SOC 2 + HIPAA Overlay Engagements: How They Work
HIPAA mapping in a SOC 2 engagement: evidence-file boundaries, bridge-letter cadence, and how auditors structure a combined SOC 2 + HIPAA report.
RSM US is a mid-tier SOC 2 audit firm in Chicago, IL, USA that charges $30K–$120K for Type II audits with 5–14 month timelines. Founded in 1926, they hold 3 accreditations and specialize in Technology, Financial Services, Healthcare, and 1 more. Their pricing is above average compared to the mid-tier average of $28.5K–$75.2K.
Free. Anonymous until you pick.
Estimated Type 1 and Type 2 ranges, placed against the broader mid-tier peer set. Numbers are directional; final pricing depends on scope, Trust Services Criteria, evidence quality, and observation period.
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
of Mid-tier firms charge more for Type II.
of Mid-tier firms have longer minimum timelines.
listed certifications. Tier average: 3.
Side-by-side pricing, timeline, and certification counts for the 5 closest-priced peers in the mid-tier tier.
| RSM US | Grant Thornton | BDO USA | Crowe LLP | Baker Tilly | AAFCPAs | |
|---|---|---|---|---|---|---|
| Type II Cost | $30K–$120K | $32K–$115K | $30K–$110K | $40K–$100K | $28K–$100K | $30K–$80K |
| Type I Cost | $20K–$60K | $22K–$65K | $20K–$62K | $25K–$50K | $18K–$55K | $20K–$60K |
| Timeline | 5–14 mo | 5–14 mo | 5–13 mo | 4–9 mo | 4–12 mo | 6–12 mo |
| Team Size | 16000-18000 | 8000–10000 | 11000–13000 | 5400–6000 | 3500–5000 | 350–1000 |
| Certifications | 3 | 3 | 3 | 3 | 3 | 3 |
| Founded | 1926 | 1924 | 1910 | 1942 | 1931 | 1973 |
For buyers in Technology and Financial Services, RSM US fits the mid-tier profile when timeline (5–14 months) and Type II pricing ($30K–$120K) align with what mid-tier firms typically deliver. Their 3 active accreditations, including Middle Market Leader, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Middle-market companies ($50M-$500M revenue) seeking Big Four quality at lower cost
Largest non-Big Four firm with middle market specialization
of 5 criteria match. Get a personalized quote
Visit RSM US's website directly, or get an anonymous quote through us. Tell us your scope, RSM US replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.
4 industries. Mid-tier average: 5.
3 certifications. Mid-tier average: 3.
RSM Portal
Firm-specific answers generated from the directory record and preserved in FAQPage schema.
RSM US SOC 2 Type I audits typically range from $20K to $60K. Type II audits range from $30K to $120K. This is above average for mid-tier firms — the mid-tier tier average is $28.487K–$75.231K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.
A typical SOC 2 engagement with RSM US takes 5 to 14 months from start to report delivery.
RSM US has deep expertise in Technology, Financial Services, Healthcare, Manufacturing. They are best suited for Middle-market companies ($50M-$500M revenue) seeking Big Four quality at lower cost
RSM US holds 3 accreditations: AICPA, CPA Firm, Middle Market Leader.
RSM US uses RSM Portal for their audit engagements. Reports are delivered via 5-7 weeks.
RSM US is a mid-tier SOC 2 audit firm founded in 1926 with 100 years of experience. Largest non-Big Four firm with middle market specialization They are best suited for organizations that need technology, financial services, healthcare expertise.
RSM US is headquartered in Chicago, IL, USA. They serve clients across the United States and can conduct SOC 2 audits remotely.
Compared to the 39 mid-tier firms in our directory, RSM US's Type II pricing ($30K–$120K) is above average (tier average: $28.487K–$75.231K). They hold 3 certifications vs. the tier average of 3. Their minimum timeline of 5 months is comparable to the tier average.
RSM US is best suited for Middle-market companies ($50M-$500M revenue) seeking Big Four quality at lower cost Their key differentiator is: Largest non-Big Four firm with middle market specialization
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
Tell us your scope. RSM US replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? See 39 similar mid-tier firms or get 3 quotes.
HIPAA mapping in a SOC 2 engagement: evidence-file boundaries, bridge-letter cadence, and how auditors structure a combined SOC 2 + HIPAA report.
A complete 2026 guide to SOC 2 for healthcare companies. Learn how SOC 2 maps to HIPAA, prioritize Trust Services Criteria, and prepare for your audit.
The best SOC 2 compliance software for healthcare in 2026. HIPAA + SOC 2 dual coverage, BAA availability, and honest pricing for digital health companies.