Who is LBMC?
LBMC is a Nashville-based professional services firm, founded in 1984, with a dedicated cybersecurity and attestation practice inside a firm of more than 900 professionals serving roughly 11,000 clients. Rather than a boutique SOC 2 shop, LBMC is a top-50 U.S.
accounting firm where SOC reporting sits alongside audit, tax, HR outsourcing, and wealth management under one “LBMC Family of Companies” umbrella — the SOC 2 buyer here is typically a mid-market or larger organization, often in healthcare, financial services, or cloud/SaaS, that also wants HITRUST, ISO 27001, or PCI handled by the same team.
LBMC’s cybersecurity group performs SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity examinations directly, issued under the firm’s own CPA license. It operates from seven U.S. offices — Nashville (headquarters, in Brentwood), Chattanooga, Knoxville, Memphis, Louisville, Charlotte, and Philadelphia — plus a delivery team in Chennai, India.
What credentials does LBMC actually hold?
LBMC is a licensed CPA firm and AICPA member that issues SOC reports itself, not through a subcontracted or partner CPA. SOC engagements are performed under AICPA SSAE 18 standards, per LBMC’s own service description.
The firm is enrolled in the AICPA Peer Review Program, the profession’s mandatory external quality check for CPA firms performing attestation work. LBMC’s most recent peer review was completed March 4, 2026, with a pass result covering the period June 1, 2024 through May 31, 2025 — a recent, current review, verifiable directly at the AICPA’s public peer-review search.
Beyond the CPA license, LBMC’s cybersecurity practice carries three accreditations that most SOC-only firms don’t hold: HITRUST Authorized External Assessor status, PCI Qualified Security Assessor (QSA) status, and ISO 27001 Lead Auditor credentials — the combination that lets one team move a client between SOC 2, HITRUST, ISO, and PCI without a handoff to a different firm.
What SOC reports does LBMC issue?
LBMC performs the full SOC family — SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity — for service organizations nationwide, offering both Type I (point-in-time design) and Type II (design and operating effectiveness) reports.
Per LBMC’s own SOC audit page, a Type II examination period typically runs 6 to 12 months, and the firm targets issuing the final report 45 to 60 days after that observation period closes.
LBMC’s stated engagement flow is discovery and scoping, an optional (but recommended) readiness assessment to surface control gaps before testing starts, control implementation/remediation by the client, the observation period itself for a Type II, then testing and report issuance. That structure is standard for a firm this size — LBMC does not shortcut the observation window, and readiness is explicitly optional rather than bundled by default.
Does LBMC assess HITRUST?
LBMC has been a HITRUST Authorized External Assessor since 2010 and markets itself as the longest-serving assessor in HITRUST’s “10-year club.” Tenure is the differentiator; confirm current assessor status on HITRUST’s list.
LBMC also states it participated in the work integrating CMS and NIST security standards into the HITRUST CSF itself, rather than simply testing against it.
LBMC’s HITRUST services span scoping and certification-type selection, readiness and gap assessment, initial and interim certification assessments, and bridge assessments for organizations extending a certification period. For healthcare organizations and their business associates that need both a SOC 2 report and a HITRUST certification, LBMC’s pitch is running both through one team rather than coordinating two separate assessors.
Is LBMC an ISO 27001 certification body?
LBMC performs ISO/IEC 27001:2022 (information security), 27701:2019 (privacy), and 9001:2015 (quality) certification audits directly, including the two-stage initial certification audit and the subsequent surveillance audits over the three-year certification cycle. LBMC’s own internal Certification Committee reviews audit results and approves or denies certification.
The firm’s marketing does not cite an ANAB or UKAS accreditation number for this certification-body function, so buyers who need certification from a specific national accreditation body should confirm that detail directly with LBMC before engaging.
Does LBMC do PCI DSS?
LBMC is a PCI Qualified Security Assessor (QSA) firm, supporting the full range of PCI work: Report on Compliance (ROC) and Attestation of Compliance (AOC) for Level 1 merchants and service providers, PCI gap analysis, quarterly ASV vulnerability scanning, and Self-Assessment Questionnaire (SAQ-D) support.
LBMC frames this as an “audit once, report many” approach — aligning PCI evidence with SOC 2 or other frameworks the client is already pursuing, which reduces duplicate evidence requests for clients running both engagements.
Does LBMC cover HIPAA?
LBMC performs HIPAA and HITECH security and privacy risk assessments for healthcare organizations and business associates, and can report the results through HITRUST or another certification framework alongside a SOC engagement.
For CMMC, LBMC provides readiness consulting, gap analysis against CMMC 2.0 requirements, and remediation support, guiding defense contractors through Level 1 self-assessment or Level 2+ formal assessment prep. LBMC’s public materials describe this readiness and advisory role clearly; they do not state that LBMC itself holds Certified Third-Party Assessor Organization (C3PAO) accreditation to issue the formal Level 2 certification. Buyers whose primary need is the formal CMMC certification assessment itself, rather than readiness, should confirm C3PAO status directly with LBMC.
LBMC also performs CSA STAR assessments (Level 1 self-assessment support and Level 2 third-party certification/attestation as an approved CSA-certified STAR auditor) and NIST 800-53/800-171 compliance assessments, drawing on more than 20 years in IT security and compliance work.
Does LBMC also sell penetration testing?
LBMC’s cybersecurity team offers penetration testing — network, web application, mobile application, cloud, wireless, and social engineering testing, plus its Advance Guard continuous-assessment retainer and LBMC Guard vulnerability-scanning service — explicitly positioned to complement PCI DSS and SOC audit work.
Worth understanding before scoping: when a SOC 2 engagement calls for an accompanying penetration test, having the same CPA firm perform both the test and the audit that relies on it creates a self-review consideration under AICPA independence rules — the pen test becomes part of the control environment the audit then evaluates. If you engage LBMC for SOC 2 attestation, raise the separation question up front rather than assuming the firm’s own pen test team should be bundled into the same engagement.
Which industries does LBMC actually serve?
LBMC’s cybersecurity and attestation clients concentrate in healthcare and claims processing, financial services, cloud service providers and SaaS/technology companies, data centers and hosting providers, private-equity portfolio companies, manufacturing, and real estate — a broader industry spread than a SOC-2-only boutique, consistent with LBMC’s position as a full-service regional firm rather than a niche specialist.
How much does an LBMC SOC 2 audit cost?
LBMC does not publish SOC 2 pricing. Directory estimates are $15,000–$45,000 Type I and $20,000–$60,000 Type II; those are ours, not LBMC’s quote.
Request a quote for a scoped number.
How long does an LBMC SOC 2 audit take?
LBMC’s own SOC audit page states report issuance 45–60 days after the observation period ends — that is the fieldwork-to-report window, not the whole engagement. A SOC 2 Type II additionally requires the client’s controls to operate over a 6–12 month observation period before that fieldwork can begin, per LBMC’s stated process.
A Type I, which has no observation period, moves faster: expect discovery, readiness (if used), and fieldwork to run on the order of several weeks rather than months. Total calendar time from kickoff to a Type II report, including the observation window, commonly lands in the 26–52 week range our base data reflects — the audit fieldwork itself is a small fraction of that.
Who is LBMC a good fit for?
Best fit for: - Healthcare, financial services, or PE-backed companies that need SOC 2 alongside HITRUST, ISO 27001, or PCI DSS handled by one accredited team - Organizations that value a firm with two decades of HITRUST tenure (Authorized External Assessor since 2010) for a HITRUST certification or bridge assessment - Mid-market and larger service organizations that want a single
regional firm covering audit, tax, and cybersecurity, not just SOC 2 in isolation - Companies that need PCI DSS ROC/AOC work coordinated with their SOC 2 evidence
Not a fit — look elsewhere if:
- You are an early-stage startup that wants a 2–6 week Type I turnaround and boutique, founder-direct pricing; LBMC’s scale and multi-framework accreditation stack carry regional-firm overhead
- Your immediate need is a formal CMMC Level 2 certification assessment; LBMC’s public materials describe readiness and gap-analysis support, not confirmed C3PAO accreditation to issue the certification itself
- You need FedRAMP or StateRAMP authorization; it is not listed among LBMC’s cybersecurity service pages
- You need same-firm penetration testing bundled into a SOC 2 engagement without an independence conversation first
When should a buyer shortlist LBMC?
LBMC’s SOC 2 practice is best understood through its HITRUST tenure: an Authorized External Assessor since 2010 and, by its own description, the longest-serving assessor in the program’s “10-year club,” backed by PCI QSA status and ISO 27001 audit capability under one roof.
That makes it a strong choice for healthcare, financial-services, or PE-backed organizations that need SOC 2 plus a second or third framework handled without switching firms. It is a licensed CPA firm with a recent, passed AICPA peer review (March 2026, covering mid-2024 through mid-2025). It is not the cheapest or fastest path to a first SOC 2 Type I — that’s a boutique specialist’s game — and buyers whose primary need is a formal CMMC or FedRAMP certification should confirm LBMC’s specific accreditation for that certification before engaging.