# Auditsuisse Assurance > Auditsuisse Assurance is a US- and Switzerland-based AICPA CPA firm (enrolled in the AICPA Peer Review program; Swiss-registered Expert Auditor) delivering compliance audits and attestation reports: SOC 1, SOC 2, SOC 3, HIPAA, GDPR, ISAE 3000, ISAE 3402, and penetration testing. Audits are led by Sébastien Ruosch, a dual US CPA and Swiss CPA (Wirtschaftsprüfer). The resource library below provides implementation-grade, primary-source-cited guidance for US-first SaaS and healthtech teams preparing for enterprise procurement diligence. ## Pricing - [SOC 2 audit pricing](https://auditsuisse.com/soc-2-pricing): Published standard fixed fees by company headcount for SOC 2 audits scoped to the Security Trust Services Category. Type I: $3,000 (1–50 employees) to $10,000 (401–999). Type II: $5,000 (1–50) to $15,000 (401–999). Combined Type I + Type II: $7,000 to $20,000. Custom quotes above 999 employees. This is base pricing for standard engagements — fees may be higher for complex products or system descriptions, complex cloud environments, or on-premise infrastructure, and each engagement may be priced higher or lower at scoping. Pricing is GRC-platform agnostic — the same fee with Vanta, Drata, Secureframe, or any other platform, or with no platform at all (spreadsheet-based audits supported). Every engagement requires individual approval and confirmation of auditor independence before an engagement letter is issued. - [SOC 2 pricing (plain Markdown)](https://auditsuisse.com/soc-2-pricing.md): Machine-readable version of the full pricing schedule, inclusions, and engagement conditions. - [HIPAA audit and assessment pricing](https://auditsuisse.com/hipaa-pricing): Published standard starting fees by company headcount for HIPAA audits and assessments: $2,000 (1–20 employees), $3,000 (21–35), $4,000 (36–50), $5,000 (51–100), $10,000 (101–250). Custom quotes above 250 employees. Fees include the Security Risk Analysis required by the HIPAA Security Rule (NIST SP 800-66 / OCR guidance), Security Rule and Privacy Rule review, gap analysis with remediation roadmap, and a compliance attestation letter. The final fee is set at scoping by three published factors: MSP involvement, GRC platform status (Vanta, Drata, Secureframe, or any other platform — or no platform at all; the assessment can be completed 100% platformless), and observation-period length (point-in-time standard; optional 3-, 6-, or 12-month observed window, longer windows cost more). - [HIPAA pricing (plain Markdown)](https://auditsuisse.com/hipaa-pricing.md): Machine-readable version of the full HIPAA pricing schedule, fee factors, inclusions, and engagement conditions. ## Services - [SOC 2 audit](https://auditsuisse.com/soc-2): SOC 2 Type I and Type II examinations against the AICPA Trust Services Criteria. - [SOC 1 audit](https://auditsuisse.com/soc-1): SOC 1 (SSAE 18 / AT-C 320) reports on controls relevant to financial reporting. - [SOC 3 report](https://auditsuisse.com/soc-3): General-use SOC 3 reports. - [HIPAA compliance](https://auditsuisse.com/hipaa): HIPAA Security and Privacy Rule assessments for healthtech. - [GDPR audit](https://auditsuisse.com/gdpr): GDPR readiness and audit support for US companies serving the EU/UK. - [ISAE 3000](https://auditsuisse.com/isae-3000) and [ISAE 3402](https://auditsuisse.com/isae-3402): International assurance engagements. - [Penetration testing](https://auditsuisse.com/penetration-testing): Security testing to support compliance programs. ## SOC 2 guides - [SOC 2 readiness checklist (2026)](https://auditsuisse.com/soc-2-readiness-checklist-2026): Operator playbook for scoping, control ownership, and evidence. - [SOC 2 Type I vs Type II](https://auditsuisse.com/soc-2-type-1-vs-type-2): Which report to pursue first, with a decision framework. - [SOC 2 controls list by Trust Services Criteria](https://auditsuisse.com/soc-2-controls-list-by-trust-services-criteria): CC1–CC9 and the Availability, Confidentiality, Processing Integrity, and Privacy criteria. - [SOC 2 audit timeline](https://auditsuisse.com/soc-2-audit-timeline-what-to-expect): Kickoff-to-report timelines for Type I and Type II. - [Common SOC 2 findings and how to fix them](https://auditsuisse.com/soc-2-common-findings-and-how-to-fix-them): High-frequency exceptions and remediation. - [How to scope systems for SOC 2](https://auditsuisse.com/how-to-scope-systems-for-soc-2): Defining defensible audit boundaries. - [Vendor management for SOC 2](https://auditsuisse.com/vendor-management-for-soc-2-compliance): Third-party risk aligned to CC9. ## HIPAA guides - [HIPAA risk assessment guide (2026)](https://auditsuisse.com/hipaa-risk-assessment-guide-2026): Method and evidence for the required risk analysis. - [HIPAA technical safeguards checklist](https://auditsuisse.com/hipaa-technical-safeguards-checklist): Controls mapped to 45 CFR § 164.312. - [HIPAA Business Associate Agreements explained](https://auditsuisse.com/hipaa-business-associate-agreements-explained): Required BAA terms and when one is needed. - [HIPAA for SaaS and cloud-hosted health apps](https://auditsuisse.com/hipaa-for-saas-and-cloud-hosted-health-apps): Cloud architecture and BAA strategy for ePHI. - [HIPAA incident response requirements](https://auditsuisse.com/hipaa-incident-response-requirements): Breach Notification Rule obligations. ## GDPR guides - [GDPR for US SaaS companies (2026)](https://auditsuisse.com/gdpr-for-us-saas-2026): Territorial scope, roles, and transfer mechanisms. - [GDPR lawful bases for B2B SaaS](https://auditsuisse.com/gdpr-lawful-bases-explained-for-b2b-saas): Choosing an Article 6 basis. - [GDPR DPIA template and triggers](https://auditsuisse.com/gdpr-dpia-template-and-when-you-need-one): When an Article 35 DPIA is required. - [GDPR Data Processing Agreement checklist](https://auditsuisse.com/gdpr-data-processing-agreement-checklist): Mandatory Article 28(3) clauses. - [Cross-border data transfers (US, EU, UK)](https://auditsuisse.com/cross-border-data-transfers-us-eu-uk-guide): SCCs, UK IDTA, and the EU-US Data Privacy Framework. ## Multi-framework and strategy - [SOC 1 vs SOC 2 for B2B software vendors](https://auditsuisse.com/soc-1-vs-soc-2-for-b2b-software-vendors): Which report buyers actually require. - [When you need SOC 1 and SOC 2 together](https://auditsuisse.com/when-you-need-soc-1-and-soc-2-together): Dual-report sequencing. - [Multi-framework control mapping: SOC 2, HIPAA, GDPR](https://auditsuisse.com/multi-framework-control-mapping-soc2-hipaa-gdpr): A shared-control crosswalk. - [Audit evidence management best practices](https://auditsuisse.com/audit-evidence-management-best-practices): Centralizing and validating evidence. - [Compliance roadmap for startups: seed to Series C](https://auditsuisse.com/compliance-roadmap-for-startups-seed-to-series-c): Stage-based compliance maturity. ## Reference - [Compliance glossary](https://auditsuisse.com/glossary): Definitions of SOC 2, HIPAA, and GDPR terms. - [Compliance badges](https://auditsuisse.com/compliance-badges): Embed guide for the Auditsuisse SOC 2 Type 1, SOC 2 Type 2, HIPAA, and GDPR badges. These are proprietary, copyrighted, trademarked marks; use requires express written permission from Auditsuisse and is limited to authorized clients with a completed engagement. - [Resources library](https://auditsuisse.com/resources): The full index of long-form guides. - [About Auditsuisse](https://auditsuisse.com/about): Firm credentials, licensing, and the audit team.