Logo Menu

Coalfire

Assurance specialist Verified Chicago, IL, USA
  • Licensed CPA firm — can issue a SOC 2 report
  • AICPA peer review: Pass · Accepted Aug 14, 2024 · Verify at AICPA → ·
    Details Review period: Dec 1, 2022–Nov 30, 2023 · Record checked: Jun 11, 2026

Coalfire is a assurance specialist SOC 2 audit firm in Chicago, IL, USA. Its estimated SOC 2 Type II audit price is $40,000–$120,000; fieldwork to report takes 4–12 weeks.

Coalfire fits regulated programs combining SOC 2 with FedRAMP High, CMMC, PCI, HITRUST, or ISO. Coalfire Controls signs SOC reports; Coalfire Certification handles ISO; Coalfire Federal is the FOCI-separated CMMC entity. Confirm which entity and SOW cover each workstream.

Independent profile, researched and maintained by this directory from public sources. Coalfire has not reviewed or verified this page. Work at Coalfire? Verify and correct it — free →

Type 1 cost
$25K–$60K est.
Type 2 cost
$40K–$120K est.
Timeline
4–12 weeks
Accreditations
8 listed

“Effectual was able to achieve SOC 2 Type 2 report within 6 months using the evidence already gathered for PCI DSS compliance and mapped in Compliance Essentials Platform. Multiple framework compliance was never easy before Compliance Essentials.”

— Jon Castaldo, Information Security Manager, Effectual
Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

How Much Does Coalfire Charge for SOC 2?

Coalfire's estimated SOC 2 Type II audit price is $40,000–$120,000; fieldwork to report takes 4–12 weeks.

Type 1 cost
$25K–$60K
Type 2 cost
$40K–$120K
Timeline
4–12 wk
Team Size
650-1000+
Report Delivery
Type 2 observation typically at least 6 months; full advisory plus examination often 6-9 months
Response Time
Quoted per engagement; public pricing unpublished

Type 2 cost Pricing Position

$2.5K observed market span · est. $450K
Coalfire: $40K–$120K Assurance specialist avg: $20.122K–$60.301K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 4–12 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.

How this directory works: firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees. Our methodology →

Pricing context
4%

of Assurance specialist firms charge more for Type II.

Timeline context
26%

of Assurance specialist firms have longer minimum timelines.

Accreditations
8

itemized accreditations. Organization-group average: 4.

Source: soc2auditors.org/auditors/coalfire/ · compiled and maintained by soc2auditors.org.

Compare

Compare Coalfire with Similar Assurance specialist Firms

Side-by-side pricing, timeline, and itemized accreditation counts for the closest-priced peers in the assurance specialist organization group. Firm-reported certification totals stay outside this comparison because they are not the same measure.

Coalfire 360 Advanced Sponsored Zero Day CPA Sponsored ControlCase Drummond Group IS Partners
Type II Cost $40K–$120K $15K–$80K $7K–$10K $35K–$120K $50K–$150K $50K–$150K
Type I Cost $25K–$60K $15K–$60K $5K–$7K $20K–$80K $35K–$100K $35K–$100K
Timeline 4–12 wk 3–12 wk2–6 wk4–18 wk4–16 wk8–16 wk
Team Size 650-1000+ 51–20025–30200–500500–200040–60
Itemized Accreditations 8 926613
Founded 2001 20042020200419992005

This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose

About

Coalfire Industry Fit

For buyers in Cloud Infrastructure and Federal/Government, Coalfire fits the assurance specialist profile when its 4–12 weeks timeline and Type II pricing ($40K–$120K) align with the buyer's scope. Their 8 active accreditations, including FedRAMP 3PAO, PCI DSS QSA, HITRUST Assessor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

Who Should Hire Coalfire?

Mid-market and enterprise teams combining SOC 2 with FedRAMP, PCI DSS, HITRUST, or CMMC.

What Makes Coalfire Different?

A 128-assessment FedRAMP High 3PAO for cloud companies that need SOC 2 alongside federal authorization.

Fit check

Is Coalfire Right for You?

  • The displayed Type II price range is compatible with enterprise scope; confirm capacity and team in the proposal
  • You need HITRUST + SOC 2 bundled in a single engagement
  • You're pursuing FedRAMP authorization alongside SOC 2
  • You handle payment data and need PCI DSS + SOC 2 together
  • You're in healthcare and need HIPAA-aware auditors
  • You're a SaaS company going through SOC 2 for the first time

Who is Coalfire?

Coalfire is a cybersecurity advisory and assessment firm founded in 2001, with headquarters at 330 N Wabash Ave in Chicago. Current offices also listed: Alpharetta, GA; Bellevue, WA; and Manchester, UK. Westminster, Colorado is the former HQ from the Carlyle/Chertoff era; it is no longer on the public contact page.

Public headcount signals sit around 650–1,000 (LinkedIn-class directories ~600–700; aggregators nearer 1,000). Delivery figures Coalfire publishes are more useful: 3,000 assessments a year, 500+ SOC reports a year, and 600+ framework specialists / 1 million+ assessment hours behind Compliance Essentials.

Funds advised by Apax Partners acquired Coalfire from Carlyle and The Chertoff Group; the sale closed in April 2020. That UK ownership is why Coalfire Federal had to keep operating as a structurally separate, wholly owned subsidiary with its own US leadership and board (FOCI / CFIUS), not as a fully independent company.

Three legal names matter on a contract:

  • Coalfire Controls — licensed CPA affiliate that issues SOC 1 / SOC 2 / SOC 3 reports under AICPA standards. Coalfire says it participates in the AICPA peer-review program.
  • Coalfire Certification Inc (coalfirecertification.com) — ANAB-accredited certification body. Rebranded from Coalfire ISO in December 2021. Current public scope: ISO/IEC 27001, ISO 9001, ISO/IEC 27701, ISO/IEC 42001, ISO 22301, ISO/IEC 20000-1. Dual UKAS accreditation was obtained in 2019–2021; the current CB site lists ANAB only.
  • Coalfire Federal (coalfirefederal.com) — FOCI-separated federal/CMMC entity.

What does Coalfire’s FedRAMP marketplace record actually show?

Coalfire Systems, Inc. is FedRAMP Marketplace assessor 138514: accredited 17 July 2015, High (Class D), with 128 assessments as of 17 August 2026. That large book is not proof it is the #1 3PAO, and it does not support a claim that 75% of all FedRAMP authorizations are theirs.

Schellman’s profile tracks a larger marketplace count. Coalfire’s own marketing line that 75% of all FedRAMP authorizations are theirs is not used here.

What the firm does publish on its SOC page, and that we can repeat as a firm claim: 75% of its SOC engagements are for cloud service providers, and it names Google, Amazon, IBM, and Microsoft as CSP examples.

FedRAMP work at Coalfire includes readiness (RAR), initial assessment (SAP/SAR), annual assessment, continuous monitoring, and FedRAMP-required penetration testing / red teaming. The current services page says authorization typically takes 12–18 months or longer, and that Coalfire’s FedRAMP service portfolio can target ATO in under six months. ACE here is Accelerated Cloud Engineering (pre-engineered FedRAMP-ready modules, marketed since 2020) — not “Accelerated Compliance Experience.” A Gartner Peer Insights federal reviewer credited ACE with beating a typical two-year ATO path; that is one review, not a rating.

DoD work is sold as DoD RMF and, in advisory bios, the DoD Cloud Computing SRG — not the same thing as IL6 or classified-facility work.

What is Coalfire Federal, and who does the CMMC work?

Coalfire Federal has operated independently of the commercial parent since the Apax close in April 2020, under FOCI/CFIUS rules. Bill Malone was promoted from EVP to President on 29 April 2020, when the subsidiary got its own board (first chair: Mary Griggs, FOCI/CFIUS background).

CMMC timeline, as the firm states it:

  • 23 August 2022 — among the first Cyber AB-authorized C3PAOs (CMMC 1.0-era authorization).
  • 3 January 2025 — began conducting official CMMC Level 2 assessments as an authorized C3PAO under the live program.
  • 16–18 July 2025 — triennial DIBCAC CMMC Level 2 re-certification, announced as a perfect score. DIBCAC is the body that re-assesses C3PAOs.

On 4 August 2025, Dr. Amy Williams, then VP of CMMC, was appointed Vice Chair of the Cyber AB C3PAO Advisory Council Accreditation Committee (two-year term). That appointment is not confirmation of her current operating title.

Coalfire Federal also assessed AWS’s Controlled Working Environment to CMMC Level 2 (announced June 2025). Its CMMC pages emphasize in-house assessors and say Level 2 assessments do not bundle remediation products; the same site still sells mock assessments and readiness. Ask which entity and which statement of work you are signing.

Which frameworks can Coalfire combine on one program?

Coalfire Controls issues SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain; related pages also list CSA STAR, BSI C5, Microsoft SSPA, and combined examples such as SOC + HIPAA and SOC + CSA STAR. PCI, HITRUST, and ISO sit in other legal entities, so the contract name matters.

PCI: Current services page positions Coalfire as a large QSAC with QSA and PFI capacity, and as a founding member of the PCI Global Executive Assessor Roundtable. Older 2021 accreditation sheets also listed PA-QSA, P2PE, and Secure Software/SLC; those extra designations were not re-confirmed on the 2026 PCI page.

HITRUST: Coalfire calls itself an original HITRUST External Assessment firm, with 35+ certified CSF practitioners. Services include e1 / i1 / r2, interim, rapid recertification, and bridge assessments, plus coordinated HITRUST + other-framework reporting.

ISO (Coalfire Certification): ANAB CB for the standards listed above, including ISO/IEC 42001. Coalfire also sells ISO 42001 readiness and pairs certification with model testing under AIMS+. Augment Code is a named ISO 42001 client.

Federal-adjacent (commercial Coalfire): FISMA, NIST SP 800-53, NIST SP 800-171, ITAR/EAR, DEA EPCS.

If Coalfire does both advisory and the SOC examination, its own FAQ says independence still has to be maintained — raise that on the first call.

What is Compliance Essentials, and does Coalfire use Audit AI?

Compliance Essentials is Coalfire’s current assessment product, not a GRC overlay it merely connects to. As of 5 May 2026 it includes Audit AI: MCP and open APIs so a client’s existing assistant can query live program data, plus AI policy/procedure review with page-level citations.

Coalfire’s launch claims: up to 40% less manual process work on the prior platform, up to 200% faster policy review in testing, and 70% greater accuracy than off-the-shelf chatbots for those reviews. Those are vendor test figures.

MCP sources named at launch: Jira, GitHub, Microsoft 365, and “hundreds” of other MCP-compatible systems. Audit AI policy review and the MCP server are included with a Coalfire assessment on Compliance Essentials.

The practical pattern, from Coalfire case studies: map PCI (or another framework) once, reuse evidence for SOC 2. Effectual went PCI ROC (2020) then SOC 2 Type 2 in six months (2022) on that mapping. BigCommerce used the same platform to stack PCI DSS, then ISO 27001, SOC 1/2/3, and ISO 27017/27018. AnewHealth reported cutting assessment duration by four weeks via the Continuous Compliance module.

CoalfireOne still appears on coordinated-assessment materials as the visibility portal. The 2026 product story is Compliance Essentials.

Homepage copy currently says coordinated assessments across 85+ frameworks; Compliance Essentials and Audit AI pages say 100+. The platform pages are the better figure for mapping.

Who leads Coalfire?

Brad Little became CEO on 6 January 2026, succeeding Tom McAndrew, who moved to the board as a senior advisor. Little’s last role was Global Head of Professional Services at Google Cloud, after more than two decades at Capgemini.

Immediate prior Capgemini titles include EVP and global head of application services (press release: ~58,000 people, ~$5B revenue) and head of Capgemini’s global SAP business. Career start: Ernst & Young. Tom McAndrew had been CEO for the prior 20 years.

Also on the current leadership page: Bill Malone (President, Coalfire Federal); Merri Chandler, CPA (CFO; KPMG, later Chartis Group); Vineet Seth (Chief Product & Technology Officer — BitSight VP of Product, SAP, RSA; CPO since 2021); Karen Laughton (EVP, Advisory Services); Adam Shnider (EVP, Assessment Services). Charles Henderson (EVP, DivisionHex) runs the offensive-security brand used for FedRAMP pentest and AI red-teaming.

How much does a Coalfire SOC 2 audit cost, and how long does it take?

Coalfire does not publish SOC prices. Directory figures are our estimates (Type 1 about $25k–$60k, Type 2 about $40k–$120k). There is no public Foundations / Advanced / Enterprise rate card on the current site.

Coalfire’s SOC FAQ: a Type 2 covers operating effectiveness typically at least six months. That is Coalfire’s usual window, not an AICPA-mandated floor. End-to-end advisory + readiness + examination is often 6–9 months. Fieldwork-to-report, once evidence is in, is the shorter 4–12 week band in the directory. Clients already in PCI or HITRUST can cut calendar time by reusing mapped evidence — that is the Effectual example, not a guarantee.

Positioning is premium: this is a Schellman / large-advisory comparable, not a first-SOC boutique.

Who is Coalfire a good fit for?

Coalfire is a poor fit for a first SOC 2 on a startup budget, or for anyone who wants the commercial parent and Coalfire Federal on one SOW. The shortlist case is FedRAMP High, CMMC, or stacked PCI/HITRUST/ISO; resolve the entity split during contracting.

Best fit

  • CSPs that need a 3PAO with a large High-capable book (128 marketplace assessments as of August 2026) and will ask for named assessor experience at their baseline.
  • DoD contractors wanting CMMC Level 2 from Coalfire Federal, with a clear split between mock/readiness and the official assessment.
  • Mid-market and enterprise programs stacking SOC 2 with PCI, HITRUST, and/or ISO, where one evidence library is the point of the engagement.
  • Healthcare SaaS that wants HITRUST plus a SOC 2 + HIPAA overlay from the same family of firms.
  • Buyers who already expect a specialist cyber brand in procurement, not a Top 50 CPA logo.

Poor fit

  • First SOC 2 on a startup budget. Estimated Type 2 sits well above boutique specialists.
  • Buyers who want Schellman’s CPA-firm / classified-adjacent story (Top 50 ranking, FCL, 200 marketplace CSOs) or A-LIGN’s SOC-volume / A-SCEND factory.
  • Anyone who needs the commercial parent and Coalfire Federal on one SOW without reading the FOCI split.
  • Teams that only want a portal overlay on Drata/Vanta/Secureframe. Those GRC names are not a documented Coalfire integration list; the native path is Compliance Essentials.

What changed recently at Coalfire?

Between January 2025 and May 2026 Coalfire Federal began official CMMC Level 2 assessments, the commercial firm appointed Brad Little CEO, and Compliance Essentials launched Audit AI. The dated list below is the source trail for those claims.

  • 5 May 2026: Audit AI launched inside Compliance Essentials (MCP + policy review).
  • 6 January 2026: Brad Little appointed CEO; Tom McAndrew to board/advisor.
  • 4 August 2025: Dr. Amy Williams (then VP of CMMC) named Vice Chair, Cyber AB C3PAO Advisory Council Accreditation Committee.
  • 16–18 July 2025: Coalfire Federal DIBCAC CMMC Level 2 re-certification, perfect score announced.
  • 18 June 2025: ISO/IEC 42001 ANAB accreditation / AIMS+ (model testing + certification).
  • 3 January 2025: Coalfire Federal began official CMMC Level 2 assessments.

When should a buyer shortlist Coalfire?

Coalfire is a specialist cyber assessor with a real FedRAMP marketplace book (128, High, as of August 2026), a CPA affiliate for SOC, an ANAB ISO certification body, and a FOCI-separated CMMC C3PAO. The operational advantage, when it exists, is Compliance Essentials mapping PCI, HITRUST, or ISO evidence into SOC 2.

That is not a 5.0 Gartner score built on a handful of reviews, and not an unsourced “top-three 3PAO” ranking.

If the question is FedRAMP High or CMMC Level 2 plus SOC 2 from one family of firms, Coalfire belongs on the short list. If the question is cheapest first Type 2, look elsewhere.

Office Locations

Chicago, IL (HQ)Alpharetta, GABellevue, WAManchester, UK

Compliance Frameworks Offered

SOC 1, SOC 2, SOC 3 SOC for Cybersecurity, SOC for Supply Chain FedRAMP (3PAO since 17 July 2015; 128 marketplace assessments as of August 2026, High) DoD RMF / DoD Cloud Computing SRG CMMC Level 2 (via Coalfire Federal; official assessments from 3 January 2025) PCI DSS (QSAC; QSA and PFI) HITRUST CSF (original External Assessment firm) ISO 27001, 27701, 42001, 9001, 22301, 20000-1 (Coalfire Certification Inc, ANAB) NIST 800-53, 800-171, NIST CSF, NIST AI RMF FISMA, GDPR DEA EPCS, ITAR/EAR CSA STAR attestation, BSI C5, Microsoft SSPA

GRC Platform Compatibility

Compliance Essentials (proprietary; Audit AI and MCP as of May 2026) MCP connectors (Jira, GitHub, Microsoft 365, plus other MCP sources) CoalfireOne (coordination portal)

Client Testimonials

"We were able to achieve SOC 2 type 2 audit within 6 months using the evidence already gathered for PCI compliance and mapped in Compliance Essentials Platform."

Jon Castaldo
Information Security Manager
Effectual

"By leveraging the Continuous Compliance module in Compliance Essentials, we shortened the overall compliance assessment duration by 4 weeks."

Rachel Gardner
Information Security Compliance Program Manager
AnewHealth (formerly Tabula Rasa Healthcare)

"Coalfire is a strategic partner rather than just a third-party vendor. We were able to get to markets faster and gain a competitive advantage by achieving PCI and SOC compliance."

Michael Parks
CIO
Effectual

"Coalfire allowed us to attain Authorization to Operate (ATO) much faster than the typical 2-year process. Coalfire's ACE service enabled us to deploy a FedRAMP-compliant environment within an impressive timeframe."

Anonymous Federal Customer
Gartner Peer Insights
Expertise

Industries, certifications, and platforms.

Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.

What Industries Does Coalfire Serve?

6 industries. Assurance specialist average: 6.

Cloud Infrastructure Federal/Government FinTech & Payments Healthcare Enterprise SaaS MSPs

What Certifications and Accreditations Does Coalfire List?

8 accreditations. Assurance specialist average: 4.

AICPA FedRAMP 3PAO PCI DSS QSA HITRUST Assessor CMMC C3PAO ISO 27001 Certification Body ISO 42001 CPA Firm

What GRC Platforms Does Coalfire Work With?

Drata Vanta Compliance Essentials (proprietary)

Audit Platform

Compliance Essentials with Audit AI and MCP evidence connectors (as of May 2026)

Discovery call

Questions to Ask Coalfire Before Hiring

A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.

  1. Your team is sized at 650-1000+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
  2. You quote 4–12 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
  3. Your Type 2 cost range is $40K–$120K. What's included at each end, and what scope changes would push pricing above the top of that range?
  4. You integrate with Drata, Vanta, Compliance Essentials (proprietary). If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
  5. Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
  6. How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
  7. When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
  8. Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Verification

Coalfire on the verification record

Coalfire's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-06-11.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from Coalfire

Tell us your scope. Coalfire replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Want to compare first? Browse All Auditors or get 3–10 quotes.

We send you 3–10 quotes from firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Coalfire's profile →