Coalfire
- Licensed CPA firm — can issue a SOC 2 report
- AICPA peer review: Pass · Accepted Aug 14, 2024 · Verify at AICPA → ·
Details
Review period: Dec 1, 2022–Nov 30, 2023 · Record checked: Jun 11, 2026
Coalfire is a assurance specialist SOC 2 audit firm in Chicago, IL, USA. Its estimated SOC 2 Type II audit price is $40,000–$120,000; fieldwork to report takes 4–12 weeks.
Coalfire fits regulated programs combining SOC 2 with FedRAMP High, CMMC, PCI, HITRUST, or ISO. Coalfire Controls signs SOC reports; Coalfire Certification handles ISO; Coalfire Federal is the FOCI-separated CMMC entity. Confirm which entity and SOW cover each workstream.
Independent profile, researched and maintained by this directory from public sources. Coalfire has not reviewed or verified this page. Work at Coalfire? Verify and correct it — free →
“Effectual was able to achieve SOC 2 Type 2 report within 6 months using the evidence already gathered for PCI DSS compliance and mapped in Compliance Essentials Platform. Multiple framework compliance was never easy before Compliance Essentials.”
— Jon Castaldo, Information Security Manager, Effectual
Free. Anonymous until you pick.
How Much Does Coalfire Charge for SOC 2?
Coalfire's estimated SOC 2 Type II audit price is $40,000–$120,000; fieldwork to report takes 4–12 weeks.
- Type 1 cost
- $25K–$60K
- Type 2 cost
- $40K–$120K
- Timeline
- 4–12 wk
- Team Size
- 650-1000+
- Report Delivery
- Type 2 observation typically at least 6 months; full advisory plus examination often 6-9 months
- Response Time
- Quoted per engagement; public pricing unpublished
Type 2 cost Pricing Position
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
Timeline: The 4–12 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.
How this directory works: firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees. Our methodology →
- Pricing context
- 4%
- Timeline context
- 26%
- Accreditations
- 8
of Assurance specialist firms charge more for Type II.
of Assurance specialist firms have longer minimum timelines.
itemized accreditations. Organization-group average: 4.
Source: soc2auditors.org/auditors/coalfire/ · compiled and maintained by soc2auditors.org.
Compare Coalfire with Similar Assurance specialist Firms
Side-by-side pricing, timeline, and itemized accreditation counts for the closest-priced peers in the assurance specialist organization group. Firm-reported certification totals stay outside this comparison because they are not the same measure.
| Coalfire | 360 Advanced Sponsored | Zero Day CPA Sponsored | ControlCase | Drummond Group | IS Partners | |
|---|---|---|---|---|---|---|
| Type II Cost | $40K–$120K | $15K–$80K | $7K–$10K | $35K–$120K | $50K–$150K | $50K–$150K |
| Type I Cost | $25K–$60K | $15K–$60K | $5K–$7K | $20K–$80K | $35K–$100K | $35K–$100K |
| Timeline | 4–12 wk | 3–12 wk | 2–6 wk | 4–18 wk | 4–16 wk | 8–16 wk |
| Team Size | 650-1000+ | 51–200 | 25–30 | 200–500 | 500–2000 | 40–60 |
| Itemized Accreditations | 8 | 9 | 2 | 6 | 6 | 13 |
| Founded | 2001 | 2004 | 2020 | 2004 | 1999 | 2005 |
This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose
Coalfire Industry Fit
For buyers in Cloud Infrastructure and Federal/Government, Coalfire fits the assurance specialist profile when its 4–12 weeks timeline and Type II pricing ($40K–$120K) align with the buyer's scope. Their 8 active accreditations, including FedRAMP 3PAO, PCI DSS QSA, HITRUST Assessor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Who Should Hire Coalfire?
Mid-market and enterprise teams combining SOC 2 with FedRAMP, PCI DSS, HITRUST, or CMMC.
What Makes Coalfire Different?
A 128-assessment FedRAMP High 3PAO for cloud companies that need SOC 2 alongside federal authorization.
Is Coalfire Right for You?
- The displayed Type II price range is compatible with enterprise scope; confirm capacity and team in the proposal
- You need HITRUST + SOC 2 bundled in a single engagement
- You're pursuing FedRAMP authorization alongside SOC 2
- You handle payment data and need PCI DSS + SOC 2 together
- You're in healthcare and need HIPAA-aware auditors
- You're a SaaS company going through SOC 2 for the first time
of 6 criteria match. Get a personalized quote
Industries served
Works with these GRC platforms
Who is Coalfire?
Coalfire is a cybersecurity advisory and assessment firm founded in 2001, with headquarters at 330 N Wabash Ave in Chicago. Current offices also listed: Alpharetta, GA; Bellevue, WA; and Manchester, UK. Westminster, Colorado is the former HQ from the Carlyle/Chertoff era; it is no longer on the public contact page.
Public headcount signals sit around 650–1,000 (LinkedIn-class directories ~600–700; aggregators nearer 1,000). Delivery figures Coalfire publishes are more useful: 3,000 assessments a year, 500+ SOC reports a year, and 600+ framework specialists / 1 million+ assessment hours behind Compliance Essentials.
Funds advised by Apax Partners acquired Coalfire from Carlyle and The Chertoff Group; the sale closed in April 2020. That UK ownership is why Coalfire Federal had to keep operating as a structurally separate, wholly owned subsidiary with its own US leadership and board (FOCI / CFIUS), not as a fully independent company.
Three legal names matter on a contract:
- Coalfire Controls — licensed CPA affiliate that issues SOC 1 / SOC 2 / SOC 3 reports under AICPA standards. Coalfire says it participates in the AICPA peer-review program.
- Coalfire Certification Inc (coalfirecertification.com) — ANAB-accredited certification body. Rebranded from Coalfire ISO in December 2021. Current public scope: ISO/IEC 27001, ISO 9001, ISO/IEC 27701, ISO/IEC 42001, ISO 22301, ISO/IEC 20000-1. Dual UKAS accreditation was obtained in 2019–2021; the current CB site lists ANAB only.
- Coalfire Federal (coalfirefederal.com) — FOCI-separated federal/CMMC entity.
What does Coalfire’s FedRAMP marketplace record actually show?
Coalfire Systems, Inc. is FedRAMP Marketplace assessor 138514: accredited 17 July 2015, High (Class D), with 128 assessments as of 17 August 2026. That large book is not proof it is the #1 3PAO, and it does not support a claim that 75% of all FedRAMP authorizations are theirs.
Schellman’s profile tracks a larger marketplace count. Coalfire’s own marketing line that 75% of all FedRAMP authorizations are theirs is not used here.
What the firm does publish on its SOC page, and that we can repeat as a firm claim: 75% of its SOC engagements are for cloud service providers, and it names Google, Amazon, IBM, and Microsoft as CSP examples.
FedRAMP work at Coalfire includes readiness (RAR), initial assessment (SAP/SAR), annual assessment, continuous monitoring, and FedRAMP-required penetration testing / red teaming. The current services page says authorization typically takes 12–18 months or longer, and that Coalfire’s FedRAMP service portfolio can target ATO in under six months. ACE here is Accelerated Cloud Engineering (pre-engineered FedRAMP-ready modules, marketed since 2020) — not “Accelerated Compliance Experience.” A Gartner Peer Insights federal reviewer credited ACE with beating a typical two-year ATO path; that is one review, not a rating.
DoD work is sold as DoD RMF and, in advisory bios, the DoD Cloud Computing SRG — not the same thing as IL6 or classified-facility work.
What is Coalfire Federal, and who does the CMMC work?
Coalfire Federal has operated independently of the commercial parent since the Apax close in April 2020, under FOCI/CFIUS rules. Bill Malone was promoted from EVP to President on 29 April 2020, when the subsidiary got its own board (first chair: Mary Griggs, FOCI/CFIUS background).
CMMC timeline, as the firm states it:
- 23 August 2022 — among the first Cyber AB-authorized C3PAOs (CMMC 1.0-era authorization).
- 3 January 2025 — began conducting official CMMC Level 2 assessments as an authorized C3PAO under the live program.
- 16–18 July 2025 — triennial DIBCAC CMMC Level 2 re-certification, announced as a perfect score. DIBCAC is the body that re-assesses C3PAOs.
On 4 August 2025, Dr. Amy Williams, then VP of CMMC, was appointed Vice Chair of the Cyber AB C3PAO Advisory Council Accreditation Committee (two-year term). That appointment is not confirmation of her current operating title.
Coalfire Federal also assessed AWS’s Controlled Working Environment to CMMC Level 2 (announced June 2025). Its CMMC pages emphasize in-house assessors and say Level 2 assessments do not bundle remediation products; the same site still sells mock assessments and readiness. Ask which entity and which statement of work you are signing.
Which frameworks can Coalfire combine on one program?
Coalfire Controls issues SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain; related pages also list CSA STAR, BSI C5, Microsoft SSPA, and combined examples such as SOC + HIPAA and SOC + CSA STAR. PCI, HITRUST, and ISO sit in other legal entities, so the contract name matters.
PCI: Current services page positions Coalfire as a large QSAC with QSA and PFI capacity, and as a founding member of the PCI Global Executive Assessor Roundtable. Older 2021 accreditation sheets also listed PA-QSA, P2PE, and Secure Software/SLC; those extra designations were not re-confirmed on the 2026 PCI page.
HITRUST: Coalfire calls itself an original HITRUST External Assessment firm, with 35+ certified CSF practitioners. Services include e1 / i1 / r2, interim, rapid recertification, and bridge assessments, plus coordinated HITRUST + other-framework reporting.
ISO (Coalfire Certification): ANAB CB for the standards listed above, including ISO/IEC 42001. Coalfire also sells ISO 42001 readiness and pairs certification with model testing under AIMS+. Augment Code is a named ISO 42001 client.
Federal-adjacent (commercial Coalfire): FISMA, NIST SP 800-53, NIST SP 800-171, ITAR/EAR, DEA EPCS.
If Coalfire does both advisory and the SOC examination, its own FAQ says independence still has to be maintained — raise that on the first call.
What is Compliance Essentials, and does Coalfire use Audit AI?
Compliance Essentials is Coalfire’s current assessment product, not a GRC overlay it merely connects to. As of 5 May 2026 it includes Audit AI: MCP and open APIs so a client’s existing assistant can query live program data, plus AI policy/procedure review with page-level citations.
Coalfire’s launch claims: up to 40% less manual process work on the prior platform, up to 200% faster policy review in testing, and 70% greater accuracy than off-the-shelf chatbots for those reviews. Those are vendor test figures.
MCP sources named at launch: Jira, GitHub, Microsoft 365, and “hundreds” of other MCP-compatible systems. Audit AI policy review and the MCP server are included with a Coalfire assessment on Compliance Essentials.
The practical pattern, from Coalfire case studies: map PCI (or another framework) once, reuse evidence for SOC 2. Effectual went PCI ROC (2020) then SOC 2 Type 2 in six months (2022) on that mapping. BigCommerce used the same platform to stack PCI DSS, then ISO 27001, SOC 1/2/3, and ISO 27017/27018. AnewHealth reported cutting assessment duration by four weeks via the Continuous Compliance module.
CoalfireOne still appears on coordinated-assessment materials as the visibility portal. The 2026 product story is Compliance Essentials.
Homepage copy currently says coordinated assessments across 85+ frameworks; Compliance Essentials and Audit AI pages say 100+. The platform pages are the better figure for mapping.
Who leads Coalfire?
Brad Little became CEO on 6 January 2026, succeeding Tom McAndrew, who moved to the board as a senior advisor. Little’s last role was Global Head of Professional Services at Google Cloud, after more than two decades at Capgemini.
Immediate prior Capgemini titles include EVP and global head of application services (press release: ~58,000 people, ~$5B revenue) and head of Capgemini’s global SAP business. Career start: Ernst & Young. Tom McAndrew had been CEO for the prior 20 years.
Also on the current leadership page: Bill Malone (President, Coalfire Federal); Merri Chandler, CPA (CFO; KPMG, later Chartis Group); Vineet Seth (Chief Product & Technology Officer — BitSight VP of Product, SAP, RSA; CPO since 2021); Karen Laughton (EVP, Advisory Services); Adam Shnider (EVP, Assessment Services). Charles Henderson (EVP, DivisionHex) runs the offensive-security brand used for FedRAMP pentest and AI red-teaming.
How much does a Coalfire SOC 2 audit cost, and how long does it take?
Coalfire does not publish SOC prices. Directory figures are our estimates (Type 1 about $25k–$60k, Type 2 about $40k–$120k). There is no public Foundations / Advanced / Enterprise rate card on the current site.
Coalfire’s SOC FAQ: a Type 2 covers operating effectiveness typically at least six months. That is Coalfire’s usual window, not an AICPA-mandated floor. End-to-end advisory + readiness + examination is often 6–9 months. Fieldwork-to-report, once evidence is in, is the shorter 4–12 week band in the directory. Clients already in PCI or HITRUST can cut calendar time by reusing mapped evidence — that is the Effectual example, not a guarantee.
Positioning is premium: this is a Schellman / large-advisory comparable, not a first-SOC boutique.
Who is Coalfire a good fit for?
Coalfire is a poor fit for a first SOC 2 on a startup budget, or for anyone who wants the commercial parent and Coalfire Federal on one SOW. The shortlist case is FedRAMP High, CMMC, or stacked PCI/HITRUST/ISO; resolve the entity split during contracting.
Best fit
- CSPs that need a 3PAO with a large High-capable book (128 marketplace assessments as of August 2026) and will ask for named assessor experience at their baseline.
- DoD contractors wanting CMMC Level 2 from Coalfire Federal, with a clear split between mock/readiness and the official assessment.
- Mid-market and enterprise programs stacking SOC 2 with PCI, HITRUST, and/or ISO, where one evidence library is the point of the engagement.
- Healthcare SaaS that wants HITRUST plus a SOC 2 + HIPAA overlay from the same family of firms.
- Buyers who already expect a specialist cyber brand in procurement, not a Top 50 CPA logo.
Poor fit
- First SOC 2 on a startup budget. Estimated Type 2 sits well above boutique specialists.
- Buyers who want Schellman’s CPA-firm / classified-adjacent story (Top 50 ranking, FCL, 200 marketplace CSOs) or A-LIGN’s SOC-volume / A-SCEND factory.
- Anyone who needs the commercial parent and Coalfire Federal on one SOW without reading the FOCI split.
- Teams that only want a portal overlay on Drata/Vanta/Secureframe. Those GRC names are not a documented Coalfire integration list; the native path is Compliance Essentials.
What changed recently at Coalfire?
Between January 2025 and May 2026 Coalfire Federal began official CMMC Level 2 assessments, the commercial firm appointed Brad Little CEO, and Compliance Essentials launched Audit AI. The dated list below is the source trail for those claims.
- 5 May 2026: Audit AI launched inside Compliance Essentials (MCP + policy review).
- 6 January 2026: Brad Little appointed CEO; Tom McAndrew to board/advisor.
- 4 August 2025: Dr. Amy Williams (then VP of CMMC) named Vice Chair, Cyber AB C3PAO Advisory Council Accreditation Committee.
- 16–18 July 2025: Coalfire Federal DIBCAC CMMC Level 2 re-certification, perfect score announced.
- 18 June 2025: ISO/IEC 42001 ANAB accreditation / AIMS+ (model testing + certification).
- 3 January 2025: Coalfire Federal began official CMMC Level 2 assessments.
When should a buyer shortlist Coalfire?
Coalfire is a specialist cyber assessor with a real FedRAMP marketplace book (128, High, as of August 2026), a CPA affiliate for SOC, an ANAB ISO certification body, and a FOCI-separated CMMC C3PAO. The operational advantage, when it exists, is Compliance Essentials mapping PCI, HITRUST, or ISO evidence into SOC 2.
That is not a 5.0 Gartner score built on a handful of reviews, and not an unsourced “top-three 3PAO” ranking.
If the question is FedRAMP High or CMMC Level 2 plus SOC 2 from one family of firms, Coalfire belongs on the short list. If the question is cheapest first Type 2, look elsewhere.
Contact & Links
Office Locations
Compliance Frameworks Offered
GRC Platform Compatibility
Client Testimonials
"We were able to achieve SOC 2 type 2 audit within 6 months using the evidence already gathered for PCI compliance and mapped in Compliance Essentials Platform."
"By leveraging the Continuous Compliance module in Compliance Essentials, we shortened the overall compliance assessment duration by 4 weeks."
"Coalfire is a strategic partner rather than just a third-party vendor. We were able to get to markets faster and gain a competitive advantage by achieving PCI and SOC compliance."
"Coalfire allowed us to attain Authorization to Operate (ATO) much faster than the typical 2-year process. Coalfire's ACE service enabled us to deploy a FedRAMP-compliant environment within an impressive timeframe."
Industries, certifications, and platforms.
Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.
What Industries Does Coalfire Serve?
6 industries. Assurance specialist average: 6.
What Certifications and Accreditations Does Coalfire List?
8 accreditations. Assurance specialist average: 4.
What GRC Platforms Does Coalfire Work With?
Audit Platform
Compliance Essentials with Audit AI and MCP evidence connectors (as of May 2026)
Questions to Ask Coalfire Before Hiring
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
- Your team is sized at 650-1000+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
- You quote 4–12 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
- Your Type 2 cost range is $40K–$120K. What's included at each end, and what scope changes would push pricing above the top of that range?
- You integrate with Drata, Vanta, Compliance Essentials (proprietary). If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
- Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
- How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
- When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
- Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Coalfire on the verification record
Coalfire's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-06-11.
See the verification record · Is this your firm? Get your badge.
Get a quote from Coalfire
Tell us your scope. Coalfire replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? Browse All Auditors or get 3–10 quotes.
Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Coalfire's profile →