Find a compliance assessment firm.
Browse assessors from official registries, with firms that describe SOC 2 services on their own sites. Compare sourced locations and check each firm’s role. 3PAOs assess; agencies authorize. SOC 2 ends in an attestation report, not a certificate.
645 firms listed · October 2026 snapshot
Search the directory
Search a firm, city, state, or service. Every result has a crawlable profile.
Browse by assessment
FedRAMP 3PAOs
Recognized third-party assessment organizations in the FedRAMP Marketplace.
Explore 47 firmsSOC 2 service firms
Firms whose own sites confirm SOC 2 examination or readiness services. Confirm which firm issues any attestation report.
Explore 20 firmsFedRAMP + SOC 2
Firms appearing in the FedRAMP extract with a separately confirmed SOC 2 practice.
Explore 14 firmsGovRAMP 3PAOs
A2LA-accredited third-party assessment organizations participating in GovRAMP, which verifies cloud providers for state and local government.
Explore 32 firmsPCI QSA companies
Qualified Security Assessor companies listed by the PCI Security Standards Council to assess merchants and service providers against PCI DSS.
Explore 414 firmsPCI Approved Scanning Vendors
Approved Scanning Vendors listed by the PCI Security Standards Council to run external vulnerability scans required by PCI DSS.
Explore 81 firmsCMMC C3PAOs
Certified Third-Party Assessment Organizations (C3PAOs) listed in the Cyber AB CMMC Marketplace, which assess defense contractors for CMMC certification.
Explore 117 firmsHITRUST external assessors
Authorized External Assessor firms listed by HITRUST to perform validated assessments for HITRUST certification.
Explore 102 firmsISO/IEC 27001 certification bodies (ANAB)
Certification bodies currently accredited by ANAB under ISO/IEC 17021-1 to certify information security management systems to ISO/IEC 27001.
Explore 50 firmsBrowse by state
Locations come from registry records and firm sites. Listings without a sourced office are not assigned a state.
Frequently asked questions
What is a recognized 3PAO?
A third-party assessment organization recognized by FedRAMP to assess cloud services for the federal authorization process. The federal agency makes the authorization decision, not the 3PAO. Check the FedRAMP Marketplace for current recognition.
Is there an official SOC 2 auditor registry?
No. SOC 2 practice labels here require a supporting page on the firm's own website; they are not a government accreditation. An independent licensed CPA firm issues a SOC 2 attestation report, not a certificate.
SOC 2 practice confirmed from each firm's own site; no official SOC 2 auditor registry exists. Firms are listed from official registries, each with its own as-of date. Locations are shown only where the registry or the firm's own site provides them. A listing records registry status, not an endorsement, and directory information may change. SOC 2 is a CPA attestation report, not a certificate. pa.tax is independent: listed firms pay nothing for inclusion, ranking or referrals, and firms are listed alphabetically.
- FedRAMP Marketplace · as of October 3, 2026
- GovRAMP program participants · as of October 3, 2026
- PCI SSC Qualified Security Assessors · as of October 3, 2026
- PCI SSC Approved Scanning Vendors · as of October 3, 2026
- Cyber AB CMMC Marketplace · as of October 3, 2026
- HITRUST external assessor list · as of October 3, 2026
- ANAB Management Systems CB Directory · as of October 3, 2026