Find a SOC 2 auditor
SOC 2 auditors, compiled from the public directories we currently observe: Drata and Vanta. Below the guidance is the current list: facts only, alphabetical, never ranked.
How to choose a SOC 2 auditor
You choose your own auditor. A SOC 2 audit is an independent engagement with a licensed CPA firm; it is not assigned by, or tied to, whichever compliance platform you run. The platform collects evidence; the audit is separate.
- Match the firm to your program, not a ranking. Experience with your framework, your industry, and your company stage matters more than any “top firms” list.
- Ask who does the fieldwork. The partner who sells the engagement is often not the person who runs it. Ask directly.
- Get the fee in writing, across tiers. Firm tier (specialist, regional CPA, mid-tier national, Big Four) drives cost more than your headcount. Quote more than one tier.
- Type 1 vs Type 2. A Type 1 is a point-in-time report; a Type 2 covers a window (commonly 3–12 months). Know which your buyer actually requires before you scope.
- Confirm independence. The firm that runs your readiness work and the firm that signs your audit opinion may need to be different. Ask.
The audit is a separate cost
The external audit is a separate engagement with a licensed CPA firm, priced independently of any platform. Firm tier drives cost more than your company size does.
- The platform fee does not include the audit.
- The audit is a separate engagement with a licensed CPA firm.
- You choose your own auditor. It is not tied to your platform.
- Firm tier drives cost more than company size.
We don’t publish audit-cost figures yet. We won’t cite numbers we can’t source to a party with no stake in them. What we do publish · methodology.
SOC 2 firms in the directory
20 firms · alphabetical
A-LIGN
Listed · public sourcesA-LIGN is listed as an Audit Partner in the Vanta directory (observed Jul 2026), founded 2009. Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and HITRUST assessment (Type 2) across GDPR and CMMC; the firm also offers penetration testing, readiness & implementation and vCISO & advisory.
CMMCFedRAMPGDPRHIPAAHITRUSTISO 27001ISO 42001PCI DSSSOC 1SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Advantage Partners
Listed · public sourcesAdvantage Partners is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm. Listed for SOC 2 attestation, ISO 27001 certification, HITRUST assessment and HIPAA assessment (Type 1 and Type 2) across CMMC; the firm also offers penetration testing, readiness & implementation and vCISO & advisory.
CMMCHIPAAHITRUSTISO 27001SOC 2
Vanta
Appears in Vanta auditor directory · observed Jul 2026
Aprio
Listed · public sourcesAprio is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation (Type 2); the firm also offers vCISO & advisory.
SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
AssurancePoint
Listed · public sourcesAssurancePoint is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, ISO 27001 certification and audit & assurance (Type 1); the firm also offers readiness & implementation.
ISO 27001SOC 2
Vanta
Appears in Vanta auditor directory · observed Jul 2026
BARR Advisory
Listed · public sourcesBARR Advisory is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm. Listed for SOC 2 attestation, ISO 27001 certification, HITRUST assessment and PCI DSS assessment (Type 1) across CMMC; the firm also offers penetration testing, readiness & implementation and vCISO & advisory.
CMMCFedRAMPHIPAAHITRUSTISO 27001PCI DSSSOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
BD Emerson CPA
Listed · public sourcesBD Emerson CPA is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and PCI DSS assessment (Type 1 and Type 2) across GDPR and CMMC; the firm also offers penetration testing, readiness & implementation and vCISO & advisory.
CMMCFedRAMPGDPRHIPAAISO 27001ISO 42001PCI DSSSOC 1SOC 2
Vanta
Appears in Vanta auditor directory · observed Jul 2026
Boulay
Listed · public sourcesBoulay is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm, founded 1934. Listed for SOC 2 attestation and ISO 27001 certification; the firm also offers vCISO & advisory.
ISO 27001SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Consilium Labs
Listed · public sourcesConsilium Labs is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm. Listed for SOC 2 attestation, ISO 27001 certification, audit & assurance and PCI DSS assessment (Type 1 and Type 2) across GDPR and CMMC; the firm also offers penetration testing, readiness & implementation and vCISO & advisory.
CMMCFedRAMPGDPRHIPAAISO 27001ISO 42001PCI DSSSOC 2SOC 3
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
ControlCase
Listed · public sourcesControlCase is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and HITRUST assessment across GDPR and CMMC; the firm also offers penetration testing and readiness & implementation.
CMMCFedRAMPGDPRHIPAAHITRUSTISO 27001PCI DSSSOC 1SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Dansa D'Arata Soucia
Listed · public sourcesDansa D'Arata Soucia is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation and audit & assurance (Type 2); the firm also offers readiness & implementation and vCISO & advisory.
SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Insight Assurance
Listed · public sourcesInsight Assurance is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and HITRUST assessment (Type 1 and Type 2) across GDPR and CMMC; the firm also offers penetration testing and readiness & implementation.
CMMCFedRAMPGDPRHIPAAHITRUSTISO 27001PCI DSSSOC 1SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Johanson Group
Listed · public sourcesJohanson Group is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm. Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and PCI DSS assessment across GDPR; the firm also offers readiness & implementation.
GDPRHIPAAISO 27001PCI DSSSOC 1SOC 2SOC 3
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Mastermind
Listed · public sourcesMastermind is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation.
SOC 2
Vanta
Appears in Vanta auditor directory · observed Jul 2026
MHM CPA
Listed · public sourcesMHM CPA is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and ISO 42001 readiness (Type 1 and Type 2); the firm also offers readiness & implementation.
ISO 27001ISO 42001SOC 1SOC 2SOC 3
Vanta
Appears in Vanta auditor directory · observed Jul 2026
MJD Advisors
Listed · public sourcesMJD Advisors is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm, founded 2021. Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and HIPAA assessment; the firm also offers readiness & implementation.
HIPAAISO 27001ISO 42001SOC 1SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Oread Risk and Advisory
Listed · public sourcesOread Risk and Advisory is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, audit & assurance and HIPAA assessment; the firm also offers vCISO & advisory.
HIPAASOC 2
Vanta
Appears in Vanta auditor directory · observed Jul 2026
RS Assurance & Advisory (RSAA)
Listed · public sourcesRS Assurance & Advisory (RSAA) is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and HIPAA assessment (Type 1 and Type 2) across CMMC; the firm also offers penetration testing, readiness & implementation and vCISO & advisory.
CMMCHIPAAISO 27001SOC 1SOC 2SOC 3
Vanta
Appears in Vanta auditor directory · observed Jul 2026
Schellman
Listed · public sourcesSchellman is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm. Listed for SOC 2 attestation, SOC 1 attestation, ISO 27001 certification and HITRUST assessment (Type 1 and Type 2) across GDPR and CMMC; the firm also offers penetration testing and readiness & implementation.
CMMCFedRAMPGDPRHIPAAHITRUSTISO 27001PCI DSSSOC 1SOC 2SOC 3
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Sensiba LLP
Listed · public sourcesSensiba LLP is listed as an Audit Partner in the Vanta directory (observed Jul 2026). Listed for SOC 2 attestation and audit & assurance; the firm also offers readiness & implementation and vCISO & advisory.
SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Tempo Audits
Listed · public sourcesTempo Audits is listed as an Audit Partner in the Vanta directory (observed Jul 2026); the firm states it is a CPA firm. Listed for SOC 2 attestation, ISO 27001 certification and audit & assurance (Type 1 and Type 2); the firm also offers readiness & implementation.
ISO 27001SOC 2
DrataVanta
Appears in Drata and Vanta auditor directories · observed Jul 2026
Want a straight read on the SOC 2 shortlist?
You’d be contacting GRC Migrate, the independent advisor, not any firm here. We’ll tell you what buyers actually pay for a SOC 2 audit at your size, and, where a vetted partner fits your need, an introduction if you want one.
Get an independent read →