Securance
- Issues SOC 2 reports
Securance is a assurance specialist SOC 2 audit firm in Leiden, Netherlands, Netherlands. Its estimated SOC 2 Type II audit price is $30,000–$80,000; fieldwork to report takes 4–14 weeks.
Independent profile, researched and maintained by this directory from public sources. Securance has not reviewed or verified this page. Work at Securance? Verify and correct it — free →
Free. Anonymous until you pick.
How Much Does Securance Charge for SOC 2?
Securance's estimated SOC 2 Type II audit price is $30,000–$80,000; fieldwork to report takes 4–14 weeks.
- Type 1 cost
- $20K–$60K
- Type 2 cost
- $30K–$80K
- Timeline
- 4–14 wk
- Team Size
- 30-60+
- Report Delivery
- Standard delivery
- Response Time
- Single point of contact model
Type 2 cost Pricing Position
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
Timeline: The 4–14 week figure is the audit fieldwork-to-report window once evidence is ready, not the full engagement. A SOC 2 Type II also requires an observation period, typically 3–12 months depending on scope, before that window begins.
How this directory works: firms can pay a flat fee for labeled placement on our lists; we take no cut of audit fees. Our methodology →
- Pricing context
- 9%
- Timeline context
- 26%
- Accreditations
- 5
of Assurance specialist firms charge more for Type II.
of Assurance specialist firms have longer minimum timelines.
itemized accreditations. Organization-group average: 4.
Source: soc2auditors.org/auditors/securance/ · compiled and maintained by soc2auditors.org.
Compare Securance with Similar Assurance specialist Firms
Side-by-side pricing, timeline, and itemized accreditation counts for the closest-priced peers in the assurance specialist organization group. Firm-reported certification totals stay outside this comparison because they are not the same measure.
| Securance | Accorp Partners | CertPro | eDelta Consulting | TrustNet | VISTA InfoSec | |
|---|---|---|---|---|---|---|
| Type II Cost | $30K–$80K | $30K–$80K | $30K–$80K | $30K–$80K | $30K–$80K | $30K–$80K |
| Type I Cost | $20K–$60K | $20K–$60K | $20K–$60K | $20K–$60K | $20K–$60K | $20K–$60K |
| Timeline | 4–14 wk | 13–26 wk | 6–12 wk | 6–12 wk | 6–12 wk | 6–12 wk |
| Team Size | 30-60+ | 115–1000 | 50–249 | 100–1000 | 100–1000 | 100–1000 |
| Itemized Accreditations | 5 | 6 | 5 | 3 | 1 | 4 |
| Founded | 2004 | 1991 | 2012 | 2000 | 2003 | 2004 |
Securance Industry Fit
For buyers in Financial Services and Technology, Securance fits the assurance specialist profile when its 4–14 weeks timeline and Type II pricing ($30K–$80K) align with the buyer's scope. Their 5 active accreditations, including ISAE 3402, ISAE 3000, ISO 27001, extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
Who Should Hire Securance?
European financial-services and insurance teams coordinating ISAE, ISO 27001, NIS2, DORA, and SOC-related work.
What Makes Securance Different?
Combines European reporting standards in one engagement; US buyers should confirm whether its SOC 2 output meets their required AICPA standard.
Is Securance Right for You?
- You're in financial services with regulatory audit requirements
- You already use Drata and want an auditor who integrates with it
- You want a firm whose practice centers on SOC 2 and information assurance
of 3 criteria match. Get a personalized quote
Industries served
Works with these GRC platforms
Who is Securance?
Securance is a Netherlands-headquartered assurance, advisory, and cybersecurity firm founded in 2004, with a team of roughly 30-60 professionals and offices in Leiderdorp and Utrecht (Netherlands), London, Berlin, and Uppsala.
It serves financial services, technology, professional services, and insurance clients across Europe who need SOC-style attestation, ISAE reporting, or ISO 27001 certification support, often alongside penetration testing and GRC advisory from the same firm.
Securance markets a “Single Audit, Multiple Standards” model: one engagement mapped to cover SOC 1, SOC 2, ISAE 3402, ISO 27001, NIS2, and DORA requirements at once, reducing duplicate evidence requests for clients that need more than one framework. Named clients referenced in its published case studies include ABN AMRO Asset Management, Fujitsu, Axians, a.s.r. (ASR), and Planday.
How does Securance issue a SOC 2 report?
Securance describes itself on its own site as “Europe’s leading issuer” of SOC 2 reports and offers “a SOC 2 report from a European issuer.” A genuine AICPA SOC 2 attestation, by definition, must be issued by a CPA firm licensed and enrolled in the AICPA structure (including the AICPA Peer Review Program).
Securance’s public materials do not name a specific U.S. or AICPA-licensed CPA entity behind its SOC 2 work, do not cite an AICPA Peer Review Program record, and describe the underlying methodology as built on ISAE 3402/ISAE 3000 (the European assurance standards) rather than U.S. attestation standards (SSAE 18/AT-C 105/205).
The practical read: Securance most likely delivers a European ISAE-based assurance report that maps to and is marketed under the SOC 2 label, not a literal AICPA-attested SOC 2 report signed by a licensed U.S. CPA firm. For most European buyers and their European counterparties this distinction may not matter — ISAE 3000 is a recognized, credible international standard. But a buyer selling into the U.S. market whose enterprise customers specifically require an AICPA SOC 2 report should confirm directly with Securance, in writing, exactly which standard the final report is issued under and whether a licensed CPA firm signs it, before assuming it will satisfy a U.S. vendor-security questionnaire.
What credentials does Securance actually hold?
Securance’s credibility case rests on its European assurance standards accreditations (ISAE 3402, ISAE 3000) and ISO 27001 certification work, plus a leadership team with Big Four backgrounds. The firm states its roots trace to one of the Big Four and that many team members previously worked there.
We found no independently verifiable AICPA Peer Review Program record for Securance (or a named affiliated CPA entity) on the AICPA’s public peer review file search — buyers who need that specific proof point should ask Securance directly for it rather than assume it exists. Izak van der Walt is listed on the team as a Chartered Accountant; the firm does not publish individual CPA license numbers or jurisdictions on its site.
What SOC reports does Securance issue?
Securance runs a six-phase SOC 2 process: impact analysis/gap analysis, process and control interviews, a control framework built on COSO 2013, drafting the SOC 2 report, a pre-audit “walkthrough,” and a remediation phase before the final report is issued.
It offers both Type I (point-in-time design opinion) and Type II (minimum six-month operating-effectiveness window) reports — note that six months is Securance’s stated minimum observation period, longer than the roughly 3-month window some U.S.-style engagements use at the low end.
SOC 1 is offered for organizations whose services affect a client’s financial reporting, alongside ISAE 3402 (the ISAE 3402 is functionally the ISAE alternative to SOC 1 that most European service organizations actually need). ISAE 3000 is used for broader non-financial assurance engagements, including sustainability and other subject matter beyond SOC scope.
Does Securance cover ISO 27001, NIS2, and DORA?
Securance is positioned to run ISO 27001 (and ISO 9001) certification-support work alongside its assurance practice, and offers NIS2 and DORA advisory services — gap analysis, incident-management design, and resilience testing — for EU financial institutions and critical-sector organizations navigating those directives.
NIS2 and DORA work here is advisory and readiness-focused, not a certification or attestation in the way SOC 2 or ISO 27001 are; buyers should not expect a signed NIS2/DORA “report” in the same sense as a SOC 2 report.
Does Securance also sell penetration testing?
Securance runs its own cybersecurity practice — network and application penetration testing, cloud security assessments, red teaming, ransomware vulnerability assessment, and phishing testing — as one of the three pillars it bundles under “Advisory, Assurance and Cyber Security under one roof.”
That bundling is exactly the case where independence needs a second look. If Securance’s assurance team is going to issue your SOC 2 or ISAE report, having that same firm’s cybersecurity team run your penetration test creates a self-review consideration: the auditor ends up forming an opinion on controls that its own colleagues tested and potentially remediated. The cleaner posture is to have the pen test performed by a different provider than whoever signs your assurance report — or, at minimum, to confirm with Securance in writing that the assurance and cybersecurity engagement teams (and sign-off) are kept structurally separate on your account before treating the “one-stop-shop” pitch as a single bundled service.
Which frameworks does Securance cover?
Securance does not list HITRUST, FedRAMP, StateRAMP, CMMC, or PCI QSA in its published catalog. It is a European SOC/ISAE/ISO/NIS2/DORA and pentest shop, not a U.S. government-framework specialist.
How much does a Securance SOC 2 audit cost?
We were not able to find published pricing on Securance’s site — like most assurance firms, it quotes after a scoping call. Based on comparable European assurance engagements of this scope and size, our directional estimate is $20,000-$60,000 for a Type I report and $30,000-$80,000 for a Type II report.
This is our estimate, not a number confirmed by Securance, and it will move with headcount, systems in scope, and how many standards are bundled into the single-audit engagement.
How long does a Securance SOC 2 audit take?
Securance’s own SOC 2 phase description (impact analysis through pre-audit and redressing) plus its FAQ noting the readiness scan alone takes “several weeks” suggests a 4-14 week fieldwork-to-report window for a Type I, which is our directional estimate absent a published SLA.
A Type II report additionally requires an observation period — Securance states a six-month minimum, longer than the roughly 3-month window some other markets use at the low end — before the report can be finalized, so buyers on a Type II track should plan total calendar time (observation window plus fieldwork) well beyond the fieldwork estimate alone.
Who is Securance a good fit for?
Best fit for: - European financial services, fintech, insurance, and technology companies that need SOC 1/SOC 2, ISAE 3402/3000, or ISO 27001 handled by one firm under a European (not U.S.-only) assurance framework - Companies that need NIS2 or DORA advisory work alongside their assurance engagement - Buyers comfortable with — or requiring — a European ISAE-based issuer rather than
specifically a U.S. AICPA-licensed CPA firm - Organizations wanting penetration testing, red teaming, and assurance available from a single vendor (with independence properly scoped)
Not a fit — look elsewhere if:
- You specifically need a U.S. AICPA-attested SOC 2 report signed by a licensed CPA firm with a documented AICPA Peer Review record, and your enterprise customer will check for that
- You need HITRUST, FedRAMP, StateRAMP, CMMC, or PCI DSS QSA work
- You want penetration testing and your SOC 2 audit performed by fully separate, unaffiliated firms without having to raise the question yourself
When should a buyer shortlist Securance?
Securance is a Netherlands-founded (2004) assurance, advisory, and cybersecurity firm that bundles SOC 1/SOC 2, ISAE 3402/3000, ISO 27001, and NIS2/DORA advisory under one roof for European buyers, with named case-study clients including ABN AMRO Asset Management, Fujitsu, Axians, ASR, and Planday.
The open question buyers should resolve before engaging is precisely how its “SOC 2” report is issued — as a European ISAE-based report marketed under the SOC 2 label, versus a report from a licensed AICPA CPA firm — since we found no AICPA Peer Review Program record or named CPA entity on its public materials. If your target customer is fine with a European-issued assurance report, Securance’s single-audit, multi-standard model is a genuine efficiency play; if your buyer specifically requires an AICPA-attested SOC 2, confirm that in writing before signing an engagement letter.
Contact & Links
Office Locations
Compliance Frameworks Offered
Industries, certifications, and platforms.
Tags below are preserved as crawlable text because they drive industry, accreditation, and GRC-platform comparisons across firm pages.
What Industries Does Securance Serve?
4 industries. Assurance specialist average: 6.
What Certifications and Accreditations Does Securance List?
5 accreditations. Assurance specialist average: 4.
What GRC Platforms Does Securance Work With?
Audit Platform
Proprietary
Questions to Ask Securance Before Hiring
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
- Your team is sized at 30-60+. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
- You quote 4–14 weeks. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
- Your Type 2 cost range is $30K–$80K. What's included at each end, and what scope changes would push pricing above the top of that range?
- You integrate with Drata. If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
- Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
- How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
- When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
- Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?
Securance on the verification record
Securance's verification record lists the facts and dates we last checked. It can be refreshed on the firm's request.
See the verification record · Is this your firm? Get your badge.
Get a quote from Securance
Tell us your scope. Securance replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? Browse All Auditors or get 3–10 quotes.
Run an audit firm? See how firms get found and shortlisted here — how it works → / Verify Securance's profile →