Independent reference.Not affiliated with the AICPA or any audit firm.See methodology.
Pillar / Real cost drivers (audit fees)

SOC 2 audit firm fees: what is knowable, and what is not.

No audit firm publishes its SOC 2 fees. Not the Big 4, not the mid-tier, not the boutiques specialising in this work. There is no register and no rate card. Everything else on this subject is somebody's estimate wearing a confident font. What you can do is understand what drives the number, insist on seeing its structure, and test the quote in front of you.
Section 01

Why there is no fee table here

Search for SOC 2 audit fees and you will find tier tables: Big 4 at one band, mid-tier at another, boutique at a third, split by Type 1 and Type 2. They look authoritative. They are not sourced to anything, because there is nothing to source them to. Audit fees are set engagement by engagement and disclosed to nobody but the client. A handful of practising firms publish a range on their own websites and say plainly that it depends on scope. That is one firm's disclosure about itself, and it is a long way from a market rate.

This page used to carry a table like that. It is gone, along with a partner-manager-senior-staff rate card that conceded in its own sentence that firm rates are confidential and then printed four numbers anyway. Neither could be stood behind, so neither should have been published.

Section 02

What actually drives the fee

A SOC 2 audit fee is auditor hours multiplied by the firm's rates. That is the whole mechanism, and everything below is a question of how many hours.

Audit type. A Type 1 assesses control design at a point in time. A Type 2 adds an observation window, sample testing across a population of evidence, and walkthrough revisits at the close. Those are additional hours that a Type 1 does not incur at all, which is why the gap is real rather than a pricing convention.

Trust Services Criteria in scope. Security is mandatory. Each optional criterion you add brings its own controls, and each control has to be tested. More controls, more hours. How much more depends on the criterion and your environment, and no firm publishes a per-criterion figure.

Environment complexity. Number of cloud regions, number of in-scope services, number of entities, and the number of vendors with material access to your data. Each vendor in scope brings its own vendor-management testing. This is usually the driver that surprises people, because it does not track headcount.

Evidence quality. A well-organised evidence set costs the auditor fewer hours to work through than a shared drive of screenshots. Whether that shows up in your fee is a matter for the engagement letter.

Section 03

What to ask for before you sign

The engagement letter is the only auditor pricing document you will ever be able to verify. Read it like one.

Questions that expose the structure of a quote
Ask forWhy it matters
The hour estimate, split by grade, alongside the total feeDivide one by the other and you have the blended rate the firm is charging you. That is a verifiable rate. No published rate card is.
The scope statement in writing: criteria, entities, systems, vendorsScope is the fee. An ambiguous scope statement is an open invoice, and mid-engagement additions are where approved budgets break.
What triggers a change order, and how it is pricedAdding an entity, a criterion, or a region mid-engagement is common. Agree the mechanism before it happens, not after.
Whether the observation window can move, and at what costType 2 windows slip. Find out whether that is a conversation or an invoice.
The firm's CPA licence and its peer review statusA SOC 2 report has to come from a CPA firm licensed by a state board of accountancy and subject to peer review. This is checkable, and it is the check that actually matters.
How the firm handles readiness safeguards, if it is doing bothThe AICPA Code permits it under conditions. A firm that cannot explain the safeguards is the problem, not the arrangement.
Section 04

What the SOW should show

The line items below are what a SOC 2 Type 2 engagement is made of. No prices are attached to them here, deliberately: attaching one would mean inventing it. The value of the list is that a quote broken into these lines can be interrogated, and a quote that arrives as a single number cannot.

The SOW lines to insist on seeing, with hours against each
SOW lineWhat you should expect
Planning and scopingAgreed scope memo, control list, sample population definition, vendor list. If this is vague, everything downstream is negotiable at the firm's discretion.
Walkthroughs and design assessmentAn interview with each control owner, the operating procedure documented, design gaps identified before fieldwork rather than during it.
Sample testing and fieldworkSampled testing across the observation window, evidence review, exception logging. The largest hour line on a Type 2, and the one that scales hardest with scope.
Reporting and management responseDraft report, exceptions discussion, your management response, the final attested report.

Ask for hours against each of those four lines. A firm that has priced the work properly can produce them without difficulty, and the split tells you where your scope is expensive. If the hours do not reconcile to the total at any plausible rate, that is worth a conversation before signature rather than after.

Section 05

Firm tiers: what the choice actually turns on

The tiers are real market segments even though their prices are not published. Big 4, mid-tier and regional firms, and boutiques specialising in SOC 2 all issue the same attestation under the same AICPA standards. A boutique's SOC 2 report is not a lesser instrument than a Big 4's.

So the choice is rarely about the report. It is about whether a downstream buyer requires a particular signatory by name, which some banks, defence counterparties and regulated insurers do, and about engagement style. A boutique expects you to ship evidence on schedule. A Big 4 firm expects you to run your project around its methodology. A mid-tier firm usually sits between the two. For a first-time SOC 2 with no named-signatory requirement, the segment that fits how your team actually works is the right one.

Where a firm is running SOC 2 alongside adjacent attestation work, asking about a combined engagement is worth doing. Whether that produces a discount, and how much, is between you and the firm. Nobody publishes bundle pricing either, and a SOC 2 report has to come from a CPA firm while an ISO 27001 certificate has to come from an accredited certification body, so a single provider covering both is a question to put rather than an assumption to budget on.

Cross-reference

Trust Services Criteria scope is the lever you control most directly; the Trust Services Criteria page sets out what each one adds. The platform decision interacts with the audit but does not include it; see the GRC platforms page, where real published prices do exist. For the year 2 shape, see the ongoing cost page. To put a modelled number on any of this, use the calculator.

Section 06

FAQ

How much does a Big 4 SOC 2 audit cost?+
Nobody outside the engagement knows, because no Big 4 firm publishes SOC 2 fees anywhere. There is no rate card, no filing, and no register. Any specific figure you see quoted for a Big 4 SOC 2 audit has been estimated by whoever published it. What can be said is structural: Big 4 engagements are priced off a larger team and a heavier methodology, and the premium is only worth paying where a downstream buyer requires that signatory by name. Get a quote, then test it against the drivers on this page.
Can the audit firm also do my readiness?+
Yes, subject to safeguards, and plenty of CPA firms sell readiness assessments. The AICPA Code of Professional Conduct treats readiness as a nonattest service and permits it for an attest client where the client assumes all management responsibilities, designates someone with suitable skills, knowledge and experience to oversee the work, evaluates the adequacy and results of it, and accepts responsibility for the outcome. That understanding must be documented in writing before the work starts, and the firm must manage the self-review threat, because it cannot use its own recommendations as audit evidence. Ask a firm how it applies those safeguards.
How do I tell whether a SOC 2 quote is reasonable?+
Ask for the hours behind it, split by grade, alongside the total. A firm that will not break the fee into hours is asking you to accept a number with no structure. Once you have hours and total, you can derive the blended rate the firm is charging, which is the only auditor rate that can be verified: it is in your own engagement letter. Compare a second quote on the same scope rather than against a published average, because no honest published average exists.
How much do SOC 2 audit fees change year to year?+
Not publicly knowable, and be wary of the confident ratios in circulation. What is structural: SOC 2 has no surveillance audit, so year 2 is a full re-audit of a fresh observation window rather than a lighter check-in. Most of the work recurs. Some of it does not, because the firm already understands your environment and the scoping and walkthrough work is lighter the second time. Whether that nets to a meaningful reduction is a question for your engagement letter, and it is worth asking before you sign year 1.

Updated 2026-07-15