I.S. Partners
I.S. Partners is a U.S. public accounting firm providing SOC audits, CMMC, HITRUST, ISO 27001, and cybersecurity compliance assessments to regulated organizations in government contracting, healthcare, financial services, and SaaS, now operating as part of Axiom GRC.
- Company typePrivate
- Founded2004
- HeadquartersDresher, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What I.S. Partners does
I.S. Partners (IS Partners, LLC) is a U.S.-headquartered public accounting and cyber assurance firm founded in 2004, operating from Dresher, Pennsylvania with a London office. The firm provides IT audit and security compliance services to regulated organizations across four primary verticals — government contracting, healthcare, financial services, and SaaS/technology — supplemented by secondary coverage of energy, insurance, manufacturing, and telecommunications. The core offering is a portfolio of SOC attestation services (SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, SOC for Supply Chain) alongside specialized frameworks including CMMC (as an Authorized C3PAO), HITRUST, HIPAA, ISO 27001 (now ANAB-accredited to issue certifications directly), ISO 42001, NIST 800-53 and NIST AI RMF, PCI DSS, GDPR, CCPA, NYDFS, FISMA, MAR/SOX, and CSA STAR. Adjacent services include penetration testing, cloud security assessments, virtual CISO, outsourced DPO, internal audit outsourcing, and eLearning compliance training.
The firm's underlying technology stack is deliberately lean: engagements are delivered using the FieldGuide audit management platform (provided free to clients), with integrations into Drata and Vanta for clients running compliance automation tools. The core intellectual property is a proprietary compliance methodology refined over 20+ years that emphasizes multi-framework control reuse — the firm claims 30%+ of SOC 1 controls can be leveraged from an existing SOC 2 — and drives annual client maintenance burden down to roughly 10–12 hours post-initial audit. The firm also offers Corestream GRC, a governance/risk/compliance software product, though service delivery rather than software licensing is the dominant revenue stream.
I.S. Partners generates revenue exclusively through professional services on a quote-based, engagement-by-engagement model. Pricing varies by audit type, organizational complexity, and scope; disclosed ranges include $20K–$60K for SOC for Cybersecurity, $30K–$60K for SOC 3 standalone, and $20K–$100K for SOC for Supply Chain, with multi-framework programs materially higher. The go-to-market is direct enterprise field sales supplemented by inside-sales inbound driven by free consultations, self-assessment tools, a cybersecurity newsletter reaching 10,000+ subscribers, content marketing, and industry events. In November 2025 the firm was acquired by Axiom GRC as the platform's first U.S. acquisition, and in February 2026 it secured ANAB accreditation to issue ISO/IEC 27001 certifications, both of which materially expand its addressable market and competitive positioning.
I.S. Partners firmographics
Firmographics- Name
- I.S. Partners
- Legal name
- IS Partners, LLC
- Website
- https://ispartnersllc.com
- Company type
- Private
- Founded year
- 2004
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- I.S. Partners is a U.S. public accounting firm providing SOC audits, CMMC, HITRUST, ISO 27001, and cybersecurity compliance assessments to regulated organizations in government contracting, healthcare, financial services, and SaaS, now operating as part of Axiom GRC.
- Ownership category
- akta.pro rank
I.S. Partners industry classification
Industry- Product category
- IT Audit and Compliance Services
- NAICS
- Offices of Certified Public Accountants (541211), Management, Scientific, and Technical Consulting Services (5416)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance (BPAEAPAG), Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI)
Keywords
Where I.S. Partners is headquartered
LocationHeadquarters
- HQ city
- Dresher
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
I.S. Partners business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Technology or R&D, Operations, Others
Revenue model
- Compliance Audit Services: Professional services revenue from conducting compliance audits including SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain examinations. Fees based on time required by auditors and scope of engagement.
- Assessment and Advisory Services: Readiness assessments, gap analyses, and remediation advisory services for frameworks including CMMC, HITRUST, ISO 27001, HIPAA, PCI DSS, NIST, and privacy regulations (GDPR, CCPA, NYDFS).
- CMMC Certification Services: As an Authorized C3PAO, providing CMMC Level 2 cybersecurity assessments for defense contractors. Separate from advisory services due to conflict of interest rules.
- Penetration Testing Services: Security testing services including network penetration testing, web application scanning, mobile application testing, and social engineering audits.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Annual | SOC for Cybersecurity examination - $20,000 to $60,000 |
| Other | Annual | SOC 3 standalone report - $30,000 to $60,000 |
| Other | Annual | SOC for Supply Chain audit - $20,000 to $100,000 |
| Other | Annual | SOC 2 audit - variable pricing |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
I.S. Partners product offering
Product offeringCore offering
I.S. Partners is a U.S.-based public accounting firm that delivers IT audit, cybersecurity, and compliance certification services. Its core offerings include SOC examinations (SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, SOC for Supply Chain), readiness assessments, and certification audits for frameworks such as CMMC, HITRUST, HIPAA, ISO 27001, ISO 42001, NIST, PCI DSS, GDPR, and other regulatory regimes. The firm complements these services with penetration testing, cloud security assessments, internal audit outsourcing, virtual CISO advisory, and a proprietary GRC software product (Corestream GRC).
Product overview
I.S. Partners is a compliance and cybersecurity audit services provider offering a comprehensive portfolio of assessment and certification services. The core offering is a suite of SOC audit services (SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, SOC for Vendor Supply Chain) supplemented by specialized compliance frameworks including CMMC (as an Authorized C3PAO), HITRUST, HIPAA, ISO 27001, ISO 42001, NIST frameworks (800-53, AI RMF), PCI DSS, and privacy regulations (GDPR, CCPA, NYDFS). The company also offers penetration testing services, cloud security assessments, and virtual CISO services. In November 2025, IS Partners was acquired by Axiom GRC to expand Axiom's North American presence. The company operates alongside a proprietary GRC software product called Corestream GRC, and integrates with platforms like Drata, Vanta, and FieldGuide for compliance management.
Differentiator
Problem solved
Functional benefit
Brands
- Corestream GRC: A GRC software product offered by IS Partners for compliance management.
Products and services
- SOC 1 SOC 1 audit services evaluating service organization controls relevant to user entity internal control over financial reporting, available as Type I or Type II reports.
- SOC 2 Readiness Assessment Pre-audit assessment evaluating an organization's readiness for SOC 2 compliance, identifying control gaps and providing a remediation roadmap.
- SOC 2 SOC 2 audit services assessing controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy), available as Type I or Type II reports.
- SOC 3 Public-facing SOC 3 reports providing general-use attestation of security, availability, confidentiality, processing integrity, and privacy controls.
- SOC for Cybersecurity Entity-wide cybersecurity risk management program assessment following AICPA standards, providing comprehensive evaluation of cybersecurity controls.
- SOC for Vendor Supply Chain Supply chain-focused SOC examination for producers, manufacturers, and distributors evaluating controls over production, manufacturing, or distribution systems.
- CMMC Compliance Services Cybersecurity Maturity Model Certification (CMMC) compliance and assessment services as an Authorized C3PAO, helping defense contractors achieve certification for DoD contracts.
- HITRUST CSF Certification HITRUST CSF certification services for healthcare organizations providing globally recognized security framework assessment and certification.
- HIPAA Compliance
Quantifiable outcome
- Clients spend only 10-12 hours annually on average on audit maintenance after initial SOC 1 audit
- +3 more outcomes
Companies that use I.S. Partners
Customer profileNamed customers7 records
Segments9 records
Ideal customer profiles4 records
I.S. Partners technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
Feature3 records
I.S. Partners partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Axiom GRCcoreAxiom GRC, a governance, risk, and compliance platform, acquired IS Partners to strengthen its North American presence and support international expansion. This marks Axiom's first U.S.-based acquisition as part of its strategy to build a leading global GRC platform. The acquisition enables Axiom to expand its offerings in cyber assurance, compliance, and resilience services across its client base.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
I.S. Partners competitors and assessment
Company assessmentBroad incumbents
- KPMG: KPMG's advisory practice includes IT assurance, SOC, ISO, CMMC and cybersecurity risk services competing for similar enterprise and government contractor clients. A broader incumbent alternative to IS Partners.
- Deloitte: Deloitte's Risk & Financial Advisory practice offers SOC, ISO, CMMC, HITRUST and cybersecurity compliance services at global scale. Represents a broader incumbent alternative for enterprise clients considering IS Partners.
- EY: EY's cybersecurity and risk practice delivers SOC, ISO, CMMC and IT audit services as part of a broader assurance portfolio. Competes with IS Partners for large enterprise and regulated-industry engagements.
- Coalfire: Coalfire is a larger, well-established cybersecurity advisory and assessment firm offering cloud security, compliance (SOC, ISO, HITRUST, FedRAMP, CMMC) and penetration testing. Overlaps heavily with IS Partners but operates at broader scale and enterprise tier.
Direct peers
- A-LIGN: A-LIGN is a similarly sized cybersecurity compliance and audit firm offering SOC, ISO 27001, HITRUST, CMMC and penetration testing services to mid-market and enterprise clients. It is one of the closest direct competitors to IS Partners in the IT audit and GRC services market.
- 360 Advanced: 360 Advanced provides cybersecurity compliance and IT audit services including SOC, ISO 27001, HITRUST and penetration testing. Comparable in scope, scale and vertical mix to IS Partners, particularly across SaaS and regulated industries.
- Linford & Co: Linford & Co is a CPA firm specializing in SOC 1, SOC 2, HITRUST, HIPAA and penetration testing for SaaS and technology clients. Directly comparable service catalog and similar target market to IS Partners.
- BARR Advisory: BARR Advisory is a cybersecurity compliance and IT audit firm delivering SOC, ISO 27001, HITRUST, PCI and FedRAMP services to SaaS and technology companies. Closely comparable in size, framework coverage, and mid-market customer focus.
- Schellman: Schellman is a leading IT audit and compliance firm specializing in SOC, ISO 27001, HITRUST, PCI and FedRAMP assessments. Highly comparable to IS Partners in service mix, accreditation breadth, and target customer profile.
Emerging players
- Drata: Drata is a compliance automation platform for SOC 2, ISO 27001, HIPAA and other frameworks with an integrated auditor marketplace. Represents an emerging software-first model that competes with and integrates alongside IS Partners' traditional audit services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
I.S. Partners social profiles
Digital presenceI.S. Partners compliance and trust
Trust signalCompliance10 records
I.S. Partners financial estimates
Financial estimateRevenue estimate
Valuation estimate
I.S. Partners leadership team
Management profileNumber of profiles
I.S. Partners funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
I.S. Partners M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about I.S. Partners
What does I.S. Partners do?
I.S. Partners is a U.S.-based public accounting firm that delivers IT audit, cybersecurity, and compliance certification services. Its core offerings include SOC examinations (SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, SOC for Supply Chain), readiness assessments, and certification audits for frameworks such as CMMC, HITRUST, HIPAA, ISO 27001, ISO 42001, NIST, PCI DSS, GDPR, and other regulatory regimes. The firm complements these services with penetration testing, cloud security assessments, internal audit outsourcing, virtual CISO advisory, and a proprietary GRC software product (Corestream GRC).
Is I.S. Partners a public or private company?
I.S. Partners is a private company. It is classified as corporate owned and is currently acquired.
When was I.S. Partners founded?
I.S. Partners was founded in 2004. It employs 11 to 50 people.
Where is I.S. Partners based?
I.S. Partners is headquartered in Dresher, United States, in the North America region.
How does I.S. Partners make money?
Four revenue lines are on record. Compliance Audit Services are the primary driver. The others are assessment and Advisory Services, CMMC Certification Services and penetration Testing Services.
Who are I.S. Partners's main competitors?
Broad incumbents on record are KPMG, Deloitte, EY and Coalfire. Direct peers are A-LIGN, 360 Advanced, Linford & Co, BARR Advisory and Schellman. Drata is listed as an emerging player.
Does I.S. Partners have an API?
No public API is recorded for I.S. Partners.
What industry is I.S. Partners in?
I.S. Partners's product category is IT Audit and Compliance Services. Its primary akta.pro industry code is BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 541211 and its SIC code is 8742.