Katz, Sapper & Miller (KSM)
Employee-owned Indiana CPA firm with a dedicated IT risk advisory team issuing the full SOC report suite.
Overview
Katz, Sapper & Miller is a licensed, employee-owned accounting and advisory firm founded in 1942 and headquartered in Indianapolis, with additional offices across the Midwest and New York. Its IT Risk Advisory practice performs SOC 1, SOC 2 (Type 1 and Type 2), SOC 3, SOC for Cybersecurity, and SOC for Supply Chain examinations. As an established multi-office CPA firm, it issues SOC reports as the licensed practitioner.
Strengths
- ✓Long-established licensed CPA firm (since 1942) with multi-state footprint
- ✓Covers the complete SOC reporting suite (SOC 1/2/3, Cybersecurity, Supply Chain)
- ✓Dedicated named IT Risk Advisory directors leading SOC engagements
Consider
- •SOC page does not list adjacent frameworks like ISO 27001 or HIPAA, so those may require separate engagement
- •Broad full-service firm rather than a SOC-only specialist
Frameworks covered
Regions served
Pricing and timeline in context
Founded in 1942 and based in Indianapolis, IN, Katz, Sapper & Miller (KSM) quotes SOC 2 work in the $18K–$90K band — in line with the national firm median of $18K–$90K across the firms we track. As an AICPA-licensed CPA firm it issues SOC 1, SOC 2 Type 1, and SOC 2 Type 2 reports directly, and the fee scales with your headcount, the Trust Services Criteria in scope, and any frameworks you bundle. Plan for roughly 8–22 weeks on a Type 2 engagement. Compare it against the full SOC 2 audit cost benchmark before you commit.
Who Katz, Sapper & Miller (KSM) is for
Katz, Sapper & Miller (KSM) works most often with SaaS and Fintech companies. Scale-ups and mid-market companies that want experienced, credible coverage without Big Four pricing are the typical fit.
Frequently asked questions
How much does a Katz, Sapper & Miller (KSM) SOC 2 audit cost?
Katz, Sapper & Miller (KSM)'s SOC 2 engagements typically run $18K–$90K, depending on your headcount, the Trust Services Criteria in scope, and how many frameworks you bundle. Because no firm publishes fixed pricing, request a scoped quote — you can get three matched quotes on identical scope to compare.
How long does a Katz, Sapper & Miller (KSM) SOC 2 audit take?
A typical Type 2 engagement with Katz, Sapper & Miller (KSM) takes about 8–22 weeks from kickoff to report, plus the observation window itself. Use the timeline calculator to estimate your own schedule.
What frameworks does Katz, Sapper & Miller (KSM) cover?
Katz, Sapper & Miller (KSM) covers SOC 1, SOC 2 Type 1, and SOC 2 Type 2. If you need several of these, bundling them into one engagement is usually cheaper than auditing each separately.
Is Katz, Sapper & Miller (KSM) an AICPA-licensed CPA firm?
Yes. Katz, Sapper & Miller (KSM) is an AICPA-licensed CPA firm, which is a requirement to issue a SOC 2 report — only licensed CPA firms can. It's worth confirming a firm's AICPA peer-review status before signing; see questions to ask a SOC 2 auditor.
Where does Katz, Sapper & Miller (KSM) operate?
Katz, Sapper & Miller (KSM) is headquartered in Indianapolis, IN and serves clients across United States. SOC 2 is a US attestation standard, so a US-licensed firm can serve clients wherever they are based.
Are you Katz, Sapper & Miller (KSM)? Add your badge
Show clients you're listed in an independent SOC 2 directory. Paste this into your site to display the badge, linked to this profile:
<a href="https://soc2-auditors.com/auditors/katz-sapper-and-miller?utm_source=badge&utm_medium=referral">
<img src="https://soc2-auditors.com/badge/listed-soc2-auditors.svg" alt="Listed on SOC 2 Auditors — Katz, Sapper & Miller (KSM)" width="220" height="60" />
</a>Firms similar to Katz, Sapper & Miller (KSM)
Other national firm SOC 2 auditors with overlapping industry focus. Compare their pricing and fit, or get three matched quotes on identical scope.
Top-tier independent assessor combining a licensed CPA firm with ISO, PCI, FedRAMP, and HITRUST accreditations.
Global compliance and cybersecurity firm serving as a licensed SOC auditor and multi-framework assessor.
Cloud-focused security and compliance CPA firm serving regulated, high-value-data organizations.
Licensed CPA firm offering SOC, PCI, ISO, HIPAA, and penetration testing across US offices.