Logo Menu

Thoropass

Specialist Verified New York, NY, USA
Type 1 cost
$8K–$15K
Type 2 cost
$12K–$30K
Timeline
2–6 weeks
Accreditations
8 listed

Thoropass is a specialist SOC 2 audit firm in New York, NY, USA that charges $12K–$30K for Type II audits with 2–6 week timelines. Founded in 2019, they hold 8 accreditations and specialize in B2B SaaS, FinTech, HealthTech, and 2 more. Their pricing is below average compared to the specialist average of $21K–$61.9K.

Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

How Much Does Thoropass Charge for SOC 2?

Estimated Type 1 and Type 2 ranges, placed against the broader specialist peer set. Numbers are directional; final pricing depends on scope, Trust Services Criteria, evidence quality, and observation period.

Type I Cost
$8K–$15K
Type II Cost
$12K–$30K
Timeline
2–6 wk
Team Size
200-250
Report Delivery
Weeks, not quarters (62% faster than traditional process)
Response Time
In-platform same-day collaboration with dedicated auditor

Type II Pricing Position

$7K $450K
Thoropass: $12K–$30K Specialist avg: $21.025K–$61.882K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Pricing context
94%

of Specialist firms charge more for Type II.

Timeline context
85%

of Specialist firms have longer minimum timelines.

Certifications
8

listed certifications. Tier average: 4.

Compare

Compare Thoropass with Similar Specialist Firms

Side-by-side pricing, timeline, and certification counts for the 5 closest-priced peers in the specialist tier.

Thoropass Tempo Audits Johanson Group Modern Assurance MJD Advisors CyberSapiens Germany
Type II Cost $12K–$30K $10K–$30K$15K–$30K$7K–$42K$15K–$35K$15K–$36K
Type I Cost $8K–$15K $8K–$20K$10K–$18K$5K–$24K$8K–$20K$10K–$20K
Timeline 2–6 wk 2–6 wk1–3 wk1–7 wk2–6 wk3–7 wk
Team Size 200-250 5–1512–202–105–1020–30
Certifications 8 14322
Founded 2019 20222014202220212019
About

Thoropass Industry Fit

For buyers in B2B SaaS and FinTech, Thoropass fits the specialist profile when timeline (2–6 weeks) and Type II pricing ($12K–$30K) align with what specialist firms typically deliver. Their 8 active accreditations, including PCI DSS QSA, PCI ASV, HITRUST Assessor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

Who Should Hire Thoropass?

First-time SOC 2 / ISO 27001 / HIPAA / PCI / HITRUST seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit, eliminating the handoff between Vanta/Drata-style automation and a separate CPA firm. Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle. Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing.

What Makes Thoropass Different?

Bundles a proprietary GRC platform with an in-house CPA firm, PCI QSAC and ASV, and HITRUST Authorized External Assessor under one roof. Same auditor from Day 1 through report issuance, no handoff between readiness vendor and audit firm. First Pass and Smart Sort AI pre-screen evidence before audit, cutting manual overhead up to 80% and completing audits up to 62% faster. 30+ frameworks on a single shared evidence set, plus a standalone audit module that works alongside Vanta, Drata, Secureframe, Hyperproof, Archer, and OneTrust. Active healthcare practice (Array Behavioral Care, Alaffia Health, HealthSnap) covering HITRUST + SOC 2 coordinated audits in PHI-sensitive environments.

Fit check

Is Thoropass Right for You?

  • You need an affordable first SOC 2 audit (starting from $12K)
  • You're on a tight deadline — they can start and deliver in as few as 2 weeks
  • You need HITRUST + SOC 2 bundled in a single engagement
  • You handle payment data and need PCI DSS + SOC 2 together
  • You're a SaaS company going through SOC 2 for the first time
  • You already use Thoropass (proprietary) and want an auditor who integrates with it

About Thoropass

Thoropass is the end-to-end cybersecurity auditor for modern compliance teams. It combines accredited auditors, AI-powered evidence automation, and a modern audit operating model to deliver faster, more transparent audits without handoffs, rework, or last-minute surprises. The company owns both ends of the SOC 2 problem: the GRC platform you use to prepare for the audit, AND the licensed CPA firm that signs the audit report. Most of the market splits these roles (Vanta, Drata, and Secureframe handle automation and refer you to a separate auditor like Schellman or A-LIGN). Thoropass collapses that handoff.

Thoropass supports 30+ frameworks (SOC 2, HITRUST, HIPAA, PCI DSS, ISO 27001/27018/42001, NIST CSF 2.0, CMMC L1, GDPR, 23 NYCRR 500, and more) and helps organizations consolidate audits into coordinated, scalable programs. With 200+ integrations and AI-powered evidence workflows, customers reduce manual audit overhead by up to 80% and complete audits up to 62% faster.

Founded in 2019 and rebranded from Laika in March 2023, Thoropass is headquartered in New York with an EMEA hub in London (opened November 2024). The firm has raised $98M across four rounds: Series A ($10M, Sept 2020, led by Canapi), Series B ($35M, led by J.P. Morgan Growth Equity Partners), and Series C ($50M, Nov 2022, led by Fin Capital with Centana Growth, J.P. Morgan, Canapi, and ThirdPrime participating). It now serves 1,000+ organizations, completes 500+ audits annually, and was named to the Inc. 5000 for a second consecutive year in 2025 with 351% three-year growth.

Audit team and credentials

  • AICPA peer-reviewed CPA firm (Laika Compliance, LLC dba Thoropass Assurance), with a “Pass” rating for the second consecutive cycle in December 2025, the highest available
  • HITRUST Authorized External Assessor, first automated compliance vendor to earn assessor status, plus MyCSF Authorized Reseller
  • PCI QSAC and ASV (Qualified Security Assessor Company and Approved Scanning Vendor)
  • Experienced audit and assurance professionals from leading audit firms
  • Embedded auditors throughout the audit lifecycle, from scoping through final report delivery, rather than handed off between roles

The Platform + Audit Bundle

This is the core of Thoropass’s positioning. Three things follow from owning both sides:

Same auditor from Day 1 to the stamp. No transition meeting from your readiness vendor to a separate audit firm. The auditor who scopes your environment is the same one signing the report, and they stay embedded across scoping, fieldwork, and delivery.

First Pass and Smart Sort AI pre-screen evidence. First Pass (Dec 2024) programmatically checks evidence completeness and accuracy before it reaches the auditor. Smart Sort (Jan 2026) ingests any GRC export and converts it into audit-ready evidence. The two work alongside human auditors to programmatically verify evidence before you ever get to audit. Thoropass reports this cuts secondary auditor requests up to 80% and reduces manual QA time by 95%.

Shared evidence across frameworks. SOC 2, ISO 27001, PCI DSS, and HITRUST use the same control set with one collection cycle. For companies pursuing two or more frameworks, this eliminates redundant evidence work and underpins the 62% faster audit cycle vs. traditional process.

The platform also supports companies who don’t want to switch GRC tools. Since 2025, the audit module is available standalone for customers already on Vanta, Drata, Secureframe, Hyperproof, Archer, or OneTrust. The “our GRC or yours” model lets buyers preserve existing investments while still consolidating audit execution.

Platform Capabilities (2025-2026 builds)

  • First Pass AI (Dec 2024), automated evidence pre-screening
  • Smart Sort AI (Jan 2026), turns any GRC export into audit-ready evidence; lets customers keep their existing GRC tool with no integration required
  • Head Start for Access Reviews (Jan 2025), reuses prior review data, cuts review work by ~95%
  • GenAI Security Questionnaire Automation, answers due-diligence questionnaires
  • Multi-Product Workspace, manage multiple products/divisions with auto-mapped controls
  • Trust Center (Sept 2025), public-facing compliance posture portal
  • Risk Register and Risk Assessment
  • Penetration Testing built into the platform
  • 200+ auditor-approved integrations spanning AWS, Azure, GCP, Snowflake, GitHub, Jira, Okta, Slack, M365, and more

The Independence Question

The AICPA issued a Peer Reviewer Alert in December 2022 about self-review threats when compliance automation platforms also have audit affiliates. Thoropass has addressed this publicly: evidence flows through standardized APIs reviewed and approved by auditors before deployment, and the licensed CPA firm operates under AICPA Code of Professional Conduct standards. They’ve now passed two AICPA peer reviews with the “Pass” rating, the highest available.

This matters because the rest of the market sometimes raises independence concerns about platform-plus-audit firms. Two peer review passes (2022 and 2025) is the strongest counter-evidence available.

Compliance Frameworks

Direct audits Thoropass conducts:

  • SOC 1 (SSAE 18 financial controls)
  • SOC 2 Type I and Type II
  • SOC 3
  • HITRUST (i1 and r2 Validated Assessment & Certification, plus MyCSF authorized reseller)
  • PCI DSS (RoC, AoC, SAQ via QSAC accreditation)
  • HIPAA / HITECH assessments

Frameworks supported via platform + partner CB:

  • ISO 27001, ISO 27018, ISO 42001
  • CMMC Level 1, NIST CSF 2.0, NIST 800-53
  • GDPR, CCPA, 23 NYCRR 500 (NYDFS Cybersecurity Requirements)

Thoropass markets coverage across 30+ frameworks total with control-mapping that lets a single evidence set satisfy several reports.

Worth noting what’s missing: no FedRAMP capability, no StateRAMP, no CMMC Level 2 C3PAO status. Companies targeting federal authorizations will need a 3PAO partner.

Does Thoropass Do HIPAA and Healthcare Audits?

Yes. Thoropass runs an active healthcare practice focused on digital health, healthcare SaaS, and PHI-sensitive environments, with HIPAA / HITECH assessments delivered in-house and HITRUST i1 and r2 Validated Assessment & Certification offered under its HITRUST Authorized External Assessor status. For most healthcare buyers the typical engagement is a coordinated HITRUST + SOC 2 audit on a single shared evidence set, which avoids duplicating control work and shortens the overall cycle.

The healthcare positioning is backed by published customer stories rather than logos alone:

  • Array Behavioral Care, a virtual behavioral health provider, on moving “beyond automation” to a true audit partner
  • Alaffia Health, an AI-driven healthcare payments company, on responsible innovation in a regulated environment
  • HealthSnap, a chronic-care management platform, on running compliance through ongoing growth

Where Thoropass tends to fit best in healthcare

  • Healthcare SaaS and digital health organizations scaling beyond their first audit
  • HITRUST + SOC 2 coordinated audits where a single evidence cycle covers both reports
  • PHI-sensitive environments that need scalable audit operations rather than one-off engagements
  • Mid-market healthcare companies managing ongoing compliance maturity across multiple frameworks (HIPAA, HITRUST, SOC 2, sometimes PCI DSS for payments)

For broader market context on this segment, see our directory of SOC 2 auditors for healthcare.

Leadership

Sam Li, Co-Founder & CEO. UVA Computer Science, Harvard MBA. Previously co-founder and CTO of Zinc Platform (YC-backed insurtech), with stints at Google, Goldman Sachs, and Cambridge Associates. Named a 2026 EY Entrepreneur Of The Year New York finalist.

Eva Pittas, Co-Founder, President & COO. Spent 20+ years at Citigroup as Managing Director of IT Risk & Control and Vendor Management for the Institutional Clients Group. Founded BRCG, a boutique fintech compliance consultancy, before Laika/Thoropass. NYU Stern.

Austin Ogilvie, Co-Founder & Executive Chairman. Background in data science and ML, previously at Alteryx.

Dicken Chaplin, CFO. Joined December 2022. Previously CFO at Turbonomic, where he grew revenue from $20M to $200M+, leading to a $2B acquisition by IBM.

Leith Khanafseh, Managing Partner, Assurance & Compliance Products. Previously led infosec audits at Coalfire for major cloud service providers, plus Big 4 experience.

Chris Biero, Senior Director, Head of SOC. 10+ years in GRC across startups and Fortune 500 firms.

Pricing

Thoropass does not publish a rate card, but their own SOC 2 cost guide publishes the following audit-fee ranges for companies between 5 and 100 employees:

  • SOC 2 Type I audit: $12,000 to $27,000
  • SOC 2 Type II audit: $15,000 to $100,000+
  • Stated savings vs. traditional audit firms: 25 to 50%
  • Marketing claim: “Zero cost overruns with fixed pricing”

For larger mid-market and enterprise engagements (50 to 200+ employees, multi-framework programs), Vendr buyer data places typical annual contract value around $30,728 median (range $20,930 to $53,273), with small companies at $20K to $40K/year and mid-sized at $40K to $90K/year for the platform subscription, plus separate auditor fees. The platform-plus-audit bundle is the most common engagement, but the audit module is also sold standalone for companies already on Vanta, Drata, Secureframe, Hyperproof, Archer, or OneTrust.

Timeline

Per Thoropass’s own SOC 2 cost guide, SOC 2 Type 1 audits take 2 to 3 months and SOC 2 Type 2 audits take 3 to 9 months (for companies between 5 and 100 employees). Larger or multi-framework engagements can extend beyond this. Thoropass markets “SOC 2 in weeks, not quarters” and reports a 62% faster time to audit completion vs. traditional process; published customer outcomes for audit-ready teams show what the fast end looks like in practice:

  • Benefix: SOC 2 Type I and Type II within 8 days post-kickoff
  • Cinchy: ISO 27001 in 4 weeks, SOC 2 in 2 weeks
  • Capitalize: up and running in 2 weeks, audit “in a fraction of the time”
  • Stylo: SOC 2 Type 1 from scratch in roughly 2 to 3 months

These are best-case outcomes. Teams starting from zero on policies, evidence collection, or first-time framework scoping should plan toward the longer end of the published range. The firm reports 80%+ of technical control evidence is auto-collected via integrations, and the First Pass AI layer reduces audit overhead by ~80%.

Client Base & Testimonials

Named customers include:

  • Nord Security (consumer cybersecurity / NordVPN)
  • Mailgun (email API)
  • SEMrush (SEO platform)
  • Sinch (CPaaS / messaging)
  • OpenVPN (VPN infrastructure)
  • Berkshire Grey (warehouse robotics)
  • Jellyfish (engineering management)
  • Moov (payments infrastructure)
  • Forage (EBT/SNAP payments)
  • AcuityMD (medical device sales platform)
  • Array Behavioral Care (virtual behavioral health, published HIPAA / SOC 2 case study)
  • Alaffia Health (AI-driven healthcare payments, published case study)
  • HealthSnap (chronic-care management, published case study)
  • Benefix, Cinchy, Capitalize, Stylo, Wayleadr, dealcloser, Kado, Fundraise Up, Bytescale, Glean.ai

G2 rating: 4.7/5 across 435+ reviews, with 74.7% in the Small-Business segment.

Critical feedback from G2 reviews surfaces a recurring set of complaints: UI can be clunky, limited bulk-edit options, occasional integration breakage, and slower performance at scale. Buyers weighing Thoropass should pressure-test the workflow against their specific cloud stack before committing.

Who Should Choose Thoropass

Best fit:

  • First-time SOC 2 / ISO 27001 / HIPAA / PCI seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit
  • Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle
  • Healthcare SaaS and digital health teams handling PHI that need HITRUST + SOC 2 coordinated audits and ongoing HIPAA assessment maturity
  • Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing
  • Teams already on Vanta, Drata, Secureframe, Hyperproof, Archer, or OneTrust who want to keep their GRC tool but consolidate audit execution under one accredited auditor
  • Teams with limited compliance resources that benefit from the auditor-built scoping roadmap and policy templates

Not ideal for:

  • Public companies or IPO candidates that need Big-4 brand on the audit report
  • Companies pursuing FedRAMP, StateRAMP, or CMMC Level 2 (Thoropass does not have these capabilities)
  • Enterprises with deep GRC customization needs at scale (platform feature set is narrower than Vanta or Drata)
  • Buyers who want fully transparent published pricing before scoping

Recent Milestones

  • Jan 2026: Smart Sort AI launches, lets customers turn any GRC export into audit-ready evidence with no integration required
  • Dec 2025: Thoropass Assurance earns AICPA Peer Review “Pass” rating for the second time
  • Sept 2025: Trust Center launches as a public-facing compliance posture product
  • Sept 2025: Named to Inc. 5000 for second consecutive year (351% three-year growth, ranked #1,246)
  • 2025: Audit module made available standalone for non-Thoropass GRC users
  • Dec 2024: First Pass AI announced (AI-driven evidence pre-screening, opt-in preview)
  • Nov 2024: London office opens as EMEA expansion hub
  • Oct 2024: First infosec compliance vendor to earn ISO 42001 certification
  • Sept 2024: Expanded HITRUST partnership as MyCSF Authorized Reseller; launched ISO 42001, NIST CSF 2.0, 23 NYCRR 500 support
  • March 2023: Rebranded from Laika to Thoropass
  • Nov 2022: Series C of $50M led by Fin Capital
  • Sept 2020: Series A of $10M led by Canapi

Bottom Line

Thoropass occupies a category of one in the SOC 2 market: the only company that ships a GRC platform AND signs the audit report. For first-time buyers pursuing multiple frameworks who value speed and fixed pricing over brand prestige, the bundle is compelling and the AICPA Peer Review track record answers the obvious independence question.

Where it gets tighter: if you already love your current GRC tool, the standalone audit module is a viable path, but you lose the workflow advantages that justify the bundle. If your buyers demand a Big-4 brand on the audit report, Thoropass is the wrong choice. And if you’re heading toward FedRAMP or CMMC Level 2 in the next 12-18 months, you’ll need a different partner anyway.

For early-to-mid-stage SaaS, fintech, and healthtech with one vendor needed, fast turnaround required, and predictable fixed pricing preferred, Thoropass is one of the most differentiated options in the specialist auditor market.

Office Locations

New York, NY (HQ)London, UK (EMEA hub)

Compliance Frameworks Offered

SOC 1 (SSAE 18) SOC 2 Type I & Type II SOC 3 HITRUST CSF (i1, r2 Validated Assessment & Certification) PCI DSS (Report on Compliance, AoC, SAQ) ISO 27001 ISO 27018 ISO 42001 (AI Management Systems) HIPAA / HITECH GDPR, CCPA NIST CSF 2.0, NIST 800-53 CMMC Level 1, 23 NYCRR 500

Platform Integrations

Thoropass Audit Lifecycle Platform (proprietary) AWS, Azure, Google Cloud, Snowflake, Digital Ocean, Heroku GitHub, GitLab, Jira, BitBucket Slack, Microsoft 365, Google Workspace, Okta Works alongside Vanta, Drata, Secureframe, Hyperproof, Archer, OneTrust 200+ auditor-approved integrations total

Client Testimonials

"Some of the best money I ever spent. Thoropass and being compliant ended up helping us close our second-largest customer."

Veronica Lim
CFO
Benefix

"Thoropass combines readiness, evidence management, and auditor interaction in a single platform. The ability to collaborate with the auditor directly in-platform reduces friction and prevents duplicative work."

Roark
Head of GRC

"For the past month, we've told our customers we're in the process of getting our SOC 2 and ISO 27001. Having the reports in our hands alleviates any concern from our customers."

Saskia
Cinchy

"With no prior knowledge, Thoropass laid out an easy-to-understand road map. Setting attainable goals with reasonable timetable made the process extremely easy with multiple team members."

Adam S.
VP of Operations
Expertise

Industries, certifications, and platforms.

Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.

What Industries Does Thoropass Serve?

5 industries. Specialist average: 6.

B2B SaaS FinTech HealthTech Insurtech Professional Services

What Certifications Does Thoropass Hold?

8 certifications. Specialist average: 4.

AICPA CPA Firm AICPA Peer Review PCI DSS QSA PCI ASV HITRUST Assessor ISO 27001 Certification Body ISO 42001

What Platforms Does Thoropass Integrate With?

Thoropass (proprietary)

Audit Platform

Thoropass Audit Lifecycle Platform (First Pass AI, Smart Sort AI, Trust Center, Access Review Automation, 200+ integrations)

Buyer questions

Thoropass SOC 2 Audit FAQ

Firm-specific answers generated from the directory record and preserved in FAQPage schema.

How much does a SOC 2 audit from Thoropass cost?

Thoropass SOC 2 Type I audits typically range from $8K to $15K. Type II audits range from $12K to $30K. This is below average for specialist firms — the specialist tier average is $21.025K–$61.882K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.

How long does a SOC 2 audit take with Thoropass?

A typical SOC 2 engagement with Thoropass takes 2 to 6 weeks from start to report delivery. They offer accelerated timelines for organizations that are audit-ready.

What industries does Thoropass specialize in?

Thoropass has deep expertise in B2B SaaS, FinTech, HealthTech, Insurtech, Professional Services. They are best suited for First-time SOC 2 / ISO 27001 / HIPAA / PCI / HITRUST seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit, eliminating the handoff between Vanta/Drata-style automation and a separate CPA firm. Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle. Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing.

What accreditations does Thoropass hold?

Thoropass holds 8 accreditations: AICPA, CPA Firm, AICPA Peer Review, PCI DSS QSA, PCI ASV, HITRUST Assessor, ISO 27001 Certification Body, ISO 42001. This is above average for specialist firms, indicating broad certification capabilities.

What audit platform does Thoropass use?

Thoropass uses Thoropass Audit Lifecycle Platform (First Pass AI, Smart Sort AI, Trust Center, Access Review Automation, 200+ integrations) for their audit engagements. They integrate with Thoropass (proprietary) for evidence collection and compliance automation. Reports are delivered via Weeks, not quarters (62% faster than traditional process).

Is Thoropass a good SOC 2 auditor?

Thoropass is a specialist SOC 2 audit firm founded in 2019 with 7 years of experience. Bundles a proprietary GRC platform with an in-house CPA firm, PCI QSAC and ASV, and HITRUST Authorized External Assessor under one roof. Same auditor from Day 1 through report issuance, no handoff between readiness vendor and audit firm. First Pass and Smart Sort AI pre-screen evidence before audit, cutting manual overhead up to 80% and completing audits up to 62% faster. 30+ frameworks on a single shared evidence set, plus a standalone audit module that works alongside Vanta, Drata, Secureframe, Hyperproof, Archer, and OneTrust. Active healthcare practice (Array Behavioral Care, Alaffia Health, HealthSnap) covering HITRUST + SOC 2 coordinated audits in PHI-sensitive environments. They are best suited for organizations that need b2b saas, fintech, healthtech expertise.

Where is Thoropass located?

Thoropass is headquartered in New York, NY, USA. They also have offices in New York, NY (HQ), London, UK (EMEA hub). They serve clients across the United States and can conduct SOC 2 audits remotely.

How does Thoropass compare to other specialist SOC 2 auditors?

Compared to the 65 specialist firms in our directory, Thoropass's Type II pricing ($12K–$30K) is below average (tier average: $21.025K–$61.882K). They hold 8 certifications vs. the tier average of 4. Their minimum timeline of 2 weeks is faster than the tier average.

Who should hire Thoropass for a SOC 2 audit?

Thoropass is best suited for First-time SOC 2 / ISO 27001 / HIPAA / PCI / HITRUST seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit, eliminating the handoff between Vanta/Drata-style automation and a separate CPA firm. Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle. Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing. Their key differentiator is: Bundles a proprietary GRC platform with an in-house CPA firm, PCI QSAC and ASV, and HITRUST Authorized External Assessor under one roof. Same auditor from Day 1 through report issuance, no handoff between readiness vendor and audit firm. First Pass and Smart Sort AI pre-screen evidence before audit, cutting manual overhead up to 80% and completing audits up to 62% faster. 30+ frameworks on a single shared evidence set, plus a standalone audit module that works alongside Vanta, Drata, Secureframe, Hyperproof, Archer, and OneTrust. Active healthcare practice (Array Behavioral Care, Alaffia Health, HealthSnap) covering HITRUST + SOC 2 coordinated audits in PHI-sensitive environments.

Discovery call

Questions to Ask Thoropass Before Hiring

A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.

  1. Your team is sized at 200-250. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
  2. You quote 2–6 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
  3. Your Type II range is $12K–$30K. What's included at each end, and what scope changes would push pricing above the top of that range?
  4. You integrate with Thoropass (proprietary). If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
  5. Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
  6. How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
  7. When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
  8. Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Quote

Get a quote from Thoropass

Tell us your scope. Thoropass replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Want to compare first? See 65 similar specialist firms or get 3 quotes.

We email you the quotes. Auditors don't see your details until you pick.

Add more detail readiness, scope, platform

No sales calls until you pick a firm.

Read by a human. Three quotes in 48 hours.