Auditor Directory

Trust Drata’s Pre-Vetted Auditor Network

It’s never too soon to build a relationship with an audit firm. Visit the listings below and click “contact us” to get the relationship started.

Let us match you
Drata will do all the work to match you with the best Auditors.
Elite Alliance Member
Sensiba LLP

Sensiba LLP

Sensiba LLP has teamed up with AssuranceLab. We are a top 75 U.S. accounting and consulting firm with a growing global presence. We’ve combined deep expertise, global reach, and an agile approach to deliver governance, risk, and compliance (GRC) services that scale with your business. Our team now supports over 10,000 clients worldwide, has completed 2,000+ audits, and includes 90+ experienced auditors. We serve fast-growing companies across software, SaaS, fintech, healthcare, life sciences, energy, and more—offering specialized knowledge in cloud-native environments like AWS, Google Cloud, and Microsoft Azure. Our audits are remote-first, flat-fee, and designed for fast turnarounds without the hassle of hourly billing or on-site delays. Leveraging AI-powered audits, we streamline evidence collection, enhance accuracy, and provide deeper insights- helping client achieve compliance faster and with greater confidence. As a Gold Tier Drata Alliance Partner, we’ve delivered quality audits for over 1000+ mutual customers and have 10+ Drata Certified Auditors on staff. Our services include: • SOC 1, SOC 2, SOC 3 • HIPAA / HITRUST • ISO/IEC 27001, 27017/27018, 27701, 42001 (ANAB and IAS Accredited) • NIST CSF, 800-171 / CMMC, 800-53 • GDPR / CCPA • CDR • CSA STAR • GS 007 • Custom Frameworks • Privacy Attestation • Penetration Testing and Vulnerability Scanning Ready to connect? Use the “Book a Meeting” link under the Resources tab or select the Contact button on the left side of this page. Sensiba Differentiators · 45+ years of experience delivering trusted audit, tax, and advisory services · 10,000+ U.S. and international clients served across diverse industries · 2,000+ active GRC customers supported with efficient, remote-first audits · 90+ experienced auditors with deep cloud, SaaS, and regulatory expertise · 200+ mutual Drata customers and 10+ Drata Certified Auditors on staff · Comprehensive service offerings across GRC, Tax, Audit & Assurance, and Advisory · Expertise in scaling businesses from startup to enterprise—adapting with your growth · Remote-first and cloud-native approach for speed, efficiency, and flexibility · Trusted partner across functions, including: • Tax (Business, International, R&D, State & Local) • Audit & Assurance (SOX, Internal Audit, Employee Benefit Plans) • Advisory & Consulting (Outsourced Accounting, ERP, BlackLine) • Sustainability (B Corp, SASB, Impact IQ platform)
5.0 (376)
Elite Alliance Member
MJD Advisors, LLC

MJD Advisors, LLC

MJD Advisors was founded in 2021 with a simple idea - information security compliance doesn't need to be complex, stressful, or unpredictable. Our clients are masters of their domain and deserve a partner that shares their passion and expertise. We work with brilliant business leaders who value our ability to move at their pace and provide a solution-focused approach, adding value by focusing on their concerns. We believe SOC 2 complexity is optional. Our solution is a boutique firm that blends niche expertise, purpose-built tools, and a modern perspective that removes the friction of traditional approaches to compliance. We’ve designed an agile and iterative approach to the service that allows us to run at our clients’ speed by leveraging technology, project management, and common sense to enhance audit quality and the client experience. Our talented team is full of certifications, but that is only part of the story. MJD offers translators, guides, and creators who bring different perspectives and a culture of ongoing learning, open-mindedness, and clear communication. We are a CPA firm, a technology company, and a group of people who have curated specific skills geared to help clients solve problems and reimagine compliance.
5.0 (59)
Elite Alliance Member
Insight Assurance

Insight Assurance

Insight Assurance is a global firm founded by former Big-4 professionals (EY and PwC) with operations in the USA, LATAM, EMEA, and APAC, providing high-quality audit services powered by compliance automation and AI. As a CPA firm (SOC 1, SOC 2, SOC 3), Certification Body (ISO), PCI-DSS QSA, HITRUST Authorized Assessor, C3PAO, 3PAO, and CSA STAR Authorized Assessor, we simplify IT compliance and elevate our clients' audit experience. With over 20 years of experience, our team has partnered with organizations ranging from startups to Fortune 500 companies, helping them achieve compliance efficiently. We provide the following services: • SOC 1, SOC 2, SOC 2+, and SOC 3 attestations • CMMC • FedRAMP • ISO/IEC 27001 Certifications • ISO 27017 (Cloud Security) and 27018 (Cloud Privacy) • ISO 27701 Certifications • ISO 42001 (AI) Certifications • PCI DSS Assessments • HIPAA/HITECH Security Assessments • HITRUST e1, i1, r2, and AI • Penetration Testing and Vulnerability Assessments • General Data Protection Regulation (GDPR) Services • Privacy Assessments based on International and State laws • NIST CSF Cybersecurity Assessments • NIST 800-53 and NIST 800-171 assessments • Risk Assessments Insight Assurance Differentiators • Founded and operated by former Big 4 professionals (EY) • Cost-effective and Efficient quality audits. • We can certify/examine your organization across several frameworks • We leverage 100% of Drata for our audits. • We serve clients across the globe and can accommodate all time zones. • We have a strong reputation with companies of all sizes, from small to large. • We offer flexible payment terms. • We offer a dedicated Slack channel.
5.0 (50)
Elite Alliance Member
A-LIGN

A-LIGN

Compliance for teams who take cybersecurity seriously: A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining deep expertise and world-class processes, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN has completed more than 16,000 audits since its founding in 2009 and is the number one global issuer of SOC 2 and HITRUST and a top three FedRAMP assessor.
4.9 (30)
Advanced Alliance Member
IS Partners, LLC

IS Partners, LLC

IS Partners has joined forces with AssurancePoint to form a market leading force as a globally recognized Certified Public Accounting firm specializing in IT Compliance and Cybersecurity Assurance. With decades of experience and deep industry knowledge, our team delivers tailored solutions that help organizations navigate complex regulatory requirements and strengthen their security posture. Our IT Compliance services include SOC 1, SOC 2, ISO 27001, HITRUST, CMMC, HIPAA, PCI DSS, and other critical frameworks, ensuring organizations meet rigorous industry standards. Our cybersecurity services encompass penetration testing, security assessments and vendor risk assessments, helping businesses proactively safeguard their data and infrastructure. IS Partners is committed to delivering industry-specific, value-added services that streamline compliance, enhance security, and build trust with stakeholders worldwide. Specialties: SOC 1, SOC 2, HITRUST, HIPAA, ISO 27001, ISO 42001, PCI DSS, CMMC, CSA STAR, NIST, DORA, GDPR, Penetration Testing, Security Assessments, IT Risk Management and Regulatory Compliance.
5.0 (34)
Advanced Alliance Member
Zero Day CPA, PC

Zero Day CPA, PC

SOC 1 | SOC 2 | HIPAA | Penetration Testing Zero Day is a premier provider of audit and penetration testing solutions catering to small, medium, and large-sized B2B, SaaS, and various other types of companies across the globe. Why Choose Us • Expert auditors and state-of-the-art compliance technology for rapid SOC 2 compliance. • Fastest turnaround time in the industry for reporting and communication. • 24/7 on-call auditors for immediate responses to inquiries. • Comprehensive, streamlined IT & compliance attestation services. • Unwavering commitment to security, safety, and client trust. • Strengthen customer trust and accelerate revenue generation with Zero Day's dependable compliance solutions. • Unparalleled client service and employee growth opportunities through people-centric technology and core values. • Tailored audit practices to suit individual client needs. • First-time SOC 2 audit clients benefit from Readiness Assessment to identify and remediate control gaps. • Certified penetration testers for in-depth organizational security assessments. • Combination of automated and manual methods to evaluate servers, workstations, wireless networks, and web applications, as well as security awareness and facility controls. • API security risk evaluation based on OWASP API Security Top 10 guidelines. • Flexible network penetration testing approaches: comprehensive or targeted. • Expertise in traffic capture, code analysis, and exploiting vulnerabilities in iOS, Android, and Windows applications. • Proprietary and custom web application development weaknesses identification and assessment. • Manual review of web application vulnerabilities per OWASP Top 10 and SANS Top 20 guidelines. • Detailed wireless infrastructure analysis utilizing innovative tools and exclusive tactics. • Custom-built assessments to meet your organization's unique goals and requirements. • Advanced social engineering tactics to uncover human-factor security vulnerabilities within your organization. • Flexible payment terms for client convenience.
5.0 (16)
Advanced Alliance Member
BARR Advisory

BARR Advisory

BARR Advisory is a cloud-based security and compliance solutions provider specializing in cybersecurity consulting and compliance for companies with high-value information in cloud environments like AWS, Microsoft Azure, and Google Cloud Platform. A trusted advisor to some of the fastest growing cloud-based organizations around the globe, BARR simplifies compliance across multiple regulatory and customer requirements in highly regulated industries including technology, financial services, healthcare, and government.
5.0 (4)
Advanced Alliance Member
Baker Tilly

Baker Tilly

Moss Adams and Baker Tilly have joined forces to redefine accounting, tax, and advisory services for the middle market. United, we bring a legacy and commitment to helping our clients embrace what’s next. With more than 11,000 professionals in 90-plus locations nationally, our reach and resources fuel our ability to bring deep industry insights, bold thinking, and holistic solutions that serve our clients’ unique needs. Our Risk Advisory Services team is made up of over 650 people focused on SOC, ISO, PCI, HITRUST, FedRAMP, CMMC, CSA, internal audit and other risk services. We are the largest in this space and bring the combined power of our firm to middle market and enterprise clients. At Baker Tilly, we unlock the power of possibility for businesses ready to move forward. Discover more at: www.mossadams.com/combo.
5.0 (4)
Advanced Alliance Member
Schellman

Schellman

Schellman is a leading global provider of attestation and compliance services — enabling enterprises to build trust, meet regulatory demands, and scale with confidence. The only Top 50 CPA firm focused exclusively on IT compliance and cybersecurity assessment, Schellman serves 1,400+ of the world's most regulated organizations across 95+ frameworks globally, including the #1 ranked FedRAMP 3PAO and the world's first ANAB-accredited ISO 42001 certification body. Our assessments span the full spectrum of compliance: SOC 1, SOC 2, and SOC 3 examinations; ISO certifications including ISO 27001, 27701, 42001, and more; FedRAMP, StateRAMP, CMMC, and federal frameworks; PCI DSS, P2PE, 3DS, and PIN; HITRUST and HIPAA; international standards including HDS, TISAX, C5, and IRAP; privacy frameworks including GDPR and CCPA; and penetration testing and offensive security services. We work with organizations at every stage of their compliance journey — from a company's first SOC 2 to global enterprises managing multiple frameworks simultaneously. Our clients don't just complete assessments; they use them to win contracts, enter new markets, and build lasting trust with the customers who demand proof. Our team has extensive experience working with clients who use compliance automation platforms, like Drata, as part of their assessment preparation and ongoing compliance programs including integration with our workflow platform. Please note: All engagements are independently scoped and contracted directly with Schellman. Drata is not a party to any client agreement. To learn more about our services, scope, and pricing, explore the resources below.
5.0 (1)
Advanced Alliance Member
360 Advanced

360 Advanced

360 Advanced is a relationship-focused cybersecurity and compliance firm providing tailored, integrated solutions. We help companies build compliance maturity, demonstrate security and protection of data, and ensure processing integrity, while maintaining open communication throughout the assessment process. Many of our clients navigate similar challenges, like reducing audit fatigue, expanding into regulated markets, and seeking meaningful feedback beyond a final report. Our approach is built on partnership and transparency, delivering actionable insights and strategic guidance that support long-term security and compliance goals. Making Better Businesses 360 Advanced was not founded on the principle of becoming an industry leader in cybersecurity and compliance. This is simply the result of an enduring passion for making better businesses. We do this by evaluating risk and establishing trust in the digital world. Cybersecurity and compliance are our mechanisms for making this a reality.
5.0 (1)
Advanced Alliance Member
Prescient Security & Assurance

Prescient Security & Assurance

Prescient Security is a renowned leader in multi-framework compliance auditing, security assessments, and penetration testing, eliminating compliance gaps and enabling a fortified security stance for organizations. Our risk-based audit approach vs requirement-based audit approach and compliance penetration testing ensures organizations are uncovering all potential security threats, not just those confined to a checklist. The Prescient Security Advantage Compliance as a Security Strategy We consider compliance as one part of a multi-pillared security strategy, assessing needs and deliverables from a cybersecurity standpoint first. Minimize compliance risk so your organization can scale sustainably. Total Compliance Provider Disparate service providers? Unify your compliance efforts across varying client, investor, and global regulatory needs with a single entity that standardizes and safeguards your cybersecurity infrastructure. Global Certifications and Support Senior Auditors across the U.S., EMEA, and APAC, supporting U.S. and global standards. Partner Agnostic We work with every major GRC and vCISO Readiness Platform.
4.9 (51)
Registered Alliance Member
Dansa D'Arata Soucia LLP

Dansa D'Arata Soucia LLP

"DDS" is a full service CPA firm, located in downtown Buffalo, New York servicing clients all around the continental United States and abroad. We pride ourselves on attracting top talent to make sure our clients are always getting the "A" team. Our areas of expertise include information security attestation and consulting (SOC 1, SOC 2, ISO internal audit, GDPR, HIPAA, and others), traditional compliance services (taxation and financial statement assurance), business valuations, mergers & acquisitions (buy and sell side diligence and sale positioning), client accounting services (outsourced bookkeeping, controller, CFO), and more! THE DDS DIFFERENCE + Peer reviewed through the AICPA's Peer Review Program. + We have often been referred to as "the friendly auditors". We have a job to do, but that does not mean we need to make your life difficult. Through careful planning and execution, we set you up for success, and make sure expectations are clear (all while maintaining our independence of course!) + We have a deep understanding of what Drata offers, and maximize Drata's automation to provide an efficient examination, passing along the cost savings to you, our client. + Our team of fully dedicated information security audit leads have each been through hundreds of SOC 2 examinations. + DDS issues approximately 200 SOC 2 examinations annually and we continue to add to our team to make sure turnaround time, and responsiveness remains best in class. + We take the time to understand your business. Through our information gathering process we can make sure we price our services correctly and competitively. No surprises allowed. + Information security attestation is not all that we offer. Our firm of 40+ CPA's and accountants has grown many of our clients that have started with SOC 2 into clients that utilize many of our service offerings. Our SOC 2 clients have also used our team for: Corporate Tax Work, Reviewed Financial Statements, M&A Diligence, State Sales and Income Tax Nexus Studies, Outsourced Bookkeeping, Outsourced Controller and CFO Services, and more. We have a small firm feel, with the expertise and network of a large regional firm. We look forward to having a conversation with you to answer any and all concerns and to find ways to make your lives simpler, and your businesses more successful.
5.0 (30)
Registered Alliance Member
Consilium Labs

Consilium Labs

Consilium Labs works as a trust enabler between you and your clients by getting you ISO 27001 Certification with a seamless process. Consilium Labs helps you achieve ISO 27001 certification without complications while saving time and cost.
5.0 (11)
Registered Alliance Member
Tempo Audits

Tempo Audits

Tempo is simplifying ISO 27001 certification for tech companies across Europe. UK based (and with UKAS accreditation), but working across Europe, it was founded by a Tech founder to remove the complexity from the certification experience for modern companies. It's built around streamlining the process for companies that use Drata, and upholds the following USPs: • Speed (fast communication, fast quotes, fast turnaround to prepare reports and certificates) • Excellent customer service • Tech focus • Remote first audits • Celebrating Drata • Competitive pricing
5.0 (9)
Registered Alliance Member
Schneider Downs & Co.

Schneider Downs & Co.

Schneider Downs provides System and Organization Controls (SOC) examinations nationally to over 160 clients annually in a variety of industries. Schneider Downs employs a unique approach to SOC reports, integrating the expertise of information technology, internal audit and external audit professionals. By combining cross-disciplinary knowledge and project management expertise, we are able to effectively deliver on our clients' expectations. The team is composed of more than 75 multidisciplinary professionals experienced in providing audit and attest services, internal audit and risk advisory services, and IT audit services. By integrating diverse, experienced individuals into the SOC examination process, we are able to provide unique and value-added insight to all of our SOC clients. Our team has combined experience working on more than 1,000 SOC examinations and works with clients across the country and world. Our team is well recognized for both its SOC experience and established service model and are leaders in the profession and recognized speakers on SOC reporting requirements regionally and nationally. Key benefits include: • Experienced team in reporting on controls at service organizations; • Leaders with global project management expertise; • Dedicated team that works collaboratively with clients to transfer knowledge; • IT leaders experienced in system controls (e.g., NIST, CMMC, COBIT, CSA CSM, HIPAA, HITRUST, PCI and ISO 27001 standards); • Approach designed to drive value for our clients and their customers; and • Incorporation of our firm’s specialists based on engagement needs.
5.0 (8)
Registered Alliance Member
Johanson Group LLP

Johanson Group LLP

Streamline your path to SOC 1, SOC 2, SOC 3, HIPAA, GDPR and ISO 27001 compliance today! We help organizations looking to build trust and reduce risk through our independent, high-quality audit services. We provide the following services: • SOC 1, SOC 2, SOC 2+, and SOC 3 Examinations • ISO/IEC 27001 Certifications • ISO 27017 (Cloud Security) and 27018 (Cloud Privacy) • ISO 27701 • HIPAA/HITECH Security Assessments • General Data Protection Regulation (GDPR) Services • Privacy Assessments based on International and State laws • NIST CSF Cybersecurity Assessments Johanson Group Differentiators • Transparency Built In - Application allowing you to track entire process from start to finish • We leverage 100% of Drata for our audits - no excel spreadsheets • Dedicated Customer Success Manager with unlimited access to audit professionals • Cost-Effective and Efficient quality audits. • We are able to certify/examine your organization across several frameworks • We serve clients across the globe and can accommodate all time zones. • We have a strong reputation with small, medium, and large companies. • We offer flexible payment terms.
5.0 (4)
Registered Alliance Member
MHM Professional Corporation

MHM Professional Corporation

MHM Professional Corporation is a boutique CPA firm of ex-Big 4 senior professionals providing Digital Trust audit & consulting for clients in North America, Europe and Israel. Our mandate is to deliver professional, technology enabled IT Security & Compliance services with pricing tailored for small and mid-sized organizations. Our areas of practice & expertise include: • SOC1 / SOC2 / SOC2+ (HIPAA, NIST, ISO27001) / SOC3 audits • ISO27001:2022 and ISO27701 certifications • ISO27001:2022 and ISO27701 internal audit (for non certification clients) • Privacy assessments (HIPAA, GDPR, etc.) • Readiness assessments & support (SOC1/SOC2, PCI, etc.) • IT Security Governance, Risk & Controls & Internal Audit MHM is based in Calgary, Alberta and led by Mark Mandel and Jose Costa, ex-PwC Partners with over 50 years of experience between them. Collectively, our team has over 100 years of Big 4 IT/Security audit and consulting experience. This level of expertise and working knowledge of the standards allows us to scope and deliver projects focused on your key risks and compliance requirements.
5.0 (3)
Registered Alliance Member
SAV Associates

SAV Associates

SAV is a full-service CPA firm. SAV’s assurance and risk advisory services division is a market leader in providing cyber security assurance and advisory services. The team specializes in Financial audits, SOC audits, ISO 27001 audits, PCI DSS, GDPR, AUP (agreed upon procedures) reporting, Internal audit outsourcing, and readiness assessment for regulatory compliance such as PCI, SOX, SOC1, SOC2, ISO 27001, GDPR, CCPA, PIPEDA, AML, cyber security audits, blockchain advisory, IT security assessment and project/system conversion reviews.
5.0 (2)
Registered Alliance Member
Boulay

Boulay

Founded in 1934, Boulay consists of approximately 300 employees, including over 100 CPAs and 35 Partners across our service lines of assurance, tax, advisory and wealth management. We work with individuals, closely-held businesses, private and public companies who are, or who aspire to be, financially successful. Our focus is to protect your business, build your wealth and secure your future by partnering with you and integrating our depth of experience designed to "help you get there". Boulay's Risk Advisory Group provides IT security compliance services to clients across the United States and globally. We specialize in conducting high-quality SOC 2 examinations and ISO 27001 certification audits for cloud-hosted SaaS organizations. Our team of experienced professionals adhere to rigorous AICPA quality control standards and are committed to providing you with the best service possible at an affordable price. Boulay Certifications, LLC is an accredited certification body for the ISO/IEC 27001:2022 standard by the ANSI National Accreditation Board (ANAB).
5.0 (2)
Registered Alliance Member
Pease Bell CPAs LLC

Pease Bell CPAs LLC

“Pease Bell” is a full-service CPA firm, headquartered in Cleveland, Oh with offices in Fairlawn, OH and Lakewood, NJ. With over 170 employees, our areas of expertise include information security attestation and consulting (SOC 1, SOC 2, ISO internal audit, GDPR, HIPAA, and others), traditional compliance services (taxation and financial statement assurance), transaction services (buy side diligence and quality of earnings), client accounting services (outsourced bookkeeping, controller, CFO), and more! Pease Bell's Risk Advisory specialists understand the growing need for IT & IS assurance and compliance services. The Risk Advisory team looks to educate and support our clients; focusing on solution-based practices for clients seeking to comply or in the process of becoming compliant. We carefully dissect each aspect of our clients’ business operations to create a strategic, tailored solution to meet one or many of their compliance needs. Our goal is to simplify and expedite the compliance reporting process to meet the stringent demands their customers, vendors and governing bodies require. The Pease Bell Difference • Our team is inquisitive and listens very well. We aim to learn about our client's operations and goals before we make any recommendations or offer any guidance. • We take a "consultative approach" to auditing. we communicate and translate in consumable language what the compliance requirements are. Through careful planning and execution, we set you up for success, and make sure expectations are clear (all while maintaining our independence of course!) • Peer reviewed through the AICPA's Peer Review Program. • We have a deep understanding of what Drata offers, and maximize Drata's automation to provide an efficient examination, passing along the cost savings to you, our client. • Our team of fully dedicated information security audit leads have each been through hundreds of SOC 2 examinations. • Information security attestation is not all that we offer. With over 100 CPA's and accountants Our clients that started with SOC 2 utilize many of our service offerings. Our SOC 2 clients have also used our team for: Corporate Tax Work, Reviewed Financial Statements, M&A Diligence, State Sales and Income Tax Nexus Studies, Outsourced Bookkeeping, Outsourced Controller and CFO Services, and more. We have a small firm feel, with the expertise and network of a large regional firm.
5.0 (1)

The information about providers and services contained in the directory does not, and is not intended to, constitute legal advice; instead, all information and content made available in this directory are for general informational purposes only. It is your responsibility to verify and investigate providers and services. Please consult your own professional advisor for all advice concerning legal, compliance or financial matters in connection with the services needed. Drata assumes no liability of any kind for the content of any information transmitted to or received by in connection with the use of this directory.