Audit Firm Pricing

Johanson Group SOC 2 Audit Cost 2026: How the Quote Is Set

Johanson Group is a boutique CPA firm with an uncommon dual credential: it is a licensed CPA firm and an IAS-accredited ISO 27001 certification body, so one firm can carry both a SOC 2 attestation and an accredited ISO 27001 certificate. Like every CPA firm, it prices each engagement individually and publishes no rate card. This page covers what moves a SOC 2 fee, what is verifiable about the firm, and how to compare quotes.

Pricing

Quoted per engagement

Tier

Boutique, dual credential

Accreditation

CPA + ISO 27001 cert body

There is no Johanson Group rate card

Johanson Group publishes no SOC 2 fee schedule. Neither does Schellman, A-LIGN, Coalfire, Linford & Co, Prescient Assurance, or any other CPA firm in this market. A SOC 2 examination is an attestation engagement performed under AICPA standards, scoped and priced per client, and fixed in an engagement letter. A fee table attributed to a named firm is a number that firm never published.

The mechanism is what you can act on. The fee is a function of auditor hours, and auditor hours are a function of the scope you define and the state of the evidence you hand over. Both are set before anyone quotes you.

What actually sets the fee

  • System boundary. The products, environments, and supporting systems inside the description of the system.
  • Trust Services Criteria in scope. Security, the Common Criteria, is the base; each additional criterion adds control points and testing. See the criteria breakdown.
  • Type 1 or Type 2. Design at a point in time, or operating effectiveness across a period. See Type 1 vs Type 2.
  • Observation window. A longer Type 2 period means more samples and more testing.
  • Readiness state. The lever you control most directly. See readiness.
  • ISO 27001 in the same engagement. SOC 2 and ISO 27001 share a substantial amount of control ground. Because Johanson can issue the ISO certificate under its own accreditation, the overlap can be evidenced once rather than twice across two firms. See SOC 2 vs ISO 27001.

What is verifiable about Johanson Group

Johanson Group LLP is a licensed CPA firm founded in 2014 and headquartered in Colorado Springs, Colorado, specialising in SOC 1, SOC 2, and SOC 3 attestations alongside a broader framework catalogue. Its positioning is set out on the firm's own site at johansonllp.com.

The credential that sets Johanson apart in the boutique tier is a matter of public record: the firm holds IAS accreditation as an ISO 27001 certification body under accreditation MSCB-314. Most boutique CPA firms can attest SOC 2 but must hand any ISO 27001 certificate to a separate accredited body. Johanson issuing both under one roof is unusual at this tier and is the right fit for a specific buyer: a company that needs SOC 2 and ISO 27001 together, commonly for simultaneous US and international enterprise sales, and would rather have one firm and one evidence cycle. Note the firm is not a FedRAMP 3PAO, so a federal roadmap still needs an accredited 3PAO such as A-LIGN or Coalfire.

Where Johanson Group belongs on the shortlist

Johanson Group belongs on your shortlist when you need SOC 2 and want the option of an accredited ISO 27001 certificate from the same firm, or when a broader framework catalogue than a pure SOC boutique matters to you. Put fellow boutique Linford & Co on the same shortlist for SOC 2 alone. Widen to Schellman, and for a federal roadmap A-LIGN or Coalfire, when the workload or the buyer's requirements point beyond the boutique tier.

Negotiation levers that actually exist

There is no list price to discount. Negotiate the shape of the engagement instead. Tighten the system boundary. Drop criteria nobody has asked for. Choose the report type deliberately. Where you need SOC 2 and ISO 27001, ask for them as one combined engagement so the shared controls are tested once, and ask explicitly how the ISO certificate is issued. Schedule with lead time. Fix the year-two renewal upfront. And bring a competing boutique quote on an identical scope, because a like-for-like comparison is the only lever a firm can respond to.

Frequently Asked Questions

How much does a Johanson Group SOC 2 audit cost?
There is no Johanson Group rate card, and no other CPA firm publishes one either. A SOC 2 examination is scoped and priced per engagement and fixed in an engagement letter. The fee tracks the system boundary, the Trust Services Criteria in scope, the report type, the observation window, and how ready your evidence is. Ask the firm for a quote against a written scope, and put that same scope in front of two other firms.
Can Johanson Group certify ISO 27001 as well as audit SOC 2?
Yes. Johanson Group LLP holds IAS accreditation as an ISO 27001 certification body (accreditation MSCB-314) in addition to being a licensed CPA firm. That combination is uncommon at the boutique tier and means one firm can deliver both the AICPA SOC 2 attestation and the accredited ISO 27001 certificate, where most boutique competitors would need a separate certification body for the ISO side. The firm is not a FedRAMP 3PAO, so a federal roadmap still needs A-LIGN, Coalfire, or another accredited 3PAO.
How does Johanson Group compare to Linford & Co?
Both are boutique CPA firms specialising in SOC examinations. The clearest difference is that Johanson Group also holds IAS accreditation as an ISO 27001 certification body, so it can deliver SOC 2 and an accredited ISO 27001 certificate under one firm and one evidence cycle. If you need only SOC 2, both are defensible; if you need SOC 2 and ISO 27001 together, Johanson's dual credential is the differentiator. Compare both on an identical written scope.
How do you compare audit-firm quotes?
Send every firm the identical written scope: system boundary, criteria in scope, report type, observation window, and report deadline. Then compare what each quote includes rather than the headline: readiness or gap assessment, the examination, the number of report review rounds, bridge letters, and the year-two renewal. Where ISO 27001 is in play, ask whether the certificate is issued by the firm under its own accreditation or handed to a separate body.

Updated 2026-07-15