Logo Menu

PCI DSS QSA Firms That Also Issue SOC 2: 28 firms compared

28 attestation-capable firm records match this combined-scope filter. Compare their relevant framework credentials, then confirm which work, evidence, entities, and schedules can actually be coordinated.

Browse 28 firms ↓

Reviewed by Peter Korpak / Last updated / Combined scope

Matching firms
28attestation-capable
Estimated Type 2 span
$10K-$150K
Fastest listed fieldwork-to-report
2 wk

Can a PCI QSA also do my SOC 2 audit?

QSA qualification covers PCI DSS validation, not SOC 2 signing. Dual delivery exists only when a CPA practice in the same group will issue the report. Verify current QSA status and the CPA signer, because the two deliverables may use different teams or entities.

A Qualified Security Assessor company performs PCI DSS assessments. The SOC 2 signer is a licensed CPA firm, not the Council-qualified QSA team, even when both sit in one company.

The PCI Security Standards Council’s registry is the source to verify before you sign. Confirm current status, region, personnel availability, CPA signer, and contracting entities. Listed timelines and prices cover SOC 2 planning only; PCI DSS work is scoped separately.

Use-case picks

Which QSA-and-SOC-2 firm fits which use case?

Compare PCI DSS QSA use-case picks with all 28 matching firms. Timelines cover fieldwork through the final report, excluding the Type 2 observation period.

PCI + SOC 2 Thoropass

Best PCI QSA that also does SOC 2 for fintech startups

Thoropass lists PCI DSS QSA and PCI ASV, making it a candidate for scanning plus a ROC alongside SOC 2. SOC 2 starts at $9,995 for Type 1 + Type 2; PCI starts at $14,995.

Financial services Schellman

Best established QSA and SOC 2 firm

Schellman lists PCI DSS QSA and a financial-services focus, making it a candidate for payment companies that also need a CPA-signed SOC 2. The Type 2 floor does not price the ROC.

All firms

Which listed QSAs also sign commercial SOC 2 reports?

Compare each firm's SOC 2 fee estimate, fieldwork-to-report timeline, and credentials relevant to this combined scope.

360 Advanced

ST. PETERSBURG, FL · USA
Verified record
Type 1
$15K-$60K
Type 2
$15K-$80K
Fieldwork to report
3–12 wk
Best fit
Mid-market and enterprise teams that want a U.S.-based team coordinating SOC 2 with other frameworks.
Distinctive strength
Coordinates shared evidence across frameworks, including an ANAB-accredited ISO 27001 certification body and a FedRAMP-listed 3PAO.
AICPAPCAOBCyberAB Enterprise IT OutsourcingManaged SecurityHealthcare Claims Management

Thoropass

NEW YORK, NY · USA
Verified record
Type 1
From $9,995 Type 1 + Type 2
Type 2
From $9,995 Type 1 + Type 2
Fieldwork to report
2–6 wk
Best fit
Established startups and SMBs seeking an auditor-led, multi-framework engagement without replacing their existing GRC platform.
Distinctive strength
Its assurance team and audit technology coordinate SOC 2, ISO 27001, HIPAA, PCI DSS, and HITRUST from a shared evidence set.
AICPACPA FirmAICPA Peer Review B2B SaaSFinTechHealthTech

Prescient Security

NASHVILLE, TN · USA
Verified record
Type 1
$5K-$35K
Type 2
$10K-$30K
Fieldwork to report
2–6 wk
Best fit
Growth-stage SaaS, AI, fintech, healthtech, and government teams combining SOC 2 with another framework.
Distinctive strength
Its licensed Prescient Assurance division combines SOC attestation with FedRAMP, CMMC, HITRUST, PCI, and ISO certification credentials.
AICPACPA FirmCREST B2B SaaSFinTechHealthTech

KirkpatrickPrice

NASHVILLE, TN · USA
Verified record
Type 1
$8K-$15K
Type 2
$12K-$45K
Fieldwork to report
3–8 wk
Best fit
Small and mid-sized MSP, technology, and healthcare teams seeking a long-term audit relationship.
Distinctive strength
Combines PCAOB registration, PCI and HITRUST assessor credentials, and experience serving more than 2,000 clients.
AICPACPA FirmPCAOB SaaSManaged Services/MSPsFinTech

A-LIGN

TAMPA, FL · USA
Verified record
Type 1
$10K-$20K
Type 2
$15K-$50K
Fieldwork to report
3–12 wk
Best fit
Mid-market and enterprise teams consolidating SOC 2, ISO 27001, HITRUST, FedRAMP, or PCI work with one provider.
Distinctive strength
Combines a top-three FedRAMP 3PAO practice with the A-SCEND platform and evidence reuse across frameworks.
AICPACPA FirmISO 27001 Certification Body TechnologyB2B SaaSHealthcare

AARC-360

ATLANTA, GA · USA
Verified record
Type 1
$10K-$30K
Type 2
$15K-$45K
Fieldwork to report
4–12 wk
Best fit
Small and mid-sized companies coordinating SOC work with ISO, FedRAMP, GovRAMP, PCI, HITRUST, or HIPAA.
Distinctive strength
Combines PCAOB registration with IAS-accredited ISO certification and A2LA-accredited FedRAMP and GovRAMP assessment capabilities.
AICPAAICPA Peer ReviewPCAOB TechnologyFinancial ServicesHealthcare

Armanino LLP

SAN RAMON, CA · USA
Verified record
Type 1
$10K-$20K
Type 2
$15K-$40K
Fieldwork to report
3–12 wk
Best fit
Mid-market technology and private-equity-backed companies combining SOC 2 with tax, advisory, or ISO certification.
Distinctive strength
Pairs its Audit Ally platform with an ANAB-accredited ISO certification practice and a broad audit, tax, and consulting team.
AICPACPA FirmISO 27001 Certification Body TechnologyHealthcareFinancial Services

BARR Advisory

KANSAS CITY, MO · USA
Verified record
Type 1
$5K-$20K
Type 2
$15K-$50K
Fieldwork to report
8–16 wk
Best fit
Cloud-native SaaS, infrastructure, healthcare, and government teams coordinating SOC 2 with another major framework.
Distinctive strength
Its Coordinated Audit approach maps evidence across SOC 2, ISO 27001, HITRUST, PCI DSS, and CMMC in one engagement.
AICPACPA FirmISO 27001 Certification Body B2B SaaSCloud Infrastructure (AWS, Azure, GCP)FinTech

LBMC

NASHVILLE, TN · USA
Verified record
Type 1
$15K-$45K
Type 2
$20K-$60K
Fieldwork to report
26–52 wk
Best fit
Healthcare and private-equity-backed mid-market teams pairing SOC reports with another security framework.
Distinctive strength
An integrated 1,000-plus-person accounting and cybersecurity practice covering HITRUST, ISO 27001, PCI DSS, NIST, CMMC, and HIPAA.
AICPAHITRUST AssessorPCI DSS QSA Healthcare and claims processingFinancial servicesCloud service providers

Schellman

TAMPA, FL · USA
Verified record
Type 1
$15K-$30K
Type 2
$20K-$100K
Fieldwork to report
3–12 wk
Best fit
Defense, federal, healthcare, and enterprise teams coordinating SOC 2 with FedRAMP, CMMC, HITRUST, PCI, or ISO.
Distinctive strength
A leading FedRAMP 3PAO and Top 50 CPA firm with DoD facility clearance and more than 1,000 SOC reports issued annually.
AICPACPA FirmPCAOB Government/DefenseHealthcareFinancial Services

Frazier & Deeter

ATLANTA, GA · USA
Verified record
Type 1
$15K-$35K
Type 2
$25K-$75K
Fieldwork to report
4–14 wk
Best fit
Middle-market teams consolidating SOC 2 with PCI, HIPAA, HITRUST, CMMC, FedRAMP, or ISO work.
Distinctive strength
Its SOC leadership includes AICPA curriculum authors and peer reviewers, with one evidence cycle designed to support several frameworks.
AICPACPA FirmAICPA Advanced SOC FinTechPayments TechnologyHealthcare

Securisea

ANNAPOLIS, MD · USA
Verified record
Type 1
$15K-$50K
Type 2
$25K-$90K
Fieldwork to report
4–12 wk
Best fit
Technology, cloud, healthcare, payments, and public-sector teams coordinating SOC work with another assessment.
Distinctive strength
Combines a licensed CPA attestation practice with PCI, HITRUST, FedRAMP, GovRAMP, CSA STAR, and ISO assessment credentials.
AICPACPA FirmCSA STAR B2B SaaSCloud ServicesHealthcare

Accorp Partners

LOS ANGELES, CA · USA
Verified record
Type 1
$20K-$60K
Type 2
$30K-$80K
Fieldwork to report
13–26 wk
Best fit
SaaS, FinTech, HealthTech, e-commerce, regulated industries, enterprises to fast-growing startups
Distinctive strength
CPA-led firm with AICPA standards, end-to-end support from readiness to attestation, global presence with local regulatory expertise, automation-driven compliance execution
AICPASOC 2ISACA FinTechSaaSHealthcare

ControlCase

FAIRFAX, VA · USA
Verified record
Type 1
$20K-$80K
Type 2
$35K-$120K
Fieldwork to report
4–18 wk
Best fit
Enterprises consolidating several annual compliance programs across a large framework portfolio.
Distinctive strength
Its One Audit approach reuses evidence across more than 60 frameworks, supported by year-round monitoring in ComplianceHub.
AICPAPCI DSS QSAISO 27001 TechnologyFinancial ServicesHealthcare

CBIZ

NEW YORK, NY · USA
Verified record
Type 1
$25K-$50K
Type 2
$40K-$100K
Fieldwork to report
4–9 wk
Best fit
Mid-market and enterprise organizations needing multi-location risk advisory and SOC reporting support.
Distinctive strength
Offers a 10,000-plus-person national platform and a credentialed risk team, with attest work handled by MHM CPAs.
AICPACPA FirmPCAOB TechnologyHealthcareFinancial Services

Coalfire

CHICAGO, IL · USA
Verified record
Type 1
$25K-$60K
Type 2
$40K-$120K
Fieldwork to report
4–12 wk
Best fit
Mid-market and enterprise teams combining SOC 2 with FedRAMP, PCI DSS, HITRUST, or CMMC.
Distinctive strength
A 128-assessment FedRAMP High 3PAO for cloud companies that need SOC 2 alongside federal authorization.
AICPAFedRAMP 3PAOPCI DSS QSA Cloud InfrastructureFederal/GovernmentFinTech & Payments

Drummond Group

USA · USA
Verified record
Type 1
$35K-$100K
Type 2
$50K-$150K
Fieldwork to report
4–16 wk
Best fit
Technology, SaaS, fintech, and healthtech teams consolidating several compliance frameworks.
Distinctive strength
Maps controls across SOC 2, ISO 27001, PCI, HIPAA, and NIST through a senior-auditor, customer-focused delivery model.
ONC AuthorizedANABPCI DSS QSA HealthcareHealth ITFinancial Services

IS Partners

DRESHER, PA · USA
Verified record
Type 1
$35K-$100K
Type 2
$50K-$150K
Fieldwork to report
8–16 wk
Best fit
Regulated mid-market and enterprise organizations coordinating SOC 2, ISO 27001, HITRUST, or CMMC.
Distinctive strength
Combines SOC and ISO audit capacity with cybersecurity and risk advisory following its integration with Axiom GRC and AssurancePoint.
CPACIPPCRMA Government ContractingHealthcareBusiness Process Outsourcing

Auditwerx

TAMPA, FL · USA
Type 1
$10K-$30K
Type 2
$15K-$45K
Fieldwork to report
3–12 wk
Best fit
Companies coordinating SOC 2 with PCI DSS, HIPAA, CMMC, or privacy requirements.
Distinctive strength
A specialized division of Top 25 CPA firm CRI, combining national resources, PCI QSA depth, readiness support, and a secure evidence dashboard.
AICPACPA FirmPCI DSS QSA TechnologySaaSHealthcare

CompliancePoint Assurance

DULUTH, GA · USA
Type 1
$10K-$40K
Type 2
$15K-$50K
Fieldwork to report
6–12 wk
Best fit
Companies combining a SOC 2 audit with PCI DSS, HITRUST, ISO 27001, HIPAA, or readiness work.
Distinctive strength
A dedicated CPA firm spun out of CompliancePoint to pair formal SOC 2 attestation with the group's compliance-program support.
AICPAPCI DSS QSAHITRUST Assessor SaaSTechnologyFinancial Services

SAV Associates

TORONTO, ON · Canada
Type 1
$10K-$30K
Type 2
$15K-$45K
Fieldwork to report
3–10 wk
Best fit
Canadian and international teams combining SOC assurance with ISO, PCI, privacy, AML, or blockchain compliance.
Distinctive strength
Operates as both a CPA audit firm and an accredited ISO certification body, with Big Four backgrounds and crypto-compliance experience.
CPACAISO 27001 Certification Body TechnologyFinancial ServicesHealthcare

PBMares

NEWPORT NEWS, VA · USA
Type 1
$15K-$40K
Type 2
$20K-$55K
Fieldwork to report
4–8 wk
Best fit
Mid-market SaaS, consulting, and government contractors seeking hands-on SOC 2 guidance with deep industry expertise.
Distinctive strength
CPA firm combining licensed CPAs with cybersecurity professionals, offering industry-specific SOC 2 expertise and practical business value beyond compliance.
AICPAPCI DSS QSA SaaSHealthcareFinancial Services

CyberCrest

ENCINITAS, CA · USA
Type 1
$15K-$50K
Type 2
$25K-$70K
Fieldwork to report
4–10 wk
Best fit
Organizations prioritizing hands-on remediation support and rapid compliance certification across multiple frameworks.
Distinctive strength
AICPA-licensed specialist offering hands-on remediation alongside auditing, with 100% documented client retention.
AICPAPCI DSS QSACMMC RPO SaaSHealthcareFinancial Services

CyberGuard Advantage

LAS VEGAS, NV · USA
Type 1
$15K-$50K
Type 2
$25K-$70K
Fieldwork to report
4–10 wk
Best fit
Fast-growing SaaS and fintech companies seeking specialist SOC 2 and cybersecurity audit expertise.
Distinctive strength
PCAOB-registered CPA firm founded by Grant Thornton partner, combining audit rigor with specialized SOC 2 and cybersecurity expertise, performing 400+ audits annually.
AICPAPCAOBISO 27001 Lead Auditor SaaSFinancial ServicesFinTech

Lazarus Alliance

SCOTTSDALE, AZ · USA
Type 1
$15K-$50K
Type 2
$25K-$70K
Fieldwork to report
4–10 wk
Best fit
Government contractors and cloud service providers needing specialized FedRAMP and SOC 2 compliance audits with expert advisory.
Distinctive strength
FedRAMP 3PAO with proprietary IT Audit Machine platform and AI-enhanced Cybervisor advisory spanning 26+ years.
AICPAPCAOBFedRAMP 3PAO GovernmentSaaSHealthcare

NDB

ATLANTA, GA · USA
Type 1
$20K-$60K
Type 2
$30K-$80K
Fieldwork to report
6–12 wk
Best fit
Technology startups and established companies coordinating SOC reporting with other compliance work.
Distinctive strength
Brings more than 1,000 compliance reports and integrations across six major GRC platforms to its SOC practice.
AICPAHITRUST AssessorISO 27001 SaaSHealthtechFinTech

VISTA InfoSec

NEW YORK, NY · USA
Type 1
$20K-$60K
Type 2
$30K-$80K
Fieldwork to report
6–12 wk
Best fit
SaaS, fintech, healthcare, and banking organizations pursuing SOC 2 assurance.
Distinctive strength
Uses an in-house audit team backed by AICPA, CREST, PCI QSA, and ISO 27001 Lead Auditor credentials.
AICPACRESTPCI DSS QSA SaaSFinTechHealthcare

Wolf & Company

BOSTON, MA · USA
Type 1
$25K-$80K
Type 2
$40K-$100K
Fieldwork to report
6–14 wk
Best fit
Mid-market to enterprise organizations in regulated industries requiring senior-led audit expertise and industry-specific guidance.
Distinctive strength
115-year independent firm with senior leadership directly involved in every engagement and specialized expertise in fintech, banking, and healthcare.
AICPAPCI DSS QSA BankingFinTechHealthcare
More questions

What is a PCI QSA?

A Qualified Security Assessor is a company qualified by the PCI Security Standards Council to assess and validate an organization’s compliance with the Payment Card Industry Data Security Standard. QSA status is granted by the Council, not self-declared, and is the check to run before you award PCI work.

PCI DSS is scoped by merchant or service-provider level and by the cardholder-data environment. Those variables do not appear in the SOC 2 planning span on this page, so ask for a separate PCI workstream in the proposal.

Council qualification and CDE scope are summarized on PCI DSS framework explained.

Do PCI DSS and SOC 2 share controls?

PCI DSS and SOC 2 share controls in network security, access control, logging, monitoring, vulnerability management, and vendor oversight. Actual reuse depends on the cardholder-data environment and SOC 2 boundary, so ask the firm to identify shared testing and framework-specific evidence in writing.

The amount of reusable evidence also depends on your role, selected Trust Services Categories, and assessment period. Ask for a control-and-evidence map that separates shared testing from PCI- and SOC-specific work.

SaaS overlap and gaps are the vs-page at SOC 2 vs PCI DSS for SaaS.

Which payments companies need both PCI DSS and SOC 2?

Payment facilitators, gateways, processors, and fintech products may face PCI DSS validation based on their role and cardholder-data environment, while commercial buyers may separately request SOC 2. Confirm both requirements before procuring a dual-scope provider rather than assuming every payments company needs both.

A processor with a large cardholder-data environment can owe a full PCI assessment while a SaaS tool that never stores PAN may owe only a lighter questionnaire. Confirm the role and CDE before you buy a dual-scope provider.

Region and qualified personnel availability also change PCI delivery. Confirm the QSA company’s current listing, geography, and who will actually be on-site or remote before you treat a dual-scope proposal as staffed, dated, scoped, and signed. Put those names in the signed engagement letter.

Role and CDE questions for processors sit on PCI DSS for service providers.

FAQ

Does a PCI ROC replace a SOC 2 report?

No. A PCI Report on Compliance documents PCI DSS validation; it does not replace a SOC 2 report signed by a CPA firm. Payments companies often need both because card brands and commercial buyers ask for different artifacts.

Does the PCI assessment cost the same as SOC 2?

No. PCI DSS is scoped and priced separately based on your merchant or service-provider level and cardholder-data environment. The SOC 2 fees here do not include PCI assessment work.

Who maintains the official QSA list?

The PCI Security Standards Council maintains the authoritative QSA registry. This page is a narrower cut — the QSA firms that also issue SOC 2.

Important · attestation

Verify before signing.

SOC 2 reports require CPA attestation. Preparation software and readiness consultants can collect evidence and reduce audit work, but the opinion has to come from an independent, licensed CPA firm.

Confirm scope in writing. Before signing, ask the firm which report or certificate it can issue directly, which work is handled by an affiliate, and what evidence carries over between frameworks or platforms.

Disclaimer · pricing estimates and fieldwork-to-report timelines are based on directory data and public information. Timelines exclude the agreed Type 2 observation period. Actual quotes vary by company size, systems, control maturity, and audit scope.

One call, not five

One brief. 3–10 matched quotes.

Tell us your platform, framework scope, company size, and deadline. We route it to firms that fit and ask them for a ballpark, a timeline, and the caveats before you book calls.

58-second form · Anonymous until you pick.