Logo Menu

Securance

Mid-tier Leiden, Netherlands, Netherlands
  • Issues SOC 2 reports — CPA licensing and AICPA peer review are US-specific

Source: soc2auditors.org/auditors/securance/ · compiled and maintained by soc2auditors.org.

Editorial profile, researched and maintained by this directory from public sources. Securance has not reviewed or verified this page. Work at Securance? Verify and correct it — free →

Type 1 cost
$20K–$60K est.
Type 2 cost
$30K–$80K est.
Timeline
4–14 weeks
Accreditations
5 listed

Securance is a mid-tier SOC 2 audit firm in Leiden, Netherlands, Netherlands that charges $30K–$80K for Type II audits with 4–14 week fieldwork-to-report timelines. Founded in 2004, they hold 5 accreditations and specialize in Financial Services, Technology, Professional Services, and 1 more. Their pricing is in the mid-range compared to the mid-tier average of $28.9K–$76.7K.

Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

How Much Does Securance Charge for SOC 2?

Estimated Type 1 and Type 2 ranges, placed against the broader mid-tier peer set. Numbers are directional; final pricing depends on scope, Trust Services Criteria, evidence quality, and observation period.

Type 1 cost
$20K–$60K
Type 2 cost
$30K–$80K
Timeline
4–14 wk
Team Size
30-60+
Report Delivery
Standard delivery
Response Time
Single point of contact model

Type 2 cost Pricing Position

$7K observed market span · est. $450K
Securance: $30K–$80K Mid-tier avg: $28.935K–$76.717K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 4–14 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.

How this directory works: we are an independent directory. Firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees, and payment never changes a firm's rating or who we match a buyer with. How we make money →

Pricing context
11%

of Mid-tier firms charge more for Type II.

Timeline context
72%

of Mid-tier firms have longer minimum timelines.

Certifications
5

listed certifications. Tier average: 2.

Compare

Compare Securance with Similar Mid-tier Firms

Side-by-side pricing, timeline, and certification counts for the closest-priced peers in the mid-tier tier.

Securance AAFCPAs Anders CPAs + Advisors Bennett Thrasher Dannible McKee FinAudit CPA
Type II Cost $30K–$80K $30K–$80K $30K–$80K $30K–$80K $30K–$80K $30K–$80K
Type I Cost $20K–$60K $20K–$60K $20K–$60K $20K–$60K $20K–$60K $20K–$60K
Timeline 4–14 wk 6–12 wk8–20 wk8–20 wk8–20 wk6–12 wk
Team Size 30-60+ 350–1000380–410480–510100–115100–1000
Certifications 5 31122
Founded 2004 19731965198019782010
About

Securance Industry Fit

For buyers in Financial Services and Technology, Securance fits the mid-tier profile when timeline (4–14 weeks) and Type II pricing ($30K–$80K) align with what mid-tier firms typically deliver. Their 5 active accreditations, including ISAE 3402, ISAE 3000, ISO 27001, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

Who Should Hire Securance?

European companies that need one engagement to cover ISAE 3402, SOC 1/2, ISO 27001, NIS2, and DORA — especially financial services and insurance, where the European standards are the ones the regulator asks for

What Makes Securance Different?

Dutch assurance practice covering the European reporting standards in one engagement (ISAE 3402, ISAE 3000, ISO 27001, NIS2, DORA) rather than a separate audit per framework. Describes its own SOC 2 as an ISAE 3000-based report issued from Europe; buyers whose US customers require an AICPA-attested SOC 2 signed by a licensed CPA firm should confirm the standard in writing first.

Fit check

Is Securance Right for You?

  • You're in financial services with regulatory audit requirements
  • You value an established firm with 22+ years of audit experience

About Securance

Securance is a Netherlands-headquartered assurance, advisory, and cybersecurity firm founded in 2004, with a team of roughly 30-60 professionals and offices in Leiderdorp and Utrecht (Netherlands), London, Berlin, and Uppsala. It serves financial services, technology, professional services, and insurance clients across Europe who need SOC-style attestation, ISAE reporting, or ISO 27001 certification support, often alongside penetration testing and GRC advisory from the same firm.

Securance markets a “Single Audit, Multiple Standards” model: one engagement mapped to cover SOC 1, SOC 2, ISAE 3402, ISO 27001, NIS2, and DORA requirements at once, reducing duplicate evidence requests for clients that need more than one framework. Named clients referenced in its published case studies include ABN AMRO Asset Management, Fujitsu, Axians, a.s.r. (ASR), and Planday.

How Securance Issues a “SOC 2” Report — Read This First

Securance describes itself on its own site as “Europe’s leading issuer” of SOC 2 reports and offers “a SOC 2 report from a European issuer.” A genuine AICPA SOC 2 attestation, by definition, must be issued by a CPA firm licensed and enrolled in the AICPA structure (including the AICPA Peer Review Program). Securance’s public materials do not name a specific U.S. or AICPA-licensed CPA entity behind its SOC 2 work, do not cite an AICPA Peer Review Program record, and describe the underlying methodology as built on ISAE 3402/ISAE 3000 (the European assurance standards) rather than U.S. attestation standards (SSAE 18/AT-C 105/205).

The practical read: Securance most likely delivers a European ISAE-based assurance report that maps to and is marketed under the SOC 2 label, not a literal AICPA-attested SOC 2 report signed by a licensed U.S. CPA firm. For most European buyers and their European counterparties this distinction may not matter — ISAE 3000 is a recognized, credible international standard. But a buyer selling into the U.S. market whose enterprise customers specifically require an AICPA SOC 2 report should confirm directly with Securance, in writing, exactly which standard the final report is issued under and whether a licensed CPA firm signs it, before assuming it will satisfy a U.S. vendor-security questionnaire.

Audit Quality and Credentials

Securance’s credibility case rests on its European assurance standards accreditations (ISAE 3402, ISAE 3000) and ISO 27001 certification work, plus a leadership team with Big Four backgrounds. The firm states its roots trace to one of the Big Four and that many team members previously worked there.

We found no independently verifiable AICPA Peer Review Program record for Securance (or a named affiliated CPA entity) on the AICPA’s public peer review file search — buyers who need that specific proof point should ask Securance directly for it rather than assume it exists. Izak van der Walt is listed on the team as a Chartered Accountant; the firm does not publish individual CPA license numbers or jurisdictions on its site.

SOC 2, SOC 1, and ISAE Practice

Securance runs a six-phase SOC 2 process: impact analysis/gap analysis, process and control interviews, a control framework built on COSO 2013, drafting the SOC 2 report, a pre-audit “walkthrough,” and a remediation phase before the final report is issued. It offers both Type I (point-in-time design opinion) and Type II (minimum six-month operating-effectiveness window) reports — note that six months is Securance’s stated minimum observation period, longer than the 3-month floor some U.S.-style engagements use.

SOC 1 is offered for organizations whose services affect a client’s financial reporting, alongside ISAE 3402 (the ISAE 3402 is functionally the ISAE alternative to SOC 1 that most European service organizations actually need). ISAE 3000 is used for broader non-financial assurance engagements, including sustainability and other subject matter beyond SOC scope.

ISO 27001, NIS2, and DORA

Securance is positioned to run ISO 27001 (and ISO 9001) certification-support work alongside its assurance practice, and offers NIS2 and DORA advisory services — gap analysis, incident-management design, and resilience testing — for EU financial institutions and critical-sector organizations navigating those directives. NIS2 and DORA work here is advisory and readiness-focused, not a certification or attestation in the way SOC 2 or ISO 27001 are; buyers should not expect a signed NIS2/DORA “report” in the same sense as a SOC 2 report.

Penetration Testing and Independence

Securance runs its own cybersecurity practice — network and application penetration testing, cloud security assessments, red teaming, ransomware vulnerability assessment, and phishing testing — as one of the three pillars it bundles under “Advisory, Assurance and Cyber Security under one roof.”

That bundling is exactly the case where independence needs a second look. If Securance’s assurance team is going to issue your SOC 2 or ISAE report, having that same firm’s cybersecurity team run your penetration test creates a self-review consideration: the auditor ends up forming an opinion on controls that its own colleagues tested and potentially remediated. The cleaner posture is to have the pen test performed by a different provider than whoever signs your assurance report — or, at minimum, to confirm with Securance in writing that the assurance and cybersecurity engagement teams (and sign-off) are kept structurally separate on your account before treating the “one-stop-shop” pitch as a single bundled service.

Frameworks Securance Does Not Cover

Securance is not positioned for HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work — none of these appear anywhere in its published service catalog. It is a European-assurance-and-cyber shop (SOC/ISAE/ISO/NIS2/DORA plus penetration testing), not a U.S. government-framework or payment-card specialist. Buyers who need any of those frameworks will need a separate firm.

Pricing

We were not able to find published pricing on Securance’s site — like most assurance firms, it quotes after a scoping call. Based on comparable European assurance engagements of this scope and size, our directional estimate is $20,000-$60,000 for a Type I report and $30,000-$80,000 for a Type II report. This is our estimate, not a number confirmed by Securance, and it will move with headcount, systems in scope, and how many standards are bundled into the single-audit engagement.

Timeline

Securance’s own SOC 2 phase description (impact analysis through pre-audit and redressing) plus its FAQ noting the readiness scan alone takes “several weeks” suggests a 4-14 week fieldwork-to-report window for a Type I, which is our directional estimate absent a published SLA. A Type II report additionally requires an observation period — Securance states a six-month minimum, longer than the 3-month floor some other markets use — before the report can be finalized, so buyers on a Type II track should plan total calendar time (observation window plus fieldwork) well beyond the fieldwork estimate alone.

Who Should Choose Securance

Best fit for:

  • European financial services, fintech, insurance, and technology companies that need SOC 1/SOC 2, ISAE 3402/3000, or ISO 27001 handled by one firm under a European (not U.S.-only) assurance framework
  • Companies that need NIS2 or DORA advisory work alongside their assurance engagement
  • Buyers comfortable with — or requiring — a European ISAE-based issuer rather than specifically a U.S. AICPA-licensed CPA firm
  • Organizations wanting penetration testing, red teaming, and assurance available from a single vendor (with independence properly scoped)

Not a fit — look elsewhere if:

  • You specifically need a U.S. AICPA-attested SOC 2 report signed by a licensed CPA firm with a documented AICPA Peer Review record, and your enterprise customer will check for that
  • You need HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work
  • You want penetration testing and your SOC 2 audit performed by fully separate, unaffiliated firms without having to raise the question yourself

Bottom Line

Securance is a Netherlands-founded (2004) assurance, advisory, and cybersecurity firm that bundles SOC 1/SOC 2, ISAE 3402/3000, ISO 27001, and NIS2/DORA advisory under one roof for European buyers, with named case-study clients including ABN AMRO Asset Management, Fujitsu, Axians, ASR, and Planday. The open question buyers should resolve before engaging is precisely how its “SOC 2” report is issued — as a European ISAE-based report marketed under the SOC 2 label, versus a report from a licensed AICPA CPA firm — since we found no AICPA Peer Review Program record or named CPA entity on its public materials. If your target customer is fine with a European-issued assurance report, Securance’s single-audit, multi-standard model is a genuine efficiency play; if your buyer specifically requires an AICPA-attested SOC 2, confirm that in writing before signing an engagement letter.

Office Locations

Leiderdorp, Netherlands (near Leiden)Utrecht, NetherlandsLondon, United KingdomBerlin, GermanyUppsala, Sweden

Compliance Frameworks Offered

SOC 2 (issued under ISAE-based methodology) SOC 1 ISAE 3402 ISAE 3000 ISO 27001 ISO 9001 NIS2 (advisory) DORA (advisory)
Expertise

Industries, certifications, and platforms.

Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.

What Industries Does Securance Serve?

4 industries. Mid-tier average: 6.

Financial Services Technology Professional Services Insurance

What Certifications Does Securance Hold?

5 certifications. Mid-tier average: 2.

ISAE 3402 ISAE 3000 ISO 27001 NIS2 DORA

Audit Platform

Proprietary

Buyer questions

Securance SOC 2 Audit FAQ

Firm-specific answers generated from the directory record and preserved in FAQPage schema.

How much does a SOC 2 audit from Securance cost?

Securance SOC 2 Type I audits typically range from $20K to $60K. Type II audits range from $30K to $80K. This is in the mid-range for mid-tier firms — the mid-tier tier average is $28.935K–$76.717K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.

How long does a SOC 2 audit take with Securance?

The 4–14 week range is Securance's audit execution and report-delivery window once evidence is available. It is the fieldwork-to-report window, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins, while a Type I is a point-in-time assessment with no observation period. Actual timelines depend on readiness, scope, and evidence availability.

What industries does Securance specialize in?

Securance has deep expertise in Financial Services, Technology, Professional Services, Insurance. They are best suited for European companies that need one engagement to cover ISAE 3402, SOC 1/2, ISO 27001, NIS2, and DORA — especially financial services and insurance, where the European standards are the ones the regulator asks for

What accreditations does Securance hold?

Securance holds 5 accreditations: ISAE 3402, ISAE 3000, ISO 27001, NIS2, DORA. This is above average for mid-tier firms, indicating broad certification capabilities.

What audit platform does Securance use?

Securance uses Proprietary for their audit engagements. Reports are delivered via Standard delivery.

Is Securance a good SOC 2 auditor?

Securance is a mid-tier SOC 2 audit firm founded in 2004 with 22 years of experience. Dutch assurance practice covering the European reporting standards in one engagement (ISAE 3402, ISAE 3000, ISO 27001, NIS2, DORA) rather than a separate audit per framework. Describes its own SOC 2 as an ISAE 3000-based report issued from Europe; buyers whose US customers require an AICPA-attested SOC 2 signed by a licensed CPA firm should confirm the standard in writing first. They are best suited for organizations that need financial services, technology, professional services expertise.

Where is Securance located?

Securance is headquartered in Leiden, Netherlands, Netherlands. They also have offices in Leiderdorp, Netherlands (near Leiden), Utrecht, Netherlands, London, United Kingdom, Berlin, Germany, Uppsala, Sweden. They serve clients across the Netherlands and can conduct SOC 2 audits remotely.

How does Securance compare to other mid-tier SOC 2 auditors?

Compared to the 46 mid-tier firms in our directory, Securance's SOC 2 Type II pricing ($30K–$80K) is in the mid-range (tier average: $28.935K–$76.717K). They hold 5 certifications vs. the tier average of 2. Their minimum timeline of 4 weeks is faster than the tier average.

Who should hire Securance for a SOC 2 audit?

Securance is best suited for European companies that need one engagement to cover ISAE 3402, SOC 1/2, ISO 27001, NIS2, and DORA — especially financial services and insurance, where the European standards are the ones the regulator asks for Their key differentiator is: Dutch assurance practice covering the European reporting standards in one engagement (ISAE 3402, ISAE 3000, ISO 27001, NIS2, DORA) rather than a separate audit per framework. Describes its own SOC 2 as an ISAE 3000-based report issued from Europe; buyers whose US customers require an AICPA-attested SOC 2 signed by a licensed CPA firm should confirm the standard in writing first.

Discovery call

Questions to Ask Securance Before Hiring

A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.

  1. Your team is sized at 30-60+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
  2. You quote 4–14 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
  3. Your Type 2 cost range is $30K–$80K. What's included at each end, and what scope changes would push pricing above the top of that range?
  4. We've talked to similar firms in the mid-tier tier. What's a question buyers like us should be asking that they usually don't?
  5. Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
  6. How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
  7. When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
  8. Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Verification

Securance on the verification record

Securance's verification record lists the facts and dates we last checked. It can be refreshed on the firm's request.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from Securance

Tell us your scope. Securance replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Want to compare first? See 46 similar mid-tier firms or get 3 quotes.

We send you 3 to 5 firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Securance's profile →