Directory

SOC 1 assessment firms

18 SOC 1 assessment practices, grouped by the buyer type they fit best. Each profile links to the firm's website. We are an independent directory -- not an assessment firm, and these listings are not paid placements or endorsements.

Verify before you engage. Only a licensed CPA firm can issue a SOC 1 report under AICPA SSAE 18 standards. Before signing, confirm the firm's credentials, ask who your examination team will be, and get the fee in writing with scope boundaries. Our methodology explains exactly how we vet firms and label prices.

Provenance: profiles are compiled from each firm's public materials (September 2026); every price carries a source label. All 18 firm websites were verified in September 2026 during our pilot research, with six spot re-checks this week -- the verification log is on our methodology page.

For small service organizations

First SOC 1 examinations on a budget: boutique and startup-friendly CPA firms with efficient Type 1 practices.

FirmTypeSOC 1 planning rangeFieldwork window
Zero Day CPABoutique licensed CPA firm$8K–$20K (planning estimate (Sept 2026))Type 1: 4–6 wk
Prescient AssuranceAICPA-accredited SOC audit firm$10K–$25K (planning estimate (Sept 2026))Type 1: 4–6 wk
MJD AdvisorsSOC-focused licensed CPA firm$10K–$30K (planning estimate (Sept 2026))Type 1: 4–8 wk
Johanson Group, LLPLicensed CPA firm focused on security compliance audits$10K–$30K (planning estimate (Sept 2026))Type 1: 4–8 wk

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

For mid-market service organizations

Growing scope or multi-location footprints: you need a credible examination practice, possibly with adjacent frameworks (SOC 2, ISO 27001) on the roadmap.

FirmTypeSOC 1 planning rangeFieldwork window
MJD AdvisorsSOC-focused licensed CPA firm$10K–$30K (planning estimate (Sept 2026))Type 1: 4–8 wk
Johanson Group, LLPLicensed CPA firm focused on security compliance audits$10K–$30K (planning estimate (Sept 2026))Type 1: 4–8 wk
SensibaTop-75 U.S. accounting and consulting firm$15K–$45K (planning estimate (Sept 2026))Type 1: 4–8 wk
KirkpatrickPriceAssurance specialist$15K–$40K (planning estimate (Sept 2026))Type 1: 4–8 wk
360 AdvancedCybersecurity and compliance audit firm$15K–$45K (planning estimate (Sept 2026))Type 1: 4–8 wk
BARR AdvisorySecurity and compliance advisory + attest practice$15K–$50K (planning estimate (Sept 2026))Type 1: 4–8 wk
ArmaninoNational full-service CPA firm$20K–$55K (planning estimate (Sept 2026))Type 1: 6–10 wk
AprioNational full-service CPA and advisory firm$20K–$55K (planning estimate (Sept 2026))Type 1: 6–10 wk
WithumNational top-ranking public accounting and advisory firm$20K–$60K (planning estimate (Sept 2026))Type 1: 6–10 wk
A-LIGNLicensed CPA firm$25K–$70K (planning estimate (Sept 2026))Type 1: 6–10 wk
BDONational full-service CPA firm$30K–$90K (planning estimate (Sept 2026))Type 1: 6–12 wk
RSMNational CPA firm focused on the middle market$30K–$85K (planning estimate (Sept 2026))Type 1: 6–12 wk
Grant ThorntonNational full-service CPA and advisory firm$30K–$95K (planning estimate (Sept 2026))Type 1: 6–12 wk

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

For large enterprises

Type 2-required environments, complex systems, or global footprints -- deep benches, national delivery, and multi-framework breadth.

FirmTypeSOC 1 planning rangeFieldwork window
A-LIGNLicensed CPA firm$25K–$70K (planning estimate (Sept 2026))Type 1: 6–10 wk
BDONational full-service CPA firm$30K–$90K (planning estimate (Sept 2026))Type 1: 6–12 wk
RSMNational CPA firm focused on the middle market$30K–$85K (planning estimate (Sept 2026))Type 1: 6–12 wk
Grant ThorntonNational full-service CPA and advisory firm$30K–$95K (planning estimate (Sept 2026))Type 1: 6–12 wk
SchellmanTop-50 CPA firm$35K–$110K (planning estimate (Sept 2026))Type 1: 8–12 wk
CoalfireCybersecurity assessment and advisory firm$35K–$120K (planning estimate (Sept 2026))Type 1: 8–12 wk
DeloitteBig Four professional-services network$50K–$200K (planning estimate (Sept 2026))Type 1: 8–16 wk

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

All 18 assessor profiles

Licensed CPA firm

Zero Day CPA

Zero Day CPA is a Michigan-based boutique licensed CPA firm focused on SOC examinations for B2B SaaS and service organizations. Its SOC 1 practice covers readiness assessments, Type 1 and Type 2 examinations, and combined SOC 1 + SOC 2 programs with remote delivery.

West Bloomfield, Michigan · Founded Not disclosed
SOC 1, SOC 2, SOC 3, HIPAA
Licensed CPA firm

Prescient Assurance

Prescient Assurance is an AICPA-accredited SOC audit firm that pairs audit teams with security-testing experience. Its SOC 1 practice serves SaaS companies needing Type 1 and Type 2 reports, with an emphasis on technology-driven, startup-friendly engagements.

New York, New York · Founded 2021
SOC 1, SOC 2, SOC 2+, CSA STAR, HIPAA/HITECH, ISO 27001
Licensed CPA firm

MJD Advisors

MJD Advisors is a SOC-focused licensed CPA firm offering SOC 1 and SOC 2 examinations. Its focused practice model suits service organizations that want a dedicated SOC auditor rather than a generalist accounting firm.

Des Moines, Iowa · Founded Not disclosed
SOC 1, SOC 2
Licensed CPA firm

Johanson Group, LLP

Johanson Group, LLP is a licensed CPA firm focused on security compliance audits, operating as a remote-first practice. Its SOC 1 examinations cover Type 1 and Type 2 reports for service organizations, alongside SOC 2 and ISO 27001 work.

United States (remote-first practice) · Founded 2015
SOC 1, SOC 2, SOC 3, ISO 27001, HIPAA, NIST 800-53 / 800-171
Licensed CPA firm

Sensiba

Sensiba (Sensiba LLP) is a top-75 U.S. accounting firm whose risk assurance practice performs SOC 1 Type 1 and Type 2 examinations for technology and service organizations, alongside SOC 2, ISO 27001, and HITRUST work.

San Ramon, California · Founded 1977
SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, NIST CSF, CMMC
Licensed CPA firm

KirkpatrickPrice

KirkpatrickPrice is an assurance specialist performing SOC 1, SOC 2, and ISO 27001 examinations. Its SOC 1 practice issues Type 1 and Type 2 reports for service organizations, with a focus on the mid-market.

Nashville, Tennessee · Founded Not disclosed
SOC 1, SOC 2, ISO 27001, HITRUST
Licensed CPA firm

360 Advanced

360 Advanced is a cybersecurity and compliance audit firm whose licensed CPA practice issues SOC 1 Type 1 and Type 2 reports. It pairs SOC examinations with penetration testing and broader compliance work for service organizations.

St. Petersburg, Florida · Founded 2004
SOC 1, SOC 2, SOC 3, ISO 27001, HIPAA, HITRUST, FedRAMP
Licensed CPA firm

BARR Advisory

BARR Advisory combines security and compliance advisory with an attest practice issuing SOC 1 Type 1 and Type 2 reports. It is known for cloud-native clientele and combined SOC 1 + SOC 2 + ISO programs.

Kansas City, Missouri · Founded 2014
SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27701, ISO 42001, HITRUST, CMMC
Licensed CPA firm

Armanino

Armanino LLP is a national full-service CPA firm whose risk assurance practice performs SOC 1 Type 1 and Type 2 examinations for service organizations, alongside SOC 2 and ISO 27001 work.

San Ramon, California · Founded 1969
SOC 1, SOC 2, ISO 27001, HITRUST

Comparing firms? Tell us your scope once -- get quotes from your shortlist. Free · 2 minutes · no obligation.

Get matched quotes
Licensed CPA firm

Aprio

Aprio is a national CPA and advisory firm whose assurance practice issues SOC 1 Type 1 and Type 2 reports for service organizations across technology, financial services, and healthcare.

Atlanta, Georgia · Founded 1952
SOC 1, SOC 2, ISO 27001, HITRUST, CMMC, FedRAMP
Licensed CPA firm

Withum

Withum is a national public accounting firm whose SOC practice performs SOC 1 Type 1 and Type 2 examinations for service organizations, with particular depth in technology and financial services.

Princeton, New Jersey · Founded 1974
SOC 1, SOC 2, SOC for Cybersecurity
Licensed CPA firm

A-LIGN

A-LIGN is a licensed CPA firm known for technology-enabled audit delivery. Its SOC 1 practice issues Type 1 and Type 2 reports at scale, often combined with SOC 2, ISO 27001, and FedRAMP work under one evidence set.

Tampa, Florida · Founded 2009
SOC 1, SOC 2, ISO 27001, FedRAMP, CMMC, HITRUST
Licensed CPA firm

BDO

BDO is a top-10 U.S. CPA firm whose assurance practice performs SOC 1 Type 1 and Type 2 examinations for large service organizations, often as part of broader financial-statement and ICFR-related audit relationships.

Chicago, Illinois · Founded 1910
SOC 1, SOC 2, SOC 3
Licensed CPA firm

RSM

RSM is a national CPA firm focused on the middle market. Its risk consulting practice issues SOC 1 Type 1 and Type 2 reports for service organizations, frequently alongside financial audit and ICFR work.

Chicago, Illinois · Founded 1926
SOC 1, SOC 2, SOC 3
Licensed CPA firm

Grant Thornton

Grant Thornton is a national CPA and advisory firm whose audit practice performs SOC 1 Type 1 and Type 2 examinations, often for clients whose user entities rely on the reports for their own ICFR audits.

Chicago, Illinois · Founded 1924
SOC 1, SOC 2, SOC 3, HITRUST, SOC for Cybersecurity
Licensed CPA firm

Schellman

Schellman (Schellman & Company, LLC) is a top-50 CPA firm and one of the largest SOC practices in the country. Its SOC 1 practice issues Type 1 and Type 2 reports for service organizations of every size, with independence-first methodology.

Tampa, Florida · Founded 2002
SOC 1, SOC 2, ISO 27001, FedRAMP, HITRUST, CMMC, ISO 42001
Licensed CPA firm

Coalfire

Coalfire is one of the largest cybersecurity assessment practices in the world. Its assurance practice performs SOC 1 and SOC 2 examinations for large service organizations, paired with deep testing and advisory benches.

Westminster, Colorado · Founded 2001
SOC 1, SOC 2, FedRAMP, HITRUST, ISO 27001
Licensed CPA firm

Deloitte

Deloitte's assurance network performs SOC 1 Type 1 and Type 2 examinations globally, frequently for service organizations whose user entities are themselves audited by Big Four firms and need maximum report reliance.

New York, New York · Founded 1845
SOC 1, SOC 2, ISO 27001 + global assurance network

How we built this directory

Read the full methodology →

Get matched with the right assessor

Answer four quick questions and receive quotes from firms that fit your size, scope, and timeline.

Get a free quote