What SOC 2 costs in 2026, split into what is published and what is not.
Half of a SOC 2 budget has real published prices behind it. The GRC vendors list annual figures on their own AWS Marketplace listings, in dollars, per line item. The other half, the audit fee, is published by nobody at any tier. Most pages on this subject blur the two and print a confident table. This one keeps them apart.
Where the budget goes
Four components account for almost all year-one SOC 2 spend. One of them has published prices. The other three do not, and the honest thing to do with those is model them from drivers you can see and rates you can set, rather than print a range and hope nobody asks where it came from. Each card links to the detail.
Auditor hours multiplied by the firm's rates. No firm publishes either, so the only rate you can verify is the one in your own engagement letter.
The tier tables you have seen elsewhere are estimates. This site models the fee instead, and says so.
Gap analysis, policy authoring, evidence map, then the remediation the gap log turns up.
Quoted per engagement by consultants who do not publish rates. Model it from days, or use the quote in front of you.
Seven vendors publish full annual list prices, per dimension, on their AWS Marketplace listings. In US dollars.
The one cost line on this site with real published prices behind it. Read them in the vendor's own units and bands.
Senior engineering and security time absorbed by evidence collection, walkthroughs and policy work.
Visible in the P&L only as missed roadmap. The hour count is this site's assumption; the hourly cost is yours.
Five questions every CFO asks before approving
The recurring questions in finance committee meetings on SOC 2 spend. Each links to the page where the reasoning sits.
There is no published benchmark to check it against, and anyone who tells you otherwise is quoting an estimate. What works instead: ask the firm for its hour estimate split by grade alongside the total, derive the blended rate, and get a second quote on identical scope. The calculator here will model the same engagement from stated assumptions so you can see whether the shape is plausible.
If a customer accepts Type 1 today and Type 2 in nine months, run Type 1. If they will wait, skip Type 1 and save the fee. The trap is the half-decision: a Type 1 that ages out before a Type 2 that starts 18 months later wastes both budgets.
This one has a real answer. Seven vendors publish annual list prices on AWS Marketplace, in dollars, per dimension. Watch the billing axis: several bill the platform and each framework separately, so the cheapest platform line can carry no framework and produce no SOC 2 report at all.
Readiness drops out and the platform renews, but the audit does not get lighter in the way people expect: SOC 2 has no surveillance audit, so year 2 is a full re-audit of a fresh observation window. The confident year-2 ratios in circulation are not published by anyone. Ask your firm what year 2 looks like before you sign year 1.
The control sets overlap heavily, which is why running both as one programme with one readiness workstream costs less than running them twice. How much less depends on your scope and whether the evidence is genuinely shared, and no firm publishes a bundle discount to quote at you.
Sanity-check your scenario
Enter a few facts about the organisation and the model returns a year-one range, the year 2 cost, and the line-by-line arithmetic that produced them. It is a model, not a price list: the hour counts are this site's assumptions and the rates are yours to set. Every assumption is on the methodology page. The version with editable rates is on the calculator page. No email is captured to release the result.
- Audit firm fee£24,700 – £41,800130 to 220 auditor hours at £190/hr
- Readiness£7,200 – £18,0008 to 20 consultant days at £900/day
- GRC platform (none)£0 – £0No platform in this scenario
- Internal time£18,800 – £33,800250 to 450 hours at £75/hr
What teams underestimate
Evidence collection takes longer than anyone plans for. Screenshots of access reviews, sample tickets, vendor attestations, onboarding records: all of it is engineering time that was not in the implementation plan, and none of it is on the SOW. The lines that are not on the SOW are where budgets break.
Scope creep mid-audit is common. A new product line ships during the observation window, a new region opens, a customer asks for an additional Trust Services Criterion halfway through readiness. Each one adds auditor hours to a fee that was approved for a smaller scope. The cleanest defence is a written scope statement agreed with the auditor before observation begins, with named exclusions and an agreed mechanism for change orders.
Internal time is the cost nobody invoices and everybody pays. A first-time SOC 2 absorbs several hundred hours of a senior security or engineering lead, plus more spread across HR, finance, IT and product. The calculator puts this site's assumed hour count against your own fully-loaded rate, which is the only part of that sum anyone can state with confidence.
Year 2 is almost always under-budgeted, because most CFO conversations stop at the year-one figure. SOC 2 has no surveillance audit: year 2 is a full re-audit of a fresh observation window, the platform contract renews, and the evidence still has to be produced. The shape is on the ongoing-cost page.
A reference, not a sales asset
This site exists because every other top-ranking page on SOC 2 cost is owned by someone selling something. The intent here is the opposite: publish what the vendors actually publish, model the rest in the open, and say which is which on every figure. There is no email gate on the calculator and no chat widget. This site takes no referral or affiliate fees from GRC platforms or audit firms, and no figure here is influenced by a commercial relationship.
If a quote is in front of you, the audit-firm fees page sets out how to take it apart. If you need a defensible budget figure for a CFO conversation, the calculator will produce one and show its working, and the methodology page lists every assumption behind it.
Seven questions, briefly
The condensed version. The full set lives on the FAQ page.