Logo Menu

Frank, Rimerman + Co.

Full-service CPA Verified Palo Alto, CA, USA
  • Licensed CPA firm — can issue a SOC 2 report
  • AICPA peer review: Pass · Accepted Mar 18, 2026 · Verify at AICPA → ·
    Details Review period: Jun 1, 2024–May 31, 2025 · Record checked: Jun 11, 2026

Frank, Rimerman + Co. is a full-service cpa SOC 2 audit firm in Palo Alto, CA, USA. Its estimated SOC 2 Type II audit price is $30,000–$80,000; fieldwork to report takes 4–12 weeks.

Independent profile, researched and maintained by this directory from public sources. Frank, Rimerman + Co. has not reviewed or verified this page. Work at Frank, Rimerman + Co.? Verify and correct it — free →

Type 1 cost
$20K–$60K est.
Type 2 cost
$30K–$80K est.
Timeline
4–12 weeks
Accreditations
3 listed
Or compare with similar firms ↓

Free. Anonymous until you pick.

Pricing

How Much Does Frank, Rimerman + Co. Charge for SOC 2?

Frank, Rimerman + Co.'s estimated SOC 2 Type II audit price is $30,000–$80,000; fieldwork to report takes 4–12 weeks.

Type 1 cost
$20K–$60K
Type 2 cost
$30K–$80K
Timeline
4–12 wk
Team Size
500-700+
Report Delivery
Standard delivery
Response Time
Unlimited partner/manager access year-round

Type 2 cost Pricing Position

$2.5K observed market span · est. $450K
Frank, Rimerman + Co.: $30K–$80K Full-service CPA avg: $31.67K–$83.106K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

Timeline: The 4–12 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.

How this directory works: firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees. Our methodology →

Pricing context
40%

of Full-service CPA firms charge more for Type II.

Timeline context
71%

of Full-service CPA firms have longer minimum timelines.

Accreditations
3

itemized accreditations. Organization-group average: 2.

Source: soc2auditors.org/auditors/frank-rimerman/ · compiled and maintained by soc2auditors.org.

Compare

Compare Frank, Rimerman + Co. with Similar Full-service CPA Firms

Side-by-side pricing, timeline, and itemized accreditation counts for the closest-priced peers in the full-service cpa organization group. Firm-reported certification totals stay outside this comparison because they are not the same measure.

Frank, Rimerman + Co. 360 Advanced Sponsored Thoropass Sponsored AAFCPAs Anders CPAs + Advisors Dannible McKee
Type II Cost $30K–$80K $15K–$80K $12K–$85K $30K–$80K $30K–$80K $30K–$80K
Type I Cost $20K–$60K $15K–$60K $8K–$15K $20K–$60K $20K–$60K $20K–$60K
Timeline 4–12 wk 3–12 wk2–6 wk6–12 wk8–20 wk8–20 wk
Team Size 500-700+ 51–200200–250350–1000380–410100–115
Itemized Accreditations 3 98312
Founded 1949 20042019197319651978

This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose

About

Frank, Rimerman + Co. Industry Fit

For buyers in SaaS and Software, Frank, Rimerman + Co. fits the full-service cpa profile when its 4–12 weeks timeline and Type II pricing ($30K–$80K) align with the buyer's scope. Their 3 active accreditations, including ISO 27001 Certification Body, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

Who Should Hire Frank, Rimerman + Co.?

Silicon Valley startups and VC-backed technology firms combining SOC work with ISO 27001 or ISO 27701.

What Makes Frank, Rimerman + Co. Different?

Pairs 75-plus years in the Silicon Valley ecosystem with ANAB-accredited ISO certification and year-round partner access.

Fit check

Is Frank, Rimerman + Co. Right for You?

  • You're in healthcare and need HIPAA-aware auditors
  • You're a SaaS company going through SOC 2 for the first time
  • You already use Drata, Vanta, Sprinto and want an auditor who integrates with it

Who is Frank Rimerman?

Frank, Rimerman + Co. LLP is a Palo Alto-based CPA firm, founded in 1949, with roughly 500-700 people across seven California and Utah offices; its SOC and ISO examination work sits inside a dedicated Risk Advisory & Assurance practice, not as a side offering of the tax and accounting business.

The firm has been embedded in Silicon Valley’s venture and technology community since the earliest days of the venture capital industry, and that client base — SaaS, software, fintech, life sciences, and venture-backed companies — is exactly who the Risk Advisory & Assurance group is built to serve.

Frank, Rimerman is also an independent member of Baker Tilly International, one of the ten largest global accountancy networks, giving it reach into 140+ territories for clients with cross-border audit or advisory needs, even though the SOC/ISO practice itself is delivered out of the US offices.

What credentials does Frank Rimerman actually hold?

Frank, Rimerman + Co. LLP is a licensed CPA firm and AICPA member, which is the baseline requirement for issuing a SOC report — a SOC 1, SOC 2, or SOC 3 attestation is only as credible as the CPA firm behind it.

The firm is enrolled in the AICPA Peer Review Program, and its most recent peer review, dated March 18, 2026, resulted in a pass rating for the engagement period June 1, 2024 through May 31, 2025. Buyers can verify this directly on the AICPA Peer Review public file search. A pass this recent is a meaningful signal — it means the firm’s SOC methodology was independently reviewed and cleared well within the current audit cycle.

What SOC reports does Frank Rimerman issue?

Frank, Rimerman’s Risk Advisory & Assurance group performs the full SOC family: SOC 1 (internal controls over financial reporting, typically used for SOX purposes), SOC 2 (Type I and Type II, covering security, availability, confidentiality, processing integrity, and privacy), SOC 3 (the public-facing condensed summary of a SOC 2), and SOC 2+, which layers additional criteria — most commonly ISO

27001 or HIPAA — onto a standard SOC 2 examination so a client only runs one evidence-collection cycle instead of two separate audits. The practice is led by Assurance and Advisory Partners Nelly Spieler and Jason Stork, and the firm advertises unlimited partner and manager access throughout the engagement rather than gating communication to a junior staff auditor.

Is Frank Rimerman an ISO 27001 certification body?

Frank, Rimerman’s real differentiator in the SOC 2 market is that it can carry a client from a SOC 2 report through to an ISO 27001 (and ISO 27701 privacy) certification under the same firm brand — a combination most SOC 2-only shops cannot offer in-house.

Get the structure right, because it matters for independence: the SOC attestation is issued by Frank, Rimerman + Co. LLP (the CPA firm), while the ISO and CSA STAR certifications are issued by Frank, Rimerman Information Security LLC, a separate legal entity that is affiliated with, but organizationally distinct from, the CPA firm. That separation is not incidental — ANAB accreditation for a certification body requires exactly this kind of structural independence from a firm’s advisory work, the same principle that keeps a CPA firm’s attest opinions clean of self-review risk.

Frank, Rimerman Information Security LLC is accredited by the ANSI-ASQ National Accreditation Board (ANAB) to certify against ISO/IEC 27001 (information security management) and ISO/IEC 27701 (the privacy extension to 27001, useful for GDPR-adjacent obligations). The firm’s marketing also references ISO 27017 (cloud security) and 27018 (PII in the cloud) as part of the “ISO family” it can assess against, but its stated ANAB accreditation covers 27001 and 27701 specifically — buyers who need a standalone 27017 or 27018 certificate should confirm current accreditation scope directly with the firm before assuming coverage. Being one of the small number of public accounting firms accredited as an ISO 27001 certification body is a genuinely uncommon capability; most SOC 2 audit firms partner out ISO work rather than issue it themselves.

Does Frank Rimerman cover CSA STAR?

Frank, Rimerman Information Security LLC also holds Cloud Security Alliance (CSA) accreditation to issue CSA STAR Level 2 Certification, which combines the ISO/IEC 27001 standard with the CSA’s Cloud Controls Matrix for a cloud-specific maturity assessment, and lists the firm on the CSA STAR Certified Auditors Registry.

This is pitched as a natural next step for cloud-native companies that already hold or are pursuing ISO 27001 and want a deeper, cloud-specific layer of assurance without a full separate audit cycle.

Which industries does Frank Rimerman actually serve?

The Risk Advisory & Assurance practice’s client base mirrors the firm’s broader technology and life sciences focus: SaaS and software companies, fintech, healthcare and health-tech, life sciences (pharma, biotech, medical device, digital health), and venture-backed companies generally.

The firm’s decades of work with Silicon Valley venture capital and growth-stage technology clients shape how its SOC and ISO teams scope and staff engagements — they are used to the pace and audit-readiness gaps typical of a company preparing for its first enterprise deal or funding round with a compliance requirement attached.

Which frameworks does Frank Rimerman cover?

Frank, Rimerman’s public service pages do not describe HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work as part of the Risk Advisory & Assurance offering. Buyers whose roadmap includes any of those frameworks should plan on a separate specialist firm for that scope, at least until Frank, Rimerman publishes evidence of accreditation in those areas.

How much does a Frank Rimerman SOC 2 audit cost?

Frank, Rimerman does not publish SOC 2 pricing. Directory estimates are $20,000–$60,000 Type I and $30,000–$80,000 Type II; a combined SOC 2+ISO job costs more than either alone.

Request a quote for a firm-specific number.

How long does a Frank Rimerman SOC 2 audit take?

Fieldwork-to-report for a SOC examination at Frank, Rimerman runs an estimated 4-12 weeks, though that window covers only the audit itself.

A SOC 2 Type II additionally requires an observation period — typically 3 to 12 months of continuous control operation — before fieldwork can even begin, a constraint of the SOC 2 standard itself rather than anything specific to this firm. Combining SOC 2 with an ISO 27001 or CSA STAR certification in one coordinated engagement is the practice’s stated goal of reducing duplicate evidence requests, but it does not shorten either framework’s underlying observation-period requirements.

Who is Frank Rimerman a good fit for?

Frank, Rimerman fits Bay Area SaaS, fintech, and life-sciences buyers that want a 75-year CPA name plus an affiliated path to ISO 27001/27701 and CSA STAR Level 2. HITRUST, FedRAMP, and PCI QSA are not in the published scope.

Best fit for:

  • SaaS, fintech, healthcare/health-tech, and life sciences companies in Frank, Rimerman’s home Silicon Valley/Bay Area market that want a recognized, 75-year-old CPA firm name on the report
  • Companies that will need both a SOC 2 report and an ISO 27001 (or 27701) certification and want that continuity handled by one affiliated firm rather than two unrelated

vendors - Cloud-native companies already holding or pursuing ISO 27001 that want to add CSA STAR Level 2 without starting a new audit relationship - Venture-backed startups whose deal or funding timeline benefits from a firm fluent in the Silicon Valley investor and enterprise-buyer context - Buyers who value direct, unlimited partner-and-manager access over being routed to junior staff

Not a fit — look elsewhere if:

  • You need HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work; none of these appear in Frank, Rimerman’s published scope
  • You want the very lowest-cost boutique SOC 2 shop; a mid-tier regional CPA firm’s overhead puts it above the cheapest specialist auditors
  • Your business has no California/Bay Area or broader life sciences/technology footprint and gets no benefit from the firm’s regional network

When should a buyer shortlist Frank Rimerman?

Shortlist Frank, Rimerman for a March 2026 AICPA peer-review pass plus an in-house path from SOC to ISO 27001/27701 and CSA STAR Level 2 via Frank, Rimerman Information Security LLC. That continuity is the mid-tier Bay Area pitch, not a HITRUST or FedRAMP shop.

For a Bay Area SaaS, fintech, or life sciences company that expects both a SOC 2 report and an ISO certification, that continuity is the reason to pay mid-tier pricing. For HITRUST, government frameworks, or the cheapest SOC 2, look to a specialist instead.

Office Locations

Palo Alto, CA (HQ)San Francisco, CASan Jose, CASacramento, CASan Diego, CASt. Helena, CALehi, UT

Compliance Frameworks Offered

SOC 1 SOC 2 (Type I & Type II) SOC 3 SOC 2+ (combined with ISO or HIPAA criteria) ISO/IEC 27001 ISO/IEC 27701 CSA STAR Level 2
Expertise

Industries, certifications, and platforms.

Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.

What Industries Does Frank, Rimerman + Co. Serve?

6 industries. Full-service CPA average: 6.

SaaS Software FinTech Healthcare Life Sciences Venture-backed Companies

What Certifications and Accreditations Does Frank, Rimerman + Co. List?

3 accreditations. Full-service CPA average: 2.

AICPA CPA Firm ISO 27001 Certification Body

What GRC Platforms Does Frank, Rimerman + Co. Work With?

Drata Vanta Sprinto

Audit Platform

Proprietary

Discovery call

Questions to Ask Frank, Rimerman + Co. Before Hiring

A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.

  1. Your team is sized at 500-700+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
  2. You quote 4–12 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
  3. Your Type 2 cost range is $30K–$80K. What's included at each end, and what scope changes would push pricing above the top of that range?
  4. You integrate with Drata, Vanta, Sprinto. If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
  5. Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
  6. How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
  7. When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
  8. Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Verification

Frank, Rimerman + Co. on the verification record

Frank, Rimerman + Co.'s registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-06-11.

See the verification record · Is this your firm? Get your badge.

Quote

Get a quote from Frank, Rimerman + Co.

Tell us your scope. Frank, Rimerman + Co. replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Want to compare first? Browse All Auditors or get 3–10 quotes.

We send you 3–10 quotes from firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.

Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Frank, Rimerman + Co.'s profile →