AuditXYZ

Auditor Directory

Find a Compliance Auditor

Search 639+ accredited firms worldwide. Filter by name, location, compliance framework, size, and budget — or let us match you automatically.

Looking for a licensed CPA firm? Verify a CPA firm across 54,000+ state board records.

Step 1 of 520%

Which framework do you need?

Find Auditors by Framework

Browse by Region

All Auditor Firms

10FA Compliance

New York, NY

$8,000–$40,000

10FA Compliance is a New York-based compliance consultancy focused on SOC 2 and ISO 27001 readiness for technology and SaaS companies.

SOC 2ISO 27001

24By7Security

Coral Springs, FL

$10,000–$60,000

24By7Security is a Coral Springs, FL cybersecurity consultancy and PCI QSA specializing in HIPAA, PCI DSS, SOC 2, and CMMC compliance.

HIPAASOC 2PCI DSSCMMC+1

360 Advanced

Nashville, TN

$18,000–$70,000

360 Advanced is a US-based compliance audit firm offering SOC 2, PCI DSS, HITRUST, ISO 27001, and HIPAA audits with a focus on technology and healthcare companies.

SOC 2SOC 1ISO 27001PCI DSS+4

A-LIGN

Featured

Tampa, FL

$15,000–$80,000

A-LIGN is one of the largest and most recognized compliance audit firms in the United States. Profile includes pricing, framework coverage, reviews, and engagement process.

SOC 2ISO 27001HIPAAPCI DSS+6

A-Systems

Dubai, UAE

$5,000–$30,000

A-Systems is a UAE-based ISO certification body offering ISO 27001, ISO 27701, and ISO 22301 certification audits for organizations in the Middle East.

ISO 27001ISO 27701ISO 22301ISO 27017+1

A1 Digital Austria

Vienna, Austria

€20,000–€80,000

A1 Digital Austria offers ISO 27001, NIS2, and TISAX compliance assessments for Austrian enterprises.

ISO 27001GDPRNIS2C5+1

AAFCPAs

Westborough, MA

$18,000–$90,000

AAFCPAs is a Massachusetts CPA firm founded in 1973 providing SOC 1, SOC 2, HIPAA, and IT audit services to service organizations.

SOC 1SOC 2HIPAA

AARC-360

Atlanta, GA

$12,000–$60,000

AARC-360 is a PCAOB-registered Atlanta CPA firm delivering SOC 1, SOC 2, ISO 27001, HIPAA, and PCI DSS assurance and compliance services.

SOC 1SOC 2SOC 3ISO 27001+3

Abacode

Tampa, FL

$12,000–$75,000

Abacode is a Tampa-based managed cybersecurity and compliance provider aligning clients to CMMC, SOC 2, ISO 27001, and HIPAA frameworks.

SOC 2CMMCISO 27001HIPAA+1

Abacus Group

New York, NY

$10,000–$60,000

Abacus Group is a New York-based IT and cybersecurity provider delivering compliance and risk services to hedge funds and private equity firms.

NIST CSFSOC 2

ACA Group

New York, NY

$25,000–$150,000

ACA Group is a global GRC advisory firm whose ACA Aponix division provides cybersecurity assessments and compliance support for financial services.

SOC 1SOC 2ISO 27001NIST CSF+1

Accredia Accredited Certification Bodies

Rome, Italy

$7,000–$40,000

Accredia is Italy's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and management system certifications in the Italian market.

ISO 27001ISO 27701ISO 22301ISO 27017+2

ACI Federal

Alexandria, VA

$35,000–$200,000

ACI Federal is a FedRAMP 3PAO and CMMC C3PAO serving federal agencies and government contractors.

FedRAMPCMMCNIST 800-53NIST 800-171+3

ACIS Professional Center

Bangkok, Thailand

$8,000–$40,000

ACIS Professional Center is Thailand's leading cybersecurity firm offering ISO 27001 and PCI DSS assessments.

ISO 27001SOC 2PCI DSSPdpa+1

Acuity Risk Management

London, United Kingdom

£15,000–£70,000

Acuity Risk Management offers ISO 27001, SOC 2, and NIS2 compliance assessments with integrated risk management.

ISO 27001SOC 2GDPRNIS2+2

Adams Brown

Wichita, KS

$15,000–$80,000

Adams Brown is a Wichita, KS CPA and advisory firm founded in 1945, offering SOC 1 and SOC 2 examinations plus audit, tax, and IT services.

SOC 1SOC 2

Advantio

Dublin

$15,000–$100,000

Advantio, an Integrity360 company based in Dublin, is a leading European PCI QSA providing PCI DSS, ISO 27001, and SOC 2 assessment services.

PCI DSSISO 27001SOC 2

Advens

Lille, France

€20,000–€100,000

Advens is a French cybersecurity firm offering ISO 27001, HDS, and NIS2 compliance assessments.

ISO 27001SOC 2GDPRNIS2+2

AENOR

Madrid, Spain

$7,000–$40,000

AENOR is Spain's national standards and certification body offering ISO 27001, ISO 27701, ENS, and management system certifications across Spain and Latin America.

ISO 27001ISO 27701ISO 22301ISO 27017+3

AFNOR Certification

Saint-Denis, France

$8,000–$50,000

AFNOR Certification is France's national standards body and a COFRAC-accredited ISO certification body offering ISO 27001, ISO 27701, and HDS audits.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Agio

New York, NY

$12,000–$75,000

Agio is a New York-based managed IT and cybersecurity firm providing SOC, ISO 27001, and SEC compliance support to financial services firms.

SOC 1SOC 2ISO 27001NIST CSF

AhnLab Cybersecurity

Seongnam, South Korea

₩25,000,000–₩100,000,000

AhnLab is South Korea's leading cybersecurity company offering ISO 27001 and ISMS-P assessments.

ISO 27001Isms PSOC 2PCI DSS+1

Al Ghaith & Co

Abu Dhabi, UAE

$8,000–$40,000

Al Ghaith & Co is a leading UAE audit and advisory firm offering SOC, ISO 27001, and compliance services for government entities and private sector organizations.

SOC 1SOC 2ISO 27001ISO 27701+1

Alder & Co

Salt Lake City, UT

$10,000–$40,000

Alder & Co is a Salt Lake City-based CPA firm providing SOC 1 and SOC 2 examinations for service organizations and technology companies.

SOC 1SOC 2

Align

New York, NY

$12,000–$80,000

Align is a New York-based technology infrastructure and managed services firm offering cybersecurity advisory and compliance services since 1986.

NIST CSFSOC 2

Alvarez & Marsal

New York, NY

$50,000–$250,000

Alvarez & Marsal is a global professional services firm founded in 1983 in New York, offering cyber risk, resilience, and compliance advisory services.

NIST CSFISO 27001SOXGDPR

AMARU

Wellington, New Zealand

NZ$15,000–NZ$50,000

AMARU is a New Zealand cybersecurity firm offering ISO 27001, SOC 2, and NIST compliance services for ANZ technology companies expanding globally.

ISO 27001SOC 2HIPAAGDPR+1

ANAB Accredited Certification Bodies

Milwaukee, WI

$10,000–$60,000

ANAB is the US national accreditation body under ANSI, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and management system certifications.

ISO 27001ISO 27701ISO 22301ISO 27017+4

Anchin Block & Anchin LLP

New York, NY

$12,000–$45,000

Anchin Block & Anchin is a New York-based CPA firm offering SOC 1, SOC 2, HIPAA, and cybersecurity audit services for mid-market companies.

SOC 1SOC 2HIPAANIST CSF+1

Aon Cyber Solutions UK

Featured

London, United Kingdom

£25,000–£150,000

Aon Cyber Solutions UK offers ISO 27001, SOC 2, and PCI DSS assessments with cyber insurance integration.

ISO 27001SOC 2PCI DSSGDPR+2

APCER

Porto, Portugal

$6,000–$35,000

APCER is a Portuguese ISO certification body offering ISO 27001, ISO 27701, and management system certifications across Portugal, Brazil, and Lusophone Africa.

ISO 27001ISO 27701ISO 22301ISO 27017+1

Apogee IT Services

Sewickley, PA

$8,000–$40,000

Apogee IT Services is a Pennsylvania-based managed IT provider offering security and compliance support to small and midsize businesses.

NIST CSFSOC 2

Aprio

Atlanta, Georgia

$20,000–$100,000

Aprio is a top-25 US CPA and advisory firm offering SOC 2, ISO 27001, HITRUST, and cybersecurity assessments with strong technology sector expertise.

SOC 1SOC 2SOC 3ISO 27001+8

Arete Advisors

Nashville, TN

$15,000–$60,000

Arete Advisors is a healthcare compliance specialist based in Nashville, focusing on HIPAA, HITRUST, and health-tech security assessments.

HIPAAHITRUSTSOC 2NIST 800-53

Ariente Advisors

Boston, MA

$10,000–$45,000

Ariente Advisors offers affordable SOC 2, ISO 27001, and PCI DSS assessments for startups.

SOC 2ISO 27001PCI DSSHIPAA+1

Armanino

San Ramon, California

$20,000–$100,000

Armanino is a top-25 US CPA firm based in California with strong technology sector focus, offering SOC 2, ISO 27001, and cybersecurity assessments.

SOC 1SOC 2SOC 3ISO 27001+9

Aronson LLC

Rockville, MD

$20,000–$90,000

Aronson LLC is a Maryland CPA firm offering SOC, SOX, and FedRAMP compliance audits for government contractors.

SOC 2SOC 1SOXHIPAA+1

ASGN Cybersecurity

Glen Allen, VA

$12,000–$60,000

ASGN Cybersecurity is a boutique US cybersecurity and compliance firm specializing in SOC 2, FedRAMP, CMMC, and HITRUST assessments for government contractors and technology companies.

SOC 2ISO 27001HIPAAPCI DSS+5

ASM Research

Fairfax, VA

$30,000–$150,000

ASM Research is a FedRAMP 3PAO and CMMC assessor for federal government contractors.

FedRAMPCMMCNIST 800-53NIST 800-171+1

Assent Risk Management

London, UK

£12,000–£40,000

Assent Risk Management is a London-based compliance firm specializing in SOC 2, ISO 27001, and GDPR assessments for UK and European technology companies.

SOC 2ISO 27001GDPR

Assurance Dimensions

Tampa, FL

$10,000–$50,000

Assurance Dimensions is a Tampa-based national audit and assurance CPA firm founded in 2008, providing SOC 1 and SOC 2 examinations.

SOC 1SOC 2

AssurancePoint

Atlanta, GA

$10,000–$45,000

AssurancePoint is a boutique CPA firm specializing in SOC 2 audits for technology companies. Profile includes pricing, framework coverage, and engagement details.

SOC 2SOC 1HIPAANIST 800-53

Assure Professional

Charlotte, NC

$12,000–$60,000

Assure Professional, acquired by A-LIGN in 2023, is an audit provider delivering SOC 1, SOC 2, SOC 3, HIPAA, HITRUST, and ISO 27001 assessments.

SOC 1SOC 2SOC 3PCI DSS+3

Astra Security

New Delhi, India

₹200,000–₹1,200,000

Astra Security is a CERT-IN empanelled, NASSCOM-awarded cybersecurity firm in New Delhi offering automated and manual penetration testing alongside compliance services.

ISO 27001SOC 2PCI DSSHIPAA+1

Atos Cybersecurity

Featured

Paris, France

€40,000–€300,000

Atos Cybersecurity is a global IT services company offering enterprise-grade ISO 27001, SOC 2, and NIS2 compliance.

ISO 27001SOC 2GDPRNIS2+4

ATX Defense

Austin, TX

$30,000–$100,000

ATX Defense is the first Google Partner to become a CMMC C3PAO, specializing in FedRAMP and CMMC assessments for defense contractors in Austin, TX.

CMMCFedRAMPNIST 800-171

Auditmacs

Jacksonville, FL

$10,000–$60,000

Auditmacs is a Jacksonville, FL firm founded in 2003 providing technology expense, asset, and lifecycle management audits for mid-sized and large enterprises.

NIST CSF

Aujas Cybersecurity

Bangalore, India

$6,000–$40,000

Aujas Cybersecurity is a Bangalore-based firm offering ISO 27001, SOC 2, and PCI DSS compliance services.

ISO 27001SOC 2PCI DSSHIPAA+3

Avertium

Phoenix, AZ

$15,000–$100,000

Avertium is a managed security and compliance firm offering PCI DSS, HIPAA, CMMC, and SOC 2 assessment services from Arizona and Tennessee.

HIPAAPCI DSSCMMCSOC 2+1

Avertro

Melbourne, Australia

A$15,000–A$60,000

Avertro is a Melbourne-based firm providing ISO 27001, SOC 2, and Essential Eight assessments.

ISO 27001SOC 2Essential EightIRAP+1

Baker Tilly

Featured

Chicago, Illinois

$30,000–$180,000

Baker Tilly is a top-10 global advisory CPA firm network with 43,000+ professionals in 141 countries, serving mid-market and growth companies.

SOC 1SOC 2SOC 3ISO 27001+6

Baker Tilly JFC

Dubai, UAE

$8,000–$40,000

Baker Tilly JFC is Baker Tilly International's Middle East member firm offering SOC, ISO 27001, PCI DSS, and compliance audit services across the Gulf region.

SOC 1SOC 2ISO 27001ISO 27701+3

Barnes Dennig

Cincinnati, OH

$15,000–$75,000

Barnes Dennig is a Cincinnati-based CPA firm with a dedicated SOC reporting team delivering SOC 1, SOC 2, and SOC 3 examinations.

SOC 1SOC 2SOC 3

BARR Advisory

Fairway, KS

$20,000–$75,000

BARR Advisory is a Kansas-based cybersecurity and compliance firm specializing in SOC 2, HITRUST, FedRAMP, and ISO 27001 audits for cloud-first companies.

SOC 2ISO 27001HITRUSTFedRAMP+3

BDO Australia

Melbourne, Australia

$18,000–$100,000

BDO Australia is a leading mid-market audit and advisory firm providing SOC 2, ISO 27001, Essential Eight, and Privacy Act compliance services to Australian businesses across technology, financial services, and healthcare.

SOC 1SOC 2ISO 27001ISO 27701+5

BDO Canada

Featured

Toronto, ON

CA$25,000–CA$120,000

BDO Canada is a leading national CPA firm offering SOC, SOX, ISO 27001, and PIPEDA compliance audits.

SOC 2SOC 1SOXISO 27001+3

BDO France

Paris, France

€25,000–€120,000

BDO France offers SOC, ISO 27001, and GDPR compliance audit services.

SOC 2SOC 1ISO 27001GDPR+2

BDO Germany

Hamburg, Germany

$20,000–$120,000

BDO Germany is a leading mid-market audit and advisory firm providing ISO 27001, C5, TISAX, SOC 2, and GDPR compliance services to German mid-market companies and the Mittelstand.

SOC 1SOC 2ISO 27001ISO 27701+6

BDO India

Mumbai, India

$6,000–$40,000

BDO India provides SOC, ISO 27001, and DPDPA compliance audit services.

SOC 2SOC 1ISO 27001SOX+2

BDO International

Featured

Brussels, Belgium

$40,000–$250,000

BDO is the fifth-largest professional services network globally, providing audit, tax, and advisory services through member firms in over 160 countries.

SOC 1SOC 2SOC 3ISO 27001+9

BDO Ireland

Dublin, Ireland

€20,000–€100,000

BDO Ireland offers SOC, ISO 27001, and GDPR compliance audit services.

SOC 2SOC 1ISO 27001GDPR+1

BDO Japan

Tokyo, Japan

$20,000–$100,000

BDO Japan is a mid-market audit and advisory firm providing ISO 27001, SOC 2, APPI, and P-Mark compliance services to mid-market companies and foreign-invested businesses operating in Japan.

SOC 1SOC 2ISO 27001ISO 27701+6

BDO Singapore

Singapore

$18,000–$80,000

BDO Singapore is a mid-market audit and advisory firm providing SOC 2, ISO 27001, PDPA, and MTCS compliance services to SMEs, mid-market firms, and listed companies in Singapore.

SOC 1SOC 2ISO 27001ISO 27701+5

BDO UAE

Dubai, UAE

$25,000–$120,000

BDO UAE is BDO International's member firm in the UAE, providing audit, tax, and advisory services with strong compliance capabilities for Gulf businesses.

SOC 1SOC 2ISO 27001ISO 27002+5

BDO UK LLP

London, United Kingdom

$20,000–$130,000

BDO UK is one of the UK's largest accountancy and business advisory firms, providing SOC 2, ISO 27001, GDPR, and Cyber Essentials audit services to mid-market and enterprise organizations.

SOC 1SOC 2ISO 27001ISO 27701+6

Berdon LLP

New York, NY

$12,000–$45,000

Berdon LLP is a New York-based CPA firm offering SOC 1, SOC 2, HIPAA, and IT audit services for mid-market real estate and financial services companies.

SOC 1SOC 2HIPAANIST CSF

Berger Toombs

Tucson, AZ

$14,000–$45,000

Berger Toombs is a Tucson CPA firm providing SOC and HIPAA audits.

SOC 2SOC 1HIPAA

Berkowitz Pollack Brant

Miami, FL

$18,000–$90,000

Berkowitz Pollack Brant is a Miami-based CPA and advisory firm founded in 1980, now part of Baker Tilly, offering SOC 1, SOC 2, and IT consulting services.

SOC 1SOC 2

BerryDunn

Portland, ME

$20,000–$100,000

BerryDunn is a Portland, Maine-based assurance and consulting firm delivering SOC 1/2, HIPAA, HITRUST, and NIST-based assessments nationwide.

SOC 1SOC 2HIPAAHITRUST+1

Beryllium InfoSec

Minneapolis, MN

$10,000–$60,000

Beryllium InfoSec is a Minneapolis-based compliance consultancy helping DoD contractors meet CMMC, NIST 800-171, and DFARS requirements via its Cuick Trac platform.

CMMCNIST 800-171NIST 800-53

Biovell Compliance

San Diego, CA

$12,000–$60,000

Biovell Compliance specializes in healthcare compliance with HIPAA, HITRUST, and ISO 27001 assessments.

HIPAAHITRUSTSOC 2ISO 27001

BKD CPAs & Advisors

Springfield, MO

$15,000–$70,000

BKD CPAs & Advisors is a leading mid-market US CPA firm based in Missouri offering SOC, ISO 27001, HIPAA, and cybersecurity audit services across the central United States.

SOC 1SOC 2ISO 27001HIPAA+3

BKM Sowan Horan

Dallas, TX

$18,000–$75,000

BKM Sowan Horan is a Dallas CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

Bland & Associates

Omaha, NE

$12,000–$55,000

Bland & Associates is an employee-owned Omaha, NE CPA firm founded in 1976, offering SOC 1 and SOC 2 examinations and assurance services.

SOC 1SOC 2

Blue & Co.

Carmel, IN

$20,000–$90,000

Blue & Co. is a Carmel, IN CPA and consulting firm offering SOC 1, SOC 2, HIPAA, and HITRUST compliance services with deep healthcare expertise.

SOC 1SOC 2HIPAAHITRUST

BlueVoyant

New York, NY

$20,000–$150,000

BlueVoyant is a New York-based cyber defense company and CMMC RPO providing NIST 800-171 and CMMC compliance services to defense contractors.

CMMCNIST 800-171NIST 800-53NIST CSF

BMSS Advisors & CPAs

Birmingham, AL

$15,000–$80,000

BMSS Advisors & CPAs is a Birmingham, AL accounting and advisory firm founded in 1991, providing SOC 1 and SOC 2 examinations and IT controls services.

SOC 1SOC 2

Bober Markey Fedorovich

Akron, OH

$15,000–$70,000

Bober Markey Fedorovich is an Akron, OH CPA and advisory firm founded in 1959, offering SOC 1 and SOC 2 examinations and assurance services.

SOC 1SOC 2

Bonadio Group

Pittsford, NY

$25,000–$120,000

The Bonadio Group is a top-50 CPA firm in Pittsford, NY whose information risk practice delivers SOC 1, SOC 2, HIPAA, HITRUST, and PCI DSS audits.

SOC 1SOC 2HIPAAHITRUST+1

Boulay Group

Minneapolis, MN

$20,000–$60,000

Boulay Group is a top-10 Minnesota CPA firm with 300+ professionals offering SOC reporting, HIPAA audits, and Microsoft SSPA assessments.

SOC 2SOC 1HIPAA

BPM LLP

San Jose, CA

$15,000–$65,000

BPM LLP is a leading West Coast accounting firm providing SOC 2, ISO 27001, and HIPAA audit services to technology companies and mid-market organizations in Silicon Valley and beyond.

SOC 1SOC 2ISO 27001HIPAA+4

Bridewell Consulting

Featured

Reading, United Kingdom

£20,000–£100,000

Bridewell Consulting is a UK cybersecurity firm offering ISO 27001, SOC 2, PCI DSS, and NIS2 assessments.

ISO 27001SOC 2PCI DSSGDPR+3

Brightsight BV

Delft, Netherlands

€25,000–€120,000

Brightsight is a Dutch security evaluation lab specializing in PCI, Common Criteria, and hardware security assessments.

PCI DSSISO 27001GDPR

Brisk InfoSec

Chennai, Tamil Nadu, India

₹250,000–₹1,500,000

Brisk InfoSec is a CREST-accredited, CERT-IN empanelled cybersecurity firm in Chennai with 100% ISO 27001 audit success rate.

ISO 27001SOC 2GDPRNIST CSF

British Assessment Bureau

Bury, UK

£2,500–£18,000

British Assessment Bureau is a UKAS-accredited certification body serving UK SMBs with ISO 27001, ISO 9001, and Cyber Essentials certifications.

ISO 27001ISO 9001ISO 14001ISO 45001+1

Brown Edwards

Roanoke, VA

$20,000–$100,000

Brown Edwards is a Roanoke, VA-based CPA firm with 13 offices across three states, offering SOC 1 and SOC 2 examinations and assurance services.

SOC 1SOC 2

BSI Group

Featured

London, UK

$10,000–$80,000

BSI Group is the world's first national standards body and largest ISO certification body, offering ISO 27001, ISO 27701, SOC 2, and Cyber Essentials audits globally.

ISO 27001ISO 27701ISO 27017ISO 27018+6

BSI Group

Featured

London, United Kingdom

$15,000–$100,000

BSI Group is the world's leading standards and certification body, providing ISO 27001, ISO 22301, and other management system certifications globally.

ISO 27001ISO 27002ISO 27017ISO 27018+8

BSI India

Featured

Mumbai, India

$5,000–$40,000

BSI India is a leading ISO certification body offering ISO 27001, ISO 9001, and ISO 27701 certifications.

ISO 27001ISO 9001ISO 14001ISO 22301+3

BSK Associates

Sacramento, CA

$16,000–$55,000

BSK Associates is a Sacramento CPA firm providing SOC and HIPAA compliance audits.

SOC 2SOC 1HIPAA

BSR & Associates LLP

Mumbai, India

$7,000–$50,000

BSR & Associates LLP is KPMG India's audit affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for enterprise and mid-market clients.

SOC 1SOC 2ISO 27001ISO 27701+4

BSR & Co (KPMG India affiliate)

Mumbai, India

$20,000–$150,000

BSR & Co is KPMG's affiliate firm in India, providing audit, assurance, tax, and advisory services with Big Four methodology to Indian enterprises.

SOC 1SOC 2ISO 27001HIPAA+4

Bulletproof

London, UK

£10,000–£50,000

Bulletproof is a London-based cybersecurity firm offering ISO 27001, SOC 2, PCI DSS, and GDPR compliance services alongside CREST-certified penetration testing.

ISO 27001SOC 2GDPRPCI DSS+1

Bureau Veritas

Featured

Paris, France

$12,000–$80,000

Bureau Veritas is a world-leading testing, inspection, and certification company providing ISO 27001 and management system certifications in 140+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

Cadre Information Security

Cincinnati, OH

$12,000–$75,000

Cadre Information Security is a Cincinnati-based security consultancy founded in 1992 offering ISO 27001, CMMC, and NIST CSF compliance and assessment services.

ISO 27001CMMCNIST CSF

Caliber Security Partners

Austin, TX

$12,000–$55,000

Caliber Security Partners is an Austin-based compliance firm specializing in SOC 2, HITRUST, and PCI DSS assessments.

SOC 2HITRUSTPCI DSSHIPAA+1

Camacho & Co

Bogota, Colombia

$4,000–$20,000

Camacho & Co is a Colombian CPA firm offering SOC, ISO 27001, and compliance audit services for mid-market companies in Colombia and the Andean region.

SOC 1SOC 2ISO 27001PCI DSS

CampusGuard

Omaha, NE

$10,000–$75,000

CampusGuard is a PCI QSA and ASV firm specializing in PCI DSS and HIPAA compliance for higher education, healthcare, and government organizations.

PCI DSSHIPAA

Canadian Cyber

Toronto, ON, Canada

CA$15,000–CA$50,000

Canadian Cyber is a Toronto-based cybersecurity and compliance firm specializing in ISO 27001, SOC 2, and privacy assessments for Canadian technology companies.

ISO 27001SOC 2GDPRPIPEDA

Carr Riggs & Ingram

Enterprise, AL

$20,000–$85,000

Carr Riggs & Ingram is a Top 25 CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

CBIZ

Cleveland, Ohio

$25,000–$130,000

CBIZ is a leading US business services company offering audit, tax, insurance, and advisory services through 100+ offices across the United States.

SOC 1SOC 2SOC 3ISO 27001+4

CBT Advisors

Boston, MA

$15,000–$60,000

CBT Advisors is a Boston-based CPA firm offering SOC 2, SOC 1, and HIPAA compliance audits for technology and healthcare companies.

SOC 2SOC 1HIPAA

Centri Business Consulting

Philadelphia, PA

$20,000–$100,000

Centri Business Consulting is a Philadelphia-based advisory firm providing SOC 1/SOC 2 reporting, ISO 27001, and SOX internal-controls services.

SOC 1SOC 2ISO 27001SOX

CERT-In Empaneled Auditors

New Delhi, India

$3,000–$50,000

CERT-In empaneled auditors are organizations authorized by India's Computer Emergency Response Team to conduct cybersecurity audits for regulatory compliance.

ISO 27001ISO 27002NIST CSFGDPR

Certification Europe

Dublin, Ireland

€5,000–€40,000

Certification Europe is an Irish-based accredited certification body specializing in ISO 27001 and management system certifications across Europe.

ISO 27001ISO 9001ISO 22301GDPR+1

CertPro

Singapore

$12,000–$45,000

CertPro is a Singapore-headquartered compliance firm offering SOC 2, ISO 27001, and PCI DSS certifications across Asia-Pacific, with offices in Hong Kong, Toronto, and London.

SOC 2ISO 27001PCI DSSGDPR+1

CGI Cybersecurity

Featured

Paris, France

€50,000–€500,000

CGI Cybersecurity offers enterprise-grade compliance services across ISO 27001, SOC 2, NIS2, and more.

ISO 27001SOC 2GDPRNIS2+4

CGI Sweden

Stockholm, Sweden

SEK 30,000–SEK 150,000

CGI Sweden offers ISO 27001, SOC 2, and NIS2 compliance assessments in the Nordics.

ISO 27001SOC 2GDPRNIS2+1

Charles River Associates

Boston, MA

$40,000–$200,000

Charles River Associates is a Boston-based global consulting firm founded in 1965 offering cyber risk, incident response, and forensic services.

NIST CSFISO 27001

Cherry Bekaert

Richmond, Virginia

$25,000–$120,000

Cherry Bekaert is a top-25 US CPA firm providing audit, tax, and advisory services with strong presence in the Southeast and growing national coverage.

SOC 1SOC 2SOC 3ISO 27001+4

Cipher Security

Miami, FL

$20,000–$120,000

Cipher Security is a global cybersecurity firm offering SOC 2, ISO 27001, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSHIPAA+4

cirosec GmbH

Heilbronn, Germany

€20,000–€80,000

cirosec is a German cybersecurity firm specializing in ISO 27001, BSI C5, and TISAX assessments.

ISO 27001C5GDPRNIS2+2

CISO Advisory

Sydney, Australia

A$20,000–A$80,000

CISO Advisory is a Sydney-based firm specializing in IRAP and Essential Eight assessments.

IRAPISO 27001Essential EightSOC 2+1

Citrin Cooperman

Featured

New York, NY

$25,000–$150,000

Citrin Cooperman is a Top 25 CPA firm offering comprehensive SOC, SOX, HIPAA, and ISO 27001 audit services.

SOC 2SOC 1SOC 3SOX+3

Claranet Cyber Security

London, United Kingdom

£20,000–£100,000

Claranet Cyber Security offers ISO 27001, PCI DSS, and Cyber Essentials assessments across Europe.

ISO 27001SOC 2PCI DSSGDPR+3

Clark Nuber

Bellevue, WA

$18,000–$70,000

Clark Nuber is a Bellevue CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

Clavister

Ornskoldsvik, Sweden

SEK 18,000–SEK 70,000

Clavister is a Swedish cybersecurity firm offering ISO 27001 and NIS2 compliance assessments.

ISO 27001GDPRNIS2NIST CSF

ClearDATA

Austin, TX

$20,000–$100,000

ClearDATA specializes in healthcare cloud compliance with HIPAA, HITRUST, and SOC 2 assessments.

HIPAAHITRUSTSOC 2ISO 27001+1

ClearView Audit Group

Denver, CO

$12,000–$50,000

ClearView Audit Group is a Denver CPA firm specializing in efficient SOC 2 and HIPAA audits for SaaS companies.

SOC 2SOC 1HIPAANIST CSF

Clearwater Compliance

Nashville, TN

$25,000–$150,000

Clearwater is a Nashville-based healthcare cybersecurity and compliance firm specializing in HIPAA risk analysis, HITRUST, and SOC 2 services.

HIPAAHITRUSTSOC 2NIST CSF

CliftonLarsonAllen

Featured

Minneapolis, MN

$25,000–$150,000

CliftonLarsonAllen is a Top 10 CPA firm offering SOC, SOX, HIPAA, FedRAMP, and ISO 27001 audits.

SOC 2SOC 1SOC 3SOX+6

CliftonLarsonAllen LLP

Featured

Minneapolis, MN

$20,000–$100,000

CliftonLarsonAllen (CLA) is a top-eight US CPA firm headquartered in Minneapolis, offering SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, and CMMC audit services nationally.

SOC 1SOC 2ISO 27001HIPAA+5

CNAS Accredited Certification Bodies

Beijing, China

$5,000–$40,000

CNAS is China's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and management system certifications in the Chinese market.

ISO 27001ISO 27701ISO 22301ISO 27017+2

Coalfire

Featured

Westminster, Colorado

$25,000–$150,000

Coalfire is a leading US cybersecurity advisory and audit firm specializing in FedRAMP, SOC 2, PCI DSS, HITRUST, and CMMC for cloud and technology companies.

SOC 1SOC 2ISO 27001ISO 27017+11

Coalfire UK

London, United Kingdom

£20,000–£100,000

Coalfire UK offers ISO 27001, SOC 2, PCI DSS, and Cyber Essentials compliance across the UK.

ISO 27001SOC 2PCI DSSGDPR+3

Coforge Cybersecurity

Noida, India

$8,000–$50,000

Coforge Cybersecurity provides ISO 27001, SOC 2, and PCI DSS compliance services globally.

ISO 27001SOC 2PCI DSSHIPAA+3

COFRAC Accredited Certification Bodies

Paris, France

$7,000–$45,000

COFRAC is France's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, HDS, and management system certifications.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Cognizant Middle East

Dubai, UAE

AED 60,000–AED 300,000

Cognizant Middle East provides ISO 27001, SOC 2, and NESA compliance services.

ISO 27001SOC 2PCI DSSNesa+2

Cohen & Company

Cleveland, OH

$25,000–$120,000

Cohen & Company is a top-tier Cleveland-based CPA firm with ~900 professionals offering SOC 1 and SOC 2 attestation alongside assurance, tax, and advisory.

SOC 1SOC 2

CohnReznick Advisory

Featured

New York, NY

$25,000–$120,000

CohnReznick Advisory is a Top 25 CPA firm offering SOC, SOX, and FedRAMP compliance audits.

SOC 2SOC 1SOXHIPAA+2

CohnReznick LLP

New York, NY

$20,000–$100,000

CohnReznick is a top-20 US accounting firm providing SOC 2, ISO 27001, HIPAA, and financial audit services to mid-market and enterprise clients across technology, financial services, and healthcare.

SOC 1SOC 2ISO 27001HIPAA+6

Compass IT Compliance

Providence, RI

$15,000–$60,000

Compass IT Compliance is a Providence-based QSA and HITRUST assessor offering PCI DSS, SOC 2, HIPAA, and penetration testing for financial and healthcare organizations.

PCI DSSSOC 2HIPAAHITRUST+2

Compass IT Compliance

Tampa, FL

$15,000–$75,000

Compass IT Compliance is a PCI DSS specialist firm serving retail, healthcare, and hospitality organizations. Profile includes pricing and framework coverage.

PCI DSSHIPAAHITRUSTSOC 2+1

Compass Security

Rapperswil, Switzerland

CHF 20,000–CHF 80,000

Compass Security is a Swiss cybersecurity firm offering ISO 27001, SOC 2, and penetration testing services.

ISO 27001SOC 2GDPRNIST CSF+1

Compliance Solutions ME

Dubai, UAE

$8,000–$40,000

Compliance Solutions ME is a boutique GRC consultancy in Dubai specializing in ISO 27001, PCI DSS, and GDPR compliance for Middle Eastern organizations.

ISO 27001PCI DSSGDPRNIST CSF+1

ComplianceForge

Scottsdale, Arizona

$5,000–$40,000

ComplianceForge provides cybersecurity documentation templates, consulting, and NIST/CMMC/ISO implementation support for organizations building compliance programs.

NIST CSFNIST 800-53ISO 27001ISO 27002+6

CompliancePoint

Duluth, GA

$20,000–$70,000

CompliancePoint is a HITRUST-authorized assessor in Georgia offering SOC 2, HITRUST, HIPAA, and ISO 27001 audits for healthcare and technology companies.

HITRUSTSOC 2HIPAAISO 27001+2

Condley and Company

Abilene, TX

$15,000–$60,000

Condley and Company is an Abilene, TX CPA firm founded in 1939 offering SOC 1 and SOC 2 examinations plus audit, tax, and consulting services.

SOC 1SOC 2

CoNetrix

Lubbock, TX

$8,000–$40,000

CoNetrix is a Lubbock, TX technology family of companies providing IT audits, security testing, and the Tandem compliance software suite to financial institutions.

NIST CSF

Conscia Norway

Oslo, Norway

NOK 20,000–NOK 80,000

Conscia Norway is a Nordic cybersecurity firm offering ISO 27001, SOC 2, and NIS2 compliance assessments.

ISO 27001SOC 2GDPRNIS2+1

Control Risks

London

$40,000–$200,000

Control Risks is a London-based global risk consultancy founded in 1975, offering cyber security consulting, data privacy, and risk assessments.

NIST CSFISO 27001GDPR

ControlCase

Fairfax, Virginia

$15,000–$80,000

ControlCase is a compliance and cybersecurity firm specializing in PCI DSS, SOC 2, ISO 27001, and HITRUST audits with a unified compliance approach.

SOC 1SOC 2ISO 27001ISO 27002+10

ControlCase India

Mumbai, India

$5,000–$35,000

ControlCase India offers PCI DSS, ISO 27001, SOC 2, and HITRUST assessments at competitive pricing.

PCI DSSISO 27001SOC 2HITRUST+3

Coretelligent

Westwood, MA

$10,000–$50,000

Coretelligent is a Massachusetts-based managed IT provider delivering cybersecurity and compliance services to financial and life sciences firms.

SOC 2NIST CSFHIPAA

CQA - Canada Quality Audit

Toronto, Canada

$8,000–$35,000

CQA (Canada Quality Audit) is a Canadian SCC-accredited ISO certification body offering ISO 27001, ISO 27701, and management system certifications across Canada.

ISO 27001ISO 27701ISO 22301ISO 27017

CRI Advantage

Virginia Beach, VA

$20,000–$100,000

CRI Advantage specializes in FedRAMP, CMMC, and NIST compliance assessments for government contractors.

SOC 2CMMCFedRAMPNIST 800-53+2

CrossCountry Consulting

McLean, VA

$25,000–$150,000

CrossCountry Consulting is a McLean, VA business advisory firm founded in 2011, offering SOC 1/SOC 2 readiness, SOX, and risk advisory services.

SOC 1SOC 2SOXNIST CSF

Crowe Global

Featured

New York, United States

$35,000–$200,000

Crowe Global is a top-10 global accounting network providing audit, tax, and advisory services through member firms in over 145 countries worldwide.

SOC 1SOC 2SOC 3ISO 27001+6

Crowe Middle East

Dubai, UAE

$18,000–$80,000

Crowe Middle East is a mid-market audit and advisory firm providing ISO 27001, SOC 2, NESA, and PDPL compliance services to SMEs and mid-market businesses across the UAE, Saudi Arabia, and Bahrain.

SOC 1SOC 2ISO 27001ISO 27701+5

CSP & Associates

Reston, VA

$25,000–$120,000

CSP & Associates is a FedRAMP 3PAO and CMMC assessment firm serving government contractors.

FedRAMPCMMCNIST 800-53NIST 800-171+2

Ctrl S Cybersecurity

Abu Dhabi, UAE

AED 40,000–AED 200,000

Ctrl S Cybersecurity provides ISO 27001, PCI DSS, and NESA compliance in the UAE.

ISO 27001SOC 2PCI DSSNesa+1

CWatch Middle East

Dubai, UAE

AED 40,000–AED 200,000

CWatch Middle East offers ISO 27001, SOC 2, and PCI DSS assessments across the GCC.

ISO 27001SOC 2PCI DSSNesa+2

Cyanre Digital Forensics

Pretoria, South Africa

ZAR 100,000–ZAR 500,000

Cyanre offers digital forensics and ISO 27001 compliance assessments in South Africa.

ISO 27001POPIANIST CSFSOC 2

Cyber Forte

Melbourne, VIC, Australia

A$18,000–A$45,000

Cyber Forte is a Melbourne-based compliance firm delivering fast-tracked SOC 2 and ISO 27001 certification with 100% first-attempt success rate for Australian tech companies.

SOC 2ISO 27001PCI DSS

Cyber Risk Opportunities

Seattle, WA

$8,000–$30,000

Cyber Risk Opportunities is a Seattle-based boutique consultancy providing vCISO services and NIST CSF-based cyber risk management to mid-market firms.

NIST CSF

CyberCX

Melbourne

$25,000–$250,000

CyberCX is Australia's largest cybersecurity firm, offering IRAP, ISO 27001, SOC 2, PCI DSS, and Essential Eight assessment and advisory services.

SOC 2ISO 27001IRAPPCI DSS+1

CyberCX New Zealand

Auckland, New Zealand

NZ$20,000–NZ$90,000

CyberCX New Zealand offers ISO 27001, SOC 2, and PCI DSS assessments across New Zealand.

ISO 27001SOC 2PCI DSSPrivacy Act+1

CyberDefense Canada

Vancouver, BC

CA$15,000–CA$55,000

CyberDefense Canada offers SOC 2, ISO 27001, and PCI DSS assessments across Western Canada.

SOC 2ISO 27001PIPEDANIST CSF+1

CyberGuard Compliance

Las Vegas, NV

$12,000–$60,000

CyberGuard Compliance is a Las Vegas-based, PCAOB-registered CPA firm focused exclusively on SOC, PCI DSS, HITRUST, and HIPAA compliance audits.

SOC 1SOC 2SOC 3ISO 27001+3

CyberGuard360

Orlando, FL

$12,000–$50,000

CyberGuard360 provides SOC 2, CMMC, and NIST compliance assessments for SMBs and government contractors.

SOC 2CMMCNIST CSFNIST 800-171+1

CyberHunter Solutions

Ottawa, ON

$8,000–$40,000

CyberHunter Solutions is an Ottawa-based boutique cybersecurity firm founded in 2016, offering penetration testing, security audits, and ISO 27001 support.

ISO 27001NIST CSF

CyberInt Malaysia

Kuala Lumpur, Malaysia

MYR 10,000–MYR 50,000

CyberInt Malaysia offers ISO 27001, SOC 2, and PCI DSS assessments for Malaysian enterprises.

ISO 27001SOC 2PCI DSSPdpa+1

Cyberis (US)

Washington, DC

$20,000–$100,000

Cyberis is a transatlantic cybersecurity consultancy offering SOC 2, ISO 27001, and PCI DSS assessments.

SOC 2ISO 27001PCI DSSNIST CSF+2

CyberMerc

Canberra, Australia

A$20,000–A$80,000

CyberMerc is a Canberra-based IRAP assessor offering Essential Eight and ISO 27001 compliance.

IRAPISO 27001Essential EightSOC 2+1

CyberNinja

Sydney, Australia

A$20,000–A$60,000

CyberNinja is a Sydney-based cybersecurity firm offering IRAP assessments, ISO 27001, SOC 2, and Essential Eight compliance for Australian organizations.

ISO 27001SOC 2Essential Eight

CyberNX Technologies

Mumbai, Maharashtra, India

₹300,000–₹1,500,000

CyberNX Technologies is a Mumbai-based CERT-IN empanelled cybersecurity firm offering cloud security, VAPT, and managed detection services for Indian enterprises.

ISO 27001SOC 2

CyberQ Consulting

Bangalore, Karnataka, India

₹400,000–₹2,000,000

CyberQ Consulting is a Bangalore-based CERT-IN empanelled information security auditor with expertise in government, telecom, and critical infrastructure security.

ISO 27001SOC 2

CyberSapiens

Melbourne, Australia

A$15,000–A$50,000

CyberSapiens is an Australian cybersecurity firm offering SOC 2, ISO 27001, PCI DSS, and HIPAA compliance services for ANZ technology companies.

SOC 2ISO 27001PCI DSSHIPAA+2

CyberSec Knight

Dubai, UAE

AED 30,000–AED 150,000

CyberSec Knight offers ISO 27001 and SOC 2 assessments for GCC startups and SMEs.

ISO 27001SOC 2PCI DSSNesa+1

CyberSecOp

New York, NY

$10,000–$75,000

CyberSecOp is a New York-based security consultancy and CMMC RPO delivering SOC 2, ISO 27001, HIPAA, and PCI compliance readiness and advisory services.

CMMCSOC 2ISO 27001HIPAA+3

CyberSheath

Reston, VA

$15,000–$100,000

CyberSheath is a Reston, VA compliance firm dedicated to DoD contractor requirements, delivering CMMC, NIST 800-171, and DFARS assessment and managed services.

CMMCNIST 800-171

CyberSmart

London, UK

£300–£8,000

CyberSmart is a UK-based Cyber Essentials specialist providing automated compliance certification for SMBs and startups.

Cyber EssentialsISO 27001GDPR

CyberTalents ME

Dubai, UAE

AED 30,000–AED 150,000

CyberTalents ME offers ISO 27001 and SOC 2 assessments across the MENA region.

ISO 27001SOC 2NesaPdpl+1

CyCraft Technology

Taipei, Taiwan

NT$300,000–NT$1,500,000

CyCraft Technology is a Taiwanese AI cybersecurity firm offering ISO 27001 and SOC 2 assessments.

ISO 27001SOC 2NIST CSF

Cyient Cybersecurity

Hyderabad, India

$6,000–$35,000

Cyient Cybersecurity provides ISO 27001 and SOC 2 compliance for technology and defense sectors.

ISO 27001SOC 2HIPAADPDPA+1

Dansa D'Arata Soucia LLP

Buffalo, NY

$10,000–$45,000

Dansa D'Arata Soucia LLP is a Buffalo, NY full-service CPA firm offering SOC 1, SOC 2, and SOC 3 attestation plus information security consulting.

SOC 1SOC 2SOC 3ISO 27001+2

DarkMatter Group

Featured

Abu Dhabi, UAE

AED 80,000–AED 400,000

DarkMatter Group is a UAE cybersecurity firm offering ISO 27001, SOC 2, and NESA compliance assessments.

ISO 27001SOC 2PCI DSSNesa+4

Daszkal Bolton

Boca Raton, FL

$15,000–$55,000

Daszkal Bolton is a South Florida CPA firm providing SOC and HIPAA compliance audit services.

SOC 2SOC 1HIPAA

Data#3 Cybersecurity

Brisbane, Australia

A$25,000–A$100,000

Data#3 Cybersecurity offers IRAP, ISO 27001, and Essential Eight assessments across Australia.

IRAPISO 27001SOC 2Essential Eight+2

Datacentrix

Midrand, South Africa

ZAR 150,000–ZAR 800,000

Datacentrix provides ISO 27001, SOC 2, and PCI DSS compliance in South Africa.

ISO 27001SOC 2PCI DSSPOPIA

DataLink Networks

Los Angeles, CA

$15,000–$70,000

DataLink Networks provides SOC 2, ISO 27001, and PCI DSS compliance assessments in Southern California.

SOC 2ISO 27001PCI DSSHIPAA+2

DataProtect

Casablanca, Morocco

€12,000–€50,000

DataProtect is a Morocco-based cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments in North Africa.

ISO 27001SOC 2PCI DSSGDPR

DBAPPSecurity

Hangzhou, China

CN¥150,000–CN¥800,000

DBAPPSecurity is a Hangzhou cybersecurity firm offering ISO 27001, MLPS, and PIPL compliance.

ISO 27001MlpsPIPLSOC 2+1

Defense Works

Edinburgh, United Kingdom

£3,000–£20,000

Defense Works provides affordable Cyber Essentials and ISO 27001 assessments for Scottish businesses.

Cyber EssentialsISO 27001GDPRNIST CSF

DEKRA

Stuttgart, Germany

$8,000–$55,000

DEKRA is one of the world's largest testing, inspection, and certification organizations offering ISO 27001, ISO 27701, and management system certifications globally.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Deloitte

Featured

London, United Kingdom

$75,000–$500,000

Deloitte is the world's largest professional services firm, offering audit, assurance, tax, and advisory services across 150+ countries worldwide.

SOC 1SOC 2SOC 3ISO 27001+16

Deloitte Australia

Featured

Sydney, Australia

$45,000–$300,000

Deloitte Australia is a Big Four professional services firm providing SOC 2, ISO 27001, IRAP, Essential Eight, and enterprise risk advisory services to Australia's largest organizations across government, financial services, and technology.

SOC 1SOC 2ISO 27001ISO 27701+8

Deloitte Canada

Featured

Toronto, Canada

$50,000–$350,000

Deloitte Canada is the country's largest Big Four professional services firm, providing SOC 2, ISO 27001, PIPEDA, SOX, and enterprise risk advisory services across financial services, technology, energy, and government sectors.

SOC 1SOC 2ISO 27001ISO 27701+6

Deloitte Haskins & Sells LLP

Featured

Mumbai, India

$8,000–$60,000

Deloitte Haskins & Sells is Deloitte's primary India affiliate, offering SOC 1, SOC 2, ISO 27001, DPDPA, and compliance audit services across India.

SOC 1SOC 2ISO 27001ISO 27701+4

Deloitte India

Featured

Mumbai, India

$28,000–$230,000

Deloitte India is a Big Four professional services firm providing SOC 2, ISO 27001, DPDPA, SOX, and comprehensive risk advisory services to India's largest corporations and multinational subsidiaries.

SOC 1SOC 2ISO 27001ISO 27701+7

Deloitte Middle East

Featured

Dubai, UAE

$60,000–$400,000

Deloitte Middle East is the region's largest professional services firm, providing Big Four audit, assurance, and advisory services across the MENA region.

SOC 1SOC 2ISO 27001ISO 27002+7

Deloitte Singapore

Featured

Singapore

$40,000–$250,000

Deloitte Singapore is a Big Four professional services firm providing SOC 2, ISO 27001, PDPA, MTCS, and enterprise risk advisory services to major corporations and government agencies across Singapore and Southeast Asia.

SOC 1SOC 2ISO 27001ISO 27701+7

Deloitte Tohmatsu

Featured

Tokyo, Japan

$60,000–$400,000

Deloitte Tohmatsu is Deloitte's Japanese member firm and one of Japan's largest audit firms, providing Big Four services including J-SOX and ISMAP compliance.

SOC 1SOC 2ISO 27001ISO 27002+7

Deloitte Touche Tohmatsu Brazil

Featured

Sao Paulo, Brazil

$10,000–$80,000

Deloitte Brazil is the largest professional services firm in Latin America, offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services.

SOC 1SOC 2ISO 27001ISO 27701+4

DIESEC

Helsinki, Finland

€20,000–€80,000

DIESEC is a Nordic cybersecurity and compliance firm offering ISO 27001, NIS2, and SOC 2 services across Finland, Sweden, Norway, and Denmark.

ISO 27001SOC 2NIS2GDPR

Dimension Data South Africa

Johannesburg, South Africa

ZAR 200,000–ZAR 1,000,000

Dimension Data South Africa provides ISO 27001, SOC 2, and PCI DSS compliance assessments.

ISO 27001SOC 2PCI DSSPOPIA+1

DIN CERTCO

Berlin, Germany

$8,000–$45,000

DIN CERTCO is a German DAkkS-accredited ISO certification body offering ISO 27001, ISO 27701, and management system certifications for European organizations.

ISO 27001ISO 27701ISO 22301GDPR+1

Dionach

Oxford, United Kingdom

£15,000–£80,000

Dionach is an Oxford-based cybersecurity firm offering PCI DSS QSA, ISO 27001, and Cyber Essentials assessments.

ISO 27001PCI DSSGDPRCyber Essentials+2

DirectDefense

Englewood, CO

$15,000–$120,000

DirectDefense is a Colorado security services firm founded in 2011 offering PCI, CMMC, HIPAA, ISO 27001, and NERC CIP compliance assessments and managed security.

PCI DSSCMMCHIPAAISO 27001+2

Dixon Hughes Goodman LLP

Charlotte, NC

$15,000–$60,000

Dixon Hughes Goodman (DHG) is a leading Southeast US CPA firm offering SOC 1, SOC 2, ISO 27001, and HIPAA compliance audit services for mid-market companies.

SOC 1SOC 2ISO 27001HIPAA+3

DNV

Featured

Oslo, Norway

$12,000–$80,000

DNV is a global assurance and risk management company providing ISO 27001, ISO 22301, and management system certifications across 100+ countries worldwide.

ISO 27001ISO 27002ISO 27017ISO 27701+5

Doeren Mayhew

Troy, MI

$20,000–$100,000

Doeren Mayhew is a Troy, Michigan CPA firm dating to 1932 offering SOC 1/2 examinations, HIPAA, and NIST-based technology assurance services.

SOC 1SOC 2HIPAANIST CSF

DQS

Frankfurt, Germany

€10,000–€60,000

DQS is a German-headquartered global certification body offering ISO 27001, TISAX, ISO 27701, and management system audits across 60+ countries.

ISO 27001ISO 27701SOC 2TISAX

Drawbridge

Palm Beach Gardens, FL

$10,000–$50,000

Drawbridge is a Florida-based cybersecurity firm delivering cyber risk assessments and GRC programs for hedge funds and private equity firms.

NIST CSFSOC 2

ECI

Boston, MA

$12,000–$70,000

ECI, formerly Eze Castle Integration, is a Boston-based managed services provider delivering cybersecurity and compliance support to financial firms.

SOC 2NIST CSF

Edgescan

Dublin, Ireland

€12,000–€60,000

Edgescan provides vulnerability management and ISO 27001 compliance assessments.

ISO 27001SOC 2GDPRNIS2+2

Eide Bailly

Featured

Fargo, ND

$20,000–$90,000

Eide Bailly is a Top 25 CPA firm offering SOC, SOX, HIPAA, and ISO 27001 audit services.

SOC 2SOC 1SOXHIPAA+1

EisnerAmper

New York, New York

$30,000–$150,000

EisnerAmper is a top-20 US accounting and advisory firm offering audit, tax, and cybersecurity services with strong presence in the Northeast and nationally.

SOC 1SOC 2SOC 3ISO 27001+6

ElevenPaths (Telefonica Cyber)

Featured

Madrid, Spain

€20,000–€120,000

ElevenPaths (Telefonica Cyber) offers ISO 27001, PCI DSS, and ENS compliance across Europe and Latin America.

ISO 27001SOC 2PCI DSSENS+4

Elliott Davis

Greenville, SC

$20,000–$80,000

Elliott Davis is a Top 40 CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

En4see

Kuala Lumpur, Malaysia

MYR 20,000–MYR 80,000

En4see is a Malaysian cybersecurity and compliance firm specializing in ISO 27001 implementation and certification support for Malaysian and Southeast Asian organizations.

ISO 27001

Ensign InfoSecurity

Featured

Singapore

SGD 20,000–SGD 100,000

Ensign InfoSecurity is Singapore's largest cybersecurity firm offering ISO 27001, SOC 2, and MTCS assessments.

ISO 27001SOC 2PCI DSSMtcs+3

Epicit

Perth, WA, Australia

A$15,000–A$50,000

Epicit is a Perth-based IT services and cybersecurity firm offering Essential Eight, ISO 27001, and APRA CPS 234 compliance for Western Australian businesses.

ISO 27001Essential EightPCI DSS

Ernst & Young (EY)

Featured

London, United Kingdom

$70,000–$500,000

EY is a Big Four professional services firm providing audit, assurance, tax, consulting, and strategy services across more than 150 countries worldwide.

SOC 1SOC 2SOC 3ISO 27001+16

Ernst & Young Brazil

Featured

Sao Paulo, Brazil

$10,000–$70,000

EY Brazil is Ernst & Young's Brazilian member firm offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services across Brazil.

SOC 1SOC 2ISO 27001ISO 27701+3

eSec Forte Technologies

Gurugram, Haryana, India

₹500,000–₹2,500,000

eSec Forte is a CMMi Level 3 certified, CERT-IN empanelled cybersecurity firm in Gurugram offering PCI DSS QSA, SOC 2, and ISO 27001 audits.

PCI DSSSOC 2ISO 27001HIPAA

ESET Enterprise Security

Bratislava, Slovakia

€15,000–€60,000

ESET Enterprise provides ISO 27001 and NIS2 compliance assessments in Central Europe.

ISO 27001GDPRNIS2NIST CSF

Etek International

Bogota, Colombia

$10,000–$50,000

Etek International offers ISO 27001, SOC 2, and PCI DSS compliance across Latin America.

ISO 27001SOC 2PCI DSSNIST CSF

Eurofins Assurance

Paris, France

€15,000–€50,000

Eurofins Assurance is the certification division of the Eurofins Group, offering ISO 27001 and management system audits across Europe with multi-country accreditation.

ISO 27001ISO 27701GDPR

Exiger

New York, NY

$25,000–$150,000

Exiger provides AI-powered compliance and risk management assessment services.

SOC 2ISO 27001NIST CSFFedRAMP+1

Exprivia Cybersecurity

Bari, Italy

€20,000–€90,000

Exprivia offers ISO 27001, GDPR, and NIS2 compliance assessments in Italy.

ISO 27001GDPRNIS2SOC 2+1

EY Australia

Featured

Sydney, Australia

$40,000–$280,000

EY Australia is a Big Four professional services firm providing SOC 2, ISO 27001, IRAP, Essential Eight, and enterprise risk advisory services across financial services, technology, and government sectors in Australia.

SOC 1SOC 2ISO 27001ISO 27701+8

EY France

Featured

Paris, France

$40,000–$280,000

EY France is a Big Four professional services firm providing ISO 27001, GDPR, HDS, SOC 2, and enterprise risk advisory services to French enterprises across financial services, technology, and manufacturing.

SOC 1SOC 2ISO 27001ISO 27701+6

EY Germany

Featured

Stuttgart, Germany

$45,000–$320,000

EY Germany is a Big Four professional services firm providing ISO 27001, C5, TISAX, SOC 2, and GDPR compliance services to German enterprises, automotive companies, and financial institutions.

SOC 1SOC 2ISO 27001ISO 27701+7

EY India

Featured

Mumbai, India

$25,000–$220,000

EY India is the largest Big Four operation in India by headcount, providing SOC 2, ISO 27001, DPDPA, SOX, and comprehensive risk advisory services across all major industries.

SOC 1SOC 2ISO 27001ISO 27701+7

EY Japan

Featured

Tokyo, Japan

$60,000–$350,000

EY Japan (EY ShinNihon) provides Big Four audit, assurance, and advisory services with expertise in J-SOX, ISMAP, and Japanese regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+6

EY MENA

Featured

Dubai, UAE

$55,000–$350,000

EY MENA provides Big Four audit, assurance, tax, and advisory services across the Middle East and North Africa with offices in 15+ MENA countries.

SOC 1SOC 2ISO 27001ISO 27002+7

EY Singapore

Featured

Singapore

$50,000–$280,000

EY Singapore provides Big Four audit, assurance, and advisory services with strong cybersecurity and regulatory compliance capabilities for the ASEAN market.

SOC 1SOC 2ISO 27001ISO 27002+7

Fluid Attacks

Bogota, Colombia

$10,000–$50,000

Fluid Attacks is a Colombian cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSHIPAA+2

Focal Point Data Risk

Tampa, FL

$18,000–$90,000

Focal Point Data Risk offers SOC 2, ISO 27001, HITRUST, and PCI DSS compliance assessments.

SOC 2ISO 27001PCI DSSHITRUST+3

Foo Kon Tan LLP

Singapore

$8,000–$35,000

Foo Kon Tan is a leading Singapore CPA firm offering SOC 1, SOC 2, ISO 27001, PDPA, and compliance audit services for SME and mid-market companies.

SOC 1SOC 2ISO 27001ISO 27701+2

Foregenix

London, United Kingdom

£15,000–£80,000

Foregenix is a UK PCI QSA and forensic investigator offering PCI DSS, ISO 27001, and Cyber Essentials.

PCI DSSISO 27001GDPRCyber Essentials+1

Fortian

Sydney, Australia

A$15,000–A$60,000

Fortian provides ISO 27001, SOC 2, and Essential Eight assessments for Australian businesses.

ISO 27001SOC 2IRAPEssential Eight+1

Forvis Mazars (US)

Featured

Springfield, Missouri

$30,000–$180,000

Forvis Mazars is a top-10 US professional services firm formed from the merger of BKD and Dixon Hughes Goodman, now part of the Mazars global network.

SOC 1SOC 2SOC 3ISO 27001+6

Frank Rimerman + Co.

Palo Alto, CA

$20,000–$100,000

Frank, Rimerman + Co. is a Palo Alto CPA firm founded in 1949, the largest headquartered in Silicon Valley, offering SOC 1, SOC 2, and IT audit services.

SOC 1SOC 2

Frazier & Deeter

Atlanta, GA

$25,000–$120,000

Frazier & Deeter is a Top 75 CPA firm in Atlanta offering comprehensive compliance audit services.

SOC 2SOC 1SOC 3HIPAA+2

Freed Maxick

Buffalo, NY

$20,000–$85,000

Freed Maxick is a regional CPA firm in Buffalo offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

Friedman LLP

New York, NY

$12,000–$45,000

Friedman LLP is a New York-based CPA firm offering SOC 1, SOC 2, HIPAA, and PCI DSS compliance audits for mid-market companies in the tristate area.

SOC 1SOC 2HIPAAPCI DSS+1

FRSecure

Minnetonka, MN

$10,000–$60,000

FRSecure is a Minnetonka, MN information security firm providing risk assessments and compliance readiness for SOC 2, ISO 27001, HIPAA, and PCI DSS.

SOC 2ISO 27001HIPAAPCI DSS+1

FTI Consulting

Washington, DC

$50,000–$250,000

FTI Consulting is a global expert firm founded in 1982, headquartered in Washington, DC, offering cybersecurity, risk, and regulatory compliance advisory.

NIST CSFNIST 800-171CMMCHIPAA+3

GBQ Partners

Columbus, OH

$20,000–$90,000

GBQ Partners is a top-100 Columbus, OH CPA and advisory firm providing SOC 1 and SOC 2 reporting and IT risk advisory services.

SOC 1SOC 2

Geels Norton

Plymouth, MN

$10,000–$45,000

Geels Norton, a Smith + Howard company, is a Minnesota-based CPA firm delivering SOC 2 audits and ISO 27001 advisory for cloud technology companies.

SOC 1SOC 2ISO 27001

genua GmbH

Kirchheim, Germany

€25,000–€100,000

genua is a German IT security company offering ISO 27001 and BSI C5 compliance assessments.

ISO 27001C5GDPRNIS2

Globant Cybersecurity

Buenos Aires, Argentina

$15,000–$80,000

Globant Cybersecurity offers ISO 27001, SOC 2, and PCI DSS compliance across the Americas.

ISO 27001SOC 2PCI DSSHIPAA+2

GMO Cybersecurity

Tokyo, Japan

¥2,000,000–¥8,000,000

GMO Cybersecurity offers ISO 27001, P-Mark, and PCI DSS assessments for Japanese technology companies.

ISO 27001SOC 2PCI DSSIsms P+1

GoSecure

Montreal, QC

$10,000–$60,000

GoSecure is a Montreal-based cybersecurity firm offering managed detection and response alongside compliance and security advisory services.

NIST CSFISO 27001PCI DSS

Grant Thornton

Featured

London, United Kingdom

$40,000–$250,000

Grant Thornton is a leading global professional services network providing audit, tax, and advisory services through member firms in over 140 countries.

SOC 1SOC 2SOC 3ISO 27001+9

Grant Thornton Bharat

New Delhi, India

$15,000–$120,000

Grant Thornton Bharat is one of India's largest professional services firms, offering audit, tax, and advisory services including cybersecurity and compliance.

SOC 1SOC 2ISO 27001ISO 27701+5

Grant Thornton LLP

Featured

Chicago, IL

$30,000–$150,000

Grant Thornton US is a top-seven national CPA firm offering SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, FedRAMP, and CMMC audit services for mid-market and enterprise companies.

SOC 1SOC 2ISO 27001HIPAA+8

Grant Thornton Netherlands

Amsterdam, Netherlands

€25,000–€100,000

Grant Thornton Netherlands provides SOC, ISO 27001, and GDPR compliance audit services.

SOC 2SOC 1ISO 27001GDPR+1

Grant Thornton UAE

Dubai, UAE

$20,000–$100,000

Grant Thornton UAE is a mid-market audit and advisory firm providing ISO 27001, SOC 2, NESA, and PDPL compliance services to businesses across the UAE.

SOC 1SOC 2ISO 27001ISO 27701+5

Grant Thornton UK LLP

London, United Kingdom

$20,000–$120,000

Grant Thornton UK is a major mid-tier audit and advisory firm providing SOC 2, ISO 27001, GDPR, and financial audit services to UK businesses from startups to listed companies.

SOC 1SOC 2ISO 27001ISO 27701+6

Grassi & Co

New York, NY

$12,000–$50,000

Grassi & Co is a New York-based mid-market CPA firm offering SOC 1, SOC 2, HIPAA, and PCI DSS compliance audit services for SMBs and mid-market companies.

SOC 1SOC 2HIPAAPCI DSS+2

Grassi Advisors & Accountants

New York, NY

$22,000–$90,000

Grassi is a Top 100 CPA firm in New York offering SOC, SOX, and HIPAA audit services.

SOC 2SOC 1SOXHIPAA

GreyCastle Security

Troy, NY

$10,000–$60,000

GreyCastle Security is a Troy, NY cybersecurity services firm, now part of DeepSeas, providing risk assessments and ISO 27001, HIPAA, and NIST CSF advisory.

ISO 27001HIPAANIST CSF

Gridware

Sydney, NSW, Australia

A$20,000–A$60,000

Gridware is a Sydney-based ISMS consultancy with PECB lead auditors delivering ISO 27001 implementations and Essential Eight assessments across Australian cities.

ISO 27001Essential EightNIST CSF

GuidePoint Security

Featured

Herndon, VA

$20,000–$150,000

GuidePoint Security offers SOC 2, ISO 27001, FedRAMP, and CMMC compliance assessments.

SOC 2ISO 27001PCI DSSFedRAMP+4

GunnChamberlain

Portland, OR

$14,000–$45,000

GunnChamberlain is a Portland CPA firm offering SOC 2 and SOC 1 audits for technology companies.

SOC 2SOC 1

HALOCK Security Labs

Schaumburg, IL

$15,000–$80,000

HALOCK Security Labs offers SOC 2, ISO 27001, HITRUST, and PCI DSS compliance assessments.

SOC 2ISO 27001PCI DSSHITRUST+3

Hancock Askew & Co

Savannah, GA

$15,000–$75,000

Hancock Askew & Co, a century-old Savannah CPA firm now part of Baker Tilly, provides SOC 1, SOC 2, and SOC 3 examinations and risk assurance.

SOC 1SOC 2SOC 3ISO 27001

Haysmacintyre LLP

London, UK

$10,000–$45,000

Haysmacintyre is a London-based chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials compliance audit services for mid-market organizations.

ISO 27001SOC 2GDPRCyber Essentials+1

HBS Group

Memphis, TN

$18,000–$70,000

HBS Group is a Memphis CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1HIPAASOX

HCLTech Cybersecurity

Featured

Noida, India

$15,000–$200,000

HCLTech Cybersecurity provides enterprise compliance services across ISO 27001, SOC, PCI DSS, and NIST.

ISO 27001SOC 2SOC 1PCI DSS+5

HCVT

Los Angeles, CA

$25,000–$150,000

HCVT (Holthouse Carlin & Van Trigt) is the largest Los Angeles-based CPA firm, providing SOC 1 and SOC 2 examinations alongside audit and tax.

SOC 1SOC 2

Hein & Associates

Denver, CO

$20,000–$80,000

Hein & Associates is a Denver CPA firm offering SOC and SOX compliance audit services.

SOC 2SOC 1SOX

Help AG

Featured

Dubai, UAE

AED 60,000–AED 300,000

Help AG is one of the largest cybersecurity firms in the Middle East offering ISO 27001, SOC 2, and NESA assessments.

ISO 27001SOC 2PCI DSSNesa+4

Hexaware Cybersecurity

Mumbai, India

$6,000–$40,000

Hexaware Cybersecurity offers ISO 27001 and SOC 2 compliance services.

ISO 27001SOC 2HIPAAGDPR+2

HLB International

London, United Kingdom

$20,000–$130,000

HLB International is a global advisory and accounting network with 40,000+ professionals in member firms spanning 156 countries and territories.

SOC 1SOC 2ISO 27001HIPAA+3

HoganTaylor

Tulsa, OK

$15,000–$80,000

HoganTaylor is a Tulsa-based CPA and advisory firm whose risk assurance team delivers SOC reports, HITRUST validated assessments, and CMMC services.

SOC 1SOC 2HITRUSTCMMC

Holbrook & Manter

Columbus, OH

$20,000–$60,000

Holbrook & Manter is a century-old Ohio CPA firm highly regarded for SOC reporting with team holding CITP, CISSP, CISA, and ISO 27001 Lead Auditor certifications.

SOC 2SOC 1ISO 27001HIPAA

Holtzman Partners

Southfield, MI

$16,000–$55,000

Holtzman Partners is a Michigan CPA firm providing SOC and HIPAA compliance audits.

SOC 2SOC 1HIPAA

Horangi Cyber Security

Singapore

SGD 12,000–SGD 50,000

Horangi Cyber Security is a Singapore-based firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSPdpa+2

Horizon CPA Group

San Jose, CA

$14,000–$45,000

Horizon CPA Group provides SOC 2 and HIPAA audits for Silicon Valley technology companies.

SOC 2SOC 1HIPAA

Hussain Lootah & Associates

Dubai, UAE

$6,000–$30,000

Hussain Lootah & Associates is a UAE-based audit firm offering SOC, ISO 27001, NESA, and compliance services for mid-market companies in Dubai and Abu Dhabi.

SOC 1SOC 2ISO 27001Nesa+1

i-Sprint Innovations

Singapore

SGD 18,000–SGD 70,000

i-Sprint Innovations provides ISO 27001, PCI DSS, and MTCS compliance for Singapore enterprises.

ISO 27001SOC 2PCI DSSPdpa+1

I.S. Partners LLC

Horsham, PA

$12,000–$60,000

I.S. Partners LLC is a Horsham, PA CPA and IT audit firm delivering SOC 1/2, HITRUST, HIPAA, PCI DSS, and ISO 27001 compliance assessments.

SOC 1SOC 2HIPAAHITRUST+3

IAS (Integrated Assessment Services)

Singapore

SGD 8,000–SGD 30,000

IAS is a Singapore-based certification body offering ISO 27001 and management system audits across Southeast Asia including Malaysia, Thailand, Vietnam, and the Philippines.

ISO 27001ISO 27701

IBSS Corporation

San Antonio, TX

$40,000–$120,000

IBSS Corporation is a 30+ year federal cybersecurity provider and CMMC C3PAO maintaining strict separation between assessment and consulting services.

CMMCISO 27001NIST 800-171

ICONTEC

Bogota, Colombia

$4,000–$25,000

ICONTEC is Colombia's national standards and certification body offering ISO 27001, ISO 27701, and management system certifications across Latin America.

ISO 27001ISO 27701ISO 22301ISO 27017

Illume Intelligence

Kozhikode, Kerala, India

₹300,000–₹1,500,000

Illume Intelligence is a Kerala-based cybersecurity firm with 16+ years experience in VAPT, red team testing, and compliance auditing for government and enterprise clients.

ISO 27001PCI DSSNIST CSFCMMC

Indusface

Vadodara, India

$5,000–$30,000

Indusface is an Indian cybersecurity firm providing affordable SOC 2, ISO 27001, and PCI DSS assessments.

SOC 2ISO 27001PCI DSSHIPAA+2

InfoSec Brigade

Mumbai, Maharashtra, India

₹300,000–₹1,500,000

InfoSec Brigade is a Mumbai-based CERT-IN empanelled information security consultancy specializing in expert-driven manual penetration testing and compliance consulting.

ISO 27001GDPRSOC 2PCI DSS

InfoSight

Miami Lakes, FL

$8,000–$50,000

InfoSight is a Miami Lakes, FL cybersecurity firm providing IT audits, GLBA risk assessments, and HIPAA compliance services to regulated industries.

HIPAASOC 2NIST CSF

Infosys BPM

Bangalore, India

$25,000–$150,000

Infosys BPM provides cybersecurity, compliance audit, and risk management services leveraging Infosys's global delivery model across 30+ countries.

ISO 27001ISO 27002ISO 27701SOC 1+5

Ingenia Security

Malaga, Spain

€15,000–€60,000

Ingenia Security is a Spanish cybersecurity firm providing ISO 27001 and ENS compliance assessments.

ISO 27001ENSGDPRNIS2

Innov8 Team

Lisbon, Portugal

€10,000–€40,000

Innov8 Team is a Portuguese cybersecurity firm offering ISO 27001 and GDPR compliance assessments.

ISO 27001GDPRNIS2SOC 2

Insight Assurance

Miami, Florida

$12,000–$60,000

Insight Assurance is a Florida-based CPA firm specializing in SOC 2, ISO 27001, and HITRUST audits for startups and growing technology companies.

SOC 1SOC 2SOC 3ISO 27001+7

Insomnia Security

Wellington, New Zealand

NZ$15,000–NZ$70,000

Insomnia Security is a Wellington-based firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2Privacy ActNIST CSF+1

Intechnica

Manchester, United Kingdom

£12,000–£60,000

Intechnica is a Manchester-based firm offering ISO 27001, PCI DSS, and Cyber Essentials assessments.

ISO 27001PCI DSSGDPRCyber Essentials+1

Integrity360

Dublin, Ireland

€20,000–€100,000

Integrity360 is an Irish cybersecurity firm offering ISO 27001, SOC 2, PCI DSS, and NIS2 assessments.

ISO 27001SOC 2PCI DSSGDPR+3

Intertek

London, United Kingdom

$12,000–$75,000

Intertek is a global quality assurance provider offering ISO 27001, ISO 22301, and management system certifications through operations in 100+ countries.

ISO 27001ISO 27002ISO 27017ISO 27701+5

IRQS

Mumbai, India

$1,500–$15,000

IRQS is an accredited ISO certification body based in India, offering ISO 27001, ISO 9001, and other management system certifications across South Asia.

ISO 27001ISO 9001ISO 14001ISO 45001+1

ISRS

Nairobi, Kenya

$2,000–$12,000

ISRS is an accredited ISO certification body based in Kenya, providing ISO 27001 and management system certifications across East Africa.

ISO 27001ISO 9001ISO 14001ISO 45001+1

ISS Consulting (Singapore)

Singapore

SGD 15,000–SGD 60,000

ISS Consulting offers ISO 27001, SOC 2, PCI DSS, and MTCS assessments in Singapore.

ISO 27001SOC 2PCI DSSPdpa+2

IT Audit Labs

Minneapolis, Minnesota

$15,000–$60,000

IT Audit Labs is a boutique US cybersecurity firm specializing in SOC 2, NIST, CMMC, and IT audit services for SMBs and defense contractors.

SOC 2ISO 27001HIPAANIST CSF+3

IT Audit Poland

Warsaw, Poland

€10,000–€40,000

IT Audit Poland offers ISO 27001 and NIS2 compliance assessments for Polish and CEE companies.

ISO 27001GDPRNIS2SOC 2

IT Governance

Ely, United Kingdom

$8,000–$50,000

IT Governance is a UK-based cybersecurity and compliance firm providing ISO 27001 implementation, GDPR consulting, and certification support services worldwide.

ISO 27001ISO 27002ISO 27701ISO 22301+5

IT Governance Ltd

Ely, Cambridgeshire, United Kingdom

$5,000–$35,000

IT Governance Ltd is a UK-based boutique specializing in ISO 27001 certification, Cyber Essentials, GDPR compliance, and PCI DSS assessments for SMEs and mid-market organizations.

ISO 27001ISO 27701ISO 27017ISO 27018+5

ITGRC Advisory

London, UK

£10,000–£35,000

ITGRC Advisory is a London-based IT governance and compliance firm offering SOC 2, ISO 27001, and GDPR services for UK technology companies expanding internationally.

SOC 2ISO 27001GDPRCyber Essentials

ITSEC Asia

Jakarta, Indonesia

$8,000–$45,000

ITSEC Asia is a Jakarta-based cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS across Southeast Asia.

ISO 27001SOC 2PCI DSSNIST CSF

ITSEC Group

Amsterdam, Netherlands

€15,000–€60,000

ITSEC Group is a Dutch cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2GDPRNIS2+2

J.S. Held

Jericho, NY

$25,000–$150,000

J.S. Held is a global consulting firm founded in 1974 in Jericho, NY, offering cyber risk, compliance, and digital investigations services.

NIST CSFISO 27001HIPAAGDPR

JAS-ANZ Accredited Certification Bodies

Canberra, Australia

$10,000–$50,000

JAS-ANZ is the joint accreditation body for Australia and New Zealand, accrediting ISO certification bodies operating in the APAC region.

ISO 27001ISO 27701ISO 22301ISO 27017+2

JISC/JAB Accredited Certification Bodies

Tokyo, Japan

$8,000–$50,000

JISC/JAB is Japan's national accreditation body for ISO certification bodies, ensuring ISO 27001 and management system certifications meet international standards.

ISO 27001ISO 27701ISO 22301ISO 27017+2

Johanson Group

Phoenix, AZ

$8,000–$35,000

Johanson Group is a boutique CPA firm in Phoenix specializing in SOC 2 audits for startups and SMBs. Profile includes pricing and engagement details.

SOC 2SOC 1HIPAA

Johnson Lambert

Vienna, VA

$18,000–$90,000

Johnson Lambert is a Vienna, VA CPA firm founded in 1986 providing SOC 1, SOC 2, and SOC 3 reporting with a specialty in the insurance industry.

SOC 1SOC 2SOC 3

JQS

Tokyo, Japan

¥500,000–¥3,000,000

JQS is a Japanese accredited certification body specializing in ISO 27001 and quality management system certifications for Japanese organizations.

ISO 27001ISO 9001ISO 14001ISO 27017+1

K Financial (K-CPA)

Louisville, CO

$12,000–$50,000

K Financial (K-CPA) is a Colorado CPA firm specializing in SOC 1 and SOC 2 reporting, employee benefit plan audits, and SOX internal audit support.

SOC 1SOC 2SOX

KAB Accredited Certification Bodies

Seoul, South Korea

$7,000–$40,000

KAB is South Korea's national accreditation body for ISO certification bodies, ensuring ISO 27001 and management system certifications meet international standards.

ISO 27001ISO 27701ISO 22301ISO 27017+1

Kaufman Rossin

Miami, FL

$25,000–$100,000

Kaufman Rossin is a Top 100 CPA firm in Miami serving technology, healthcare, and real estate clients with SOC 2, HIPAA, and SOX audits.

SOC 2SOC 1HIPAAPCI DSS+1

KavachOne

Noida, Uttar Pradesh, India

₹400,000–₹1,800,000

KavachOne is a PCI DSS QSA certified and US Registered CPA firm in India specializing in payment security, ISO 27001, and SOC 2 compliance.

PCI DSSISO 27001SOC 2GDPR

KBKG

Pasadena, CA

$20,000–$65,000

KBKG is a Pasadena-based CPA firm offering SOC 2 and SOC 1 audit services.

SOC 2SOC 1

Keiter

Richmond, VA

$15,000–$80,000

Keiter is a Richmond, VA CPA and consulting firm providing SOC 1 and SOC 2 examinations, cybersecurity risk advisory, and HIPAA and NIST CSF services.

SOC 1SOC 2NIST CSFHIPAA

Kelleher & Associates

Towson, MD

$15,000–$50,000

Kelleher & Associates is a Maryland CPA firm providing SOC and HIPAA compliance audits.

SOC 2SOC 1HIPAA

KForce Cybersecurity

Tampa, FL

$15,000–$70,000

KForce Cybersecurity provides SOC 2, ISO 27001, NIST, and CMMC compliance assessments.

SOC 2ISO 27001NIST CSFCMMC+1

Kinetic IT

Perth, Australia

A$25,000–A$100,000

Kinetic IT provides IRAP, ISO 27001, and Essential Eight assessments for Australian government and resources.

IRAPISO 27001Essential EightSOC 2

KirkpatrickPrice

Bethesda, MD

$15,000–$70,000

KirkpatrickPrice is a licensed CPA firm with 20,000+ reports issued, specializing in SOC 2, HITRUST, ISO 27001, and PCI DSS audits for technology and healthcare companies.

SOC 2SOC 1ISO 27001HITRUST+2

Kivu Consulting

San Francisco, CA

$15,000–$100,000

Kivu Consulting, part of Quorum Cyber since 2025, is a cyber incident response and digital forensics firm offering risk and compliance assessments.

NIST CSFISO 27001

Kiwa

Rijswijk, Netherlands

$8,000–$50,000

Kiwa is a Netherlands-based global testing, inspection, and certification body offering ISO 27001, ISO 27701, and management system certifications across Europe.

ISO 27001ISO 27701ISO 22301ISO 27017+2

KLR

Providence, RI

$15,000–$80,000

KLR (Kahn, Litwin, Renza) is a Providence, RI CPA and advisory firm founded in 1975 offering SOC 1, SOC 2, and enterprise risk services.

SOC 1SOC 2

Knowit Secure

Oslo, Norway

NOK 20,000–NOK 80,000

Knowit Secure is a Nordic cybersecurity consultancy offering ISO 27001, SOC 2, and NIS2 assessments.

ISO 27001SOC 2GDPRNIS2+1

KPMG

Featured

Amstelveen, Netherlands

$70,000–$500,000

KPMG is a Big Four professional services firm providing audit, tax, and advisory services through a global network spanning 143 countries and territories.

SOC 1SOC 2SOC 3ISO 27001+16

KPMG Australia

Featured

Sydney, Australia

$50,000–$300,000

KPMG Australia provides Big Four audit, assurance, and cybersecurity services with deep expertise in APRA, CPS 234, and Australian regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+6

KPMG AZSA LLC

Featured

Tokyo, Japan

$45,000–$320,000

KPMG AZSA (KPMG Japan) is a Big Four audit firm providing SOC 2, ISO 27001, APPI, ISMAP, and enterprise risk advisory services to Japan's largest corporations across technology, manufacturing, and financial services.

SOC 1SOC 2ISO 27001ISO 27701+8

KPMG Brazil

Featured

Sao Paulo, Brazil

$10,000–$65,000

KPMG Brazil is KPMG's Brazilian member firm offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services for enterprises and mid-market companies.

SOC 1SOC 2ISO 27001ISO 27701+3

KPMG Canada

Featured

Toronto, Canada

$42,000–$280,000

KPMG Canada is a Big Four professional services firm providing SOC 2, ISO 27001, PIPEDA, SOX, and enterprise risk advisory services to Canadian organizations across financial services, technology, energy, and government.

SOC 1SOC 2ISO 27001ISO 27701+6

KPMG China

Featured

Beijing, China

$40,000–$300,000

KPMG China is one of China's largest Big Four firms, providing audit, assurance, and advisory services with expertise in Chinese regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+7

KPMG India

Featured

Mumbai, India

$25,000–$200,000

KPMG India is a Big Four professional services firm providing SOC 2, ISO 27001, DPDPA, and enterprise risk advisory services to India's largest organizations across financial services, technology, and government sectors.

SOC 1SOC 2ISO 27001ISO 27701+7

KPMG Lower Gulf

Featured

Dubai, UAE

$50,000–$300,000

KPMG Lower Gulf is KPMG's UAE and Oman practice, providing Big Four audit, assurance, tax, and advisory services across the Gulf region.

SOC 1SOC 2ISO 27001ISO 27002+7

KPMG Singapore

Featured

Singapore

$50,000–$300,000

KPMG Singapore is KPMG's ASEAN hub, providing Big Four audit, assurance, tax, and advisory services with strong regulatory and compliance expertise.

SOC 1SOC 2ISO 27001ISO 27002+7

Kratikal

Noida, Uttar Pradesh, India

₹300,000–₹1,500,000

Kratikal is a CERT-IN empanelled cybersecurity auditor in Noida offering VAPT, ISO 27001, and SOC 2 compliance services for Indian enterprises and startups.

ISO 27001SOC 2

Kratos Defense

San Diego, CA

$50,000–$300,000

Kratos Defense is one of the largest FedRAMP 3PAOs and among the first authorized CMMC C3PAOs, assessing cloud providers and defense contractors.

FedRAMPCMMCFismaNIST 800-53+2

Kreston Reeves LLP

London, UK

$8,000–$40,000

Kreston Reeves is a UK chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials compliance services across London and Southeast England.

ISO 27001SOC 2GDPRCyber Essentials

Kroll

Featured

New York, New York

$35,000–$200,000

Kroll is a global risk and financial advisory firm providing cybersecurity, compliance, and investigation services with deep expertise in digital forensics.

SOC 1SOC 2ISO 27001ISO 27002+10

Kroll (UK)

Featured

London, United Kingdom

£30,000–£200,000

Kroll UK is a global risk advisory firm offering ISO 27001, SOC 2, PCI DSS, and enterprise-grade compliance assessments.

ISO 27001SOC 2PCI DSSGDPR+3

KSM (Katz, Sapper & Miller)

Indianapolis, Indiana

$20,000–$90,000

KSM (Katz, Sapper & Miller) is a top-50 US CPA firm based in Indianapolis providing audit, tax, and IT risk advisory services to mid-market clients.

SOC 1SOC 2ISO 27001HIPAA+3

Kudelski Security

Featured

Lausanne, Switzerland

CHF 30,000–CHF 150,000

Kudelski Security is a Swiss cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments globally.

ISO 27001SOC 2PCI DSSGDPR+2

LAC Co., Ltd.

Featured

Tokyo, Japan

¥3,000,000–¥12,000,000

LAC is one of Japan's largest cybersecurity firms offering ISO 27001, ISMS, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSIsms P+2

Landreth Advisory

Austin, TX

$8,000–$30,000

Landreth Advisory provides fast-track SOC 2 and ISO 27001 assessments for early-stage startups.

SOC 2ISO 27001HIPAACCPA+1

Lazarus Alliance

Scottsdale, AZ

$30,000–$150,000

Lazarus Alliance is a FedRAMP 3PAO and StateRAMP assessor in Scottsdale, AZ offering fast-track FedRAMP, SOC 2, PCI DSS, and CMMC assessments for government contractors.

FedRAMPSOC 2PCI DSSCMMC+2

LBMC Information Security

Brentwood, TN

$18,000–$85,000

LBMC Information Security is a Tennessee-based firm offering SOC 2, HITRUST, and PCI DSS assessments.

SOC 2SOC 1PCI DSSHITRUST+3

LGMS

Kuala Lumpur, Malaysia

MYR 8,000–MYR 40,000

LGMS is a Malaysian cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSPdpa+2

Linford & Company

Denver, CO

$12,000–$60,000

Linford & Company is a Denver-based CPA firm specializing in SOC, ISO 27001, and FedRAMP audits. Profile includes pricing and framework coverage.

SOC 2SOC 1ISO 27001PCI DSS+3

Liquid Cyber Security

Johannesburg, South Africa

ZAR 150,000–ZAR 700,000

Liquid Cyber Security offers ISO 27001 and SOC 2 compliance across Africa.

ISO 27001SOC 2PCI DSSPOPIA

LMG Security

Missoula, MT

$10,000–$50,000

LMG Security is a Missoula, MT cybersecurity consultancy providing compliance advisory, technical testing, and training for SOC 2, HIPAA, and PCI DSS.

SOC 2HIPAAPCI DSSNIST CSF

LRQA

Featured

London, United Kingdom

$15,000–$90,000

LRQA is a global assurance and certification provider specializing in ISO 27001, ISO 22301, cybersecurity, and management system certifications worldwide.

ISO 27001ISO 27002ISO 27017ISO 27018+8

LTIMindtree Cybersecurity

Featured

Mumbai, India

$8,000–$60,000

LTIMindtree Cybersecurity offers enterprise-grade ISO 27001, SOC 2, and PCI DSS compliance services.

ISO 27001SOC 2SOC 1PCI DSS+4

Macnica Cybersecurity

Yokohama, Japan

¥2,500,000–¥10,000,000

Macnica Cybersecurity is a Japanese firm offering ISO 27001, PCI DSS, and ISMS assessments.

ISO 27001SOC 2PCI DSSIsms P+1

Mahajan & Aibara

Mumbai, India

$5,000–$30,000

Mahajan & Aibara is a boutique Indian chartered accountancy firm specializing in SOC 2, ISO 27001, and DPDPA compliance audits for startups, SaaS companies, and mid-market technology firms.

SOC 1SOC 2ISO 27001ISO 27701+4

MaloneBailey LLP

Houston, TX

$20,000–$80,000

MaloneBailey LLP is a Houston-based CPA firm offering SOC and SOX audit services with expertise in energy and technology.

SOC 2SOC 1SOX

Mandiant Germany

Featured

Munich, Germany

€40,000–€250,000

Mandiant Germany offers ISO 27001, BSI C5, and NIS2 compliance for enterprise clients.

ISO 27001C5GDPRNIS2+2

Marcum LLP

New York, NY

$18,000–$90,000

Marcum LLP is a top-15 US national accounting and advisory firm providing SOC 2, ISO 27001, HIPAA, and financial audit services to mid-market organizations.

SOC 1SOC 2ISO 27001HIPAA+5

Marcum Technology

New York, NY

$22,000–$100,000

Marcum Technology is a Top 15 CPA firm offering SOC, SOX, and HIPAA compliance audit services.

SOC 2SOC 1SOXHIPAA+2

Mauldin & Jenkins

Atlanta, GA

$20,000–$120,000

Mauldin & Jenkins is a Top 100 Atlanta-based CPA firm founded in 1918, performing SOC 1, SOC 2, SOC 3, and HIPAA-related examinations.

SOC 1SOC 2SOC 3HIPAA

Maxis Technology Group

Tampa, FL

$12,000–$55,000

Maxis Technology Group offers SOC 2, ISO 27001, CMMC, and PCI DSS compliance assessments.

SOC 2ISO 27001CMMCPCI DSS+2

Maxwell Locke & Ritter

Austin, TX

$15,000–$70,000

Maxwell Locke & Ritter is Austin's largest locally owned CPA firm, founded in 1991, offering SOC exams, IT security, and risk assurance services.

SOC 1SOC 2

Mayer Hoffman McCann

Kansas City, MO

$20,000–$80,000

Mayer Hoffman McCann is a CPA firm offering SOC and SOX compliance audits.

SOC 2SOC 1SOX

Mazars

Featured

Paris, France

$35,000–$200,000

Mazars is an international audit, tax, and advisory firm operating as an integrated partnership across 95+ countries with 47,000+ professionals.

SOC 1SOC 2ISO 27001ISO 27002+8

Mazars France

Paris, France

$20,000–$120,000

Mazars France is the home practice of the Forvis Mazars network, providing ISO 27001, GDPR, HDS, and SOC 2 compliance services to French mid-market companies and enterprises at competitive pricing.

SOC 1SOC 2ISO 27001ISO 27701+5

Mazars India

Gurugram, India

$5,000–$35,000

Mazars India provides SOC, ISO 27001, and SOX compliance audit services.

SOC 2SOC 1ISO 27001SOX+1

Mazars Ireland

Dublin, Ireland

€20,000–€80,000

Mazars Ireland is a leading Irish audit firm offering SOC 2, ISO 27001, and GDPR compliance assessments.

SOC 2ISO 27001GDPRSOX+1

Mazars Middle East

Dubai, UAE

$25,000–$120,000

Mazars Middle East is a mid-market audit and advisory firm providing ISO 27001, SOC 2, NESA, and PDPL compliance services across the UAE, Saudi Arabia, and Qatar.

SOC 1SOC 2ISO 27001ISO 27701+6

Mazars UK

London, United Kingdom

$15,000–$80,000

Mazars UK is a leading mid-market audit and advisory firm providing ISO 27001, SOC 2, GDPR, and Cyber Essentials compliance services to UK businesses across financial services, technology, and the public sector.

SOC 1SOC 2ISO 27001ISO 27701+5

McGrathNicol Cyber

Featured

Sydney, Australia

A$25,000–A$120,000

McGrathNicol Cyber offers IRAP, ISO 27001, and SOC 2 assessments for Australian enterprises and government agencies.

ISO 27001SOC 2IRAPEssential Eight+3

McKonly & Asbury

Camp Hill, PA

$15,000–$75,000

McKonly & Asbury is a Camp Hill, PA CPA firm providing SOC 1, SOC 2, SOC 3, and HIPAA compliance audits alongside traditional assurance services.

SOC 1SOC 2SOC 3HIPAA+1

Metabase Q

Mexico City, Mexico

MX$200,000–MX$1,000,000

Metabase Q is a Mexican cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSNIST CSF

MGO

Los Angeles, CA

$25,000–$150,000

MGO (Macias Gini & O'Connell) is a Los Angeles-based CPA firm of 600+ professionals providing SOC 1, SOC 2, and broad assurance services.

SOC 1SOC 2

MHM (Morgan Hockey Malpas)

Calgary, AB, Canada

CA$20,000–CA$60,000

MHM is a Canadian CPA firm with offices in Calgary, Edmonton, and Vancouver, specializing in SOC reporting, ISO 27001, and IT audit for western Canadian companies.

SOC 2SOC 1ISO 27001HIPAA+1

Microland Cybersecurity

Bangalore, India

$6,000–$35,000

Microland Cybersecurity provides ISO 27001 and SOC 2 compliance services for Indian enterprises.

ISO 27001SOC 2HIPAAGDPR+2

Middle East Certifications

Dubai, UAE

$3,000–$25,000

Middle East Certifications is an accredited ISO certification body based in Dubai, serving organizations across the GCC with ISO 27001 and management system certifications.

ISO 27001ISO 9001ISO 14001ISO 45001+1

MindPoint Group

Alexandria, VA

$50,000–$250,000

MindPoint Group, a Tyto Athene company, is an Alexandria, VA FedRAMP 3PAO providing FedRAMP, FISMA, SOC 2, and ISO 27001 assessment services.

FedRAMPFismaSOC 2ISO 27001+2

MMP Chartered Professional Accountants

Toronto, ON

CA$18,000–CA$60,000

MMP is a Toronto CPA firm providing SOC 2 and PIPEDA compliance audits.

SOC 2SOC 1PIPEDAHIPAA

mnemonic AS

Featured

Oslo, Norway

NOK 25,000–NOK 120,000

mnemonic is Norway's largest cybersecurity firm offering ISO 27001, SOC 2, and NIS2 compliance assessments.

ISO 27001SOC 2GDPRNIS2+2

MNP LLP

Calgary, Canada

$15,000–$80,000

MNP LLP is Canada's largest national accounting and consulting firm, providing SOC 2, ISO 27001, PIPEDA, and cybersecurity compliance services to mid-market businesses across all Canadian provinces.

SOC 1SOC 2ISO 27001ISO 27701+4

Moore Global

London, United Kingdom

$25,000–$150,000

Moore Global is a top-15 international accounting and advisory network with 34,000+ professionals serving clients across 110+ countries worldwide.

SOC 1SOC 2ISO 27001HIPAA+3

Moore Kingston Smith LLP

London, UK

$10,000–$50,000

Moore Kingston Smith is a London-based chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials audit services as part of the Moore Global network.

ISO 27001SOC 2GDPRCyber Essentials+1

Moss Adams

Seattle, Washington

$30,000–$150,000

Moss Adams is one of the largest US CPA firms, providing audit, tax, and consulting services from 30+ offices primarily across the Western United States.

SOC 1SOC 2SOC 3ISO 27001+5

Mphasis Cybersecurity

Bangalore, India

$8,000–$50,000

Mphasis Cybersecurity provides ISO 27001, SOC 2, and PCI DSS compliance services.

ISO 27001SOC 2PCI DSSHIPAA+3

MSKA & Associates

Mumbai, India

$5,000–$35,000

MSKA & Associates is BDO India's audit affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for mid-market companies in India.

SOC 1SOC 2ISO 27001ISO 27701+3

MTN Cybersecurity

Johannesburg, South Africa

ZAR 200,000–ZAR 900,000

MTN Cybersecurity provides ISO 27001 and SOC 2 compliance services in South Africa.

ISO 27001SOC 2POPIANIST CSF

N Praveen & Associates

Hyderabad

$8,000–$30,000

N Praveen & Associates is a Hyderabad, India chartered accountancy firm providing SOC 2 attestation, ISO 27001, and IT general controls audits.

SOC 2ISO 27001

Nangia Andersen

New Delhi, India

$10,000–$80,000

Nangia Andersen is a leading Indian professional services firm and Andersen Global member, providing audit, tax, and compliance services across India.

SOC 1SOC 2ISO 27001ISO 27701+5

Nardello & Co.

New York, NY

$25,000–$150,000

Nardello & Co. is a New York-based global investigations firm founded in 2003, offering digital investigations, cyber risk, and compliance services.

NIST CSF

NCC Group (US)

Featured

New York, NY

$30,000–$200,000

NCC Group is a global cybersecurity consultancy offering SOC 2, ISO 27001, PCI DSS, and FedRAMP assessments.

SOC 2ISO 27001PCI DSSFedRAMP+5

Nclose

Johannesburg, South Africa

ZAR 150,000–ZAR 800,000

Nclose is a South African cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSPOPIA+1

NDNB Assurance

Atlanta, GA

$8,000–$40,000

NDNB Assurance is an Atlanta-based national audit firm offering fixed-fee SOC 1, SOC 2, SOC 3, PCI DSS, and HIPAA compliance assessments.

SOC 1SOC 2SOC 3PCI DSS+1

Neeyamo Compliance

Bangalore, India

$4,000–$20,000

Neeyamo Compliance offers affordable ISO 27001 and SOC 2 assessments for Indian startups.

ISO 27001SOC 2GDPRDPDPA

NeoSecure

Santiago, Chile

$12,000–$60,000

NeoSecure is a Chilean cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS across the Andes.

ISO 27001SOC 2PCI DSSNIST CSF

Neoway Cybersecurity

Florianopolis, Brazil

R$20,000–R$80,000

Neoway Cybersecurity provides ISO 27001, SOC 2, and LGPD assessments for Brazilian tech companies.

ISO 27001SOC 2LGPDNIST CSF

NetDiligence

Philadelphia, PA

$15,000–$70,000

NetDiligence specializes in cyber risk assessment and compliance services.

SOC 2ISO 27001PCI DSSHIPAA+1

Netgain

St. Cloud, MN

$8,000–$40,000

Netgain is a Minnesota-based managed cloud provider delivering HIPAA-compliant hosting and IT services to healthcare, accounting, and legal firms.

HIPAASOC 2NIST CSF

Netrika Consulting

New Delhi, India

₹500,000–₹3,000,000

Netrika Consulting is a CERT-IN empanelled risk and integrity management firm in New Delhi offering IT security audits, GDPR compliance, and enterprise risk management.

ISO 27001GDPRSOC 2

Nettitude (US)

New York, NY

$20,000–$100,000

Nettitude is a transatlantic cybersecurity firm offering SOC 2, ISO 27001, and PCI DSS assessments.

SOC 2ISO 27001PCI DSSNIST CSF+2

Nexia International

London, United Kingdom

$25,000–$150,000

Nexia International is a global network of independent accounting and consulting firms with 39,000+ professionals across 125+ countries worldwide.

SOC 1SOC 2ISO 27001HIPAA+3

Nexia SAB&T

Johannesburg, South Africa

$4,000–$22,000

Nexia SAB&T is a leading South African audit firm and Nexia International member offering SOC, ISO 27001, POPIA, and compliance services.

SOC 1SOC 2ISO 27001POPIA+1

NII Consulting

Bangalore, India

$6,000–$40,000

NII Consulting is a Bangalore-based firm offering SOC 2, ISO 27001, and PCI DSS assessments at competitive pricing.

SOC 2ISO 27001PCI DSSHIPAA+3

Nixu Oyj

Featured

Helsinki, Finland

€25,000–€120,000

Nixu Oyj is a leading Nordic cybersecurity firm offering ISO 27001, SOC 2, NIS2, and GDPR compliance assessments.

ISO 27001SOC 2GDPRNIS2+3

Nordic Cyber Group

Stockholm, Sweden

SEK 15,000–SEK 60,000

Nordic Cyber Group is a Swedish cybersecurity firm offering ISO 27001, NIS2 compliance, and ISO-as-a-Service for Scandinavian technology and manufacturing companies.

ISO 27001NIS2GDPRSOC 2

Nordic Defence

Fredrikstad, Norway

NOK 200,000–NOK 800,000

Nordic Defence is a Norwegian cybersecurity firm offering ISO 27001, NIS2 compliance, and managed security services for Nordic enterprises and critical infrastructure.

ISO 27001NIS2GDPR

Norse Consulting Group

Raleigh, NC

$10,000–$50,000

Norse Consulting Group offers SOC 2, ISO 27001, and CMMC assessments for mid-market companies.

SOC 2ISO 27001CMMCNIST CSF+2

Norse Shield

Washington, DC

$20,000–$100,000

Norse Shield specializes in CMMC, FedRAMP, and NIST compliance for defense contractors.

SOC 2ISO 27001CMMCNIST 800-171+2

Northwave Cybersecurity

Utrecht, Netherlands

€20,000–€90,000

Northwave is a Dutch cybersecurity firm offering ISO 27001, SOC 2, and NIS2 compliance assessments.

ISO 27001SOC 2PCI DSSGDPR+2

Noventiq Middle East

Dubai, UAE

AED 50,000–AED 250,000

Noventiq Middle East offers ISO 27001, SOC 2, and PCI DSS compliance across the GCC.

ISO 27001SOC 2PCI DSSNesa+2

Novogradac

San Francisco, CA

$20,000–$100,000

Novogradac is a top-50 national CPA firm headquartered in San Francisco offering SOC 1 and SOC 2 examinations with deep real estate expertise.

SOC 1SOC 2

NQA

Warwick, United Kingdom

$8,000–$50,000

NQA is a UKAS and ANAB accredited certification body providing affordable ISO 27001, ISO 22301, and management system certifications for organizations globally.

ISO 27001ISO 27002ISO 27701ISO 22301+3

NRI SecureTechnologies

Featured

Tokyo, Japan

¥3,000,000–¥15,000,000

NRI SecureTechnologies is a leading Japanese cybersecurity firm offering ISO 27001, PCI DSS, and ISMS assessments.

ISO 27001SOC 2PCI DSSIsms P+2

NSFOCUS Technologies

Featured

Beijing, China

CN¥200,000–CN¥1,000,000

NSFOCUS is a leading Chinese cybersecurity firm offering ISO 27001, MLPS, and PCI DSS assessments.

ISO 27001MlpsPIPLSOC 2+1

NZINFOSEC

Auckland, New Zealand

NZ$15,000–NZ$45,000

NZINFOSEC is a New Zealand information security firm offering ISO 27001, SOC 2, and PCI DSS compliance services with over 300 assessments completed.

ISO 27001PCI DSSSOC 2HIPAA

OCD Tech

Braintree, MA

$12,000–$70,000

OCD Tech is a Braintree, MA IT audit and cybersecurity firm delivering SOC 2 reporting, CMMC readiness, and IT security assessments across New England.

SOC 2SOC 3ISO 27001CMMC+1

Optima Partners

New York, NY

$15,000–$80,000

Optima Partners is a global regulatory compliance and risk advisory firm serving investment managers from New York, London, and Asia.

NIST CSFGDPR

Optiv Security

Featured

Denver, CO

$25,000–$200,000

Optiv Security is one of the largest cybersecurity solutions firms offering SOC 2, ISO 27001, HITRUST, and FedRAMP.

SOC 2ISO 27001PCI DSSHITRUST+6

Orange Cyberdefense

Paris, France

€30,000–€200,000

Orange Cyberdefense is a major European cybersecurity firm offering ISO 27001, NIS2, SOC 2, and GDPR compliance services with managed security operations across the continent.

ISO 27001SOC 2NIS2GDPR+1

Orange Cyberdefense Belgium

Brussels, Belgium

€20,000–€90,000

Orange Cyberdefense Belgium offers ISO 27001, SOC 2, and NIS2 compliance assessments across the Benelux.

ISO 27001SOC 2GDPRNIS2+1

Packetlabs

Mississauga, ON

$10,000–$60,000

Packetlabs is a CREST-accredited Ontario penetration testing firm founded in 2011, delivering compliance-driven security testing across North America.

NIST CSFISO 27001SOC 2

PALO IT Singapore

Singapore

SGD 15,000–SGD 60,000

PALO IT Singapore offers ISO 27001 and SOC 2 compliance for ASEAN technology companies.

ISO 27001SOC 2PdpaNIST CSF

Panacea InfoSec

Delhi

$8,000–$40,000

Panacea InfoSec is a Delhi-based PCI QSA firm, now part of SGS, providing PCI DSS, ISO 27001, SOC, HIPAA, and GDPR compliance services.

PCI DSSISO 27001SOC 2HIPAA+1

Paramount Cybersecurity

Riyadh, Saudi Arabia

SAR 50,000–SAR 300,000

Paramount Cybersecurity is a Saudi firm offering ISO 27001, SOC 2, and NCA-ECC compliance.

ISO 27001SOC 2PCI DSSPdpl+2

PBMares

Newport News, VA

$20,000–$120,000

PBMares is a top-100 CPA firm based in Newport News, VA offering SOC attestations, cybersecurity assessments, and DoD compliance services.

SOC 1SOC 2NIST CSFCMMC

PCI Consulting Australia

Sydney, NSW, Australia

A$15,000–A$50,000

PCI Consulting Australia is a 100% Australian-owned boutique QSA firm specializing exclusively in PCI DSS compliance for merchants and payment processors.

PCI DSS

PECB

Montreal, Canada

$5,000–$35,000

PECB is a global certification and training organization specializing in ISO standards, offering both professional certifications and management system audits.

ISO 27001ISO 9001ISO 22301ISO 27701+2

Penten

Canberra, Australia

A$30,000–A$120,000

Penten is a Canberra-based cybersecurity firm specializing in IRAP and Essential Eight assessments for government.

IRAPISO 27001Essential EightNIST CSF

Pentest Ltd

Leeds, United Kingdom

£8,000–£40,000

Pentest Ltd is a Leeds-based firm offering penetration testing, ISO 27001, and Cyber Essentials assessments.

ISO 27001Cyber EssentialsGDPRPCI DSS+1

Pitcher Partners

Melbourne, Australia

$15,000–$75,000

Pitcher Partners is a leading Australian mid-market accounting firm providing SOC 2, ISO 27001, Essential Eight, and Privacy Act compliance services to mid-market businesses and family enterprises.

SOC 1SOC 2ISO 27001ISO 27701+5

Pivot Point Security

Hamilton, NJ

$15,000–$80,000

Pivot Point Security is a New Jersey firm specializing in ISO 27001 certification, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSHITRUST+3

PKF Africa

Johannesburg, South Africa

$4,000–$25,000

PKF Africa provides audit, ISO 27001, POPIA, and compliance services across Sub-Saharan Africa through the PKF International network.

SOC 1SOC 2ISO 27001POPIA+1

PKF International

London, United Kingdom

$20,000–$120,000

PKF International is a global network of independent accounting and advisory firms with 22,000+ professionals across 150+ countries worldwide.

SOC 1SOC 2ISO 27001HIPAA+3

PKF International (Middle East)

Dubai, UAE

$7,000–$35,000

PKF Middle East is PKF International's regional practice offering SOC, ISO 27001, PCI DSS, and compliance audit services across the Gulf states.

SOC 1SOC 2ISO 27001PCI DSS+2

PKF Littlejohn LLP

London, United Kingdom

$12,000–$55,000

PKF Littlejohn is a London-based mid-market accountancy firm providing SOC 2, ISO 27001, GDPR, and Cyber Essentials audit services to growing UK businesses.

SOC 1SOC 2ISO 27001GDPR+3

PKF O'Connor Davies

New York, NY

$25,000–$80,000

PKF O'Connor Davies is a top-tier New York CPA firm offering SOC 1/2/3 reporting, ISO 27001, and risk advisory services for financial services and technology companies.

SOC 2SOC 1ISO 27001HIPAA

PKF Singapore

Singapore

$7,000–$30,000

PKF Singapore is PKF International's Singapore member firm offering SOC, ISO 27001, PDPA, and compliance audit services for mid-market companies.

SOC 1SOC 2ISO 27001Pdpa+1

Plante Moran

Southfield, Michigan

$30,000–$150,000

Plante Moran is a top-15 US CPA firm known for exceptional workplace culture, providing audit, tax, and cybersecurity services to mid-market companies.

SOC 1SOC 2SOC 3ISO 27001+5

Plurilock

Toronto, ON, Canada

CA$20,000–CA$80,000

Plurilock is a Canadian cybersecurity and compliance firm offering SOC 2, ISO 27001, HITRUST, and FedRAMP assessments for technology and government organizations.

SOC 2ISO 27001HITRUSTFedRAMP+2

Pondurance

Indianapolis, IN

$15,000–$80,000

Pondurance provides managed detection and compliance assessments including SOC 2, ISO 27001, and CMMC.

SOC 2ISO 27001CMMCNIST CSF+2

Praetorian

Austin, TX

$20,000–$150,000

Praetorian is an Austin-based offensive security firm founded in 2010 providing penetration testing and security assessments supporting SOC 2 and ISO 27001 programs.

SOC 2ISO 27001NIST CSF

Prager Metis

New York, NY

$22,000–$95,000

Prager Metis is a Top 100 CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

Prescient Assurance

Toronto, Canada

$12,000–$50,000

Prescient Assurance is a startup-friendly CPA firm offering affordable SOC 2, ISO 27001, and HIPAA audits with fast turnaround for growing companies.

SOC 1SOC 2SOC 3ISO 27001+9

Prescient Security

Nashville, TN

$18,000–$80,000

Prescient Security is a global compliance auditor with 3,600+ SOC 2 audits and 5,000+ customers, offering SOC 2, ISO 27001, HITRUST, FedRAMP, and CMMC assessments.

SOC 2ISO 27001HITRUSTFedRAMP+4

Prevue Compliance

Calgary, AB

CA$12,000–CA$45,000

Prevue Compliance provides SOC 2 and ISO 27001 assessments for Western Canadian companies.

SOC 2ISO 27001PIPEDANIST CSF

PricewaterhouseCoopers (PwC)

Featured

London, United Kingdom

$75,000–$500,000

PwC is one of the Big Four professional services firms, providing audit, assurance, tax, and consulting services to major organizations in 152 countries.

SOC 1SOC 2SOC 3ISO 27001+16

PricewaterhouseCoopers Brazil

Featured

Sao Paulo, Brazil

$10,000–$70,000

PwC Brazil is PricewaterhouseCoopers' Brazilian member firm offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services for Latin America's largest market.

SOC 1SOC 2ISO 27001ISO 27701+3

Pristine InfoSolutions

Mumbai, India

$4,000–$25,000

Pristine InfoSolutions offers PCI DSS, ISO 27001, and SOC 2 assessments at competitive Indian pricing.

ISO 27001SOC 2PCI DSSHIPAA+2

ProCircular

Coralville, IA

$8,000–$40,000

ProCircular is a Midwest cybersecurity consultancy based in Coralville, IA offering PCI, HIPAA, ISO 27001, and NIST-aligned compliance and testing services.

PCI DSSHIPAAISO 27001NIST CSF

Protiviti

Featured

Menlo Park, California

$40,000–$250,000

Protiviti is a global consulting firm specializing in internal audit, risk management, and compliance with 9,000+ professionals across 25+ countries.

SOC 1SOC 2ISO 27001ISO 27002+12

Protiviti India

Mumbai, India

$15,000–$100,000

Protiviti India provides internal audit, IT risk, and compliance services including ISO 27001, SOC 2, and CERT-In assessments for Indian enterprises.

ISO 27001ISO 27002ISO 27701SOC 1+6

Protiviti Middle East

Dubai, UAE

$25,000–$150,000

Protiviti Middle East provides internal audit, IT risk, and compliance services including ISO 27001 and SOC 2 for organizations across the Gulf region.

ISO 27001ISO 27002ISO 27701SOC 1+6

PwC Aarata LLC

Featured

Tokyo, Japan

$50,000–$350,000

PwC Aarata (PwC Japan) is a Big Four audit firm providing SOC 2, ISO 27001, APPI, ISMAP, and enterprise risk advisory services to Japan's leading corporations across financial services, technology, and manufacturing.

SOC 1SOC 2ISO 27001ISO 27701+8

PwC Australia

Featured

Sydney, Australia

$50,000–$350,000

PwC Australia is one of Australia's largest professional services firms, providing Big Four audit, assurance, and cybersecurity services across Oceania.

SOC 1SOC 2ISO 27001ISO 27002+7

PwC Canada

Featured

Toronto, Canada

$45,000–$300,000

PwC Canada is a Big Four professional services firm providing SOC 2, ISO 27001, PIPEDA, SOX, and enterprise risk advisory services to Canada's largest organizations across financial services, technology, energy, and government.

SOC 1SOC 2ISO 27001ISO 27701+6

PwC China

Featured

Shanghai, China

$40,000–$350,000

PwC China is the largest Big Four firm in China, providing audit, assurance, and advisory services with deep expertise in Chinese regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+7

PwC France

Featured

Paris, France

$45,000–$300,000

PwC France is a Big Four professional services firm providing ISO 27001, GDPR, HDS, SOC 2, and enterprise risk advisory services to French enterprises across financial services, technology, healthcare, and government.

SOC 1SOC 2ISO 27001ISO 27701+6

PwC Germany

Featured

Frankfurt, Germany

$50,000–$350,000

PwC Germany is a Big Four professional services firm providing ISO 27001, C5, TISAX, SOC 2, and GDPR compliance services to German enterprises across automotive, manufacturing, technology, and financial services.

SOC 1SOC 2ISO 27001ISO 27701+7

PwC India

Featured

Mumbai, India

$30,000–$250,000

PwC India is a Big Four professional services firm providing SOC 2, ISO 27001, DPDPA, SOX, and enterprise risk advisory services to India's largest corporations and multinational subsidiaries.

SOC 1SOC 2ISO 27001ISO 27701+7

PwC Middle East

Featured

Dubai, UAE

$55,000–$380,000

PwC Middle East is a Big Four professional services firm providing SOC 2, ISO 27001, NESA, PDPL, and enterprise risk advisory services across the UAE, Saudi Arabia, and the broader Middle East region.

SOC 1SOC 2ISO 27001ISO 27701+8

PwC Singapore

Featured

Singapore

$40,000–$250,000

PwC Singapore is a Big Four professional services firm providing SOC 2, ISO 27001, PDPA, MTCS, and enterprise risk advisory services to financial institutions, technology companies, and government agencies in Singapore and the APAC region.

SOC 1SOC 2ISO 27001ISO 27701+7

PYA

Knoxville, TN

$25,000–$80,000

PYA is a Top-100 national CPA firm specializing in healthcare compliance, SOC 2, HITRUST, and HIPAA audits for SaaS and cloud-based companies.

SOC 2HIPAAHITRUSTISO 27001

Q-Inspect

Prague, Czech Republic

€5,000–€25,000

Q-Inspect is a Czech-based accredited certification body offering ISO 27001 and management system audits across Central and Eastern Europe.

ISO 27001

QCert360

Seoul, South Korea

₩15,000,000–₩50,000,000

QCert360 is a South Korean information security firm specializing in K-ISMS-P and ISO 27001 certification for Korean technology and financial companies.

ISO 27001

QI-ANXIN Technology

Featured

Beijing, China

CN¥200,000–CN¥1,000,000

QI-ANXIN is one of China's largest cybersecurity firms offering ISO 27001, MLPS, and PIPL compliance.

ISO 27001MlpsPIPLSOC 2+1

QMS International

Doncaster, UK

£3,000–£25,000

QMS International is a UKAS-accredited UK certification body specializing in ISO 27001 and management system certifications for SMBs.

ISO 27001ISO 9001ISO 14001ISO 45001+1

QRC Consulting

Navi Mumbai

$8,000–$40,000

QRC (QRC Assurance and Solutions) is a Navi Mumbai-based PCI QSA and accredited ISO certification body covering PCI DSS, ISO 27001, and data privacy.

PCI DSSISO 27001ISO 27701ISO 9001+2

Quality Austria

Vienna, Austria

€8,000–€40,000

Quality Austria is a Vienna-based accredited certification body offering ISO 27001, ISO 27701, and management system certifications across Central Europe.

ISO 27001ISO 27701

Qualysec Technologies

Bangalore, Karnataka, India

₹150,000–₹800,000

Qualysec is a Bangalore-based penetration testing company offering VAPT for web, mobile, cloud, IoT, and blockchain with compliance readiness services.

ISO 27001SOC 2PCI DSSHIPAA

Quann (Singapore)

Singapore

SGD 15,000–SGD 60,000

Quann is a Singapore cybersecurity firm offering ISO 27001, SOC 2, and MTCS assessments.

ISO 27001SOC 2PCI DSSPdpa+1

ramsac

Godalming, United Kingdom

£5,000–£25,000

ramsac provides Cyber Essentials and ISO 27001 assessments for UK SMBs and charities.

Cyber EssentialsISO 27001GDPR

Raymond Chabot Grant Thornton

Montreal, QC

CA$25,000–CA$100,000

Raymond Chabot Grant Thornton is one of Quebec's largest CPA firms offering SOC, SOX, and PIPEDA audits.

SOC 2SOC 1SOXISO 27001+1

RBSM LLP

New York, NY

$20,000–$80,000

RBSM LLP is a New York CPA firm providing SOC 2, SOC 1, and SOX compliance audits.

SOC 2SOC 1SOX

RedPoint Cybersecurity

San Antonio, TX

$10,000–$45,000

RedPoint Cybersecurity offers CMMC, SOC 2, and NIST compliance assessments in Texas.

SOC 2CMMCNIST CSFNIST 800-171+1

Redspin

Duluth, GA

$30,000–$120,000

Redspin is the first authorized CMMC C3PAO in the US, conducting ~25% of all CMMC Level 2 assessments with former DoD cybersecurity professionals.

CMMCHIPAAHITRUSTPCI DSS+1

Rehmann Advisors

Troy, MI

$20,000–$80,000

Rehmann Advisors is a Michigan-based Top 50 CPA firm offering SOC, SOX, and HIPAA audits.

SOC 2SOC 1SOXHIPAA

Reply Cyber Security

Featured

Turin, Italy

€35,000–€200,000

Reply Cyber Security is a European IT consultancy offering ISO 27001, SOC 2, and NIS2 compliance for enterprises.

ISO 27001SOC 2GDPRNIS2+2

ResGuard Solutions

Singapore

SGD 15,000–SGD 40,000

ResGuard Solutions is a Singapore-based cybersecurity and compliance firm offering SOC 2, ISO 27001, and GDPR services for Southeast Asian technology companies.

SOC 2ISO 27001GDPR

RFA

New York, NY

$10,000–$60,000

RFA is a New York-based managed IT, cloud, and cybersecurity provider offering compliance services to hedge funds and alternative investment firms.

NIST CSFSOC 2

Richter (Canada)

Montreal, QC

CA$25,000–CA$100,000

Richter is a leading Canadian CPA firm offering SOC, SOX, and PIPEDA compliance audits.

SOC 2SOC 1SOXPIPEDA+1

Richter LLP

Montreal, Canada

$12,000–$55,000

Richter is a leading Canadian mid-market accounting and advisory firm based in Montreal, providing SOC 2, ISO 27001, PIPEDA, and cybersecurity compliance services with full bilingual capability.

SOC 1SOC 2ISO 27001GDPR+3

Right Click Security

Seattle, WA

$10,000–$40,000

Right Click Security offers affordable SOC 2 and ISO 27001 audits for startups and SaaS companies in the Pacific Northwest.

SOC 2ISO 27001HIPAANIST CSF

Rightworks

Hudson, NH

$8,000–$40,000

Rightworks, formerly Right Networks, is a New Hampshire-based cloud provider delivering secure, compliance-focused hosting for accounting firms.

SOC 2NIST CSF

RINA

Genoa, Italy

$8,000–$45,000

RINA is an Italian multinational inspection, certification, and engineering consultancy offering ISO 27001, ISO 27701, and management system certifications globally.

ISO 27001ISO 27701ISO 22301ISO 27017+2

RISCPoint

Richmond, VA

$25,000–$250,000

RISCPoint is a security and compliance advisory firm and FedRAMP/StateRAMP 3PAO covering SOC 2, ISO 27001, CMMC, HITRUST, and federal frameworks.

FedRAMPSOC 2ISO 27001CMMC+3

Risk Associates

Sydney, NSW, Australia

A$30,000–A$120,000

Risk Associates is a Sydney-based Tier 1 Security Cleared assessor providing Essential Eight maturity assessments and GRC solutions for Australian government and enterprise.

ISO 27001Essential EightPCI DSS

Risk Crew

London, United Kingdom

$10,000–$50,000

Risk Crew is a UK cybersecurity consultancy providing ISO 27001, GDPR, and penetration testing services for startups and mid-market technology companies.

ISO 27001ISO 27002ISO 27701GDPR+3

Risk3Sixty

Roswell, GA

$15,000–$75,000

Risk3Sixty is a Roswell, GA security and compliance firm delivering SOC 2, ISO 27001, PCI DSS, HITRUST, and CMMC assessments plus vCISO services.

SOC 2PCI DSSISO 27001HIPAA+3

Riskpro India

Chennai, Tamil Nadu, India

₹400,000–₹2,000,000

Riskpro India is a Chennai-based SOC 2 specialist with 1400+ completed audits and in-house US CPA professionals, serving IT services and SaaS companies.

SOC 2SOC 1GDPRHIPAA+1

Riverpoint Technology

Nashville, TN

$12,000–$55,000

Riverpoint Technology specializes in healthcare compliance with HITRUST, HIPAA, and SOC 2 assessments.

SOC 2HITRUSTHIPAAISO 27001+1

RKL LLP

Lancaster, PA

$20,000–$100,000

RKL LLP is Pennsylvania's largest homegrown CPA and advisory firm, providing SOC 1 and SOC 2 examinations, IT audit, and HIPAA-related services.

SOC 1SOC 2HIPAA

RL Datix Compliance

Chicago, IL

$20,000–$80,000

RL Datix Compliance specializes in healthcare compliance with HITRUST, HIPAA, and SOC 2 assessments.

HIPAAHITRUSTSOC 2ISO 27001+1

Roedl & Partner

Nuremberg, Germany

$18,000–$100,000

Roedl & Partner is a German mid-market professional services firm providing ISO 27001, TISAX, C5, and GDPR compliance services to the Mittelstand and international businesses with German operations.

ISO 27001ISO 27701ISO 22301GDPR+4

RQM+

Dubai, UAE

$10,000–$60,000

RQM+ is a regulatory compliance specialist serving medical device and healthcare organizations from the UAE and US, covering ISO 13485, ISO 27001, and FDA requirements.

ISO 27001Iso 13485GDPRHIPAA

RSI Security

San Diego, CA

$15,000–$100,000

RSI Security is a San Diego compliance and cybersecurity firm — PCI QSA, CMMC C3PAO, and HITRUST External Assessor — covering SOC 2, HIPAA, and NIST.

SOC 2PCI DSSHITRUSTHIPAA+3

RSM France

Paris, France

€22,000–€100,000

RSM France provides SOC, ISO 27001, and GDPR compliance audit services.

SOC 2SOC 1ISO 27001GDPR+1

RSM Germany

Dusseldorf, Germany

€25,000–€100,000

RSM Germany provides SOC, ISO 27001, and BSI C5 compliance audits.

SOC 2SOC 1ISO 27001C5+2

RSM India

Mumbai, India

$5,000–$35,000

RSM India provides SOC, ISO 27001, and SOX compliance audit services.

SOC 2SOC 1ISO 27001SOX+1

RSM International

Featured

London, United Kingdom

$35,000–$200,000

RSM International is the sixth-largest global professional services network, delivering audit, tax, and consulting services across 120+ countries.

SOC 1SOC 2SOC 3ISO 27001+7

RSM Netherlands

Amsterdam, Netherlands

€25,000–€100,000

RSM Netherlands offers SOC, ISO 27001, and GDPR compliance audit services.

SOC 2SOC 1ISO 27001GDPR+1

RSM Singapore

Singapore

$15,000–$60,000

RSM Singapore is a mid-market audit and advisory firm providing SOC 2, ISO 27001, PDPA, and PCI DSS compliance services to SMEs and growing businesses in Singapore.

SOC 1SOC 2ISO 27001ISO 27701+4

RSM US LLP

Featured

Chicago, IL

$25,000–$120,000

RSM US LLP is the fifth-largest US CPA firm and a leading mid-market auditor offering SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, FedRAMP, and CMMC services nationwide.

SOC 1SOC 2ISO 27001HIPAA+8

RubinBrown

St. Louis, MO

$25,000–$120,000

RubinBrown is a St. Louis-based national CPA firm founded in 1952 offering SOC 1/2 examinations, PCI DSS, HIPAA, and IT risk services.

SOC 1SOC 2PCI DSSHIPAA

Ruihua Certified Public Accountants

Beijing, China

$4,000–$30,000

Ruihua Certified is one of China's largest domestic CPA firms offering ISO 27001, MLPS, and financial audit services for Chinese enterprises.

SOC 1ISO 27001MlpsPIPL

S-RM

London

$25,000–$120,000

S-RM is a London-based intelligence and cyber security consultancy founded in 2005, offering cyber resilience, assessment, and incident response services.

NIST CSFISO 27001GDPR

S.R. Batliboi & Associates LLP

Mumbai, India

$7,000–$50,000

S.R. Batliboi & Associates is EY's primary India affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for Indian enterprises.

SOC 1SOC 2ISO 27001ISO 27701+4

S2 Grupo

Valencia, Spain

€20,000–€90,000

S2 Grupo is a Spanish cybersecurity firm offering ISO 27001, ENS, and NIS2 compliance assessments.

ISO 27001ENSGDPRNIS2+2

SABS

Pretoria, South Africa

ZAR 30,000–ZAR 250,000

SABS is the South African Bureau of Standards, offering accredited ISO 27001 and management system certifications as the national standards body.

ISO 27001ISO 9001ISO 14001ISO 45001+1

SACAS

Johannesburg, South Africa

ZAR 80,000–ZAR 300,000

SACAS is a South African accredited certification body offering ISO 27001 and management system audits across Southern Africa.

ISO 27001

SAI Global

Sydney, Australia

A$5,000–A$40,000

SAI Global is an Australian certification body and compliance solutions provider offering ISO certifications and risk management services across APAC.

ISO 27001ISO 9001ISO 14001ISO 45001+1

Samil PricewaterhouseCoopers

Featured

Seoul, South Korea

$15,000–$80,000

Samil PwC is PricewaterhouseCoopers' South Korean member firm offering SOC 1, SOC 2, ISO 27001, ISMS-P, and compliance audit services for Korean enterprises.

SOC 1SOC 2ISO 27001ISO 27701+4

Sangfor Technologies

Shenzhen, China

CN¥150,000–CN¥800,000

Sangfor Technologies provides cybersecurity and compliance services including ISO 27001 and MLPS.

ISO 27001MlpsPIPLSOC 2

SASA Technologies

Nairobi, Kenya

$8,000–$40,000

SASA Technologies provides ISO 27001 and PCI DSS compliance in East and West Africa.

ISO 27001SOC 2PCI DSSNIST CSF

Sax LLP

Parsippany, NJ

$20,000–$85,000

Sax LLP is a New Jersey-based Top 100 CPA firm offering SOC, SOX, and HIPAA audit services.

SOC 2SOC 1SOXHIPAA

SBS CyberSecurity

Madison, SD

$8,000–$45,000

SBS CyberSecurity is a Madison, SD consulting and audit firm helping banks and financial institutions with IT audits, risk management, and regulatory compliance.

NIST CSF

SC&H Group

Sparks, MD

$20,000–$100,000

SC&H Group is a Maryland-based CPA and consulting firm providing SOC 1/2 examinations, ISO 27001, and NIST CSF assessments plus IT audit services.

SOC 1SOC 2ISO 27001NIST CSF

ScaleSec

San Diego, CA

$15,000–$150,000

ScaleSec is a San Diego cloud security consultancy guiding companies through SOC 2, ISO 27001, HIPAA, and FedRAMP readiness on AWS and Google Cloud.

SOC 2ISO 27001FedRAMPHIPAA+1

Schellman (EU Office)

Frankfurt, Germany

$20,000–$90,000

Schellman EU is the European office of Schellman & Company, providing SOC 2, ISO 27001, GDPR, and C5 compliance audits for European technology companies.

SOC 2ISO 27001ISO 27017ISO 27018+6

Schellman & Company

Featured

Tampa, Florida

$20,000–$100,000

Schellman is a leading US compliance audit firm specializing in SOC 2, ISO 27001, FedRAMP, HITRUST, and PCI DSS assessments for technology companies.

SOC 1SOC 2SOC 3ISO 27001+13

Schneider Downs

Pittsburgh, PA

$22,000–$90,000

Schneider Downs is a Pittsburgh-based Top 60 CPA firm offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA+1

SEC Consult

Vienna, Austria

€20,000–€100,000

SEC Consult is an Austrian cybersecurity consultancy offering ISO 27001, SOC 2, and NIS2 compliance assessments.

ISO 27001SOC 2GDPRNIS2+2

Seccom Global

Melbourne, Australia

A$20,000–A$80,000

Seccom Global is a Melbourne cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSIRAP+2

SECUINFRA GmbH

Berlin, Germany

€20,000–€80,000

SECUINFRA is a Berlin-based cybersecurity firm offering ISO 27001, BSI C5, and TISAX assessments.

ISO 27001C5GDPRNIS2+2

secunet Security Networks

Featured

Essen, Germany

€30,000–€200,000

secunet is Germany's leading IT security company offering ISO 27001, BSI C5, and NIS2 compliance for enterprises.

ISO 27001C5GDPRNIS2+2

Secura BV

Amsterdam, Netherlands

€20,000–€100,000

Secura BV is a Dutch cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments across the Benelux region.

ISO 27001SOC 2PCI DSSGDPR+3

SecureClick

Manchester, United Kingdom

£5,000–£25,000

SecureClick offers affordable Cyber Essentials, ISO 27001, and GDPR compliance for UK SMBs.

Cyber EssentialsISO 27001GDPR

SecureIT

Reston, VA

$30,000–$250,000

SecureIT is a Reston, VA cybersecurity compliance firm and FedRAMP 3PAO performing FedRAMP, FISMA, SOC, and ISO 27001 assessments.

FedRAMPFismaSOC 1SOC 2+2

SecureWorks

Atlanta, GA

$25,000–$150,000

SecureWorks is an Atlanta-based cybersecurity company, now part of Sophos, offering compliance consulting and cyber risk assessment services.

NIST CSFISO 27001

Securisea

Atlanta, GA

$12,000–$100,000

Securisea is an Atlanta-based PCI QSA company and FedRAMP 3PAO offering PCI DSS, SOC 1/2, HITRUST, and ISO 27001 assessment services.

PCI DSSSOC 1SOC 2HITRUST+3

SecurIT360

Birmingham, AL

$10,000–$60,000

SecurIT360 is a Birmingham, AL cybersecurity consultancy offering ISO 27001, CMMC, and NIST CSF compliance assessments alongside a 24/7 SOC.

ISO 27001CMMCNIST CSFHIPAA

SecurityCentric

Canberra, ACT, Australia

A$35,000–A$100,000

SecurityCentric is a Canberra-based endorsed IRAP assessor offering comprehensive compliance assessments for Australian government agencies and defense contractors.

ISO 27001Essential Eight

SecurityMetrics

Orem, UT

$10,000–$60,000

SecurityMetrics is a US-based compliance and cybersecurity firm specializing in PCI DSS, HIPAA, and HITRUST assessments with forensic investigation capabilities.

PCI DSSHIPAAHITRUST

Securium Solutions

Noida, Uttar Pradesh, India

₹200,000–₹1,000,000

Securium Solutions is a CERT-IN empanelled cybersecurity firm in Noida specializing in ISO 27001, SEBI compliance, and security auditing for regulated Indian companies.

ISO 27001ISO 27701PCI DSS

Seiler LLP

Redwood City, CA

$20,000–$100,000

Seiler LLP is a Redwood City, CA accounting firm, now part of Baker Tilly, providing SOC 1, SOC 2, IT risk, assurance, and advisory services.

SOC 1SOC 2

Seiso

Pittsburgh, PA

$15,000–$80,000

Seiso is a Pittsburgh-based cybersecurity and GRC consultancy guiding growing companies through ISO 27001, SOC 2, CMMC, and NIST compliance.

ISO 27001SOC 2CMMCNIST CSF+1

Sense of Security

Sydney, Australia

A$20,000–A$90,000

Sense of Security is a Sydney-based firm offering IRAP, ISO 27001, and PCI DSS compliance assessments.

ISO 27001SOC 2PCI DSSIRAP+1

Sensiba

San Jose, California

$18,000–$80,000

Sensiba (formerly SingerLewak) is a California-based CPA firm specializing in SOC 2, ISO 27001, and compliance audits for technology and SaaS companies.

SOC 1SOC 2SOC 3ISO 27001+6

Sensible Security

Charlotte, NC

$10,000–$45,000

Sensible Security offers affordable SOC 2, ISO 27001, and HIPAA compliance assessments for growing companies.

SOC 2ISO 27001HIPAANIST CSF+1

Sequretek

Mumbai, India

$5,000–$30,000

Sequretek is a Mumbai cybersecurity firm offering ISO 27001, SOC 2, and DPDPA compliance.

ISO 27001SOC 2HIPAAGDPR+2

Sera-Brynn

Chesapeake, VA

$25,000–$200,000

Sera-Brynn is a veteran-owned Virginia firm operating as an authorized CMMC C3PAO and FedRAMP 3PAO for defense and government cloud assessments.

CMMCFedRAMPNIST 800-171

Serianu

Nairobi, Kenya

$10,000–$50,000

Serianu is East Africa's leading cybersecurity firm offering ISO 27001, SOC 2, and PCI DSS assessments.

ISO 27001SOC 2PCI DSSNIST CSF

SGS

Featured

Geneva, Switzerland

$12,000–$80,000

SGS is the world's largest testing, inspection, and certification company, providing ISO 27001 and management system certifications across 140+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

ShineWing Certified Public Accountants

Beijing, China

$5,000–$40,000

ShineWing is one of China's largest domestic CPA firms offering SOC, ISO 27001, MLPS, and compliance audit services for Chinese and multinational companies.

SOC 1SOC 2ISO 27001ISO 27701+3

Siege Cyber

Brisbane, QLD, Australia

A$15,000–A$40,000

Siege Cyber is a Brisbane-based SOC 2 and ISO 27001 specialist for Australian SaaS companies, partnering with Vanta and Drata compliance platforms.

SOC 2ISO 27001

Sikich

Naperville, Illinois

$25,000–$120,000

Sikich is a top-30 US professional services firm offering audit, technology, and cybersecurity services with strong Midwest presence and CMMC capabilities.

SOC 1SOC 2SOC 3ISO 27001+6

Silent Sector

Scottsdale, AZ

$10,000–$60,000

Silent Sector is a Scottsdale, AZ cybersecurity firm guiding mid-market companies through SOC 2, ISO 27001, CMMC, and HIPAA compliance.

SOC 2ISO 27001CMMCHIPAA+2

SingerLewak

Los Angeles, CA

$18,000–$90,000

SingerLewak is a Los Angeles CPA firm founded in 1959 offering SOC 1, SOC 2, and IT audit services through its business risk practice.

SOC 1SOC 2

Sirar by STC

Featured

Riyadh, Saudi Arabia

SAR 60,000–SAR 350,000

Sirar by STC is Saudi Arabia's leading cybersecurity firm offering ISO 27001, NCA-ECC, and PDPL assessments.

ISO 27001SOC 2PCI DSSPdpl+2

SISA Information Security

Featured

Bangalore, India

$5,000–$40,000

SISA is India's largest PCI QSA company offering PCI DSS, ISO 27001, and SOC 2 assessments globally.

PCI DSSISO 27001SOC 2HIPAA+3

SizweNtsalubaGobodo-Grant Thornton

Johannesburg, South Africa

$5,000–$30,000

SizweNtsalubaGobodo-Grant Thornton is South Africa's largest Black-owned audit firm offering SOC, ISO 27001, POPIA, and compliance services.

SOC 1SOC 2ISO 27001ISO 27701+2

SK shieldus

Featured

Seoul, South Korea

₩30,000,000–₩120,000,000

SK shieldus is South Korea's largest cybersecurity firm offering ISO 27001, ISMS-P, and SOC 2 assessments.

ISO 27001Isms PSOC 2PCI DSS+1

Smith & Williamson

London, UK

$12,000–$55,000

Smith & Williamson is a UK-based chartered accountancy and advisory firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials audit services.

ISO 27001SOC 2GDPRPCI DSS+1

SNG Grant Thornton

Johannesburg, South Africa

ZAR 200,000–ZAR 1,000,000

SNG Grant Thornton is a South African CPA firm offering SOC, ISO 27001, and POPIA compliance audits.

SOC 2SOC 1ISO 27001POPIA+1

SOCOTEC

Paris, France

€6,000–€50,000

SOCOTEC is a major French certification body offering ISO 27001 and multi-standard certifications across Europe. Profile includes pricing and framework coverage.

ISO 27001ISO 9001ISO 14001ISO 22301+2

Sogeti Cybersecurity

Featured

Paris, France

€40,000–€300,000

Sogeti Cybersecurity is a Capgemini subsidiary offering enterprise-grade compliance services across Europe.

ISO 27001SOC 2GDPRNIS2+4

SOMPO Cyber Security

Tokyo, Japan

¥3,000,000–¥10,000,000

SOMPO Cyber Security provides ISO 27001 and SOC 2 assessments for Japanese enterprises.

ISO 27001SOC 2Isms PNIST CSF

Spire Solutions

Dubai, UAE

AED 50,000–AED 250,000

Spire Solutions provides ISO 27001, SOC 2, and PCI DSS assessments across the UAE.

ISO 27001SOC 2PCI DSSNesa+1

SRKAY Consulting

New Delhi, India

$5,000–$40,000

SRKAY Consulting is a CERT-In empaneled cybersecurity and compliance firm in India offering ISO 27001, SOC 2, GDPR, and PCI DSS consulting services.

ISO 27001ISO 27002ISO 27701SOC 2+4

ST Engineering Cybersecurity

Featured

Singapore

SGD 25,000–SGD 120,000

ST Engineering Cybersecurity is a leading Singapore firm offering ISO 27001, SOC 2, and MTCS assessments.

ISO 27001SOC 2PCI DSSMtcs+3

StackArmor

Tysons, VA

$30,000–$150,000

StackArmor specializes in FedRAMP and CMMC compliance for government cloud deployments.

FedRAMPCMMCNIST 800-53NIST 800-171+2

StickmanCyber

Sydney

$12,000–$80,000

StickmanCyber is a Sydney-based PCI QSA and cybersecurity firm delivering PCI DSS, ISO 27001, SOC 2, and Essential Eight compliance services.

PCI DSSISO 27001SOC 2Essential Eight

StoneTurn

New York, NY

$30,000–$150,000

StoneTurn is a New York-based advisory firm founded in 2004, now part of Province, offering compliance, risk controls, and forensic services.

SOXNIST CSF

Straits Interactive

Singapore

SGD 10,000–SGD 40,000

Straits Interactive specializes in data protection and privacy compliance across ASEAN.

ISO 27001PdpaGDPRSOC 2

Stratica

Melbourne, VIC, Australia

A$25,000–A$80,000

Stratica is Australia's only PCI Forensic Investigator (PFI) firm and most qualified QSA, specializing in payment card security for retail, finance, and travel sectors.

PCI DSSSOC 2

StrongBox IT

Bangalore, Karnataka, India

₹250,000–₹1,200,000

StrongBox IT is a Bangalore-based NASSCOM-listed cybersecurity firm providing in-depth security assessments, ISO 27001 implementation, and OT security audits.

ISO 27001SOC 2

Stroz Friedberg (Aon)

Featured

New York, NY

$30,000–$200,000

Stroz Friedberg (Aon Cyber Solutions) offers SOC 2, ISO 27001, and cyber risk compliance services.

SOC 2ISO 27001PCI DSSHIPAA+3

Suma Soft

Pune, India

$5,000–$25,000

Suma Soft provides ISO 27001 and SOC 2 compliance assessments from Pune, India.

ISO 27001SOC 2HIPAAGDPR+1

Summit 7 Systems

Huntsville, AL

$20,000–$100,000

Summit 7 Systems specializes in CMMC and NIST compliance for defense industrial base contractors.

CMMCNIST 800-171NIST 800-53ITAR+1

SureCloud

London, United Kingdom

£15,000–£70,000

SureCloud offers ISO 27001, PCI DSS, and Cyber Essentials assessments with integrated GRC platform.

ISO 27001SOC 2PCI DSSGDPR+2

SynerComm

Brookfield, WI

$10,000–$70,000

SynerComm is a Wisconsin cybersecurity and IT solutions firm founded in 1990 offering PCI compliance, IT audit, and penetration testing services.

PCI DSSHIPAANIST CSF

SysDream

Paris, France

€18,000–€70,000

SysDream is a French cybersecurity firm offering ISO 27001, HDS, and NIS2 compliance assessments.

ISO 27001GDPRNIS2Hds+1

SysGroup IT Security

Zurich, Switzerland

CHF 25,000–CHF 100,000

SysGroup provides ISO 27001 and SOC 2 assessments for Swiss financial services and technology companies.

ISO 27001SOC 2GDPRNIST CSF+1

SysGroup UK

Liverpool, United Kingdom

£8,000–£40,000

SysGroup UK offers ISO 27001 and Cyber Essentials compliance for UK businesses.

ISO 27001Cyber EssentialsGDPRSOC 2

Systancia

Paris, France

€20,000–€80,000

Systancia is a French cybersecurity firm offering ISO 27001, HDS, and NIS2 compliance assessments.

ISO 27001HdsGDPRNIS2

System 1 Inc.

Denver, CO

$15,000–$80,000

System 1 Inc. is a Denver-area cybersecurity consultancy advising government and critical infrastructure clients on IT audit and NIST-based compliance.

NIST CSFNIST 800-53NIST 800-171

Talal Abu-Ghazaleh & Co International

Amman, Jordan

$6,000–$45,000

Talal Abu-Ghazaleh & Co is the largest Arab professional services firm, offering audit, ISO certification, SOC, and compliance services across the MENA region.

SOC 1SOC 2ISO 27001ISO 27701+4

Tanner LLC

Salt Lake City, UT

$18,000–$75,000

Tanner LLC is a full-service CPA firm in Salt Lake City specializing in SOC, HIPAA, and ISO 27001 audits.

SOC 2SOC 1SOC 3HIPAA+1

Tata Advanced Systems Cyber

Hyderabad, India

$8,000–$50,000

Tata Advanced Systems provides cybersecurity compliance for defense and aerospace sectors.

ISO 27001SOC 2NIST CSFDPDPA

Tata Elxsi Cybersecurity

Bangalore, India

$6,000–$40,000

Tata Elxsi Cybersecurity offers ISO 27001 and SOC 2 assessments with automotive and IoT specialization.

ISO 27001SOC 2HIPAAGDPR+2

TCS (Tata Consultancy Services)

Featured

Mumbai, India

$30,000–$200,000

TCS is India's largest IT services company offering cybersecurity, compliance audit, and risk advisory services to enterprises across 46 countries worldwide.

ISO 27001ISO 27002ISO 27701ISO 22301+7

TCS Cybersecurity

Featured

Mumbai, India

$15,000–$200,000

TCS Cybersecurity provides enterprise-grade compliance services across SOC, ISO 27001, PCI DSS, and more.

ISO 27001SOC 2SOC 1PCI DSS+5

Tech Mahindra Cybersecurity

Featured

Pune, India

$10,000–$150,000

Tech Mahindra Cybersecurity offers ISO 27001, SOC 2, and PCI DSS compliance for enterprises globally.

ISO 27001SOC 2PCI DSSHIPAA+3

TechGuard Security

Chesterfield, MO

$10,000–$60,000

TechGuard Security is a woman-owned Chesterfield, MO cybersecurity firm providing CMMC readiness, NIST 800-171 assessments, and IT audit services.

CMMCNIST 800-171NIST CSF

Telos Compliance

Ashburn, VA

$25,000–$150,000

Telos provides FedRAMP, CMMC, and NIST compliance assessment services for government contractors.

FedRAMPCMMCNIST 800-53NIST 800-171+2

Telstra Purple (Cybersecurity)

Featured

Melbourne, Australia

A$30,000–A$150,000

Telstra Purple is a leading Australian cybersecurity firm offering IRAP, ISO 27001, and SOC 2 assessments.

ISO 27001SOC 2IRAPEssential Eight+3

Tempest Security Intelligence

Recife, Brazil

R$30,000–R$150,000

Tempest Security is Brazil's largest cybersecurity firm offering ISO 27001, SOC 2, and LGPD compliance.

ISO 27001SOC 2PCI DSSLGPD+1

Tempo Audits

Bristol, UK

£8,000–£35,000

Tempo Audits is a UK-based UKAS-accredited certification body offering fast-track ISO 27001 and SOC 2 audits for technology startups and scale-ups.

ISO 27001SOC 2

Tesserent

Melbourne, VIC, Australia

A$30,000–A$150,000

Tesserent is Australia's largest ASX-listed cybersecurity firm (now Thales subsidiary) offering IRAP assessments, ISO 27001, SOC 2, and Essential Eight compliance.

ISO 27001SOC 2PCI DSSEssential Eight

Tetra Defense (Arctic Wolf)

Madison, WI

$20,000–$100,000

Tetra Defense (Arctic Wolf) provides SOC 2, ISO 27001, and incident response compliance services.

SOC 2ISO 27001PCI DSSHIPAA+2

Tevora

Irvine, CA

$10,000–$50,000

Tevora is a boutique cybersecurity and compliance firm based in Southern California specializing in SOC 2, PCI DSS, HITRUST, and ISO 27001 assessments for startups and mid-market companies.

SOC 2ISO 27001HIPAAPCI DSS+5

Thoropass

New York, NY

$10,000–$60,000

Thoropass is a New York compliance company pairing an automation platform with in-house auditors for SOC 2, ISO 27001, HITRUST, PCI DSS, and HIPAA.

SOC 1SOC 2ISO 27001HITRUST+2

Thrive

Foxborough, MA

$12,000–$90,000

Thrive is a Massachusetts-based global technology outsourcing provider delivering managed security and compliance services across regulated industries.

SOC 2NIST CSFHIPAACMMC

TopCertifier

Dubai, UAE

$10,000–$50,000

TopCertifier is a global compliance consulting firm with offices in Dubai, LATAM, and Asia offering ISO 27001, SOC 2, and multi-framework certifications.

SOC 2SOC 1ISO 27001GDPR+2

TQS

Singapore

SGD 4,000–SGD 20,000

TQS is a Singapore-based accredited certification body offering ISO 27001 and management system certifications across Southeast Asia.

ISO 27001ISO 9001ISO 14001ISO 22301+1

TraceSecurity

Baton Rouge, LA

$8,000–$45,000

TraceSecurity is a Baton Rouge firm providing IT risk assessments, audits, and penetration testing to banks and credit unions under GLBA, FFIEC, and NCUA rules.

NIST CSFHIPAA

Trout CPA

Lancaster, PA

$15,000–$50,000

Trout CPA is a Pennsylvania-based firm offering SOC and HIPAA compliance audits for mid-market companies.

SOC 2SOC 1HIPAA

True Digital Security

Tulsa, OK

$10,000–$60,000

True Digital Security is a Tulsa-based cybersecurity operations and compliance firm, now part of CISO Global (formerly Cerberus Sentinel).

SOC 1SOC 2HIPAANIST CSF+1

True North Networks

Philadelphia, PA

$15,000–$60,000

True North Networks provides cybersecurity compliance and SOC 2 assessments for financial services firms.

SOC 2NIST CSFHIPAA

Truesec

Featured

Stockholm, Sweden

SEK 25,000–SEK 100,000

Truesec is a leading Swedish cybersecurity firm offering ISO 27001, SOC 2, and NIS2 compliance assessments.

ISO 27001SOC 2GDPRNIS2+1

TrustedSec

Strongsville, OH

$15,000–$120,000

TrustedSec is an Ohio-based security consultancy founded in 2012 by David Kennedy offering PCI DSS, HIPAA, and risk assessment services.

PCI DSSHIPAANIST CSF

Trustwave

Featured

Chicago, IL

$20,000–$120,000

Trustwave is a global cybersecurity firm specializing in PCI DSS, SOC 2, and ISO 27001 assessments.

PCI DSSSOC 2ISO 27001HIPAA+2

TUV Austria

Vienna, Austria

$8,000–$50,000

TUV Austria is an Austrian testing, inspection, and certification organization offering ISO 27001, ISO 27701, and management system certifications across Central and Eastern Europe.

ISO 27001ISO 27701ISO 22301ISO 27017+2

TUV India

Mumbai, India

$4,000–$35,000

TUV India is a leading ISO certification body offering ISO 27001, ISO 9001, and related certifications.

ISO 27001ISO 9001ISO 14001ISO 22301+2

TUV Nord

Hanover, Germany

$10,000–$70,000

TUV Nord is a German certification body providing ISO 27001, TISAX, and management system certifications with strong European and Asian market presence.

ISO 27001ISO 27002ISO 27701ISO 22301+3

TUV Rheinland

Featured

Cologne, Germany

$12,000–$85,000

TUV Rheinland is a world-leading German certification and testing body providing ISO 27001, TISAX, and management system certifications across 60+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

TUV SUD

Featured

Munich, Germany

$12,000–$80,000

TUV SUD is a leading German testing, inspection, and certification body providing ISO 27001, TISAX, and management system certifications across 50+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

TwoSense Cybersecurity

Phoenix, AZ

$10,000–$45,000

TwoSense Cybersecurity offers SOC 2, ISO 27001, and CMMC assessments for growing companies.

SOC 2ISO 27001CMMCNIST CSF+1

UHY Hacker Young

London, UK

$10,000–$45,000

UHY Hacker Young is a UK chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials audit services through the UHY International network.

ISO 27001SOC 2GDPRCyber Essentials+1

UHY LLP

Farmington Hills, MI

$25,000–$150,000

UHY LLP is a national CPA firm and UHY International member offering SOC examinations, ISO 27001, PCI DSS, HITRUST, and IT risk advisory services.

SOC 1SOC 2ISO 27001PCI DSS+1

UKAS Accredited Certification Bodies

Staines-upon-Thames, UK

$8,000–$50,000

UKAS is the UK's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and other management system certifications.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Univate Solutions

Bangalore, Karnataka, India

₹400,000–₹1,800,000

Univate Solutions is a Bangalore-based SOC 2 expert with 70+ successful implementations, serving Fortune 100 organizations across India and APAC.

SOC 2SOC 1ISO 27001

ValueMentor

Kochi

$8,000–$45,000

ValueMentor is a Kochi-based cybersecurity and payment security firm offering PCI DSS, ISO 27001, and SOC 2 compliance services.

PCI DSSISO 27001SOC 2

Vantage Point Security

Singapore

$10,000–$80,000

Vantage Point Security is a CREST-accredited Singapore security assurance firm offering penetration testing and PCI DSS and ISO 27001 assessment services.

PCI DSSISO 27001

VantagePoint Advisory

Chicago, IL

$12,000–$55,000

VantagePoint Advisory is a Chicago-based compliance firm offering SOC 2, ISO 27001, and PCI DSS assessments.

SOC 2ISO 27001PCI DSSHIPAA+2

Varutra Consulting

Pune, India

$4,000–$25,000

Varutra Consulting provides PCI DSS, ISO 27001, and SOC 2 assessments from Pune, India.

ISO 27001SOC 2PCI DSSHIPAA+2

Vectra Corp

Adelaide, SA, Australia

A$25,000–A$80,000

Vectra Corp is Australia's pioneering PCI DSS QSA firm (certified since 2006), headquartered in Adelaide with offices in all major Australian cities.

PCI DSSISO 27001

Veritas Advisory Switzerland

Geneva, Switzerland

CHF 30,000–CHF 120,000

Veritas Advisory Switzerland offers ISO 27001 and SOC 2 assessments for Swiss financial institutions.

ISO 27001SOC 2GDPRNIST CSF

Vertech

Auckland, New Zealand

NZ$12,000–NZ$35,000

Vertech is an Auckland-based IT security and compliance firm offering SOC 2, ISO 27001, and Compliance-as-a-Service for New Zealand technology startups and scale-ups.

SOC 2ISO 27001

Viettel Cyber Security

Hanoi, Vietnam

$5,000–$25,000

Viettel Cyber Security offers ISO 27001 and SOC 2 assessments in Vietnam.

ISO 27001SOC 2PCI DSSNIST CSF

Viking Cloud

Chicago, IL

$10,000–$150,000

VikingCloud is a Chicago-based PCI Qualified Security Assessor company with 100+ QSAs delivering PCI DSS assessments and compliance programs globally.

PCI DSS

Virtusa Middle East

Dubai, UAE

AED 50,000–AED 250,000

Virtusa Middle East offers ISO 27001, SOC 2, and NESA compliance for GCC enterprises.

ISO 27001SOC 2PCI DSSNesa+1

Vista InfoSec

Mumbai, India

$8,000–$50,000

Vista InfoSec is a global cybersecurity and compliance firm offering PCI DSS, SOC 2, ISO 27001, and GDPR assessments at competitive international pricing.

SOC 1SOC 2ISO 27001ISO 27002+7

VNPT Cyber Security

Ho Chi Minh City, Vietnam

$4,000–$20,000

VNPT Cyber Security provides ISO 27001 and SOC 2 assessments in Vietnam.

ISO 27001SOC 2PCI DSS

Walker Chandiok & Co LLP

New Delhi, India

$6,000–$40,000

Walker Chandiok & Co is Grant Thornton's India affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for mid-market and enterprise clients.

SOC 1SOC 2ISO 27001ISO 27701+4

Warren Averett

Birmingham, Alabama

$20,000–$90,000

Warren Averett is a top-50 US CPA firm based in Alabama providing audit, tax, and cybersecurity advisory services across the Southeastern United States.

SOC 1SOC 2ISO 27001HIPAA+3

Warren Lott & Associates

Minneapolis, MN

$14,000–$50,000

Warren Lott & Associates is a Minneapolis CPA firm providing SOC and HIPAA compliance audits.

SOC 2SOC 1HIPAA

Waverley Lake

London, United Kingdom

£12,000–£50,000

Waverley Lake is a London cybersecurity consultancy offering ISO 27001, SOC 2, and Cyber Essentials assessments.

ISO 27001SOC 2GDPRCyber Essentials+2

Wavestone

Featured

Paris, France

€30,000–€200,000

Wavestone is a French management and technology consultancy offering ISO 27001, NIS2, and GDPR compliance.

ISO 27001SOC 2GDPRNIS2+3

Waystone

Dublin

$20,000–$120,000

Waystone is a Dublin-headquartered global governance, risk, and compliance solutions provider serving asset managers and financial institutions.

NIST CSFGDPR

we45 Solutions

Chennai, India

$5,000–$30,000

we45 Solutions is a Chennai-based security firm offering SOC 2, ISO 27001, and DevSecOps assessments.

SOC 2ISO 27001HIPAAGDPR+2

Weaver

Houston, TX

$25,000–$150,000

Weaver is a top-50 Texas-founded national CPA firm offering SOC reporting, PCI DSS, HITRUST, and IT advisory alongside assurance and tax services.

SOC 1SOC 2SOC 3PCI DSS+2

Weide & Miller

Las Vegas, NV

$10,000–$45,000

Weide & Miller is a Las Vegas, NV firm listed for SOC 1, SOC 2, and compliance services for service organizations in the region.

SOC 1SOC 2

Weinberg & Company

Los Angeles, CA

$18,000–$65,000

Weinberg & Company is an LA-based CPA firm specializing in SOC 2, SOC 1, and SOX audits for technology companies.

SOC 2SOC 1SOX

Welch LLP

Ottawa, ON

CA$20,000–CA$80,000

Welch LLP is an Ottawa CPA firm offering SOC and PIPEDA compliance audits.

SOC 2SOC 1SOXPIPEDA

Wessel & Company

Johnstown, PA

$12,000–$50,000

Wessel & Company is a Johnstown, PA CPA firm founded in 1958 providing SOC 1 and SOC 2 examinations, financial audits, and compliance services.

SOC 1SOC 2

Whitley Penn

Fort Worth, TX

$20,000–$80,000

Whitley Penn is a Top 50 CPA firm in Texas offering SOC, SOX, and HIPAA compliance audits.

SOC 2SOC 1SOXHIPAA

Windham Brannon

Atlanta, GA

$20,000–$80,000

Windham Brannon is an Atlanta-based CPA firm with deep SOC, HIPAA, and SOX audit expertise.

SOC 2SOC 1HIPAASOX

Wipfli

Milwaukee, Wisconsin

$25,000–$120,000

Wipfli is a top-20 US CPA and consulting firm with strong Midwest presence, providing audit, tax, and cybersecurity advisory services to mid-market clients.

SOC 1SOC 2SOC 3ISO 27001+5

Wipro Cybersecurity

Featured

Bangalore, India

$15,000–$200,000

Wipro Cybersecurity offers enterprise-grade compliance services across ISO 27001, SOC, and PCI DSS.

ISO 27001SOC 2SOC 1PCI DSS+5

WithSecure

Featured

Helsinki, Finland

€25,000–€120,000

WithSecure (formerly F-Secure Business) is a Finnish cybersecurity firm offering ISO 27001 and NIS2 compliance.

ISO 27001SOC 2GDPRNIS2+1

WithumSmith+Brown

Princeton, NJ

$15,000–$65,000

WithumSmith+Brown is a top-25 US CPA and advisory firm based in New Jersey, offering SOC 1, SOC 2, ISO 27001, and HIPAA audit services for mid-market companies.

SOC 1SOC 2ISO 27001HIPAA+4

Wolf & Company

Boston, MA

$25,000–$100,000

Wolf & Company is a century-old Boston-based CPA firm with deep expertise in IT audit, SOC reporting, HITRUST, and financial services compliance.

SOC 2SOC 1ISO 27001HIPAA+4

Xcina Consulting

London, United Kingdom

£12,000–£60,000

Xcina Consulting provides ISO 27001, GDPR, and NIS2 compliance assessments for UK enterprises.

ISO 27001GDPRNIS2Cyber Essentials+1

Xynexis International

Jakarta, Indonesia

$6,000–$35,000

Xynexis International is an Indonesian cybersecurity firm offering ISO 27001 and PCI DSS assessments.

ISO 27001SOC 2PCI DSSNIST CSF

Yarix S.r.l.

Montebelluna, Italy

€18,000–€80,000

Yarix is an Italian cybersecurity firm offering ISO 27001, GDPR, and NIS2 compliance assessments.

ISO 27001GDPRNIS2SOC 2+1

YHB

Winchester, VA

$15,000–$80,000

YHB is a Virginia-based CPA and advisory firm founded in 1947 offering SOC 1 and SOC 2 examinations through its risk advisory services team.

SOC 1SOC 2

Showing 639 of 639 firms