SaaSInsightBrowse reviews
Security & compliance

How much SOC 2 costs

SOC 2 is three purchases: a CPA firm's audit, an optional compliance platform, and the supporting work. Only a licensed CPA firm can issue the report. Of eight platforms whose pricing pages we read, one publishes a figure, so budget for a scoping call rather than expecting a price list.

By Rajat Kapoor

Updated September 2026

Key takeaways

  • Only a licensed CPA firm can perform a SOC 2 examination and issue the report, so no compliance platform can give your customer what they asked for.

  • Of eight compliance platforms whose pricing pages we read, seven publish no figure at all.

  • The CPA firm's fee is normally the larger half of what you pay, and it is the half with the least published information.

  • The AICPA has flagged unlicensed practitioners and unreviewed firms performing SOC work, so verify your auditor on a state board register and the public peer review file.

  • Ask for the audit fee as a separate line from the platform subscription, and refuse a bundled quote that will not decompose.

  • Most enterprise buyers mean Type 2, so buying Type 1 to move faster often means paying for two engagements instead of one.

A customer has asked for your SOC 2 report, and a deal is now waiting on it. You go looking for what that will cost and find two kinds of page: companies selling compliance software, and directories that look like independent comparisons until you notice every listing is a placement. Both quote ranges. Neither shows you a price anyone actually publishes.

There is a reason for that, and it is the most useful thing to understand before you spend anything. SOC 2 is not one purchase, the biggest part of it is sold by a profession that does not advertise fees, and the cheapest route available to you can produce a report your customer's security team is entitled to reject. This page separates the parts, reports what this market genuinely discloses, and gives you three free checks to run before you sign anything.

Three purchases, and only one of them is the audit

The audit. A SOC 2 report is an attestation engagement, and only a licensed CPA firm can perform one and issue the report. This is the fact everything else hangs off. No compliance platform, however much it automates, can give you the document your customer asked for.

The platform. Vanta, Drata, Secureframe and the rest collect evidence, monitor controls and hold your policies. Useful, sometimes close to essential, and entirely optional. It is the part of the bill with the most competition and the most marketing.

The supporting work. A readiness or gap assessment, remediation of whatever that finds, often a penetration test, and staff time that nobody invoices you for but which is usually the largest real cost in the first year.

One structural decision sits across all three. A Type 1 report describes your controls at a single date. A Type 2 describes how they operated across an observation window, commonly three to twelve months. Customers overwhelmingly want Type 2, so buying Type 1 first to move faster often means paying for two engagements to arrive where one would have taken you. Choose deliberately rather than by whichever quote arrives first.

What the platforms publish

We read the pricing pages of eight compliance platforms on 14 September 2026. Seven publish no figure at all.

Vanta, Drata, Secureframe, Oneleet, Thoropass, Comp AI and Scrut all route you to a demo or a sales conversation. The wording is consistent enough to be worth quoting: Oneleet says its pricing model depends on factors specific to your needs so it will need to get in touch, and Scrut notes that additional services like audit charges may influence the final quote.

The exception is Delve, which publishes nothing on its own site but lists a Foundation package at $12,000 for a twelve month contract, for one to twenty employees, on the AWS Marketplace. That is the only number in the set you could put in a budget before speaking to anyone.

Two things worth taking from this. Nobody is hiding an unreasonable price; quote-gating is simply how this category sells, so treat the scoping call as part of the purchase. And be sceptical of the ranges you find elsewhere. Two directories currently state Comp AI's pricing as specific monthly figures. Comp AI's own pricing page carries no figure at all.

Why the audit fee is the hard number to find

CPA firms are bound by professional standards on how they market and price, and most quote per engagement after scoping. So the audit, which is usually the larger half of your first year, is the part with the least published information.

That vacuum is where the risk sits, and the AICPA has said so directly. On its SOC 2 page it states that it is investigating allegations about a compliance vendor offering SOC services, with the concern that auditors may not have performed audits in accordance with professional standards, may not have been enrolled in peer review, or may be unlicensed. It also says it refers unlicensed firms and practitioners to state boards of accountancy, and separately flags the ethics considerations that arise when a CPA firm has a business arrangement with a SOC 2 tool provider.

Read that alongside how the cheap end of this market is packaged. Several platforms bundle the audit with the software, and Thoropass says plainly that its pricing reflects both components because the platform combines software and audit delivery. Bundling is not itself a problem, and for a small company it can be the sensible buy. But it makes the auditor someone else's choice, and you are the one who has to hand the report to a customer.

Three checks before you accept a cheap audit

All three are free, take a few minutes, and are the highest-value work in this entire purchase.

  1. Confirm the firm is licensed. Every US state board of accountancy publishes a licence lookup. The entity signing your report should appear in it. If you are being sold an audit by a company whose name you cannot find on any board's register, stop there.
  2. Check the peer review record. Peer review results for CPA firms are publicly searchable through the AICPA's public file. Enrolment is the baseline expectation for a firm performing attestation work, and the AICPA has named its absence as a concern.
  3. Ask for the audit fee as a separate line. Whoever quotes you, ask what portion is the CPA firm's fee, who that firm is, and whether you may speak to them before committing. A bundled quote that will not decompose is telling you something.

What moves your number

Five inputs, and you can settle all of them before a call: how many of the five trust services criteria you include beyond Security, which almost nobody needs all of; whether you are buying Type 1 or Type 2 and how long the observation window runs; headcount, because most platforms price against it; how much evidence already exists, since a company with written policies and configured logging is a cheaper engagement than one starting from nothing; and how many subservice organisations sit in scope, because each one adds review work.

Frequently asked questions

How much does a SOC 2 audit cost?

Almost nobody publishes a figure, which is the honest answer and the reason every range you find online comes from a party selling something. The audit itself is performed by a CPA firm that quotes per engagement after scoping, and the compliance platform most companies buy alongside it is separately quote-gated at seven of the eight vendors whose pricing pages we read. Budget for a scoping conversation rather than expecting a price list, and get the audit fee quoted as a line of its own.

Why will nobody tell me the price?

Two different reasons that get confused. Compliance platforms quote-gate as a sales tactic, because pricing against headcount and framework count gives them room to negotiate. CPA firms are a regulated profession that prices attestation work per engagement after understanding scope, which is a professional norm rather than a tactic. The practical consequence is the same either way: you cannot budget this from public information, so treat the scoping calls as the first step of the purchase.

Do I need a compliance platform, or can I do SOC 2 without one?

You can do it without one, and companies did for years. A platform buys you automated evidence collection and continuous monitoring, which saves real staff time and matters most if you have no written policies and no centralised logging today. What it cannot do is issue your report, because only a licensed CPA firm can. Treat it as a way to make the audit cheaper and less painful, not as the thing you are buying.

Is a bundled platform and audit package a good deal?

It can be, particularly for a small company with no compliance function. What you are giving up is the choice of auditor, and that is the part worth protecting. Ask which CPA firm performs the engagement, confirm it holds a licence with a state board of accountancy, and check its peer review record before you accept the bundle. The AICPA has publicly flagged both unlicensed practitioners in this space and the ethics questions raised by arrangements between audit firms and tool vendors.

Should I get Type 1 or Type 2 first?

Ask the customer who requested the report which they will accept, because that answer decides it and nothing else does. Type 1 describes your controls at one date and can be produced quickly. Type 2 describes how they operated over an observation window, commonly three to twelve months, and is what most enterprise buyers mean when they ask for SOC 2. Buying Type 1 to move a deal along frequently means paying for two engagements instead of one.

What is the most expensive part of getting SOC 2?

Usually the part nobody invoices you for, which is your own staff time in the first year: writing policies, changing how access is granted, configuring logging, and collecting evidence. Of the amounts you actually pay, the CPA firm's fee is normally larger than the platform subscription, which is the opposite of the impression most comparison pages give. Remediation is the wildcard, because you cannot scope it until a readiness assessment tells you what is missing.

Where to go next