Independent reference.Not affiliated with the AICPA or any audit firm.See methodology.
Independent cost reference / 2026

What SOC 2 costs in 2026, split into what is published and what is not.

Half of a SOC 2 budget has real published prices behind it. The GRC vendors list annual figures on their own AWS Marketplace listings, in dollars, per line item. The other half, the audit fee, is published by nobody at any tier. Most pages on this subject blur the two and print a confident table. This one keeps them apart.

Where the budget goes

Four components account for almost all year-one SOC 2 spend. One of them has published prices. The other three do not, and the honest thing to do with those is model them from drivers you can see and rates you can set, rather than print a range and hope nobody asks where it came from. Each card links to the detail.

Five questions every CFO asks before approving

The recurring questions in finance committee meetings on SOC 2 spend. Each links to the page where the reasoning sits.

Is the Type 2 quote in front of us reasonable?

There is no published benchmark to check it against, and anyone who tells you otherwise is quoting an estimate. What works instead: ask the firm for its hour estimate split by grade alongside the total, derive the blended rate, and get a second quote on identical scope. The calculator here will model the same engagement from stated assumptions so you can see whether the shape is plausible.

Type 1 first or skip to Type 2?

If a customer accepts Type 1 today and Type 2 in nine months, run Type 1. If they will wait, skip Type 1 and save the fee. The trap is the half-decision: a Type 1 that ages out before a Type 2 that starts 18 months later wastes both budgets.

What will a GRC platform actually cost?

This one has a real answer. Seven vendors publish annual list prices on AWS Marketplace, in dollars, per dimension. Watch the billing axis: several bill the platform and each framework separately, so the cheapest platform line can carry no framework and produce no SOC 2 report at all.

What happens to the cost in year 2?

Readiness drops out and the platform renews, but the audit does not get lighter in the way people expect: SOC 2 has no surveillance audit, so year 2 is a full re-audit of a fresh observation window. The confident year-2 ratios in circulation are not published by anyone. Ask your firm what year 2 looks like before you sign year 1.

ISO 27001 too?

The control sets overlap heavily, which is why running both as one programme with one readiness workstream costs less than running them twice. How much less depends on your scope and whether the evidence is genuinely shared, and no firm publishes a bundle discount to quote at you.

Sanity-check your scenario

Enter a few facts about the organisation and the model returns a year-one range, the year 2 cost, and the line-by-line arithmetic that produced them. It is a model, not a price list: the hour counts are this site's assumptions and the rates are yours to set. Every assumption is on the methodology page. The version with editable rates is on the calculator page. No email is captured to release the result.

Scenario model
This site's model, GBP
This is a model, not a price list. Audit firms do not publish fees, so nothing below is a market rate. The hour and day counts are this site's assumptions; the rates are yours to set. Use it to test a quote you have been given, not to predict one.
Year 1 modelled (audit, readiness, platform, internal time)
£50,700 – £93,600
Year 2 modelled (full re-audit, platform, reduced internal time)
£34,100 – £58,700
Two-year total
£84,700 – £152,200
How the year 1 number is built
  • Audit firm fee£24,700 – £41,800
    130 to 220 auditor hours at £190/hr
  • Readiness£7,200 – £18,000
    8 to 20 consultant days at £900/day
  • GRC platform (none)£0 – £0
    No platform in this scenario
  • Internal time£18,800 – £33,800
    250 to 450 hours at £75/hr
The model's assumptions: auditor hours and readiness days scale with company size; a Type 1 is assumed to take 60 percent of the Type 2 hours for the same scope, because it has no observation window and no sample testing; each optional Trust Services Criterion is assumed to add between 10 and 25 percent to auditor hours; year 2 repeats the audit in full, because SOC 2 has no surveillance audit.Every one of those is our assumption rather than an observed figure. They are set out in full, with the reasoning, on the methodology page.

What teams underestimate

Evidence collection takes longer than anyone plans for. Screenshots of access reviews, sample tickets, vendor attestations, onboarding records: all of it is engineering time that was not in the implementation plan, and none of it is on the SOW. The lines that are not on the SOW are where budgets break.

Scope creep mid-audit is common. A new product line ships during the observation window, a new region opens, a customer asks for an additional Trust Services Criterion halfway through readiness. Each one adds auditor hours to a fee that was approved for a smaller scope. The cleanest defence is a written scope statement agreed with the auditor before observation begins, with named exclusions and an agreed mechanism for change orders.

Internal time is the cost nobody invoices and everybody pays. A first-time SOC 2 absorbs several hundred hours of a senior security or engineering lead, plus more spread across HR, finance, IT and product. The calculator puts this site's assumed hour count against your own fully-loaded rate, which is the only part of that sum anyone can state with confidence.

Year 2 is almost always under-budgeted, because most CFO conversations stop at the year-one figure. SOC 2 has no surveillance audit: year 2 is a full re-audit of a fresh observation window, the platform contract renews, and the evidence still has to be produced. The shape is on the ongoing-cost page.

A reference, not a sales asset

This site exists because every other top-ranking page on SOC 2 cost is owned by someone selling something. The intent here is the opposite: publish what the vendors actually publish, model the rest in the open, and say which is which on every figure. There is no email gate on the calculator and no chat widget. This site takes no referral or affiliate fees from GRC platforms or audit firms, and no figure here is influenced by a commercial relationship.

If a quote is in front of you, the audit-firm fees page sets out how to take it apart. If you need a defensible budget figure for a CFO conversation, the calculator will produce one and show its working, and the methodology page lists every assumption behind it.

Seven questions, briefly

The condensed version. The full set lives on the FAQ page.

How much does SOC 2 cost?+
The honest answer has two halves. The GRC platform half is published: the vendors list annual prices on AWS Marketplace, starting at $7,500 a year for a platform line, with several billing each compliance framework on top. The audit half is not published by anyone, at any tier. So this site publishes the platform prices as the vendors state them, and models the rest from stated assumptions and rates you supply. Anyone quoting a confident all-in figure for your company has estimated it.
Why does this site not just give me a number?+
Because the number would be invented, and inventing it is exactly what every other page on this topic does. Audit firms do not publish fees. Readiness consultants do not publish day rates. There is no register and no filing. What this site can honestly give you is the vendors' own published platform prices, a model whose every assumption is stated, and the questions that will get a real figure out of a real firm.
What is the difference between SOC 2 Type 1 and Type 2 in cost terms?+
A Type 1 assesses control design at a point in time. A Type 2 adds an observation window of three to twelve months, sample testing across a population of evidence, and walkthrough revisits at the close. Those extra workstreams are auditor hours a Type 1 never incurs, so a Type 2 costs meaningfully more for identical scope. The strategic question is rarely the fee gap; it is whether the customer or investor deadline can wait the longer Type 2 timeline.
Is SOC 2 legally required?+
SOC 2 is not legally mandated. It is customer-required in B2B SaaS, especially where the buyer is regulated, and investor-required at series A or B fundraises. Compare with HIPAA or PCI DSS, which are obligation-driven. SOC 2 is an attestation performed by CPA firms licensed by state boards of accountancy, under professional standards published by the AICPA.
Can I do SOC 2 without Vanta or Drata?+
Yes. The audit firm is non-negotiable; the platform is not. Doing it yourself means in-house readiness, in-house evidence collection and in-house policy work, plus the same CPA audit. The trade-off is not really cash against cash. It is cash against the concentration of several hundred hours on one senior engineer.
Does SOC 2 expire?+
A SOC 2 report covers a stated period, typically twelve months for a Type 2, and customers expect annual renewal. SOC 2 has no formal surveillance audit, unlike ISO 27001, so each annual report is essentially a full re-audit against a fresh observation window rather than a lighter check-in.
How many Trust Services Criteria do I need?+
Security is mandatory and is the only category every SOC 2 report must include. The other four, Availability, Confidentiality, Processing Integrity and Privacy, are scope choices driven by what your customer contracts actually require. Each one you add brings controls that have to be tested, so each one adds auditor hours and readiness work. No firm publishes a per-criterion figure, so treat any specific percentage you see, including the modelled bracket used on this site, as an assumption rather than a fact.

Updated 2026-07-15