LBMC
- Licensed CPA firm — can issue a SOC 2 report
- AICPA peer review: Pass · Accepted Mar 4, 2026 · Verify at AICPA → ·
Details
Review period: Jun 1, 2024–May 31, 2025 · Record checked: Jun 11, 2026
LBMC is a full-service cpa SOC 2 audit firm in Nashville, TN, USA. Its estimated SOC 2 Type II audit price is $20,000–$60,000; fieldwork to report takes 26–52 weeks.
Independent profile, researched and maintained by this directory from public sources. LBMC has not reviewed or verified this page. Work at LBMC? Verify and correct it — free →
Free. Anonymous until you pick.
How Much Does LBMC Charge for SOC 2?
LBMC's estimated SOC 2 Type II audit price is $20,000–$60,000; fieldwork to report takes 26–52 weeks.
- Type 1 cost
- $15K–$45K
- Type 2 cost
- $20K–$60K
- Timeline
- 26–52 wk
- Team Size
- 50-150+
- Report Delivery
- 45-60 days after reporting period ends
- Response Time
- Standard
Type 2 cost Pricing Position
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
Timeline: The 26–52 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.
How this directory works: firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees. Our methodology →
- Pricing context
- 80%
- Timeline context
- 0%
- Accreditations
- 4
of Full-service CPA firms charge more for Type II.
of Full-service CPA firms have longer minimum timelines.
itemized accreditations. Organization-group average: 2.
Source: soc2auditors.org/auditors/lbmc/ · compiled and maintained by soc2auditors.org.
Compare LBMC with Similar Full-service CPA Firms
Side-by-side pricing, timeline, and itemized accreditation counts for the closest-priced peers in the full-service cpa organization group. Firm-reported certification totals stay outside this comparison because they are not the same measure.
| LBMC | 360 Advanced Sponsored | Thoropass Sponsored | Carr, Riggs & Ingram (CRI) | Forvis Mazars | GRF CPAs & Advisors | |
|---|---|---|---|---|---|---|
| Type II Cost | $20K–$60K | $15K–$80K | $12K–$85K | $25K–$55K | $25K–$55K | $20K–$60K |
| Type I Cost | $15K–$45K | $15K–$60K | $8K–$15K | $15K–$30K | $15K–$30K | $15K–$45K |
| Timeline | 26–52 wk | 3–12 wk | 2–6 wk | 4–10 wk | 5–12 wk | 6–12 wk |
| Team Size | 50-150+ | 51–200 | 200–250 | 1600–1700 | 35000–45000 | 20–100 |
| Itemized Accreditations | 4 | 9 | 8 | 3 | 4 | 2 |
| Founded | 1984 | 2004 | 2019 | 1997 | 2024 | 1981 |
This comparison may include sponsored firms, marked above — only where they're a relevant alternative. How we choose
LBMC Industry Fit
For buyers in Healthcare and claims processing and Financial services, LBMC fits the full-service cpa profile when its 26–52 weeks timeline and Type II pricing ($20K–$60K) align with the buyer's scope. Their 4 active accreditations, including HITRUST Assessor, PCI DSS QSA, ISO 27001 Lead Auditor, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Who Should Hire LBMC?
Healthcare and private-equity-backed mid-market teams pairing SOC reports with another security framework.
What Makes LBMC Different?
An integrated 1,000-plus-person accounting and cybersecurity practice covering HITRUST, ISO 27001, PCI DSS, NIST, CMMC, and HIPAA.
Is LBMC Right for You?
- You need HITRUST + SOC 2 bundled in a single engagement
- You handle payment data and need PCI DSS + SOC 2 together
- You're in healthcare and need HIPAA-aware auditors
- You're in financial services with regulatory audit requirements
- You're a SaaS company going through SOC 2 for the first time
- You already use Drata and want an auditor who integrates with it
of 6 criteria match. Get a personalized quote
Industries served
Works with these GRC platforms
Who is LBMC?
LBMC is a Nashville-based professional services firm, founded in 1984, with a dedicated cybersecurity and attestation practice inside a firm of more than 900 professionals serving roughly 11,000 clients. Rather than a boutique SOC 2 shop, LBMC is a top-50 U.S.
accounting firm where SOC reporting sits alongside audit, tax, HR outsourcing, and wealth management under one “LBMC Family of Companies” umbrella — the SOC 2 buyer here is typically a mid-market or larger organization, often in healthcare, financial services, or cloud/SaaS, that also wants HITRUST, ISO 27001, or PCI handled by the same team.
LBMC’s cybersecurity group performs SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity examinations directly, issued under the firm’s own CPA license. It operates from seven U.S. offices — Nashville (headquarters, in Brentwood), Chattanooga, Knoxville, Memphis, Louisville, Charlotte, and Philadelphia — plus a delivery team in Chennai, India.
What credentials does LBMC actually hold?
LBMC is a licensed CPA firm and AICPA member that issues SOC reports itself, not through a subcontracted or partner CPA. SOC engagements are performed under AICPA SSAE 18 standards, per LBMC’s own service description.
The firm is enrolled in the AICPA Peer Review Program, the profession’s mandatory external quality check for CPA firms performing attestation work. LBMC’s most recent peer review was completed March 4, 2026, with a pass result covering the period June 1, 2024 through May 31, 2025 — a recent, current review, verifiable directly at the AICPA’s public peer-review search.
Beyond the CPA license, LBMC’s cybersecurity practice carries three accreditations that most SOC-only firms don’t hold: HITRUST Authorized External Assessor status, PCI Qualified Security Assessor (QSA) status, and ISO 27001 Lead Auditor credentials — the combination that lets one team move a client between SOC 2, HITRUST, ISO, and PCI without a handoff to a different firm.
What SOC reports does LBMC issue?
LBMC performs the full SOC family — SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity — for service organizations nationwide, offering both Type I (point-in-time design) and Type II (design and operating effectiveness) reports.
Per LBMC’s own SOC audit page, a Type II examination period typically runs 6 to 12 months, and the firm targets issuing the final report 45 to 60 days after that observation period closes.
LBMC’s stated engagement flow is discovery and scoping, an optional (but recommended) readiness assessment to surface control gaps before testing starts, control implementation/remediation by the client, the observation period itself for a Type II, then testing and report issuance. That structure is standard for a firm this size — LBMC does not shortcut the observation window, and readiness is explicitly optional rather than bundled by default.
Does LBMC assess HITRUST?
LBMC has been a HITRUST Authorized External Assessor since 2010 and markets itself as the longest-serving assessor in HITRUST’s “10-year club.” Tenure is the differentiator; confirm current assessor status on HITRUST’s list.
LBMC also states it participated in the work integrating CMS and NIST security standards into the HITRUST CSF itself, rather than simply testing against it.
LBMC’s HITRUST services span scoping and certification-type selection, readiness and gap assessment, initial and interim certification assessments, and bridge assessments for organizations extending a certification period. For healthcare organizations and their business associates that need both a SOC 2 report and a HITRUST certification, LBMC’s pitch is running both through one team rather than coordinating two separate assessors.
Is LBMC an ISO 27001 certification body?
LBMC performs ISO/IEC 27001:2022 (information security), 27701:2019 (privacy), and 9001:2015 (quality) certification audits directly, including the two-stage initial certification audit and the subsequent surveillance audits over the three-year certification cycle. LBMC’s own internal Certification Committee reviews audit results and approves or denies certification.
The firm’s marketing does not cite an ANAB or UKAS accreditation number for this certification-body function, so buyers who need certification from a specific national accreditation body should confirm that detail directly with LBMC before engaging.
Does LBMC do PCI DSS?
LBMC is a PCI Qualified Security Assessor (QSA) firm, supporting the full range of PCI work: Report on Compliance (ROC) and Attestation of Compliance (AOC) for Level 1 merchants and service providers, PCI gap analysis, quarterly ASV vulnerability scanning, and Self-Assessment Questionnaire (SAQ-D) support.
LBMC frames this as an “audit once, report many” approach — aligning PCI evidence with SOC 2 or other frameworks the client is already pursuing, which reduces duplicate evidence requests for clients running both engagements.
Does LBMC cover HIPAA?
LBMC performs HIPAA and HITECH security and privacy risk assessments for healthcare organizations and business associates, and can report the results through HITRUST or another certification framework alongside a SOC engagement.
For CMMC, LBMC provides readiness consulting, gap analysis against CMMC 2.0 requirements, and remediation support, guiding defense contractors through Level 1 self-assessment or Level 2+ formal assessment prep. LBMC’s public materials describe this readiness and advisory role clearly; they do not state that LBMC itself holds Certified Third-Party Assessor Organization (C3PAO) accreditation to issue the formal Level 2 certification. Buyers whose primary need is the formal CMMC certification assessment itself, rather than readiness, should confirm C3PAO status directly with LBMC.
LBMC also performs CSA STAR assessments (Level 1 self-assessment support and Level 2 third-party certification/attestation as an approved CSA-certified STAR auditor) and NIST 800-53/800-171 compliance assessments, drawing on more than 20 years in IT security and compliance work.
Does LBMC also sell penetration testing?
LBMC’s cybersecurity team offers penetration testing — network, web application, mobile application, cloud, wireless, and social engineering testing, plus its Advance Guard continuous-assessment retainer and LBMC Guard vulnerability-scanning service — explicitly positioned to complement PCI DSS and SOC audit work.
Worth understanding before scoping: when a SOC 2 engagement calls for an accompanying penetration test, having the same CPA firm perform both the test and the audit that relies on it creates a self-review consideration under AICPA independence rules — the pen test becomes part of the control environment the audit then evaluates. If you engage LBMC for SOC 2 attestation, raise the separation question up front rather than assuming the firm’s own pen test team should be bundled into the same engagement.
Which industries does LBMC actually serve?
LBMC’s cybersecurity and attestation clients concentrate in healthcare and claims processing, financial services, cloud service providers and SaaS/technology companies, data centers and hosting providers, private-equity portfolio companies, manufacturing, and real estate — a broader industry spread than a SOC-2-only boutique, consistent with LBMC’s position as a full-service regional firm rather than a niche specialist.
How much does an LBMC SOC 2 audit cost?
LBMC does not publish SOC 2 pricing. Directory estimates are $15,000–$45,000 Type I and $20,000–$60,000 Type II; those are ours, not LBMC’s quote.
Request a quote for a scoped number.
How long does an LBMC SOC 2 audit take?
LBMC’s own SOC audit page states report issuance 45–60 days after the observation period ends — that is the fieldwork-to-report window, not the whole engagement. A SOC 2 Type II additionally requires the client’s controls to operate over a 6–12 month observation period before that fieldwork can begin, per LBMC’s stated process.
A Type I, which has no observation period, moves faster: expect discovery, readiness (if used), and fieldwork to run on the order of several weeks rather than months. Total calendar time from kickoff to a Type II report, including the observation window, commonly lands in the 26–52 week range our base data reflects — the audit fieldwork itself is a small fraction of that.
Who is LBMC a good fit for?
Best fit for: - Healthcare, financial services, or PE-backed companies that need SOC 2 alongside HITRUST, ISO 27001, or PCI DSS handled by one accredited team - Organizations that value a firm with two decades of HITRUST tenure (Authorized External Assessor since 2010) for a HITRUST certification or bridge assessment - Mid-market and larger service organizations that want a single
regional firm covering audit, tax, and cybersecurity, not just SOC 2 in isolation - Companies that need PCI DSS ROC/AOC work coordinated with their SOC 2 evidence
Not a fit — look elsewhere if:
- You are an early-stage startup that wants a 2–6 week Type I turnaround and boutique, founder-direct pricing; LBMC’s scale and multi-framework accreditation stack carry regional-firm overhead
- Your immediate need is a formal CMMC Level 2 certification assessment; LBMC’s public materials describe readiness and gap-analysis support, not confirmed C3PAO accreditation to issue the certification itself
- You need FedRAMP or StateRAMP authorization; it is not listed among LBMC’s cybersecurity service pages
- You need same-firm penetration testing bundled into a SOC 2 engagement without an independence conversation first
When should a buyer shortlist LBMC?
LBMC’s SOC 2 practice is best understood through its HITRUST tenure: an Authorized External Assessor since 2010 and, by its own description, the longest-serving assessor in the program’s “10-year club,” backed by PCI QSA status and ISO 27001 audit capability under one roof.
That makes it a strong choice for healthcare, financial-services, or PE-backed organizations that need SOC 2 plus a second or third framework handled without switching firms. It is a licensed CPA firm with a recent, passed AICPA peer review (March 2026, covering mid-2024 through mid-2025). It is not the cheapest or fastest path to a first SOC 2 Type I — that’s a boutique specialist’s game — and buyers whose primary need is a formal CMMC or FedRAMP certification should confirm LBMC’s specific accreditation for that certification before engaging.
Contact & Links
Office Locations
Compliance Frameworks Offered
Industries, certifications, and platforms.
Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.
What Industries Does LBMC Serve?
8 industries. Full-service CPA average: 6.
What Certifications and Accreditations Does LBMC List?
4 accreditations. Full-service CPA average: 2.
What GRC Platforms Does LBMC Work With?
Audit Platform
Proprietary
Questions to Ask LBMC Before Hiring
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
- Your team is sized at 50-150+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
- You quote 26–52 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
- Your Type 2 cost range is $20K–$60K. What's included at each end, and what scope changes would push pricing above the top of that range?
- You integrate with Drata. If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
- Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
- How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
- When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
- Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
LBMC on the verification record
LBMC's registry record was last verified 2026-06-11. Its AICPA peer-review result is Pass, retrieved 2026-06-11.
See the verification record · Is this your firm? Get your badge.
Get a quote from LBMC
Tell us your scope. LBMC replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? Browse All Auditors or get 3–10 quotes.
Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify LBMC's profile →