dedicated customer-success team.
Named clients on Johanson’s own site and partner pages include Bitkub Exchange (SOC 2 Type II) and Scisco Genetics (SOC 2, published as a six-week engagement). LendAPI announced Johanson as its SOC 2 firm in its own blog. Testimonials on johansonllp.com name WunderGraph, Clozd, and Kaboom AI.
Johanson is enrolled in the AICPA Peer Review Program. The public file pulled for this directory (retrieved 17 August 2026) shows a review dated 30 April 2025 covering 1 August 2023 to 31 July 2024. The rating is not disclosed in that public record.
How long does Johanson say a SOC 2 audit takes?
Johanson’s homepage states a 4–8 week audit planning range for SOC 2, ISO 27001, PCI DSS, GDPR, and HIPAA. The footnote says timelines are approximate and depend on readiness, scope, and client responsiveness. The SOC 2 service page is more specific for Type 1.
| Deliverable | What Johanson publishes | What that number does not include |
|---|---|---|
| SOC 2 Type 1 | 4–6 weeks on the SOC 2 page | Control design work you still have to finish before kickoff |
| SOC 2 Type 2 | 6–12 month observation window in the homepage FAQ, then fieldwork/reporting | The observation period itself |
| ISO 27001, PCI DSS ROC, HIPAA attestation | 4–8 weeks sitewide planning range | Stage-1/Stage-2 sequencing for ISO; acquirer calendars for PCI |
The 1–3 week Type 1 figure previously shown in this directory was not on the firm’s current site and has been removed. Type 2 observation (usually 6–12 months on Johanson’s own FAQ) is a separate clock from the 4–8 week planning range.
What does Johanson’s ISO 27001 accreditation actually cover?
Johanson Group LLP holds IAS certification-body accreditation MSCB-314 for ISO/IEC 27001:2022. The certificate on file, effective 7 April 2026 (accredited since 16 April 2023), attests ISO/IEC 17021-1:2015 compliance for a virtual Colorado Springs operation. It lists:
- Certification standard: ISO/IEC 27001:2022
- Additional level-4 standards: ISO/IEC 27006:2015/AMD 1:2020 and ISO/IEC 27006-1:2024
- Operating model: virtual, from the Colorado Springs address
- IAS contact on the certificate: Thomas Miller
When Johanson issues an ISO/IEC 27001:2022 certificate under that accreditation, it is a certification-body deliverable, not an advisory letter. IAF CertSearch also lists the firm as a certification body under IAS.
The firm now also sells ISO 42001 certification audits (Stage 1 documentation review and Stage 2 implementation audit). The current MSCB-314 scope does not list ISO/IEC 42001. Treat 42001 as a marketed service until an accreditor record names it. Buyers who need an accredited 42001 certificate should ask which accreditation, if any, would sit on that certificate.
ISO/IEC 27017 and 27018 appear as service pages. ISO 27701 and BSI C5, which older write-ups attributed to Johanson, are not in the current public service menu.
What SOC, HIPAA, and PCI work does Johanson perform?
Johanson lists SOC 1, SOC 2, and SOC 3 under SOC & Attestation, plus standalone HIPAA attestation and a QSA-led PCI DSS ROC. Concurrent programs collect shared evidence once; they do not replace a HIPAA attestation or an ISO certificate.
The SOC 2 page walks Type 1 (point in time) and Type 2 (typically 6–12 months of operating effectiveness) and says the firm regularly runs concurrent SOC 1 + SOC 2, SOC 2 + ISO 27001, and SOC 2 + HIPAA programs.
HIPAA is a standalone attestation service covering Privacy, Security, and Breach Notification, including a Security Risk Analysis and BAA review. There is no HIPAA certification body; this is third-party attestation, which is why the directory records it as an assessment role rather than a credential.
PCI DSS is sold as a QSA-led Report on Compliance against PCI DSS v4.0.1, producing a ROC and AOC. Anthony Fulda is listed as Director of PCI with QSA in his credentials. This profile does not add a firm-level PCI DSS QSA badge until the company (not only an individual) is confirmed on the PCI SSC QSA list.
GDPR, CCPA, and NIST assessments are in the current menu. Johanson does not list FedRAMP, StateRAMP, CMMC, HITRUST, or FFIEC. Its homepage FAQ mentions CMMC and NIST as frameworks buyers sometimes need; that is not the same as Johanson being a C3PAO or 3PAO.
Which GRC platforms does Johanson work with?
Johanson’s partners directory (17 August 2026) names four compliance-automation partners: Drata, Vanta, Secureframe, and Sprinto. Drata’s auditor directory lists Johanson as a Registered Alliance Member with the Code of Ethics Pledge, English and Spanish, and client sizes from SMB through enterprise.
Rippling, TrustCloud, and Securicy are not on the current partners page, so they are no longer listed here. The firm says it audits inside the client’s existing GRC tools rather than requiring a proprietary platform.
Who leads Johanson Group?
Ryan Johanson, CPA, and Ramil Cortez are the named co-founding partners on Johanson’s About page as of 17 August 2026. Stewart Riley leads the ISO practice; Anthony Fulda is Director of PCI; John Miller is ISO Quality Director.
Public About-page titles, reviewed 17 August 2026:
- Ryan Johanson, CPA — Partner & Co-Founder
- Ramil Cortez — Partner & Co-Founder
- Stewart Riley — ISO Managing Director
- Anthony Fulda, CISA, CISSP, QSA — Director of PCI (not a named partner on the current roster)
- John Miller — ISO Quality Director (lead auditor credentials listed for 27001 and 42001)
- Keshia Belong — Audit Director
- Ryan McBride — Vice President of Sales
- Tom Miller — CTO, VP Product Development. The IAS certificate names Thomas Miller as the contact; the About page does not spell out whether that is the same person.
Customer-success leadership on the same page includes Mark Andia (Manager, Customer Success). Earlier mentions of Raahsaan Fox as a current CS contact are not on the current roster.
How much does a Johanson SOC 2 audit cost?
Johanson does not publish a rate card. Directory estimates remain $10,000–$18,000 for SOC 2 Type 1 and $15,000–$30,000 for Type 2 for typical startup-to-SMB SaaS scope. Those figures are ours, not firm-confirmed, and they do not price ISO certification, HIPAA attestation, or a PCI ROC.
A testimonial on Johanson’s site (Sheryl Briggs, CEO, Classapps) cites affordable pricing as a reason for switching firms. That is a client comment, not a public price list. Request a quote for a scoped number.
Who is Johanson Group a good fit for?
Johanson is a poor fit for FedRAMP, CMMC, HITRUST, or a Big Four name on the report. The same-entity SOC 2 plus accredited ISO 27001 case is the shortlist reason; buyers needing those other credentials should compare broader firms.
Best fit for:
- Teams that want a CPA-issued SOC 2 and an IAS-accredited ISO/IEC 27001:2022 certificate without hiring a second firm
- Companies already on Drata, Vanta, Secureframe, or Sprinto
- Healthtech buyers who need a HIPAA attestation alongside SOC 2
- Payments and fintech teams evaluating a QSA-led PCI DSS ROC from the same relationship (confirm QSA company status in the proposal)
- Buyers who want a named CSM and a published 4–8 week planning range, with Type 2 observation scheduled separately
Not ideal for:
- Enterprise or public-company procurement that requires a Big Four or Top 25 firm name on the report
- FedRAMP, StateRAMP, CMMC, HITRUST, or FFIEC scope
- Buyers who need an accredited ISO 42001 certificate unless Johanson can show a current accreditation that includes 42001
- Anyone treating the 4–8 week planning range as a guaranteed Type 2 calendar — the observation window still has to run
How current is this Johanson profile?
This profile was checked against Johanson’s public site, the IAS MSCB-314 certificate, IAF CertSearch, and the AICPA peer-review public file on 17 August 2026. Re-check ISO 42001 accreditation and PCI QSA company status before you sign.
- Johanson Group homepage, About, SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, and partners
- IAS MSCB-314 certificate (PDF)
- IAF CertSearch listing
- Drata Audit Alliance directory
- LendAPI announcement
- AICPA Peer Review public file (enrollment and 30 April 2025 review date)
Contact & Links
Office Locations
Compliance Frameworks Offered
GRC Platform Compatibility
Client Testimonials
"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process."
"This was our fourth audit with Johanson Group LLP. Every time they have been very easy to work with. There has been clear communication on evidence requests and the auditors have been helpful with advice on providing alternate evidence when that requested isn't available. Audits are conducted in a timely fashion and reports are delivered when promised."
Industries, certifications, and platforms.
Match this firm to your industry, overlapping frameworks you need alongside SOC 2, and the GRC stack you already run.
What Industries Does Johanson Group Serve?
7 industries. Assurance specialist average: 6.
What Certifications and Accreditations Does Johanson Group List?
4 accreditations. Assurance specialist average: 4.
What GRC Platforms Does Johanson Group Work With?
Audit Platform
Audits inside the client's GRC tools; listed partners are Drata, Vanta, Secureframe, and Sprinto
Questions to Ask Johanson Group Before Hiring
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
- Your team is sized at 50-60. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
- You quote 4–8 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
- Your Type 2 cost range is $15K–$30K. What's included at each end, and what scope changes would push pricing above the top of that range?
- You integrate with Drata, Vanta, Secureframe. If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
- Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
- How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
- When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
- Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Johanson Group on the verification record
Johanson Group's registry record was last verified 2026-08-17.
See the verification record · Is this your firm? Get your badge.
Get a quote from Johanson Group
Tell us your scope. Johanson Group replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? Browse All Auditors or get 3–10 quotes.
Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Johanson Group's profile →