AuditXYZ

Auditor Directory

Find a Compliance Auditor

Search 263+ accredited firms worldwide. Filter by name, location, compliance framework, size, and budget — or let us match you automatically.

Step 1 of 520%

Which framework do you need?

Find Auditors by Framework

Browse by Region

All Auditor Firms

360 Advanced

Nashville, TN

$18,000–$70,000

360 Advanced is a US-based compliance audit firm offering SOC 2, PCI DSS, HITRUST, ISO 27001, and HIPAA audits with a focus on technology and healthcare companies.

SOC 2SOC 1ISO 27001PCI DSS+4

A-LIGN

Featured

Tampa, FL

$15,000–$80,000

A-LIGN is one of the largest and most recognized compliance audit firms in the United States. Profile includes pricing, framework coverage, reviews, and engagement process.

SOC 2ISO 27001HIPAAPCI DSS+6

A-Systems

Dubai, UAE

$5,000–$30,000

A-Systems is a UAE-based ISO certification body offering ISO 27001, ISO 27701, and ISO 22301 certification audits for organizations in the Middle East.

ISO 27001ISO 27701ISO 22301ISO 27017+1

Accredia Accredited Certification Bodies

Rome, Italy

$7,000–$40,000

Accredia is Italy's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and management system certifications in the Italian market.

ISO 27001ISO 27701ISO 22301ISO 27017+2

AENOR

Madrid, Spain

$7,000–$40,000

AENOR is Spain's national standards and certification body offering ISO 27001, ISO 27701, ENS, and management system certifications across Spain and Latin America.

ISO 27001ISO 27701ISO 22301ISO 27017+3

AFNOR Certification

Saint-Denis, France

$8,000–$50,000

AFNOR Certification is France's national standards body and a COFRAC-accredited ISO certification body offering ISO 27001, ISO 27701, and HDS audits.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Al Ghaith & Co

Abu Dhabi, UAE

$8,000–$40,000

Al Ghaith & Co is a leading UAE audit and advisory firm offering SOC, ISO 27001, and compliance services for government entities and private sector organizations.

SOC 1SOC 2ISO 27001ISO 27701+1

AMARU

Wellington, New Zealand

NZ$15,000–NZ$50,000

AMARU is a New Zealand cybersecurity firm offering ISO 27001, SOC 2, and NIST compliance services for ANZ technology companies expanding globally.

ISO 27001SOC 2HIPAAGDPR+1

ANAB Accredited Certification Bodies

Milwaukee, WI

$10,000–$60,000

ANAB is the US national accreditation body under ANSI, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and management system certifications.

ISO 27001ISO 27701ISO 22301ISO 27017+4

Anchin Block & Anchin LLP

New York, NY

$12,000–$45,000

Anchin Block & Anchin is a New York-based CPA firm offering SOC 1, SOC 2, HIPAA, and cybersecurity audit services for mid-market companies.

SOC 1SOC 2HIPAANIST CSF+1

APCER

Porto, Portugal

$6,000–$35,000

APCER is a Portuguese ISO certification body offering ISO 27001, ISO 27701, and management system certifications across Portugal, Brazil, and Lusophone Africa.

ISO 27001ISO 27701ISO 22301ISO 27017+1

Aprio

Atlanta, Georgia

$20,000–$100,000

Aprio is a top-25 US CPA and advisory firm offering SOC 2, ISO 27001, HITRUST, and cybersecurity assessments with strong technology sector expertise.

SOC 1SOC 2SOC 3ISO 27001+8

Arete Advisors

Nashville, TN

$15,000–$60,000

Arete Advisors is a healthcare compliance specialist based in Nashville, focusing on HIPAA, HITRUST, and health-tech security assessments.

HIPAAHITRUSTSOC 2NIST 800-53

Armanino

San Ramon, California

$20,000–$100,000

Armanino is a top-25 US CPA firm based in California with strong technology sector focus, offering SOC 2, ISO 27001, and cybersecurity assessments.

SOC 1SOC 2SOC 3ISO 27001+9

ASGN Cybersecurity

Glen Allen, VA

$12,000–$60,000

ASGN Cybersecurity is a boutique US cybersecurity and compliance firm specializing in SOC 2, FedRAMP, CMMC, and HITRUST assessments for government contractors and technology companies.

SOC 2ISO 27001HIPAAPCI DSS+5

Assent Risk Management

London, UK

£12,000–£40,000

Assent Risk Management is a London-based compliance firm specializing in SOC 2, ISO 27001, and GDPR assessments for UK and European technology companies.

SOC 2ISO 27001GDPR

AssurancePoint

Atlanta, GA

$10,000–$45,000

AssurancePoint is a boutique CPA firm specializing in SOC 2 audits for technology companies. Profile includes pricing, framework coverage, and engagement details.

SOC 2SOC 1HIPAANIST 800-53

Astra Security

New Delhi, India

₹200,000–₹1,200,000

Astra Security is a CERT-IN empanelled, NASSCOM-awarded cybersecurity firm in New Delhi offering automated and manual penetration testing alongside compliance services.

ISO 27001SOC 2PCI DSSHIPAA+1

ATX Defense

Austin, TX

$30,000–$100,000

ATX Defense is the first Google Partner to become a CMMC C3PAO, specializing in FedRAMP and CMMC assessments for defense contractors in Austin, TX.

CMMCFedRAMPNIST 800-171

AuditBoard Partner Network

Cerritos, California

$30,000–$150,000

AuditBoard Partner Network connects enterprises with vetted audit firms that integrate with AuditBoard's GRC and internal audit management platform.

SOC 1SOC 2ISO 27001HIPAA+6

Baker Tilly

Featured

Chicago, Illinois

$30,000–$180,000

Baker Tilly is a top-10 global advisory CPA firm network with 43,000+ professionals in 141 countries, serving mid-market and growth companies.

SOC 1SOC 2SOC 3ISO 27001+6

Baker Tilly JFC

Dubai, UAE

$8,000–$40,000

Baker Tilly JFC is Baker Tilly International's Middle East member firm offering SOC, ISO 27001, PCI DSS, and compliance audit services across the Gulf region.

SOC 1SOC 2ISO 27001ISO 27701+3

BARR Advisory

Fairway, KS

$20,000–$75,000

BARR Advisory is a Kansas-based cybersecurity and compliance firm specializing in SOC 2, HITRUST, FedRAMP, and ISO 27001 audits for cloud-first companies.

SOC 2ISO 27001HITRUSTFedRAMP+3

BDO Australia

Melbourne, Australia

$18,000–$100,000

BDO Australia is a leading mid-market audit and advisory firm providing SOC 2, ISO 27001, Essential Eight, and Privacy Act compliance services to Australian businesses across technology, financial services, and healthcare.

SOC 1SOC 2ISO 27001ISO 27701+5

BDO Germany

Hamburg, Germany

$20,000–$120,000

BDO Germany is a leading mid-market audit and advisory firm providing ISO 27001, C5, TISAX, SOC 2, and GDPR compliance services to German mid-market companies and the Mittelstand.

SOC 1SOC 2ISO 27001ISO 27701+6

BDO International

Featured

Brussels, Belgium

$40,000–$250,000

BDO is the fifth-largest professional services network globally, providing audit, tax, and advisory services through member firms in over 160 countries.

SOC 1SOC 2SOC 3ISO 27001+9

BDO Japan

Tokyo, Japan

$20,000–$100,000

BDO Japan is a mid-market audit and advisory firm providing ISO 27001, SOC 2, APPI, and P-Mark compliance services to mid-market companies and foreign-invested businesses operating in Japan.

SOC 1SOC 2ISO 27001ISO 27701+6

BDO Singapore

Singapore

$18,000–$80,000

BDO Singapore is a mid-market audit and advisory firm providing SOC 2, ISO 27001, PDPA, and MTCS compliance services to SMEs, mid-market firms, and listed companies in Singapore.

SOC 1SOC 2ISO 27001ISO 27701+5

BDO UAE

Dubai, UAE

$25,000–$120,000

BDO UAE is BDO International's member firm in the UAE, providing audit, tax, and advisory services with strong compliance capabilities for Gulf businesses.

SOC 1SOC 2ISO 27001ISO 27002+5

BDO UK LLP

London, United Kingdom

$20,000–$130,000

BDO UK is one of the UK's largest accountancy and business advisory firms, providing SOC 2, ISO 27001, GDPR, and Cyber Essentials audit services to mid-market and enterprise organizations.

SOC 1SOC 2ISO 27001ISO 27701+6

Berdon LLP

New York, NY

$12,000–$45,000

Berdon LLP is a New York-based CPA firm offering SOC 1, SOC 2, HIPAA, and IT audit services for mid-market real estate and financial services companies.

SOC 1SOC 2HIPAANIST CSF

BKD CPAs & Advisors

Springfield, MO

$15,000–$70,000

BKD CPAs & Advisors is a leading mid-market US CPA firm based in Missouri offering SOC, ISO 27001, HIPAA, and cybersecurity audit services across the central United States.

SOC 1SOC 2ISO 27001HIPAA+3

Boulay Group

Minneapolis, MN

$20,000–$60,000

Boulay Group is a top-10 Minnesota CPA firm with 300+ professionals offering SOC reporting, HIPAA audits, and Microsoft SSPA assessments.

SOC 2SOC 1HIPAA

BPM LLP

San Jose, CA

$15,000–$65,000

BPM LLP is a leading West Coast accounting firm providing SOC 2, ISO 27001, and HIPAA audit services to technology companies and mid-market organizations in Silicon Valley and beyond.

SOC 1SOC 2ISO 27001HIPAA+4

Brisk InfoSec

Chennai, Tamil Nadu, India

₹250,000–₹1,500,000

Brisk InfoSec is a CREST-accredited, CERT-IN empanelled cybersecurity firm in Chennai with 100% ISO 27001 audit success rate.

ISO 27001SOC 2GDPRNIST CSF

British Assessment Bureau

Bury, UK

£2,500–£18,000

British Assessment Bureau is a UKAS-accredited certification body serving UK SMBs with ISO 27001, ISO 9001, and Cyber Essentials certifications.

ISO 27001ISO 9001ISO 14001ISO 45001+1

BSI Group

Featured

London, UK

$10,000–$80,000

BSI Group is the world's first national standards body and largest ISO certification body, offering ISO 27001, ISO 27701, SOC 2, and Cyber Essentials audits globally.

ISO 27001ISO 27701ISO 27017ISO 27018+6

BSI Group

Featured

London, United Kingdom

$15,000–$100,000

BSI Group is the world's leading standards and certification body, providing ISO 27001, ISO 22301, and other management system certifications globally.

ISO 27001ISO 27002ISO 27017ISO 27018+8

BSR & Associates LLP

Mumbai, India

$7,000–$50,000

BSR & Associates LLP is KPMG India's audit affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for enterprise and mid-market clients.

SOC 1SOC 2ISO 27001ISO 27701+4

BSR & Co (KPMG India affiliate)

Mumbai, India

$20,000–$150,000

BSR & Co is KPMG's affiliate firm in India, providing audit, assurance, tax, and advisory services with Big Four methodology to Indian enterprises.

SOC 1SOC 2ISO 27001HIPAA+4

Bulletproof

London, UK

£10,000–£50,000

Bulletproof is a London-based cybersecurity firm offering ISO 27001, SOC 2, PCI DSS, and GDPR compliance services alongside CREST-certified penetration testing.

ISO 27001SOC 2GDPRPCI DSS+1

Bureau Veritas

Featured

Paris, France

$12,000–$80,000

Bureau Veritas is a world-leading testing, inspection, and certification company providing ISO 27001 and management system certifications in 140+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

Camacho & Co

Bogota, Colombia

$4,000–$20,000

Camacho & Co is a Colombian CPA firm offering SOC, ISO 27001, and compliance audit services for mid-market companies in Colombia and the Andean region.

SOC 1SOC 2ISO 27001PCI DSS

Canadian Cyber

Toronto, ON, Canada

CA$15,000–CA$50,000

Canadian Cyber is a Toronto-based cybersecurity and compliance firm specializing in ISO 27001, SOC 2, and privacy assessments for Canadian technology companies.

ISO 27001SOC 2GDPRPIPEDA

CBIZ

Cleveland, Ohio

$25,000–$130,000

CBIZ is a leading US business services company offering audit, tax, insurance, and advisory services through 100+ offices across the United States.

SOC 1SOC 2SOC 3ISO 27001+4

CERT-In Empaneled Auditors

New Delhi, India

$3,000–$50,000

CERT-In empaneled auditors are organizations authorized by India's Computer Emergency Response Team to conduct cybersecurity audits for regulatory compliance.

ISO 27001ISO 27002NIST CSFGDPR

Certification Europe

Dublin, Ireland

€5,000–€40,000

Certification Europe is an Irish-based accredited certification body specializing in ISO 27001 and management system certifications across Europe.

ISO 27001ISO 9001ISO 22301GDPR+1

CertPro

Singapore

$12,000–$45,000

CertPro is a Singapore-headquartered compliance firm offering SOC 2, ISO 27001, and PCI DSS certifications across Asia-Pacific, with offices in Hong Kong, Toronto, and London.

SOC 2ISO 27001PCI DSSGDPR+1

Cherry Bekaert

Richmond, Virginia

$25,000–$120,000

Cherry Bekaert is a top-25 US CPA firm providing audit, tax, and advisory services with strong presence in the Southeast and growing national coverage.

SOC 1SOC 2SOC 3ISO 27001+4

CliftonLarsonAllen LLP

Featured

Minneapolis, MN

$20,000–$100,000

CliftonLarsonAllen (CLA) is a top-eight US CPA firm headquartered in Minneapolis, offering SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, and CMMC audit services nationally.

SOC 1SOC 2ISO 27001HIPAA+5

CNAS Accredited Certification Bodies

Beijing, China

$5,000–$40,000

CNAS is China's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and management system certifications in the Chinese market.

ISO 27001ISO 27701ISO 22301ISO 27017+2

Coalfire

Featured

Westminster, Colorado

$25,000–$150,000

Coalfire is a leading US cybersecurity advisory and audit firm specializing in FedRAMP, SOC 2, PCI DSS, HITRUST, and CMMC for cloud and technology companies.

SOC 1SOC 2ISO 27001ISO 27017+11

COFRAC Accredited Certification Bodies

Paris, France

$7,000–$45,000

COFRAC is France's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, HDS, and management system certifications.

ISO 27001ISO 27701ISO 22301ISO 27017+3

CohnReznick LLP

New York, NY

$20,000–$100,000

CohnReznick is a top-20 US accounting firm providing SOC 2, ISO 27001, HIPAA, and financial audit services to mid-market and enterprise clients across technology, financial services, and healthcare.

SOC 1SOC 2ISO 27001HIPAA+6

Compass IT Compliance

Providence, RI

$15,000–$60,000

Compass IT Compliance is a Providence-based QSA and HITRUST assessor offering PCI DSS, SOC 2, HIPAA, and penetration testing for financial and healthcare organizations.

PCI DSSSOC 2HIPAAHITRUST+2

Compass IT Compliance

Tampa, FL

$15,000–$75,000

Compass IT Compliance is a PCI DSS specialist firm serving retail, healthcare, and hospitality organizations. Profile includes pricing and framework coverage.

PCI DSSHIPAAHITRUSTSOC 2+1

Compliance Solutions ME

Dubai, UAE

$8,000–$40,000

Compliance Solutions ME is a boutique GRC consultancy in Dubai specializing in ISO 27001, PCI DSS, and GDPR compliance for Middle Eastern organizations.

ISO 27001PCI DSSGDPRNIST CSF+1

ComplianceForge

Scottsdale, Arizona

$5,000–$40,000

ComplianceForge provides cybersecurity documentation templates, consulting, and NIST/CMMC/ISO implementation support for organizations building compliance programs.

NIST CSFNIST 800-53ISO 27001ISO 27002+6

CompliancePoint

Duluth, GA

$20,000–$70,000

CompliancePoint is a HITRUST-authorized assessor in Georgia offering SOC 2, HITRUST, HIPAA, and ISO 27001 audits for healthcare and technology companies.

HITRUSTSOC 2HIPAAISO 27001+2

Continuum GRC

Austin, TX

$25,000–$100,000

Continuum GRC is the first FedRAMP-authorized GRC SaaS platform with integrated assessment capabilities for FedRAMP, CMMC, SOC 2, and ISO 27001.

FedRAMPCMMCSOC 2ISO 27001+3

ControlCase

Fairfax, Virginia

$15,000–$80,000

ControlCase is a compliance and cybersecurity firm specializing in PCI DSS, SOC 2, ISO 27001, and HITRUST audits with a unified compliance approach.

SOC 1SOC 2ISO 27001ISO 27002+10

CQA - Canada Quality Audit

Toronto, Canada

$8,000–$35,000

CQA (Canada Quality Audit) is a Canadian SCC-accredited ISO certification body offering ISO 27001, ISO 27701, and management system certifications across Canada.

ISO 27001ISO 27701ISO 22301ISO 27017

Crowe Global

Featured

New York, United States

$35,000–$200,000

Crowe Global is a top-10 global accounting network providing audit, tax, and advisory services through member firms in over 145 countries worldwide.

SOC 1SOC 2SOC 3ISO 27001+6

Crowe Middle East

Dubai, UAE

$18,000–$80,000

Crowe Middle East is a mid-market audit and advisory firm providing ISO 27001, SOC 2, NESA, and PDPL compliance services to SMEs and mid-market businesses across the UAE, Saudi Arabia, and Bahrain.

SOC 1SOC 2ISO 27001ISO 27701+5

Cyber Forte

Melbourne, VIC, Australia

A$18,000–A$45,000

Cyber Forte is a Melbourne-based compliance firm delivering fast-tracked SOC 2 and ISO 27001 certification with 100% first-attempt success rate for Australian tech companies.

SOC 2ISO 27001PCI DSS

CyberNinja

Sydney, Australia

A$20,000–A$60,000

CyberNinja is a Sydney-based cybersecurity firm offering IRAP assessments, ISO 27001, SOC 2, and Essential Eight compliance for Australian organizations.

ISO 27001SOC 2Essential Eight

CyberNX Technologies

Mumbai, Maharashtra, India

₹300,000–₹1,500,000

CyberNX Technologies is a Mumbai-based CERT-IN empanelled cybersecurity firm offering cloud security, VAPT, and managed detection services for Indian enterprises.

ISO 27001SOC 2

CyberQ Consulting

Bangalore, Karnataka, India

₹400,000–₹2,000,000

CyberQ Consulting is a Bangalore-based CERT-IN empanelled information security auditor with expertise in government, telecom, and critical infrastructure security.

ISO 27001SOC 2

CyberSapiens

Melbourne, Australia

A$15,000–A$50,000

CyberSapiens is an Australian cybersecurity firm offering SOC 2, ISO 27001, PCI DSS, and HIPAA compliance services for ANZ technology companies.

SOC 2ISO 27001PCI DSSHIPAA+2

CyberSmart

London, UK

£300–£8,000

CyberSmart is a UK-based Cyber Essentials specialist providing automated compliance certification for SMBs and startups.

Cyber EssentialsISO 27001GDPR

DEKRA

Stuttgart, Germany

$8,000–$55,000

DEKRA is one of the world's largest testing, inspection, and certification organizations offering ISO 27001, ISO 27701, and management system certifications globally.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Deloitte

Featured

London, United Kingdom

$75,000–$500,000

Deloitte is the world's largest professional services firm, offering audit, assurance, tax, and advisory services across 150+ countries worldwide.

SOC 1SOC 2SOC 3ISO 27001+16

Deloitte Australia

Featured

Sydney, Australia

$45,000–$300,000

Deloitte Australia is a Big Four professional services firm providing SOC 2, ISO 27001, IRAP, Essential Eight, and enterprise risk advisory services to Australia's largest organizations across government, financial services, and technology.

SOC 1SOC 2ISO 27001ISO 27701+8

Deloitte Canada

Featured

Toronto, Canada

$50,000–$350,000

Deloitte Canada is the country's largest Big Four professional services firm, providing SOC 2, ISO 27001, PIPEDA, SOX, and enterprise risk advisory services across financial services, technology, energy, and government sectors.

SOC 1SOC 2ISO 27001ISO 27701+6

Deloitte Haskins & Sells LLP

Featured

Mumbai, India

$8,000–$60,000

Deloitte Haskins & Sells is Deloitte's primary India affiliate, offering SOC 1, SOC 2, ISO 27001, DPDPA, and compliance audit services across India.

SOC 1SOC 2ISO 27001ISO 27701+4

Deloitte India

Featured

Mumbai, India

$28,000–$230,000

Deloitte India is a Big Four professional services firm providing SOC 2, ISO 27001, DPDPA, SOX, and comprehensive risk advisory services to India's largest corporations and multinational subsidiaries.

SOC 1SOC 2ISO 27001ISO 27701+7

Deloitte Middle East

Featured

Dubai, UAE

$60,000–$400,000

Deloitte Middle East is the region's largest professional services firm, providing Big Four audit, assurance, and advisory services across the MENA region.

SOC 1SOC 2ISO 27001ISO 27002+7

Deloitte Singapore

Featured

Singapore

$40,000–$250,000

Deloitte Singapore is a Big Four professional services firm providing SOC 2, ISO 27001, PDPA, MTCS, and enterprise risk advisory services to major corporations and government agencies across Singapore and Southeast Asia.

SOC 1SOC 2ISO 27001ISO 27701+7

Deloitte Tohmatsu

Featured

Tokyo, Japan

$60,000–$400,000

Deloitte Tohmatsu is Deloitte's Japanese member firm and one of Japan's largest audit firms, providing Big Four services including J-SOX and ISMAP compliance.

SOC 1SOC 2ISO 27001ISO 27002+7

Deloitte Touche Tohmatsu Brazil

Featured

Sao Paulo, Brazil

$10,000–$80,000

Deloitte Brazil is the largest professional services firm in Latin America, offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services.

SOC 1SOC 2ISO 27001ISO 27701+4

DIESEC

Helsinki, Finland

€20,000–€80,000

DIESEC is a Nordic cybersecurity and compliance firm offering ISO 27001, NIS2, and SOC 2 services across Finland, Sweden, Norway, and Denmark.

ISO 27001SOC 2NIS2GDPR

DIN CERTCO

Berlin, Germany

$8,000–$45,000

DIN CERTCO is a German DAkkS-accredited ISO certification body offering ISO 27001, ISO 27701, and management system certifications for European organizations.

ISO 27001ISO 27701ISO 22301GDPR+1

Dixon Hughes Goodman LLP

Charlotte, NC

$15,000–$60,000

Dixon Hughes Goodman (DHG) is a leading Southeast US CPA firm offering SOC 1, SOC 2, ISO 27001, and HIPAA compliance audit services for mid-market companies.

SOC 1SOC 2ISO 27001HIPAA+3

DNV

Featured

Oslo, Norway

$12,000–$80,000

DNV is a global assurance and risk management company providing ISO 27001, ISO 22301, and management system certifications across 100+ countries worldwide.

ISO 27001ISO 27002ISO 27017ISO 27701+5

DQS

Frankfurt, Germany

€10,000–€60,000

DQS is a German-headquartered global certification body offering ISO 27001, TISAX, ISO 27701, and management system audits across 60+ countries.

ISO 27001ISO 27701SOC 2TISAX

EisnerAmper

New York, New York

$30,000–$150,000

EisnerAmper is a top-20 US accounting and advisory firm offering audit, tax, and cybersecurity services with strong presence in the Northeast and nationally.

SOC 1SOC 2SOC 3ISO 27001+6

En4see

Kuala Lumpur, Malaysia

MYR 20,000–MYR 80,000

En4see is a Malaysian cybersecurity and compliance firm specializing in ISO 27001 implementation and certification support for Malaysian and Southeast Asian organizations.

ISO 27001

Epicit

Perth, WA, Australia

A$15,000–A$50,000

Epicit is a Perth-based IT services and cybersecurity firm offering Essential Eight, ISO 27001, and APRA CPS 234 compliance for Western Australian businesses.

ISO 27001Essential EightPCI DSS

Ernst & Young (EY)

Featured

London, United Kingdom

$70,000–$500,000

EY is a Big Four professional services firm providing audit, assurance, tax, consulting, and strategy services across more than 150 countries worldwide.

SOC 1SOC 2SOC 3ISO 27001+16

Ernst & Young Brazil

Featured

Sao Paulo, Brazil

$10,000–$70,000

EY Brazil is Ernst & Young's Brazilian member firm offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services across Brazil.

SOC 1SOC 2ISO 27001ISO 27701+3

eSec Forte Technologies

Gurugram, Haryana, India

₹500,000–₹2,500,000

eSec Forte is a CMMi Level 3 certified, CERT-IN empanelled cybersecurity firm in Gurugram offering PCI DSS QSA, SOC 2, and ISO 27001 audits.

PCI DSSSOC 2ISO 27001HIPAA

Eurofins Assurance

Paris, France

€15,000–€50,000

Eurofins Assurance is the certification division of the Eurofins Group, offering ISO 27001 and management system audits across Europe with multi-country accreditation.

ISO 27001ISO 27701GDPR

EY Australia

Featured

Sydney, Australia

$40,000–$280,000

EY Australia is a Big Four professional services firm providing SOC 2, ISO 27001, IRAP, Essential Eight, and enterprise risk advisory services across financial services, technology, and government sectors in Australia.

SOC 1SOC 2ISO 27001ISO 27701+8

EY France

Featured

Paris, France

$40,000–$280,000

EY France is a Big Four professional services firm providing ISO 27001, GDPR, HDS, SOC 2, and enterprise risk advisory services to French enterprises across financial services, technology, and manufacturing.

SOC 1SOC 2ISO 27001ISO 27701+6

EY Germany

Featured

Stuttgart, Germany

$45,000–$320,000

EY Germany is a Big Four professional services firm providing ISO 27001, C5, TISAX, SOC 2, and GDPR compliance services to German enterprises, automotive companies, and financial institutions.

SOC 1SOC 2ISO 27001ISO 27701+7

EY India

Featured

Mumbai, India

$25,000–$220,000

EY India is the largest Big Four operation in India by headcount, providing SOC 2, ISO 27001, DPDPA, SOX, and comprehensive risk advisory services across all major industries.

SOC 1SOC 2ISO 27001ISO 27701+7

EY Japan

Featured

Tokyo, Japan

$60,000–$350,000

EY Japan (EY ShinNihon) provides Big Four audit, assurance, and advisory services with expertise in J-SOX, ISMAP, and Japanese regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+6

EY MENA

Featured

Dubai, UAE

$55,000–$350,000

EY MENA provides Big Four audit, assurance, tax, and advisory services across the Middle East and North Africa with offices in 15+ MENA countries.

SOC 1SOC 2ISO 27001ISO 27002+7

EY Singapore

Featured

Singapore

$50,000–$280,000

EY Singapore provides Big Four audit, assurance, and advisory services with strong cybersecurity and regulatory compliance capabilities for the ASEAN market.

SOC 1SOC 2ISO 27001ISO 27002+7

Foo Kon Tan LLP

Singapore

$8,000–$35,000

Foo Kon Tan is a leading Singapore CPA firm offering SOC 1, SOC 2, ISO 27001, PDPA, and compliance audit services for SME and mid-market companies.

SOC 1SOC 2ISO 27001ISO 27701+2

Forvis Mazars (US)

Featured

Springfield, Missouri

$30,000–$180,000

Forvis Mazars is a top-10 US professional services firm formed from the merger of BKD and Dixon Hughes Goodman, now part of the Mazars global network.

SOC 1SOC 2SOC 3ISO 27001+6

Friedman LLP

New York, NY

$12,000–$45,000

Friedman LLP is a New York-based CPA firm offering SOC 1, SOC 2, HIPAA, and PCI DSS compliance audits for mid-market companies in the tristate area.

SOC 1SOC 2HIPAAPCI DSS+1

Grant Thornton

Featured

London, United Kingdom

$40,000–$250,000

Grant Thornton is a leading global professional services network providing audit, tax, and advisory services through member firms in over 140 countries.

SOC 1SOC 2SOC 3ISO 27001+9

Grant Thornton Bharat

New Delhi, India

$15,000–$120,000

Grant Thornton Bharat is one of India's largest professional services firms, offering audit, tax, and advisory services including cybersecurity and compliance.

SOC 1SOC 2ISO 27001ISO 27701+5

Grant Thornton LLP

Featured

Chicago, IL

$30,000–$150,000

Grant Thornton US is a top-seven national CPA firm offering SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, FedRAMP, and CMMC audit services for mid-market and enterprise companies.

SOC 1SOC 2ISO 27001HIPAA+8

Grant Thornton UAE

Dubai, UAE

$20,000–$100,000

Grant Thornton UAE is a mid-market audit and advisory firm providing ISO 27001, SOC 2, NESA, and PDPL compliance services to businesses across the UAE.

SOC 1SOC 2ISO 27001ISO 27701+5

Grant Thornton UK LLP

London, United Kingdom

$20,000–$120,000

Grant Thornton UK is a major mid-tier audit and advisory firm providing SOC 2, ISO 27001, GDPR, and financial audit services to UK businesses from startups to listed companies.

SOC 1SOC 2ISO 27001ISO 27701+6

Grassi & Co

New York, NY

$12,000–$50,000

Grassi & Co is a New York-based mid-market CPA firm offering SOC 1, SOC 2, HIPAA, and PCI DSS compliance audit services for SMBs and mid-market companies.

SOC 1SOC 2HIPAAPCI DSS+2

Gridware

Sydney, NSW, Australia

A$20,000–A$60,000

Gridware is a Sydney-based ISMS consultancy with PECB lead auditors delivering ISO 27001 implementations and Essential Eight assessments across Australian cities.

ISO 27001Essential EightNIST CSF

Haysmacintyre LLP

London, UK

$10,000–$45,000

Haysmacintyre is a London-based chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials compliance audit services for mid-market organizations.

ISO 27001SOC 2GDPRCyber Essentials+1

HLB International

London, United Kingdom

$20,000–$130,000

HLB International is a global advisory and accounting network with 40,000+ professionals in member firms spanning 156 countries and territories.

SOC 1SOC 2ISO 27001HIPAA+3

Holbrook & Manter

Columbus, OH

$20,000–$60,000

Holbrook & Manter is a century-old Ohio CPA firm highly regarded for SOC reporting with team holding CITP, CISSP, CISA, and ISO 27001 Lead Auditor certifications.

SOC 2SOC 1ISO 27001HIPAA

Hussain Lootah & Associates

Dubai, UAE

$6,000–$30,000

Hussain Lootah & Associates is a UAE-based audit firm offering SOC, ISO 27001, NESA, and compliance services for mid-market companies in Dubai and Abu Dhabi.

SOC 1SOC 2ISO 27001Nesa+1

IAS (Integrated Assessment Services)

Singapore

SGD 8,000–SGD 30,000

IAS is a Singapore-based certification body offering ISO 27001 and management system audits across Southeast Asia including Malaysia, Thailand, Vietnam, and the Philippines.

ISO 27001ISO 27701

IBSS Corporation

San Antonio, TX

$40,000–$120,000

IBSS Corporation is a 30+ year federal cybersecurity provider and CMMC C3PAO maintaining strict separation between assessment and consulting services.

CMMCISO 27001NIST 800-171

ICONTEC

Bogota, Colombia

$4,000–$25,000

ICONTEC is Colombia's national standards and certification body offering ISO 27001, ISO 27701, and management system certifications across Latin America.

ISO 27001ISO 27701ISO 22301ISO 27017

Illume Intelligence

Kozhikode, Kerala, India

₹300,000–₹1,500,000

Illume Intelligence is a Kerala-based cybersecurity firm with 16+ years experience in VAPT, red team testing, and compliance auditing for government and enterprise clients.

ISO 27001PCI DSSNIST CSFCMMC

InfoSec Brigade

Mumbai, Maharashtra, India

₹300,000–₹1,500,000

InfoSec Brigade is a Mumbai-based CERT-IN empanelled information security consultancy specializing in expert-driven manual penetration testing and compliance consulting.

ISO 27001GDPRSOC 2PCI DSS

Infosys BPM

Bangalore, India

$25,000–$150,000

Infosys BPM provides cybersecurity, compliance audit, and risk management services leveraging Infosys's global delivery model across 30+ countries.

ISO 27001ISO 27002ISO 27701SOC 1+5

Insight Assurance

Miami, Florida

$12,000–$60,000

Insight Assurance is a Florida-based CPA firm specializing in SOC 2, ISO 27001, and HITRUST audits for startups and growing technology companies.

SOC 1SOC 2SOC 3ISO 27001+7

Intertek

London, United Kingdom

$12,000–$75,000

Intertek is a global quality assurance provider offering ISO 27001, ISO 22301, and management system certifications through operations in 100+ countries.

ISO 27001ISO 27002ISO 27017ISO 27701+5

IRQS

Mumbai, India

$1,500–$15,000

IRQS is an accredited ISO certification body based in India, offering ISO 27001, ISO 9001, and other management system certifications across South Asia.

ISO 27001ISO 9001ISO 14001ISO 45001+1

ISRS

Nairobi, Kenya

$2,000–$12,000

ISRS is an accredited ISO certification body based in Kenya, providing ISO 27001 and management system certifications across East Africa.

ISO 27001ISO 9001ISO 14001ISO 45001+1

IT Audit Labs

Minneapolis, Minnesota

$15,000–$60,000

IT Audit Labs is a boutique US cybersecurity firm specializing in SOC 2, NIST, CMMC, and IT audit services for SMBs and defense contractors.

SOC 2ISO 27001HIPAANIST CSF+3

IT Governance

Ely, United Kingdom

$8,000–$50,000

IT Governance is a UK-based cybersecurity and compliance firm providing ISO 27001 implementation, GDPR consulting, and certification support services worldwide.

ISO 27001ISO 27002ISO 27701ISO 22301+5

IT Governance Ltd

Ely, Cambridgeshire, United Kingdom

$5,000–$35,000

IT Governance Ltd is a UK-based boutique specializing in ISO 27001 certification, Cyber Essentials, GDPR compliance, and PCI DSS assessments for SMEs and mid-market organizations.

ISO 27001ISO 27701ISO 27017ISO 27018+5

ITGRC Advisory

London, UK

£10,000–£35,000

ITGRC Advisory is a London-based IT governance and compliance firm offering SOC 2, ISO 27001, and GDPR services for UK technology companies expanding internationally.

SOC 2ISO 27001GDPRCyber Essentials

JAS-ANZ Accredited Certification Bodies

Canberra, Australia

$10,000–$50,000

JAS-ANZ is the joint accreditation body for Australia and New Zealand, accrediting ISO certification bodies operating in the APAC region.

ISO 27001ISO 27701ISO 22301ISO 27017+2

JISC/JAB Accredited Certification Bodies

Tokyo, Japan

$8,000–$50,000

JISC/JAB is Japan's national accreditation body for ISO certification bodies, ensuring ISO 27001 and management system certifications meet international standards.

ISO 27001ISO 27701ISO 22301ISO 27017+2

Johanson Group

Phoenix, AZ

$8,000–$35,000

Johanson Group is a boutique CPA firm in Phoenix specializing in SOC 2 audits for startups and SMBs. Profile includes pricing and engagement details.

SOC 2SOC 1HIPAA

JQS

Tokyo, Japan

¥500,000–¥3,000,000

JQS is a Japanese accredited certification body specializing in ISO 27001 and quality management system certifications for Japanese organizations.

ISO 27001ISO 9001ISO 14001ISO 27017+1

KAB Accredited Certification Bodies

Seoul, South Korea

$7,000–$40,000

KAB is South Korea's national accreditation body for ISO certification bodies, ensuring ISO 27001 and management system certifications meet international standards.

ISO 27001ISO 27701ISO 22301ISO 27017+1

KavachOne

Noida, Uttar Pradesh, India

₹400,000–₹1,800,000

KavachOne is a PCI DSS QSA certified and US Registered CPA firm in India specializing in payment security, ISO 27001, and SOC 2 compliance.

PCI DSSISO 27001SOC 2GDPR

KirkpatrickPrice

Bethesda, MD

$15,000–$70,000

KirkpatrickPrice is a licensed CPA firm with 20,000+ reports issued, specializing in SOC 2, HITRUST, ISO 27001, and PCI DSS audits for technology and healthcare companies.

SOC 2SOC 1ISO 27001HITRUST+2

Kiwa

Rijswijk, Netherlands

$8,000–$50,000

Kiwa is a Netherlands-based global testing, inspection, and certification body offering ISO 27001, ISO 27701, and management system certifications across Europe.

ISO 27001ISO 27701ISO 22301ISO 27017+2

KPMG

Featured

Amstelveen, Netherlands

$70,000–$500,000

KPMG is a Big Four professional services firm providing audit, tax, and advisory services through a global network spanning 143 countries and territories.

SOC 1SOC 2SOC 3ISO 27001+16

KPMG Australia

Featured

Sydney, Australia

$50,000–$300,000

KPMG Australia provides Big Four audit, assurance, and cybersecurity services with deep expertise in APRA, CPS 234, and Australian regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+6

KPMG AZSA LLC

Featured

Tokyo, Japan

$45,000–$320,000

KPMG AZSA (KPMG Japan) is a Big Four audit firm providing SOC 2, ISO 27001, APPI, ISMAP, and enterprise risk advisory services to Japan's largest corporations across technology, manufacturing, and financial services.

SOC 1SOC 2ISO 27001ISO 27701+8

KPMG Brazil

Featured

Sao Paulo, Brazil

$10,000–$65,000

KPMG Brazil is KPMG's Brazilian member firm offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services for enterprises and mid-market companies.

SOC 1SOC 2ISO 27001ISO 27701+3

KPMG Canada

Featured

Toronto, Canada

$42,000–$280,000

KPMG Canada is a Big Four professional services firm providing SOC 2, ISO 27001, PIPEDA, SOX, and enterprise risk advisory services to Canadian organizations across financial services, technology, energy, and government.

SOC 1SOC 2ISO 27001ISO 27701+6

KPMG China

Featured

Beijing, China

$40,000–$300,000

KPMG China is one of China's largest Big Four firms, providing audit, assurance, and advisory services with expertise in Chinese regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+7

KPMG India

Featured

Mumbai, India

$25,000–$200,000

KPMG India is a Big Four professional services firm providing SOC 2, ISO 27001, DPDPA, and enterprise risk advisory services to India's largest organizations across financial services, technology, and government sectors.

SOC 1SOC 2ISO 27001ISO 27701+7

KPMG Lower Gulf

Featured

Dubai, UAE

$50,000–$300,000

KPMG Lower Gulf is KPMG's UAE and Oman practice, providing Big Four audit, assurance, tax, and advisory services across the Gulf region.

SOC 1SOC 2ISO 27001ISO 27002+7

KPMG Singapore

Featured

Singapore

$50,000–$300,000

KPMG Singapore is KPMG's ASEAN hub, providing Big Four audit, assurance, tax, and advisory services with strong regulatory and compliance expertise.

SOC 1SOC 2ISO 27001ISO 27002+7

Kratikal

Noida, Uttar Pradesh, India

₹300,000–₹1,500,000

Kratikal is a CERT-IN empanelled cybersecurity auditor in Noida offering VAPT, ISO 27001, and SOC 2 compliance services for Indian enterprises and startups.

ISO 27001SOC 2

Kreston Reeves LLP

London, UK

$8,000–$40,000

Kreston Reeves is a UK chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials compliance services across London and Southeast England.

ISO 27001SOC 2GDPRCyber Essentials

Kroll

Featured

New York, New York

$35,000–$200,000

Kroll is a global risk and financial advisory firm providing cybersecurity, compliance, and investigation services with deep expertise in digital forensics.

SOC 1SOC 2ISO 27001ISO 27002+10

KSM (Katz, Sapper & Miller)

Indianapolis, Indiana

$20,000–$90,000

KSM (Katz, Sapper & Miller) is a top-50 US CPA firm based in Indianapolis providing audit, tax, and IT risk advisory services to mid-market clients.

SOC 1SOC 2ISO 27001HIPAA+3

Lazarus Alliance

Scottsdale, AZ

$30,000–$150,000

Lazarus Alliance is a FedRAMP 3PAO and StateRAMP assessor in Scottsdale, AZ offering fast-track FedRAMP, SOC 2, PCI DSS, and CMMC assessments for government contractors.

FedRAMPSOC 2PCI DSSCMMC+2

Linford & Company

Denver, CO

$12,000–$60,000

Linford & Company is a Denver-based CPA firm specializing in SOC, ISO 27001, and FedRAMP audits. Profile includes pricing and framework coverage.

SOC 2SOC 1ISO 27001PCI DSS+3

LRQA

Featured

London, United Kingdom

$15,000–$90,000

LRQA is a global assurance and certification provider specializing in ISO 27001, ISO 22301, cybersecurity, and management system certifications worldwide.

ISO 27001ISO 27002ISO 27017ISO 27018+8

Mahajan & Aibara

Mumbai, India

$5,000–$30,000

Mahajan & Aibara is a boutique Indian chartered accountancy firm specializing in SOC 2, ISO 27001, and DPDPA compliance audits for startups, SaaS companies, and mid-market technology firms.

SOC 1SOC 2ISO 27001ISO 27701+4

Marcum LLP

New York, NY

$18,000–$90,000

Marcum LLP is a top-15 US national accounting and advisory firm providing SOC 2, ISO 27001, HIPAA, and financial audit services to mid-market organizations.

SOC 1SOC 2ISO 27001HIPAA+5

Mazars

Featured

Paris, France

$35,000–$200,000

Mazars is an international audit, tax, and advisory firm operating as an integrated partnership across 95+ countries with 47,000+ professionals.

SOC 1SOC 2ISO 27001ISO 27002+8

Mazars France

Paris, France

$20,000–$120,000

Mazars France is the home practice of the Forvis Mazars network, providing ISO 27001, GDPR, HDS, and SOC 2 compliance services to French mid-market companies and enterprises at competitive pricing.

SOC 1SOC 2ISO 27001ISO 27701+5

Mazars Middle East

Dubai, UAE

$25,000–$120,000

Mazars Middle East is a mid-market audit and advisory firm providing ISO 27001, SOC 2, NESA, and PDPL compliance services across the UAE, Saudi Arabia, and Qatar.

SOC 1SOC 2ISO 27001ISO 27701+6

Mazars UK

London, United Kingdom

$15,000–$80,000

Mazars UK is a leading mid-market audit and advisory firm providing ISO 27001, SOC 2, GDPR, and Cyber Essentials compliance services to UK businesses across financial services, technology, and the public sector.

SOC 1SOC 2ISO 27001ISO 27701+5

MHM (Morgan Hockey Malpas)

Calgary, AB, Canada

CA$20,000–CA$60,000

MHM is a Canadian CPA firm with offices in Calgary, Edmonton, and Vancouver, specializing in SOC reporting, ISO 27001, and IT audit for western Canadian companies.

SOC 2SOC 1ISO 27001HIPAA+1

Middle East Certifications

Dubai, UAE

$3,000–$25,000

Middle East Certifications is an accredited ISO certification body based in Dubai, serving organizations across the GCC with ISO 27001 and management system certifications.

ISO 27001ISO 9001ISO 14001ISO 45001+1

MNP LLP

Calgary, Canada

$15,000–$80,000

MNP LLP is Canada's largest national accounting and consulting firm, providing SOC 2, ISO 27001, PIPEDA, and cybersecurity compliance services to mid-market businesses across all Canadian provinces.

SOC 1SOC 2ISO 27001ISO 27701+4

Moore Global

London, United Kingdom

$25,000–$150,000

Moore Global is a top-15 international accounting and advisory network with 34,000+ professionals serving clients across 110+ countries worldwide.

SOC 1SOC 2ISO 27001HIPAA+3

Moore Kingston Smith LLP

London, UK

$10,000–$50,000

Moore Kingston Smith is a London-based chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials audit services as part of the Moore Global network.

ISO 27001SOC 2GDPRCyber Essentials+1

Moss Adams

Seattle, Washington

$30,000–$150,000

Moss Adams is one of the largest US CPA firms, providing audit, tax, and consulting services from 30+ offices primarily across the Western United States.

SOC 1SOC 2SOC 3ISO 27001+5

MSKA & Associates

Mumbai, India

$5,000–$35,000

MSKA & Associates is BDO India's audit affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for mid-market companies in India.

SOC 1SOC 2ISO 27001ISO 27701+3

Nangia Andersen

New Delhi, India

$10,000–$80,000

Nangia Andersen is a leading Indian professional services firm and Andersen Global member, providing audit, tax, and compliance services across India.

SOC 1SOC 2ISO 27001ISO 27701+5

Netrika Consulting

New Delhi, India

₹500,000–₹3,000,000

Netrika Consulting is a CERT-IN empanelled risk and integrity management firm in New Delhi offering IT security audits, GDPR compliance, and enterprise risk management.

ISO 27001GDPRSOC 2

Nexia International

London, United Kingdom

$25,000–$150,000

Nexia International is a global network of independent accounting and consulting firms with 39,000+ professionals across 125+ countries worldwide.

SOC 1SOC 2ISO 27001HIPAA+3

Nexia SAB&T

Johannesburg, South Africa

$4,000–$22,000

Nexia SAB&T is a leading South African audit firm and Nexia International member offering SOC, ISO 27001, POPIA, and compliance services.

SOC 1SOC 2ISO 27001POPIA+1

Nordic Cyber Group

Stockholm, Sweden

SEK 15,000–SEK 60,000

Nordic Cyber Group is a Swedish cybersecurity firm offering ISO 27001, NIS2 compliance, and ISO-as-a-Service for Scandinavian technology and manufacturing companies.

ISO 27001NIS2GDPRSOC 2

Nordic Defence

Fredrikstad, Norway

NOK 200,000–NOK 800,000

Nordic Defence is a Norwegian cybersecurity firm offering ISO 27001, NIS2 compliance, and managed security services for Nordic enterprises and critical infrastructure.

ISO 27001NIS2GDPR

NQA

Warwick, United Kingdom

$8,000–$50,000

NQA is a UKAS and ANAB accredited certification body providing affordable ISO 27001, ISO 22301, and management system certifications for organizations globally.

ISO 27001ISO 27002ISO 27701ISO 22301+3

NZINFOSEC

Auckland, New Zealand

NZ$15,000–NZ$45,000

NZINFOSEC is a New Zealand information security firm offering ISO 27001, SOC 2, and PCI DSS compliance services with over 300 assessments completed.

ISO 27001PCI DSSSOC 2HIPAA

Orange Cyberdefense

Paris, France

€30,000–€200,000

Orange Cyberdefense is a major European cybersecurity firm offering ISO 27001, NIS2, SOC 2, and GDPR compliance services with managed security operations across the continent.

ISO 27001SOC 2NIS2GDPR+1

PCI Consulting Australia

Sydney, NSW, Australia

A$15,000–A$50,000

PCI Consulting Australia is a 100% Australian-owned boutique QSA firm specializing exclusively in PCI DSS compliance for merchants and payment processors.

PCI DSS

PECB

Montreal, Canada

$5,000–$35,000

PECB is a global certification and training organization specializing in ISO standards, offering both professional certifications and management system audits.

ISO 27001ISO 9001ISO 22301ISO 27701+2

Pitcher Partners

Melbourne, Australia

$15,000–$75,000

Pitcher Partners is a leading Australian mid-market accounting firm providing SOC 2, ISO 27001, Essential Eight, and Privacy Act compliance services to mid-market businesses and family enterprises.

SOC 1SOC 2ISO 27001ISO 27701+5

PKF Africa

Johannesburg, South Africa

$4,000–$25,000

PKF Africa provides audit, ISO 27001, POPIA, and compliance services across Sub-Saharan Africa through the PKF International network.

SOC 1SOC 2ISO 27001POPIA+1

PKF International

London, United Kingdom

$20,000–$120,000

PKF International is a global network of independent accounting and advisory firms with 22,000+ professionals across 150+ countries worldwide.

SOC 1SOC 2ISO 27001HIPAA+3

PKF International (Middle East)

Dubai, UAE

$7,000–$35,000

PKF Middle East is PKF International's regional practice offering SOC, ISO 27001, PCI DSS, and compliance audit services across the Gulf states.

SOC 1SOC 2ISO 27001PCI DSS+2

PKF Littlejohn LLP

London, United Kingdom

$12,000–$55,000

PKF Littlejohn is a London-based mid-market accountancy firm providing SOC 2, ISO 27001, GDPR, and Cyber Essentials audit services to growing UK businesses.

SOC 1SOC 2ISO 27001GDPR+3

PKF O'Connor Davies

New York, NY

$25,000–$80,000

PKF O'Connor Davies is a top-tier New York CPA firm offering SOC 1/2/3 reporting, ISO 27001, and risk advisory services for financial services and technology companies.

SOC 2SOC 1ISO 27001HIPAA

PKF Singapore

Singapore

$7,000–$30,000

PKF Singapore is PKF International's Singapore member firm offering SOC, ISO 27001, PDPA, and compliance audit services for mid-market companies.

SOC 1SOC 2ISO 27001Pdpa+1

Plante Moran

Southfield, Michigan

$30,000–$150,000

Plante Moran is a top-15 US CPA firm known for exceptional workplace culture, providing audit, tax, and cybersecurity services to mid-market companies.

SOC 1SOC 2SOC 3ISO 27001+5

Plurilock

Toronto, ON, Canada

CA$20,000–CA$80,000

Plurilock is a Canadian cybersecurity and compliance firm offering SOC 2, ISO 27001, HITRUST, and FedRAMP assessments for technology and government organizations.

SOC 2ISO 27001HITRUSTFedRAMP+2

Prescient Assurance

Toronto, Canada

$12,000–$50,000

Prescient Assurance is a startup-friendly CPA firm offering affordable SOC 2, ISO 27001, and HIPAA audits with fast turnaround for growing companies.

SOC 1SOC 2SOC 3ISO 27001+9

Prescient Security

Nashville, TN

$18,000–$80,000

Prescient Security is a global compliance auditor with 3,600+ SOC 2 audits and 5,000+ customers, offering SOC 2, ISO 27001, HITRUST, FedRAMP, and CMMC assessments.

SOC 2ISO 27001HITRUSTFedRAMP+4

PricewaterhouseCoopers (PwC)

Featured

London, United Kingdom

$75,000–$500,000

PwC is one of the Big Four professional services firms, providing audit, assurance, tax, and consulting services to major organizations in 152 countries.

SOC 1SOC 2SOC 3ISO 27001+16

PricewaterhouseCoopers Brazil

Featured

Sao Paulo, Brazil

$10,000–$70,000

PwC Brazil is PricewaterhouseCoopers' Brazilian member firm offering SOC 1, SOC 2, ISO 27001, LGPD, and compliance audit services for Latin America's largest market.

SOC 1SOC 2ISO 27001ISO 27701+3

Protiviti

Featured

Menlo Park, California

$40,000–$250,000

Protiviti is a global consulting firm specializing in internal audit, risk management, and compliance with 9,000+ professionals across 25+ countries.

SOC 1SOC 2ISO 27001ISO 27002+12

Protiviti India

Mumbai, India

$15,000–$100,000

Protiviti India provides internal audit, IT risk, and compliance services including ISO 27001, SOC 2, and CERT-In assessments for Indian enterprises.

ISO 27001ISO 27002ISO 27701SOC 1+6

Protiviti Middle East

Dubai, UAE

$25,000–$150,000

Protiviti Middle East provides internal audit, IT risk, and compliance services including ISO 27001 and SOC 2 for organizations across the Gulf region.

ISO 27001ISO 27002ISO 27701SOC 1+6

PwC Aarata LLC

Featured

Tokyo, Japan

$50,000–$350,000

PwC Aarata (PwC Japan) is a Big Four audit firm providing SOC 2, ISO 27001, APPI, ISMAP, and enterprise risk advisory services to Japan's leading corporations across financial services, technology, and manufacturing.

SOC 1SOC 2ISO 27001ISO 27701+8

PwC Australia

Featured

Sydney, Australia

$50,000–$350,000

PwC Australia is one of Australia's largest professional services firms, providing Big Four audit, assurance, and cybersecurity services across Oceania.

SOC 1SOC 2ISO 27001ISO 27002+7

PwC Canada

Featured

Toronto, Canada

$45,000–$300,000

PwC Canada is a Big Four professional services firm providing SOC 2, ISO 27001, PIPEDA, SOX, and enterprise risk advisory services to Canada's largest organizations across financial services, technology, energy, and government.

SOC 1SOC 2ISO 27001ISO 27701+6

PwC China

Featured

Shanghai, China

$40,000–$350,000

PwC China is the largest Big Four firm in China, providing audit, assurance, and advisory services with deep expertise in Chinese regulatory compliance.

SOC 1SOC 2ISO 27001ISO 27002+7

PwC France

Featured

Paris, France

$45,000–$300,000

PwC France is a Big Four professional services firm providing ISO 27001, GDPR, HDS, SOC 2, and enterprise risk advisory services to French enterprises across financial services, technology, healthcare, and government.

SOC 1SOC 2ISO 27001ISO 27701+6

PwC Germany

Featured

Frankfurt, Germany

$50,000–$350,000

PwC Germany is a Big Four professional services firm providing ISO 27001, C5, TISAX, SOC 2, and GDPR compliance services to German enterprises across automotive, manufacturing, technology, and financial services.

SOC 1SOC 2ISO 27001ISO 27701+7

PwC India

Featured

Mumbai, India

$30,000–$250,000

PwC India is a Big Four professional services firm providing SOC 2, ISO 27001, DPDPA, SOX, and enterprise risk advisory services to India's largest corporations and multinational subsidiaries.

SOC 1SOC 2ISO 27001ISO 27701+7

PwC Middle East

Featured

Dubai, UAE

$55,000–$380,000

PwC Middle East is a Big Four professional services firm providing SOC 2, ISO 27001, NESA, PDPL, and enterprise risk advisory services across the UAE, Saudi Arabia, and the broader Middle East region.

SOC 1SOC 2ISO 27001ISO 27701+8

PwC Singapore

Featured

Singapore

$40,000–$250,000

PwC Singapore is a Big Four professional services firm providing SOC 2, ISO 27001, PDPA, MTCS, and enterprise risk advisory services to financial institutions, technology companies, and government agencies in Singapore and the APAC region.

SOC 1SOC 2ISO 27001ISO 27701+7

PYA

Knoxville, TN

$25,000–$80,000

PYA is a Top-100 national CPA firm specializing in healthcare compliance, SOC 2, HITRUST, and HIPAA audits for SaaS and cloud-based companies.

SOC 2HIPAAHITRUSTISO 27001

Q-Inspect

Prague, Czech Republic

€5,000–€25,000

Q-Inspect is a Czech-based accredited certification body offering ISO 27001 and management system audits across Central and Eastern Europe.

ISO 27001

QCert360

Seoul, South Korea

₩15,000,000–₩50,000,000

QCert360 is a South Korean information security firm specializing in K-ISMS-P and ISO 27001 certification for Korean technology and financial companies.

ISO 27001

QMS International

Doncaster, UK

£3,000–£25,000

QMS International is a UKAS-accredited UK certification body specializing in ISO 27001 and management system certifications for SMBs.

ISO 27001ISO 9001ISO 14001ISO 45001+1

Quality Austria

Vienna, Austria

€8,000–€40,000

Quality Austria is a Vienna-based accredited certification body offering ISO 27001, ISO 27701, and management system certifications across Central Europe.

ISO 27001ISO 27701

Qualysec Technologies

Bangalore, Karnataka, India

₹150,000–₹800,000

Qualysec is a Bangalore-based penetration testing company offering VAPT for web, mobile, cloud, IoT, and blockchain with compliance readiness services.

ISO 27001SOC 2PCI DSSHIPAA

Redspin

Duluth, GA

$30,000–$120,000

Redspin is the first authorized CMMC C3PAO in the US, conducting ~25% of all CMMC Level 2 assessments with former DoD cybersecurity professionals.

CMMCHIPAAHITRUSTPCI DSS+1

ResGuard Solutions

Singapore

SGD 15,000–SGD 40,000

ResGuard Solutions is a Singapore-based cybersecurity and compliance firm offering SOC 2, ISO 27001, and GDPR services for Southeast Asian technology companies.

SOC 2ISO 27001GDPR

Richter LLP

Montreal, Canada

$12,000–$55,000

Richter is a leading Canadian mid-market accounting and advisory firm based in Montreal, providing SOC 2, ISO 27001, PIPEDA, and cybersecurity compliance services with full bilingual capability.

SOC 1SOC 2ISO 27001GDPR+3

RINA

Genoa, Italy

$8,000–$45,000

RINA is an Italian multinational inspection, certification, and engineering consultancy offering ISO 27001, ISO 27701, and management system certifications globally.

ISO 27001ISO 27701ISO 22301ISO 27017+2

Risk Associates

Sydney, NSW, Australia

A$30,000–A$120,000

Risk Associates is a Sydney-based Tier 1 Security Cleared assessor providing Essential Eight maturity assessments and GRC solutions for Australian government and enterprise.

ISO 27001Essential EightPCI DSS

Risk Crew

London, United Kingdom

$10,000–$50,000

Risk Crew is a UK cybersecurity consultancy providing ISO 27001, GDPR, and penetration testing services for startups and mid-market technology companies.

ISO 27001ISO 27002ISO 27701GDPR+3

Riskpro India

Chennai, Tamil Nadu, India

₹400,000–₹2,000,000

Riskpro India is a Chennai-based SOC 2 specialist with 1400+ completed audits and in-house US CPA professionals, serving IT services and SaaS companies.

SOC 2SOC 1GDPRHIPAA+1

Roedl & Partner

Nuremberg, Germany

$18,000–$100,000

Roedl & Partner is a German mid-market professional services firm providing ISO 27001, TISAX, C5, and GDPR compliance services to the Mittelstand and international businesses with German operations.

ISO 27001ISO 27701ISO 22301GDPR+4

RQM+

Dubai, UAE

$10,000–$60,000

RQM+ is a regulatory compliance specialist serving medical device and healthcare organizations from the UAE and US, covering ISO 13485, ISO 27001, and FDA requirements.

ISO 27001Iso 13485GDPRHIPAA

RSM International

Featured

London, United Kingdom

$35,000–$200,000

RSM International is the sixth-largest global professional services network, delivering audit, tax, and consulting services across 120+ countries.

SOC 1SOC 2SOC 3ISO 27001+7

RSM Singapore

Singapore

$15,000–$60,000

RSM Singapore is a mid-market audit and advisory firm providing SOC 2, ISO 27001, PDPA, and PCI DSS compliance services to SMEs and growing businesses in Singapore.

SOC 1SOC 2ISO 27001ISO 27701+4

RSM US LLP

Featured

Chicago, IL

$25,000–$120,000

RSM US LLP is the fifth-largest US CPA firm and a leading mid-market auditor offering SOC 1, SOC 2, ISO 27001, HIPAA, HITRUST, FedRAMP, and CMMC services nationwide.

SOC 1SOC 2ISO 27001HIPAA+8

Ruihua Certified Public Accountants

Beijing, China

$4,000–$30,000

Ruihua Certified is one of China's largest domestic CPA firms offering ISO 27001, MLPS, and financial audit services for Chinese enterprises.

SOC 1ISO 27001MlpsPIPL

S.R. Batliboi & Associates LLP

Mumbai, India

$7,000–$50,000

S.R. Batliboi & Associates is EY's primary India affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for Indian enterprises.

SOC 1SOC 2ISO 27001ISO 27701+4

SABS

Pretoria, South Africa

ZAR 30,000–ZAR 250,000

SABS is the South African Bureau of Standards, offering accredited ISO 27001 and management system certifications as the national standards body.

ISO 27001ISO 9001ISO 14001ISO 45001+1

SACAS

Johannesburg, South Africa

ZAR 80,000–ZAR 300,000

SACAS is a South African accredited certification body offering ISO 27001 and management system audits across Southern Africa.

ISO 27001

SAI Global

Sydney, Australia

A$5,000–A$40,000

SAI Global is an Australian certification body and compliance solutions provider offering ISO certifications and risk management services across APAC.

ISO 27001ISO 9001ISO 14001ISO 45001+1

Samil PricewaterhouseCoopers

Featured

Seoul, South Korea

$15,000–$80,000

Samil PwC is PricewaterhouseCoopers' South Korean member firm offering SOC 1, SOC 2, ISO 27001, ISMS-P, and compliance audit services for Korean enterprises.

SOC 1SOC 2ISO 27001ISO 27701+4

Schellman (EU Office)

Frankfurt, Germany

$20,000–$90,000

Schellman EU is the European office of Schellman & Company, providing SOC 2, ISO 27001, GDPR, and C5 compliance audits for European technology companies.

SOC 2ISO 27001ISO 27017ISO 27018+6

Schellman & Company

Featured

Tampa, Florida

$20,000–$100,000

Schellman is a leading US compliance audit firm specializing in SOC 2, ISO 27001, FedRAMP, HITRUST, and PCI DSS assessments for technology companies.

SOC 1SOC 2SOC 3ISO 27001+13

Secureframe Audit Partners

San Francisco, California

$10,000–$60,000

Secureframe Audit Partners is a network of vetted audit firms integrated with Secureframe's compliance automation platform for streamlined certifications.

SOC 1SOC 2SOC 3ISO 27001+10

SecurityCentric

Canberra, ACT, Australia

A$35,000–A$100,000

SecurityCentric is a Canberra-based endorsed IRAP assessor offering comprehensive compliance assessments for Australian government agencies and defense contractors.

ISO 27001Essential Eight

SecurityMetrics

Orem, UT

$10,000–$60,000

SecurityMetrics is a US-based compliance and cybersecurity firm specializing in PCI DSS, HIPAA, and HITRUST assessments with forensic investigation capabilities.

PCI DSSHIPAAHITRUST

Securium Solutions

Noida, Uttar Pradesh, India

₹200,000–₹1,000,000

Securium Solutions is a CERT-IN empanelled cybersecurity firm in Noida specializing in ISO 27001, SEBI compliance, and security auditing for regulated Indian companies.

ISO 27001ISO 27701PCI DSS

Sensiba

San Jose, California

$18,000–$80,000

Sensiba (formerly SingerLewak) is a California-based CPA firm specializing in SOC 2, ISO 27001, and compliance audits for technology and SaaS companies.

SOC 1SOC 2SOC 3ISO 27001+6

SGS

Featured

Geneva, Switzerland

$12,000–$80,000

SGS is the world's largest testing, inspection, and certification company, providing ISO 27001 and management system certifications across 140+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

ShineWing Certified Public Accountants

Beijing, China

$5,000–$40,000

ShineWing is one of China's largest domestic CPA firms offering SOC, ISO 27001, MLPS, and compliance audit services for Chinese and multinational companies.

SOC 1SOC 2ISO 27001ISO 27701+3

Siege Cyber

Brisbane, QLD, Australia

A$15,000–A$40,000

Siege Cyber is a Brisbane-based SOC 2 and ISO 27001 specialist for Australian SaaS companies, partnering with Vanta and Drata compliance platforms.

SOC 2ISO 27001

Sikich

Naperville, Illinois

$25,000–$120,000

Sikich is a top-30 US professional services firm offering audit, technology, and cybersecurity services with strong Midwest presence and CMMC capabilities.

SOC 1SOC 2SOC 3ISO 27001+6

SizweNtsalubaGobodo-Grant Thornton

Johannesburg, South Africa

$5,000–$30,000

SizweNtsalubaGobodo-Grant Thornton is South Africa's largest Black-owned audit firm offering SOC, ISO 27001, POPIA, and compliance services.

SOC 1SOC 2ISO 27001ISO 27701+2

Smith & Williamson

London, UK

$12,000–$55,000

Smith & Williamson is a UK-based chartered accountancy and advisory firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials audit services.

ISO 27001SOC 2GDPRPCI DSS+1

SOCOTEC

Paris, France

€6,000–€50,000

SOCOTEC is a major French certification body offering ISO 27001 and multi-standard certifications across Europe. Profile includes pricing and framework coverage.

ISO 27001ISO 9001ISO 14001ISO 22301+2

SRKAY Consulting

New Delhi, India

$5,000–$40,000

SRKAY Consulting is a CERT-In empaneled cybersecurity and compliance firm in India offering ISO 27001, SOC 2, GDPR, and PCI DSS consulting services.

ISO 27001ISO 27002ISO 27701SOC 2+4

Stratica

Melbourne, VIC, Australia

A$25,000–A$80,000

Stratica is Australia's only PCI Forensic Investigator (PFI) firm and most qualified QSA, specializing in payment card security for retail, finance, and travel sectors.

PCI DSSSOC 2

StrongBox IT

Bangalore, Karnataka, India

₹250,000–₹1,200,000

StrongBox IT is a Bangalore-based NASSCOM-listed cybersecurity firm providing in-depth security assessments, ISO 27001 implementation, and OT security audits.

ISO 27001SOC 2

Talal Abu-Ghazaleh & Co International

Amman, Jordan

$6,000–$45,000

Talal Abu-Ghazaleh & Co is the largest Arab professional services firm, offering audit, ISO certification, SOC, and compliance services across the MENA region.

SOC 1SOC 2ISO 27001ISO 27701+4

TCS (Tata Consultancy Services)

Featured

Mumbai, India

$30,000–$200,000

TCS is India's largest IT services company offering cybersecurity, compliance audit, and risk advisory services to enterprises across 46 countries worldwide.

ISO 27001ISO 27002ISO 27701ISO 22301+7

Tempo Audits

Bristol, UK

£8,000–£35,000

Tempo Audits is a UK-based UKAS-accredited certification body offering fast-track ISO 27001 and SOC 2 audits for technology startups and scale-ups.

ISO 27001SOC 2

Tesserent

Melbourne, VIC, Australia

A$30,000–A$150,000

Tesserent is Australia's largest ASX-listed cybersecurity firm (now Thales subsidiary) offering IRAP assessments, ISO 27001, SOC 2, and Essential Eight compliance.

ISO 27001SOC 2PCI DSSEssential Eight

Tevora

Irvine, CA

$10,000–$50,000

Tevora is a boutique cybersecurity and compliance firm based in Southern California specializing in SOC 2, PCI DSS, HITRUST, and ISO 27001 assessments for startups and mid-market companies.

SOC 2ISO 27001HIPAAPCI DSS+5

TopCertifier

Dubai, UAE

$10,000–$50,000

TopCertifier is a global compliance consulting firm with offices in Dubai, LATAM, and Asia offering ISO 27001, SOC 2, and multi-framework certifications.

SOC 2SOC 1ISO 27001GDPR+2

TQS

Singapore

SGD 4,000–SGD 20,000

TQS is a Singapore-based accredited certification body offering ISO 27001 and management system certifications across Southeast Asia.

ISO 27001ISO 9001ISO 14001ISO 22301+1

TUV Austria

Vienna, Austria

$8,000–$50,000

TUV Austria is an Austrian testing, inspection, and certification organization offering ISO 27001, ISO 27701, and management system certifications across Central and Eastern Europe.

ISO 27001ISO 27701ISO 22301ISO 27017+2

TUV Nord

Hanover, Germany

$10,000–$70,000

TUV Nord is a German certification body providing ISO 27001, TISAX, and management system certifications with strong European and Asian market presence.

ISO 27001ISO 27002ISO 27701ISO 22301+3

TUV Rheinland

Featured

Cologne, Germany

$12,000–$85,000

TUV Rheinland is a world-leading German certification and testing body providing ISO 27001, TISAX, and management system certifications across 60+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

TUV SUD

Featured

Munich, Germany

$12,000–$80,000

TUV SUD is a leading German testing, inspection, and certification body providing ISO 27001, TISAX, and management system certifications across 50+ countries.

ISO 27001ISO 27002ISO 27017ISO 27018+7

UHY Hacker Young

London, UK

$10,000–$45,000

UHY Hacker Young is a UK chartered accountancy firm offering ISO 27001, SOC 2, GDPR, and Cyber Essentials audit services through the UHY International network.

ISO 27001SOC 2GDPRCyber Essentials+1

UKAS Accredited Certification Bodies

Staines-upon-Thames, UK

$8,000–$50,000

UKAS is the UK's national accreditation body, accrediting ISO certification bodies to deliver ISO 27001, ISO 27701, and other management system certifications.

ISO 27001ISO 27701ISO 22301ISO 27017+3

Univate Solutions

Bangalore, Karnataka, India

₹400,000–₹1,800,000

Univate Solutions is a Bangalore-based SOC 2 expert with 70+ successful implementations, serving Fortune 100 organizations across India and APAC.

SOC 2SOC 1ISO 27001

Vectra Corp

Adelaide, SA, Australia

A$25,000–A$80,000

Vectra Corp is Australia's pioneering PCI DSS QSA firm (certified since 2006), headquartered in Adelaide with offices in all major Australian cities.

PCI DSSISO 27001

Vertech

Auckland, New Zealand

NZ$12,000–NZ$35,000

Vertech is an Auckland-based IT security and compliance firm offering SOC 2, ISO 27001, and Compliance-as-a-Service for New Zealand technology startups and scale-ups.

SOC 2ISO 27001

Vista InfoSec

Mumbai, India

$8,000–$50,000

Vista InfoSec is a global cybersecurity and compliance firm offering PCI DSS, SOC 2, ISO 27001, and GDPR assessments at competitive international pricing.

SOC 1SOC 2ISO 27001ISO 27002+7

Walker Chandiok & Co LLP

New Delhi, India

$6,000–$40,000

Walker Chandiok & Co is Grant Thornton's India affiliate, offering SOC 1, SOC 2, ISO 27001, and compliance audit services for mid-market and enterprise clients.

SOC 1SOC 2ISO 27001ISO 27701+4

Warren Averett

Birmingham, Alabama

$20,000–$90,000

Warren Averett is a top-50 US CPA firm based in Alabama providing audit, tax, and cybersecurity advisory services across the Southeastern United States.

SOC 1SOC 2ISO 27001HIPAA+3

Wipfli

Milwaukee, Wisconsin

$25,000–$120,000

Wipfli is a top-20 US CPA and consulting firm with strong Midwest presence, providing audit, tax, and cybersecurity advisory services to mid-market clients.

SOC 1SOC 2SOC 3ISO 27001+5

WithumSmith+Brown

Princeton, NJ

$15,000–$65,000

WithumSmith+Brown is a top-25 US CPA and advisory firm based in New Jersey, offering SOC 1, SOC 2, ISO 27001, and HIPAA audit services for mid-market companies.

SOC 1SOC 2ISO 27001HIPAA+4

Wolf & Company

Boston, MA

$25,000–$100,000

Wolf & Company is a century-old Boston-based CPA firm with deep expertise in IT audit, SOC reporting, HITRUST, and financial services compliance.

SOC 2SOC 1ISO 27001HIPAA+4

Showing 263 of 263 firms