Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do major security assurance providers compare?

Last verified

How do major assurance providers compare? This matrix compares authorizations by scheme — not a ranking. Verify each cell before you buy. Inclusion is not endorsement. Not legal advice.

Security assurance guidance, last verified 10 September 2026 against AICPA, IAF, PCI SSC, FedRAMP, and HITRUST public programme materials. Cells marked UNKNOWN were not verified on this page — check the current register. Not procurement advice.

Stated comparison criteria — verify before you buy

This page compares what named firms are authorized or accredited to perform — not quality, price, or fit. Rows are alphabetical by brand. Inclusion is not endorsement. Not a ranking. Last verified 10 September 2026.

  • Verify before you buy: open the relevant register for every cell you rely on.
  • UNKNOWN means not verified on this page — not a fail and not a pass.
  • One brand may include multiple legal entities — match the entity on YOUR engagement letter.

Provider × authorization matrix

Major assurance providers by authorization (alphabetical — not a ranking, not an endorsement). Last verified 10 September 2026. Verify before you buy.
Provider (alphabetical)SOC 2 CPA attestationISO 27001 CBISO 42001 CBPCI QSAFedRAMP 3PAOHITRUST assessor
A-LIGNPublic SOC 2 offering — CPA attestation not verified on this pagePublic ISO 27001 offering — accreditation not verified on this pageUNKNOWN — check IAF CertSearchUNKNOWN — check PCI SSC QSA listUNKNOWN — check FedRAMP 3PAO rosterUNKNOWN — check HITRUST assessor list
BDOPublic SOC 2 offering — CPA not verified on this pageUNKNOWNUNKNOWNUNKNOWNUNKNOWNUNKNOWN
CoalfirePublic SOC 2 offering — CPA not verified on this pageUNKNOWNUNKNOWNPublic PCI practice — QSA listing not verified on this pageFedRAMP 3PAO mentioned publicly — not verified on this pageUNKNOWN
DeloittePublic SOC 2 offering — CPA not verified on this pagePublic ISO offering — CB accreditation not verified on this pageUNKNOWNUNKNOWNUNKNOWNUNKNOWN
EYPublic SOC 2 offering — CPA not verified on this pageUNKNOWNUNKNOWNUNKNOWNUNKNOWNUNKNOWN
KPMGPublic SOC 2 offering — CPA not verified on this pageUNKNOWNUNKNOWNUNKNOWNUNKNOWNUNKNOWN
PwCPublic SOC 2 offering — CPA not verified on this pageUNKNOWNUNKNOWNUNKNOWNUNKNOWNUNKNOWN
SchellmanPublic SOC 2 offering — CPA not verified on this pagePublic ISO 27001 offering — accreditation not verified on this pageUNKNOWN — verify ISO/IEC 42001 accreditation on IAF CertSearch; ISO 42001 docs hub on this siteUNKNOWNUNKNOWNUNKNOWN

What to do now

  • Pick the column that matches YOUR required deliverable — ignore other columns.
  • Open registers and replace UNKNOWN cells before shortlisting.
  • Use best SOC 2 audit firms and best ISO 27001 certification bodies pages for deeper criteria — not rankings.
  • Print questions-before-hiring-an-auditor guide before calls.

Checklist

  • Every relied-on cell verified on current register?
  • Signing legal entity matches register entry?
  • Independence clear for YOUR prep history?
  • Proposal scope matches the authorization column YOU need?

Where this shows up in ShipReady Metrics

ShipReadyMetrics is vendor-neutral readiness tooling — evidence collection and review. It does not endorse any row in the matrix, does not issue SOC 2 reports or ISO certificates, and is not legal advice.

Frequently asked questions