Logo Menu

LBMC

Full-service CPA Verified Nashville, TN, USA
  • Licensed CPA firm — can issue a SOC 2 report
  • AICPA peer review: Pass · Accepted Mar 4, 2026 · Verify at AICPA → ·
    Details Review period: Jun 1, 2024–May 31, 2025 · Record checked: Sep 3, 2026

LBMC is a full-service cpa SOC 2 audit firm in Nashville, TN, USA. Its estimated SOC 2 Type II audit price is $20,000–$60,000; fieldwork to report takes 26–52 weeks.

Independent profile, researched and maintained by this directory from public sources. LBMC has not reviewed or verified this page. Work at LBMC? Verify and correct it — free →

Type 1 cost
$15K–$45K est.
Type 2 cost
$20K–$60K est.
Timeline
26–52 weeks
Accreditations
4 listed

Free. Anonymous until you pick.

Pricing

LBMC's estimated SOC 2 Type II audit price is $20,000–$60,000; fieldwork to report takes 26–52 weeks.

Type 1 cost
$15K–$45K
Type 2 cost
$20K–$60K
Timeline
26–52 wk
Team Size
50-150+
Report Delivery
45-60 days after reporting period ends
Response Time
Standard

Type 2 cost Pricing Position

$2.5K observed market span · est. $450K
LBMC: $20K–$60K Full-service CPA avg: $31.187K–$82.355K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 26–52 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires a separate observation period, typically 3–12 months depending on scope.

Pricing context
81%

of Full-service CPA firms charge more for Type II.

Timeline context
0%

of Full-service CPA firms have longer minimum timelines.

Accreditations
4

verified accreditations. Group average: 2.

Source: soc2auditors.org/auditors/lbmc/ · compiled and maintained by soc2auditors.org.

Who is LBMC?

LBMC is a Nashville-based professional services firm, founded in 1984, with a dedicated cybersecurity and attestation practice inside a firm of more than 900 professionals serving roughly 11,000 clients. Rather than a boutique SOC 2 shop, LBMC is a top-50 U.S.

accounting firm where SOC reporting sits alongside audit, tax, HR outsourcing, and wealth management under one “LBMC Family of Companies” umbrella — the SOC 2 buyer here is typically a mid-market or larger organization, often in healthcare, financial services, or cloud/SaaS, that also wants HITRUST, ISO 27001, or PCI handled by the same team.

LBMC’s cybersecurity group performs SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity examinations directly, issued under the firm’s own CPA license. It operates from seven U.S. offices — Nashville (headquarters, in Brentwood), Chattanooga, Knoxville, Memphis, Louisville, Charlotte, and Philadelphia — plus a delivery team in Chennai, India.

What credentials does LBMC actually hold?

LBMC is a licensed CPA firm and AICPA member that issues SOC reports itself, not through a subcontracted or partner CPA. SOC engagements are performed under AICPA SSAE 18 standards, per LBMC’s own service description.

The firm is enrolled in the AICPA Peer Review Program, the profession’s mandatory external quality check for CPA firms performing attestation work. LBMC’s most recent peer review was completed March 4, 2026, with a pass result covering the period June 1, 2024 through May 31, 2025 — a recent, current review, verifiable directly at the AICPA’s public peer-review search.

Beyond the CPA license, LBMC’s cybersecurity practice carries three accreditations that most SOC-only firms don’t hold: HITRUST Authorized External Assessor status, PCI Qualified Security Assessor (QSA) status, and ISO 27001 Lead Auditor credentials — the combination that lets one team move a client between SOC 2, HITRUST, ISO, and PCI without a handoff to a different firm.

What SOC reports does LBMC issue?

LBMC performs the full SOC family — SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity — for service organizations nationwide, offering both Type I (point-in-time design) and Type II (design and operating effectiveness) reports.

Per LBMC’s own SOC audit page, a Type II examination period typically runs 6 to 12 months, and the firm targets issuing the final report 45 to 60 days after that observation period closes.

LBMC’s stated engagement flow is discovery and scoping, an optional (but recommended) readiness assessment to surface control gaps before testing starts, control implementation/remediation by the client, the observation period itself for a Type II, then testing and report issuance. That structure is standard for a firm this size — LBMC does not shortcut the observation window, and readiness is explicitly optional rather than bundled by default.

Does LBMC assess HITRUST?

LBMC has been a HITRUST Authorized External Assessor since 2010 and markets itself as the longest-serving assessor in HITRUST’s “10-year club.” Tenure is the differentiator; confirm current assessor status on HITRUST’s list.

LBMC also states it participated in the work integrating CMS and NIST security standards into the HITRUST CSF itself, rather than simply testing against it.

LBMC’s HITRUST services span scoping and certification-type selection, readiness and gap assessment, initial and interim certification assessments, and bridge assessments for organizations extending a certification period. For healthcare organizations and their business associates that need both a SOC 2 report and a HITRUST certification, LBMC’s pitch is running both through one team rather than coordinating two separate assessors.

Is LBMC an ISO 27001 certification body?

LBMC performs ISO/IEC 27001:2022 (information security), 27701:2019 (privacy), and 9001:2015 (quality) certification audits directly, including the two-stage initial certification audit and the subsequent surveillance audits over the three-year certification cycle. LBMC’s own internal Certification Committee reviews audit results and approves or denies certification.

The firm’s marketing does not cite an ANAB or UKAS accreditation number for this certification-body function, so buyers who need certification from a specific national accreditation body should confirm that detail directly with LBMC before engaging.

Does LBMC do PCI DSS?

LBMC is a PCI Qualified Security Assessor (QSA) firm, supporting the full range of PCI work: Report on Compliance (ROC) and Attestation of Compliance (AOC) for Level 1 merchants and service providers, PCI gap analysis, quarterly ASV vulnerability scanning, and Self-Assessment Questionnaire (SAQ-D) support.

LBMC frames this as an “audit once, report many” approach — aligning PCI evidence with SOC 2 or other frameworks the client is already pursuing, which reduces duplicate evidence requests for clients running both engagements.

Does LBMC cover HIPAA?

LBMC performs HIPAA and HITECH security and privacy risk assessments for healthcare organizations and business associates, and can report the results through HITRUST or another certification framework alongside a SOC engagement.

For CMMC, LBMC provides readiness consulting, gap analysis against CMMC 2.0 requirements, and remediation support, guiding defense contractors through Level 1 self-assessment or Level 2+ formal assessment prep. LBMC’s public materials describe this readiness and advisory role clearly; they do not state that LBMC itself holds Certified Third-Party Assessor Organization (C3PAO) accreditation to issue the formal Level 2 certification. Buyers whose primary need is the formal CMMC certification assessment itself, rather than readiness, should confirm C3PAO status directly with LBMC.

LBMC also performs CSA STAR assessments (Level 1 self-assessment support and Level 2 third-party certification/attestation as an approved CSA-certified STAR auditor) and NIST 800-53/800-171 compliance assessments, drawing on more than 20 years in IT security and compliance work.

Does LBMC also sell penetration testing?

LBMC’s cybersecurity team offers penetration testing — network, web application, mobile application, cloud, wireless, and social engineering testing, plus its Advance Guard continuous-assessment retainer and LBMC Guard vulnerability-scanning service — explicitly positioned to complement PCI DSS and SOC audit work.

Worth understanding before scoping: when a SOC 2 engagement calls for an accompanying penetration test, having the same CPA firm perform both the test and the audit that relies on it creates a self-review consideration under AICPA independence rules — the pen test becomes part of the control environment the audit then evaluates. If you engage LBMC for SOC 2 attestation, raise the separation question up front rather than assuming the firm’s own pen test team should be bundled into the same engagement.

Which industries does LBMC actually serve?

LBMC’s cybersecurity and attestation clients concentrate in healthcare and claims processing, financial services, cloud service providers and SaaS/technology companies, data centers and hosting providers, private-equity portfolio companies, manufacturing, and real estate — a broader industry spread than a SOC-2-only boutique, consistent with LBMC’s position as a full-service regional firm rather than a niche specialist.

How much does an LBMC SOC 2 audit cost?

LBMC does not publish SOC 2 pricing. Directory estimates are $15,000–$45,000 Type I and $20,000–$60,000 Type II; those are ours, not LBMC’s quote.

Request a quote for a scoped number.

How long does an LBMC SOC 2 audit take?

LBMC’s own SOC audit page states report issuance 45–60 days after the observation period ends — that is the fieldwork-to-report window, not the whole engagement. A SOC 2 Type II additionally requires the client’s controls to operate over a 6–12 month observation period before that fieldwork can begin, per LBMC’s stated process.

A Type I, which has no observation period, moves faster: expect discovery, readiness (if used), and fieldwork to run on the order of several weeks rather than months. Total calendar time from kickoff to a Type II report, including the observation window, commonly lands in the 26–52 week range our base data reflects — the audit fieldwork itself is a small fraction of that.

Who is LBMC a good fit for?

Best fit for: - Healthcare, financial services, or PE-backed companies that need SOC 2 alongside HITRUST, ISO 27001, or PCI DSS handled by one accredited team - Organizations that value a firm with two decades of HITRUST tenure (Authorized External Assessor since 2010) for a HITRUST certification or bridge assessment - Mid-market and larger service organizations that want a single

regional firm covering audit, tax, and cybersecurity, not just SOC 2 in isolation - Companies that need PCI DSS ROC/AOC work coordinated with their SOC 2 evidence

Not a fit — look elsewhere if:

  • You are an early-stage startup that wants a 2–6 week Type I turnaround and boutique, founder-direct pricing; LBMC’s scale and multi-framework accreditation stack carry regional-firm overhead
  • Your immediate need is a formal CMMC Level 2 certification assessment; LBMC’s public materials describe readiness and gap-analysis support, not confirmed C3PAO accreditation to issue the certification itself
  • You need FedRAMP or StateRAMP authorization; it is not listed among LBMC’s cybersecurity service pages
  • You need same-firm penetration testing bundled into a SOC 2 engagement without an independence conversation first

When should a buyer shortlist LBMC?

LBMC’s SOC 2 practice is best understood through its HITRUST tenure: an Authorized External Assessor since 2010 and, by its own description, the longest-serving assessor in the program’s “10-year club,” backed by PCI QSA status and ISO 27001 audit capability under one roof.

That makes it a strong choice for healthcare, financial-services, or PE-backed organizations that need SOC 2 plus a second or third framework handled without switching firms. It is a licensed CPA firm with a recent, passed AICPA peer review (March 2026, covering mid-2024 through mid-2025). It is not the cheapest or fastest path to a first SOC 2 Type I — that’s a boutique specialist’s game — and buyers whose primary need is a formal CMMC or FedRAMP certification should confirm LBMC’s specific accreditation for that certification before engaging.

Compare

Which firms are closest to LBMC on Type II price and timeline?

Closest-priced peers in the full-service cpa organization group, by Type II range, timeline, and verified accreditations. Firm-reported certification totals are left out — they are not the same measure as the badges we verify.

LBMC 360 Advanced Sponsored Thoropass Sponsored Assurance Dimensions Carr, Riggs & Ingram (CRI) Forvis Mazars
Type II Cost $20K–$60K $15K–$80K $12K–$85K $20K–$60K $25K–$55K $25K–$55K
Type I Cost $15K–$45K $15K–$60K $8K–$15K $12K–$45K $15K–$30K $15K–$30K
Timeline 26–52 wk 3–12 wk2–6 wk8–16 wk4–10 wk5–12 wk
Team Size 50-150+ 51–200200–25060–751600–170035000–45000
Itemized Accreditations 4 98234
Licensed CPA issuer Yes YesYesYesYesYes
AICPA peer review Pass PassPassPassPassPass
Founded 1984 20042019200819972024

Sponsored alternatives are labeled in the table. How we make money

About

For buyers in Healthcare and claims processing and Financial services, LBMC fits the full-service cpa profile when its 26–52 weeks timeline and Type II pricing ($20K–$60K) align with the buyer's scope. Their 4 active accreditations, including HITRUST Assessor, PCI DSS QSA, ISO 27001 Lead Auditor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

What Makes LBMC Different?

An integrated 1,000-plus-person accounting and cybersecurity practice covering HITRUST, ISO 27001, PCI DSS, NIST, CMMC, and HIPAA.

Office Locations

Nashville (Brentwood), TN (HQ)Chattanooga, TNKnoxville, TNMemphis, TNLouisville, KYCharlotte, NCPhiladelphia, PAChennai, India (delivery team)
Public announcement evidence

Publicly announced work involving LBMC

These dated company announcements name the examining firm and describe the SOC 2 work to varying levels of detail. Compare only the stated scope with your proposed engagement.

  • CData Software

    CData Software named LBMC as the firm that performed its audit.

    Company / product context
    Data-access and connectivity software
    Report system / scope
    Exact report system not stated
    Role
    Examining firm · LBMC
    Report type
    SOC 2 Type II
    Report period
    Not stated in announcement

    The announcement refers to CData Software systems without naming the exact system examined.

    Company announcement · Published Oct 17, 2023 · Checked Sep 26, 2026 · Suggest a factual correction

These are historical company statements, not a current client or subscriber list, an endorsement, or a review of the underlying SOC 2 reports.

Compliance Frameworks Offered

SOC 1, SOC 2, SOC 3, SOC for Cybersecurity HITRUST CSF ISO/IEC 27001, 27701, 9001 PCI DSS (QSA) HIPAA / HITECH risk and privacy assessments NIST 800-53, NIST 800-171, NIST CSF CMMC readiness and gap assessment CSA STAR (Level 1 and Level 2) Penetration testing and vCISO advisory
Expertise

Match this firm to your industry, overlapping frameworks you need alongside SOC 2, and the GRC stack you already run.

Industries

8 industries. Full-service CPA average: 6.

Healthcare and claims processing Financial services Cloud service providers SaaS and technology companies Data centers and hosting providers Private equity portfolio companies Manufacturing and distribution Real estate
Certifications

4 accreditations. Full-service CPA average: 2.

AICPA HITRUST Assessor PCI DSS QSA ISO 27001 Lead Auditor
GRC platforms
Drata

Audit Platform

Proprietary

Verification

LBMC on the verification record

LBMC's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-09-03.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from LBMC

Tell us your scope. LBMC replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Preparing to interview auditors? Use our checklist of questions to ask any SOC 2 auditor.

Want to compare first? Browse All Auditors or get 3–10 quotes.

We send you 3–10 quotes from firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify LBMC's profile →