Back to Blog

CaseWare, Suralink, Fieldguide, Thoropass: How the Cyber-Attest Software Stack Actually Compares in 2026

Five categories of cyber-attest platform, each with a distinct buyer profile. The category-by-category comparison — legacy workpaper (CaseWare, TeamMate+), PBC specialist (Suralink), AI-native workflow (Fieldguide), bundled auditor+platform (Thoropass, A-LIGN A-SCEND), and independent audit-firm substrate (vCISO Lite for Auditors) — plus the flat requirement-by-requirement table.

Quick Answer

Five categories of cyber-attest platform, each with a distinct buyer profile. The category-by-category comparison — legacy workpaper (CaseWare, TeamMate+), PBC specialist (Suralink), AI-native workflow (Fieldguide), bundled auditor+platform (Thoropass, A-LIGN A-SCEND), and independent audit-firm substrate (vCISO Lite for Auditors) — plus the flat requirement-by-requirement table.

The cyber-attest software market has consolidated into five distinct categories of platform, and the fit for a specific audit-firm practice depends less on which vendor is "best" and more on which category matches the practice's positioning. A SOC 2 shop running 200 engagements a year has different needs from a boutique running 12 recurring clients across three frameworks, and both have different needs from a mid-sized firm running SOC 2, ISO 27001, PCI DSS, and HITRUST across a 40-engagement book. This is the honest comparison, category by category, with the specific fit criteria that determine which is the right choice.

Nothing about this piece is a pure product pitch — vCISO Lite for Auditors sits in one of the five categories, is compared alongside the alternatives, and the fit criteria are the ones a rational practice would apply regardless of which vendor is on the page.

5 categories
of cyber-attest platform: legacy workpaper, PBC/portal specialist, AI-native workflow, bundled auditor+platform, and independent audit-firm substrate — each with distinct fit criteria
60-100 hours
typical margin delta per SOC 2 II engagement between the framework-silo model and the unified-console model — the size of the tooling decision
2 axes
the choice among the 5 categories reduces to 2 axes — independence architecture (does the platform vendor also audit?) and cross-framework primitive (does the tool treat a multi-framework client as one book?). Get these right and the vendor selection inside the category is a smaller decision.

Category 1: Legacy workpaper platforms — CaseWare, Wolters Kluwer CCH Axcess, Thomson Reuters AdvanceFlow, TeamMate+

The category that predates cyber attest and was retrofitted into it. These are financial-audit workpaper systems with deep support for the traditional audit workflow — trial balance integration, tax-adjacent workpaper structures, review-note threads, sign-off hierarchies. The cyber-attest layer is either an add-on module, a template library, or a workflow customization the firm builds itself.

Strengths

Deep workpaper structure. Mature review-note and sign-off hierarchies. Established peer-review posture — these platforms have been through many inspection cycles, and the workpaper shape peer reviewers expect matches what the platform produces. Strong retention and archival guarantees.

Fits firms whose primary practice is financial audit and where cyber attest is an adjacent product line the same practitioners work on.

Weaknesses

No PBC portal in the modern sense — evidence collection lives outside the platform (Suralink, ShareFile, email). No framework-specific templates for SOC 2 II, ISO 27001, PCI DSS out of the box; the firm builds these or buys template packs. Weak on cross-framework evidence deduplication. No AI-assisted evidence review. Cross-cycle state carrying is minimal — prior workpapers are in a prior-year folder, not surfaced at kickoff.

Category 2: PBC/portal specialists — Suralink

Best-in-class client-side evidence request management. The auditor publishes a PBC (Prepared By Client) list; the client uploads evidence against each item; the auditor accepts, rejects, or comments. The workflow is mature, the client UX is professional, and the tool integrates with several workpaper platforms as a data source.

Strengths

Excellent PBC workflow. Strong client-side UX — auditees actually enjoy using it, which is rare. Robust access controls on the evidence-request layer. Integrations with CaseWare, TeamMate+, and other workpaper systems as a data source.

Fits as a component of a stack — usually paired with a workpaper platform (CaseWare or TeamMate+) that handles the audit-side workpaper structure and a specialty tool for framework templates.

Weaknesses

Not a workpaper platform — the audit-side structure lives elsewhere. No framework-specific testing templates. No cross-framework evidence deduplication (the same evidence uploaded once for SOC 2 must be re-uploaded or re-referenced for ISO 27001). No cross-cycle state. No AI-assisted evidence review. Client-side experience is strong but does not close the auditor-side gap.

Category 3: AI-native cyber-attest workflow — Fieldguide

The most sophisticated new-generation workflow platform. Fieldguide is AI-native from the ground up — evidence review, request generation, testing procedure suggestions, and report compilation all use LLM-assisted workflows. Strong at the individual-engagement layer, especially for firms doing high-volume single-framework work.

Strengths

AI-assisted evidence review is genuinely useful — pattern extraction from documents, suggested testing procedures, draft report language from working papers. Modern UX, well-designed audit-side workflows, integrates with multiple client-side data sources. Established at several top-100 CPA firms.

Fits large practices doing high-volume single-framework work — SOC 2 shops with 100+ engagements per year, where the AI assistance amplifies practitioner productivity within a well-defined engagement shape.

Weaknesses

Individual-engagement layer is strong; cross-framework book-view is weaker. Cross-cycle drift detection is limited. Framework support is broad but the cross-framework primitive (one evidence artifact satisfies multiple criteria) is not the platform's central abstraction. Enterprise-priced — best fit for firms at scale rather than boutique or mid-sized practices.

Category 4: Bundled auditor-and-platform — Thoropass, A-LIGN A-SCEND

The commercial-innovation category. The vendor is both the software provider and the auditor — the client contracts with the vendor for the SOC 2 II examination, and the vendor's audit staff (or a partner network the vendor manages) performs the engagement using the vendor's platform. The economics are attractive: the vendor captures both revenue streams and can price the software below cost as customer acquisition for the audit engagement.

Strengths

Fastest time-to-first-attestation for a new client. Coherent client experience — one vendor, one contract, one platform, one report. Aggressive pricing at the entry tier. Rapid growth trajectory in the SMB and lower-mid-market segments.

Fits practices that want to enter cyber attest quickly on commodity economics and are willing to accept the appearance-independence tradeoff. Also fits clients that want a fast, cheap first-cycle attestation and are less sensitive to the auditor-vs-platform question.

Weaknesses

Structural independence-in-appearance question — the vendor is both auditor and software provider. The AICPA rules permit this within specific limits, but the appearance in a peer review or a state board inspection is the risk. Channel conflict for partner firms — the vendor can (and does) invite the firm's clients to switch to the vendor's own audit practice. Lock-in — the auditee's compliance state, working papers, and evidence all live on the vendor's platform, and portability guarantees are limited.

Not a fit for firms that differentiate on independence and audit quality — those practices cannot use the bundled model without giving up the differentiation.

Category 5: Independent audit-firm substrate — vCISO Lite for Auditors

The category this piece is part of. Independent SaaS vendor with no attestation practice of its own — the vendor provides the working-paper substrate, evidence organization, and cross-framework/cross-cycle capabilities; the audit firm holds the engagement letter, the license, and the professional-standards obligations. Architecturally read-only into the auditee's environment, cryptographic integrity on evidence and working papers.

Strengths

Cross-framework book view — one console across SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, and DORA. Cross-cycle drift detection as a first-class primitive. Extraction-lineage capture for IPE. Free-forever client evidence portal (auditee never pays a platform tax to submit its own evidence). Read-only architecture preserves independence-in-appearance without policy-only assurances. Hash-chained timestamp-anchored evidence integrity survives platform migration or vendor consolidation.

Fits cyber-attest practices running multi-framework books at scale (25-200 engagements per year across three or more frameworks) where the practice differentiates on independence and audit quality.

Weaknesses

Newer category — less installed base than CaseWare or Suralink. Not the right fit for firms whose primary practice is financial audit and where cyber attest is a small adjacent product line (Category 1 is likely a better fit there). Not the cheapest option at the entry tier — the bundled model wins on sticker price for a new practice's first engagement.

The requirement-by-requirement comparison

The following table is the flat comparison across the requirements the modern cyber-attest practice actually cares about. Green means the platform meets the requirement out of the box; amber means it meets it partially or through customization; red means it does not.

Suralink is omitted from the flat comparison because it is a PBC/portal specialist rather than a workpaper platform — it sits as a component of a stack rather than as an alternative to the workpaper platforms compared here.

Requirement
CaseWare / TeamMate+
Fieldguide
Thoropass / A-SCEND
vCISO Lite for Auditors
One book view across every framework, every client, every cycle
Amber (portfolio view exists; cross-cycle carry is manual)
Amber (strong per-engagement; cross-framework weaker)
Green (single vendor, coherent view)
Green (native cross-framework, cross-cycle)
Cross-framework evidence deduplication
Red (framework-siloed workpaper templates)
Amber (partial framework crosswalks)
Green (single vendor)
Green (native cross-framework primitive)
Year-over-year control drift detection
Red (prior-year workpaper folder only)
Amber (per-engagement history)
Amber (cross-cycle within one vendor)
Green (drift as first-class primitive)
IPE extraction-lineage capture
Red
Amber (evidence review; not lineage)
Amber
Green (lineage as first-class field)
Free-forever client evidence portal
Red (client-side tool is separate purchase)
Amber (client-side varies)
Green (client access included)
Green (auditee never pays platform tax)
Cryptographic evidence integrity (hash + timestamp anchor)
Red (log-based integrity)
Red
Red
Green (hash + external timestamp anchor)
Independence-by-design (no write paths to auditee)
Green (no client-side write scope)
Green
Red (bundled vendor also audits)
Green (architectural, verifiable)
AI-assisted evidence review
Red
Green (native strength)
Amber
Green (agentic review pipelines)
Report compilation from working papers with provenance
Amber (template-based)
Green (AI-assisted)
Green (integrated pipeline)
Green (provenance preserved)

Which category fits which practice

The category selection follows a straightforward decision tree based on the practice's shape, positioning, and scale:

  • Financial audit is the primary practice; cyber attest is an adjacent product line at low volume.: Category 1 (legacy workpaper platform, likely CaseWare or TeamMate+) is the right fit. The infrastructure to support the primary practice already exists; cyber attest can be added as a workflow layer without a new tool acquisition. Pair with Suralink for client-side experience if PBC workflow is important.
  • SOC 2 shop with 100+ engagements per year, primarily single-framework.: Category 3 (Fieldguide) is the strongest fit. AI-assisted individual-engagement workflow amplifies the practitioner productivity that carries a high-volume practice.
  • New practice entering cyber attest, price-sensitive, willing to trade appearance-independence for speed and economics.: Category 4 (Thoropass or A-LIGN A-SCEND) is the pragmatic choice. Understand the tradeoff — the vendor is both the auditor and the platform provider, and that shape produces a channel conflict and an appearance-independence question that will surface at inspection eventually.
  • Multi-framework practice, 25-200 engagements per year, differentiates on independence and audit quality.: Category 5 (vCISO Lite for Auditors, or an independent-substrate alternative if one emerges) is the fit. The cross-framework primitive, cross-cycle state, extraction-lineage capture, and architectural independence match the practice's positioning and its operational shape.
  • Boutique practice, small number of high-touch recurring clients, personal-relationship-driven.: Any of Categories 1, 2, or 5 can work. The choice depends on framework mix — single-framework favors Category 1+2 (workpaper + portal), multi-framework favors Category 5 (unified cross-framework substrate). Category 3 is likely overkill for the volume, and Category 4 is a poor fit for high-touch relationships that would resist vendor lock-in.
The independence question that decides the shortlist

Before running the full evaluation, decide the independence question: does the practice differentiate on independence and audit quality, or does it compete on price and speed? Category 4 is only a viable option if the answer is "we compete on price and speed and can accept the appearance-independence tradeoff." Every other category preserves independence architecture; only Category 4 puts it on the table. Get this decision explicit early — it eliminates a whole category of vendors from the shortlist or brings one back onto it.

The switching-cost reality

Any of these platforms represents a 12-24 month change-management effort to migrate an established practice. Working papers must be portable, evidence must be exportable, framework templates must be re-authored (or accepted from the new platform), and the practitioners must be trained. The tooling decision is not "which vendor is best this quarter" — it is "which vendor's category matches where we want the practice to be five years from now." Practices that switch platforms every two years compound the operational disruption without capturing the strategic benefit.

The bottom line

The five-category framing above is the honest shape of the cyber-attest software market in 2026. The choice among them is a positioning decision more than a feature decision — every serious vendor in each category has strong feature coverage, and the ones that don't do not last long in the market. Get the category right and the specific vendor within the category is a smaller decision. Get the category wrong and no amount of vendor-selection effort recovers the fit.

See the independent-substrate model in action

vCISO Lite for Auditors is the Category 5 platform for practices differentiating on independence and audit quality — cross-framework book view, cross-cycle drift detection, IPE extraction-lineage capture, cryptographic evidence integrity, free-forever client evidence portal, architecturally-read-only into every auditee. Built for CPA firms, QSAs, 3PAOs, C3PAOs, HITRUST assessors, and ISO 27001 lead auditors running multi-framework books at scale.

If Category 5 is your fit, or you want to see whether it is, visit firm.vcisolite.com to walk the console.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.