There is no Johanson Group rate card
Johanson Group publishes no SOC 2 fee schedule. Neither does Schellman, A-LIGN, Coalfire, Linford & Co, Prescient Assurance, or any other CPA firm in this market. A SOC 2 examination is an attestation engagement performed under AICPA standards, scoped and priced per client, and fixed in an engagement letter. A fee table attributed to a named firm is a number that firm never published.
The mechanism is what you can act on. The fee is a function of auditor hours, and auditor hours are a function of the scope you define and the state of the evidence you hand over. Both are set before anyone quotes you.
What actually sets the fee
- System boundary. The products, environments, and supporting systems inside the description of the system.
- Trust Services Criteria in scope. Security, the Common Criteria, is the base; each additional criterion adds control points and testing. See the criteria breakdown.
- Type 1 or Type 2. Design at a point in time, or operating effectiveness across a period. See Type 1 vs Type 2.
- Observation window. A longer Type 2 period means more samples and more testing.
- Readiness state. The lever you control most directly. See readiness.
- ISO 27001 in the same engagement. SOC 2 and ISO 27001 share a substantial amount of control ground. Because Johanson can issue the ISO certificate under its own accreditation, the overlap can be evidenced once rather than twice across two firms. See SOC 2 vs ISO 27001.
What is verifiable about Johanson Group
Johanson Group LLP is a licensed CPA firm founded in 2014 and headquartered in Colorado Springs, Colorado, specialising in SOC 1, SOC 2, and SOC 3 attestations alongside a broader framework catalogue. Its positioning is set out on the firm's own site at johansonllp.com.
The credential that sets Johanson apart in the boutique tier is a matter of public record: the firm holds IAS accreditation as an ISO 27001 certification body under accreditation MSCB-314. Most boutique CPA firms can attest SOC 2 but must hand any ISO 27001 certificate to a separate accredited body. Johanson issuing both under one roof is unusual at this tier and is the right fit for a specific buyer: a company that needs SOC 2 and ISO 27001 together, commonly for simultaneous US and international enterprise sales, and would rather have one firm and one evidence cycle. Note the firm is not a FedRAMP 3PAO, so a federal roadmap still needs an accredited 3PAO such as A-LIGN or Coalfire.
Where Johanson Group belongs on the shortlist
Johanson Group belongs on your shortlist when you need SOC 2 and want the option of an accredited ISO 27001 certificate from the same firm, or when a broader framework catalogue than a pure SOC boutique matters to you. Put fellow boutique Linford & Co on the same shortlist for SOC 2 alone. Widen to Schellman, and for a federal roadmap A-LIGN or Coalfire, when the workload or the buyer's requirements point beyond the boutique tier.
Negotiation levers that actually exist
There is no list price to discount. Negotiate the shape of the engagement instead. Tighten the system boundary. Drop criteria nobody has asked for. Choose the report type deliberately. Where you need SOC 2 and ISO 27001, ask for them as one combined engagement so the shared controls are tested once, and ask explicitly how the ISO certificate is issued. Schedule with lead time. Fix the year-two renewal upfront. And bring a competing boutique quote on an identical scope, because a like-for-like comparison is the only lever a firm can respond to.