Logo Menu

Firms That Do Both SOC 2 and ISO 27001: 19 firms compared

19 attestation-capable firm records match this combined-scope filter. Compare their relevant framework credentials, then confirm which work, evidence, entities, and schedules can actually be coordinated.

Browse 19 firms ↓

Reviewed by Peter Korpak / Last updated / Combined scope

Matching firms
19attestation-capable
Estimated Type 2 span
$8K-$150K
Fastest listed fieldwork-to-report
2 wk

Can one firm do both SOC 2 and ISO 27001?

ISO 27001 certification-body capability can sit alongside SOC 2 attestation in one provider group. The SOC 2 report and the ISO certificate remain separate deliverables, sometimes issued through related legal entities, so confirm the arrangement in writing before you sign.

Customers that require both a SOC 2 report and an accredited ISO 27001 certificate should verify current accreditation scope, legal entity, and certificate issuer. A generic ISO 27001 credential does not establish that a firm can issue the certificate.

Listed timelines cover SOC 2 fieldwork through report delivery and do not replace the Type 2 observation period or the ISO stage timetable. Treat the price range as a SOC 2 planning input and ask for renewal responsibilities in writing.

Use-case picks

Which dual-scope firm fits which use case?

Compare ISO 27001 use-case picks with all 19 matching firms. Timelines cover fieldwork through the final report, excluding the Type 2 observation period.

Combined engagement Armanino LLP

Best mid-market firm for SOC 2 plus ISO 27001

Armanino Certified, LLC is the ANAB-accredited ISO/IEC 27001 and 27701 body, making it a candidate for mid-market certificate issuance. Audit Ally does not issue the certificate.

Enterprise Schellman

Best enterprise firm for SOC 2 and ISO 27001

Schellman Compliance, LLC is the named ISO 27001 body (ANAB and UKAS), making it a candidate for global recognition. Confirm which entity signs the SOC 2 report.

All firms

Which firms can issue a SOC 2 report and an ISO 27001 certificate?

Compare each firm's SOC 2 fee estimate, fieldwork-to-report timeline, and credentials relevant to this combined scope.

360 Advanced

ST. PETERSBURG, FL · USA
Verified record
Type 1
$15K-$60K
Type 2
$15K-$80K
Fieldwork to report
3–12 wk
Best fit
Mid-market and enterprise teams that want a U.S.-based team coordinating SOC 2 with other frameworks.
Distinctive strength
Coordinates shared evidence across frameworks, including an ANAB-accredited ISO 27001 certification body and a FedRAMP-listed 3PAO.
AICPAPCAOBCyberAB Enterprise IT OutsourcingManaged SecurityHealthcare Claims Management

Thoropass

NEW YORK, NY · USA
Verified record
Type 1
From $9,995 Type 1 + Type 2
Type 2
From $9,995 Type 1 + Type 2
Fieldwork to report
2–6 wk
Best fit
Established startups and SMBs seeking an auditor-led, multi-framework engagement without replacing their existing GRC platform.
Distinctive strength
Its assurance team and audit technology coordinate SOC 2, ISO 27001, HIPAA, PCI DSS, and HITRUST from a shared evidence set.
AICPACPA FirmAICPA Peer Review B2B SaaSFinTechHealthTech

Decrypt Compliance

SAN JOSE, CA · USA
Verified record
Type 1
$3K-$15K
Type 2
$8K-$40K
Fieldwork to report
4–8 wk
Best fit
Cloud-native software teams and mature organizations with complex, multi-framework environments.
Distinctive strength
Uses an internal evidence-analysis engine and a platform-neutral review process for GRC-sourced evidence.
CPA FirmAICPA Peer ReviewISO 27001 Certification Body B2B SaaSAIFintech

Prescient Security

NASHVILLE, TN · USA
Verified record
Type 1
$5K-$35K
Type 2
$10K-$30K
Fieldwork to report
2–6 wk
Best fit
Growth-stage SaaS, AI, fintech, healthtech, and government teams combining SOC 2 with another framework.
Distinctive strength
Its licensed Prescient Assurance division combines SOC attestation with FedRAMP, CMMC, HITRUST, PCI, and ISO certification credentials.
AICPACPA FirmCREST B2B SaaSFinTechHealthTech

A-LIGN

TAMPA, FL · USA
Verified record
Type 1
$10K-$20K
Type 2
$15K-$50K
Fieldwork to report
3–12 wk
Best fit
Mid-market and enterprise teams consolidating SOC 2, ISO 27001, HITRUST, FedRAMP, or PCI work with one provider.
Distinctive strength
Combines a top-three FedRAMP 3PAO practice with the A-SCEND platform and evidence reuse across frameworks.
AICPACPA FirmISO 27001 Certification Body TechnologyB2B SaaSHealthcare

AARC-360

ATLANTA, GA · USA
Verified record
Type 1
$10K-$30K
Type 2
$15K-$45K
Fieldwork to report
4–12 wk
Best fit
Small and mid-sized companies coordinating SOC work with ISO, FedRAMP, GovRAMP, PCI, HITRUST, or HIPAA.
Distinctive strength
Combines PCAOB registration with IAS-accredited ISO certification and A2LA-accredited FedRAMP and GovRAMP assessment capabilities.
AICPAAICPA Peer ReviewPCAOB TechnologyFinancial ServicesHealthcare

Armanino LLP

SAN RAMON, CA · USA
Verified record
Type 1
$10K-$20K
Type 2
$15K-$40K
Fieldwork to report
3–12 wk
Best fit
Mid-market technology and private-equity-backed companies combining SOC 2 with tax, advisory, or ISO certification.
Distinctive strength
Pairs its Audit Ally platform with an ANAB-accredited ISO certification practice and a broad audit, tax, and consulting team.
AICPACPA FirmISO 27001 Certification Body TechnologyHealthcareFinancial Services

BARR Advisory

KANSAS CITY, MO · USA
Verified record
Type 1
$5K-$20K
Type 2
$15K-$50K
Fieldwork to report
8–16 wk
Best fit
Cloud-native SaaS, infrastructure, healthcare, and government teams coordinating SOC 2 with another major framework.
Distinctive strength
Its Coordinated Audit approach maps evidence across SOC 2, ISO 27001, HITRUST, PCI DSS, and CMMC in one engagement.
AICPACPA FirmISO 27001 Certification Body B2B SaaSCloud Infrastructure (AWS, Azure, GCP)FinTech

MHM Professional Corporation

CALGARY, AB · Canada
Verified record
Type 1
$10K-$30K
Type 2
$15K-$45K
Fieldwork to report
2–8 wk
Best fit
Canadian growth and established companies combining SOC work with ISO security, privacy, cloud, or AI certification.
Distinctive strength
Former PwC partners lead a senior-only team with no offshore delivery, including Canada's first SCC-accredited ISO 42001 audit capability.
CPACPA CanadaSCC TechnologySaaSFinancial Services

Schellman

TAMPA, FL · USA
Verified record
Type 1
$15K-$30K
Type 2
$20K-$100K
Fieldwork to report
3–12 wk
Best fit
Defense, federal, healthcare, and enterprise teams coordinating SOC 2 with FedRAMP, CMMC, HITRUST, PCI, or ISO.
Distinctive strength
A leading FedRAMP 3PAO and Top 50 CPA firm with DoD facility clearance and more than 1,000 SOC reports issued annually.
AICPACPA FirmPCAOB Government/DefenseHealthcareFinancial Services

Sensiba LLP

PLEASANTON, CA · USA
Verified record
Type 1
$15K-$35K
Type 2
$20K-$50K
Fieldwork to report
4–10 wk
Best fit
VC-backed SaaS and Bay Area technology companies combining SOC 2 with ISO 27001 or ISO 42001.
Distinctive strength
An ANAB-accredited ISO certification body and Top 75 CPA firm with a broad GRC-platform ecosystem and expanded global audit reach.
AICPACPA FirmISO 27001 Certification Body B2B SaaSTechnologyFinTech

Securisea

ANNAPOLIS, MD · USA
Verified record
Type 1
$15K-$50K
Type 2
$25K-$90K
Fieldwork to report
4–12 wk
Best fit
Technology, cloud, healthcare, payments, and public-sector teams coordinating SOC work with another assessment.
Distinctive strength
Combines a licensed CPA attestation practice with PCI, HITRUST, FedRAMP, GovRAMP, CSA STAR, and ISO assessment credentials.
AICPACPA FirmCSA STAR B2B SaaSCloud ServicesHealthcare

Frank, Rimerman + Co.

PALO ALTO, CA · USA
Verified record
Type 1
$20K-$60K
Type 2
$30K-$80K
Fieldwork to report
4–12 wk
Best fit
Silicon Valley startups and VC-backed technology firms combining SOC work with ISO 27001 or ISO 27701.
Distinctive strength
Pairs 75-plus years in the Silicon Valley ecosystem with ANAB-accredited ISO certification and year-round partner access.
AICPACPA FirmISO 27001 Certification Body SaaSSoftwareFinTech

Coalfire

CHICAGO, IL · USA
Verified record
Type 1
$25K-$60K
Type 2
$40K-$120K
Fieldwork to report
4–12 wk
Best fit
Mid-market and enterprise teams combining SOC 2 with FedRAMP, PCI DSS, HITRUST, or CMMC.
Distinctive strength
A 128-assessment FedRAMP High 3PAO for cloud companies that need SOC 2 alongside federal authorization.
AICPAFedRAMP 3PAOPCI DSS QSA Cloud InfrastructureFederal/GovernmentFinTech & Payments

Drummond Group

USA · USA
Verified record
Type 1
$35K-$100K
Type 2
$50K-$150K
Fieldwork to report
4–16 wk
Best fit
Technology, SaaS, fintech, and healthtech teams consolidating several compliance frameworks.
Distinctive strength
Maps controls across SOC 2, ISO 27001, PCI, HIPAA, and NIST through a senior-auditor, customer-focused delivery model.
ONC AuthorizedANABPCI DSS QSA HealthcareHealth ITFinancial Services

IS Partners

DRESHER, PA · USA
Verified record
Type 1
$35K-$100K
Type 2
$50K-$150K
Fieldwork to report
8–16 wk
Best fit
Regulated mid-market and enterprise organizations coordinating SOC 2, ISO 27001, HITRUST, or CMMC.
Distinctive strength
Combines SOC and ISO audit capacity with cybersecurity and risk advisory following its integration with Axiom GRC and AssurancePoint.
CPACIPPCRMA Government ContractingHealthcareBusiness Process Outsourcing

Consilium Labs

EL DORADO HILLS, CA · USA
Type 1
$7K-$14K
Type 2
$10K-$16K
Fieldwork to report
2–6 wk
Best fit
SaaS, cloud, AI, and regulated organizations coordinating SOC 2 with ISO, federal, privacy, or testing work.
Distinctive strength
Uses a structured evidence workflow from scoping through report delivery, with a Drata-native client experience.
IASANABA2LA TechnologySaaSCloud Services

SAV Associates

TORONTO, ON · Canada
Type 1
$10K-$30K
Type 2
$15K-$45K
Fieldwork to report
3–10 wk
Best fit
Canadian and international teams combining SOC assurance with ISO, PCI, privacy, AML, or blockchain compliance.
Distinctive strength
Operates as both a CPA audit firm and an accredited ISO certification body, with Big Four backgrounds and crypto-compliance experience.
CPACAISO 27001 Certification Body TechnologyFinancial ServicesHealthcare

Accedere

DENVER, CO · USA
Type 1
$15K-$50K
Type 2
$25K-$70K
Fieldwork to report
4–10 wk
Best fit
Cloud service providers and SaaS companies seeking SOC 2 Type 2 and ISO certifications with cybersecurity rigor.
Distinctive strength
AI-assisted SOC 2 audits with PCAOB registration, deep cybersecurity expertise, and technical assessment services.
AICPAPCAOBANAB SaaSCloud InfrastructureFinancial Services
More questions

Do SOC 2 and ISO 27001 share the same evidence?

SOC 2 and ISO 27001 can share evidence in access control, change management, risk assessment, vendor management, and incident response. The amount of reuse depends on the SOC 2 system boundary, ISO management-system scope, and audit periods, so ask for an evidence map that marks shared work.

A coordinated provider may align interviews, but that is not a fixed saving. Ask the provider to distinguish shared testing from each framework’s separate procedures rather than assuming one fieldwork week covers both.

Shared controls still sit on two programs; the framework primer is ISO 27001 framework explained.

Is the same assessor allowed to issue both reports?

One provider group can deliver both, but the deliverables differ in kind: a SOC 2 report is a CPA attestation, while ISO 27001 is a certificate from an accredited certification body. Related entities may handle the two roles under a coordinated engagement.

Ask for the entities, audit stages, and separate ISO scope in writing. A certification-body logo on a website is not proof that the legal entity in your contract is the one that will issue the certificate.

Entity questions are not a vs-page; that comparison lives at SOC 2 vs ISO 27001: how they differ.

Should ISO 27001 wait until after the first SOC 2 report?

ISO 27001 should wait only when no current buyer requires the certificate. If buyers already need both, coordinating them may reduce duplicate evidence and interviews. Ask the provider to show sequencing rather than assume a combined engagement is cheaper or faster.

How much cheaper is a combined SOC 2 and ISO 27001 audit?

A combined SOC 2 and ISO 27001 audit has no defensible fixed percentage without like-for-like proposals. Coordinated fieldwork can reuse evidence and interviews, but scope determines the result. Ask for a proposal that identifies shared work, then compare it with separately scoped engagements.

A cheaper combined fee that omits Stage 2, surveillance years, or a narrower ISO scope is not a saving. Put shared interviews, unique tests, and each deliverable’s legal issuer on one page before you pick the lower number.

Surveillance-year ISO work and year-two SOC 2 testing are different commercial events. Ask how a stable scope changes each fee instead of assuming the first-year combined number repeats.

Certificate issuers without a SOC 2 cut are listed on ISO 27001 certification companies.

FAQ

Which comes first, SOC 2 or ISO 27001?

Either can come first, but doing them together avoids duplicated evidence work. US-market companies often lead with SOC 2; companies selling into Europe and Asia often need ISO 27001 sooner.

Is ISO 27001 a certification and SOC 2 a report?

Yes. ISO 27001 results in a certificate from an accredited certification body; SOC 2 results in an attestation report from a licensed CPA firm. They are different deliverables that cover overlapping controls.

Will customers accept one combined report?

You still receive two distinct deliverables — a SOC 2 report and an ISO 27001 certificate — from the combined engagement, so each customer gets the document their procurement process expects.

Important · attestation

Verify before signing.

SOC 2 reports require CPA attestation. Preparation software and readiness consultants can collect evidence and reduce audit work, but the opinion has to come from an independent, licensed CPA firm.

Confirm scope in writing. Before signing, ask the firm which report or certificate it can issue directly, which work is handled by an affiliate, and what evidence carries over between frameworks or platforms.

Disclaimer · pricing estimates and fieldwork-to-report timelines are based on directory data and public information. Timelines exclude the agreed Type 2 observation period. Actual quotes vary by company size, systems, control maturity, and audit scope.

One call, not five

One brief. 3–10 matched quotes.

Tell us your platform, framework scope, company size, and deadline. We route it to firms that fit and ask them for a ballpark, a timeline, and the caveats before you book calls.

58-second form · Anonymous until you pick.