SOC 2 audit firm fees: what is knowable, and what is not.
Why there is no fee table here
Search for SOC 2 audit fees and you will find tier tables: Big 4 at one band, mid-tier at another, boutique at a third, split by Type 1 and Type 2. They look authoritative. They are not sourced to anything, because there is nothing to source them to. Audit fees are set engagement by engagement and disclosed to nobody but the client. A handful of practising firms publish a range on their own websites and say plainly that it depends on scope. That is one firm's disclosure about itself, and it is a long way from a market rate.
This page used to carry a table like that. It is gone, along with a partner-manager-senior-staff rate card that conceded in its own sentence that firm rates are confidential and then printed four numbers anyway. Neither could be stood behind, so neither should have been published.
What actually drives the fee
A SOC 2 audit fee is auditor hours multiplied by the firm's rates. That is the whole mechanism, and everything below is a question of how many hours.
Audit type. A Type 1 assesses control design at a point in time. A Type 2 adds an observation window, sample testing across a population of evidence, and walkthrough revisits at the close. Those are additional hours that a Type 1 does not incur at all, which is why the gap is real rather than a pricing convention.
Trust Services Criteria in scope. Security is mandatory. Each optional criterion you add brings its own controls, and each control has to be tested. More controls, more hours. How much more depends on the criterion and your environment, and no firm publishes a per-criterion figure.
Environment complexity. Number of cloud regions, number of in-scope services, number of entities, and the number of vendors with material access to your data. Each vendor in scope brings its own vendor-management testing. This is usually the driver that surprises people, because it does not track headcount.
Evidence quality. A well-organised evidence set costs the auditor fewer hours to work through than a shared drive of screenshots. Whether that shows up in your fee is a matter for the engagement letter.
What to ask for before you sign
The engagement letter is the only auditor pricing document you will ever be able to verify. Read it like one.
| Ask for | Why it matters |
|---|---|
| The hour estimate, split by grade, alongside the total fee | Divide one by the other and you have the blended rate the firm is charging you. That is a verifiable rate. No published rate card is. |
| The scope statement in writing: criteria, entities, systems, vendors | Scope is the fee. An ambiguous scope statement is an open invoice, and mid-engagement additions are where approved budgets break. |
| What triggers a change order, and how it is priced | Adding an entity, a criterion, or a region mid-engagement is common. Agree the mechanism before it happens, not after. |
| Whether the observation window can move, and at what cost | Type 2 windows slip. Find out whether that is a conversation or an invoice. |
| The firm's CPA licence and its peer review status | A SOC 2 report has to come from a CPA firm licensed by a state board of accountancy and subject to peer review. This is checkable, and it is the check that actually matters. |
| How the firm handles readiness safeguards, if it is doing both | The AICPA Code permits it under conditions. A firm that cannot explain the safeguards is the problem, not the arrangement. |
What the SOW should show
The line items below are what a SOC 2 Type 2 engagement is made of. No prices are attached to them here, deliberately: attaching one would mean inventing it. The value of the list is that a quote broken into these lines can be interrogated, and a quote that arrives as a single number cannot.
| SOW line | What you should expect |
|---|---|
| Planning and scoping | Agreed scope memo, control list, sample population definition, vendor list. If this is vague, everything downstream is negotiable at the firm's discretion. |
| Walkthroughs and design assessment | An interview with each control owner, the operating procedure documented, design gaps identified before fieldwork rather than during it. |
| Sample testing and fieldwork | Sampled testing across the observation window, evidence review, exception logging. The largest hour line on a Type 2, and the one that scales hardest with scope. |
| Reporting and management response | Draft report, exceptions discussion, your management response, the final attested report. |
Ask for hours against each of those four lines. A firm that has priced the work properly can produce them without difficulty, and the split tells you where your scope is expensive. If the hours do not reconcile to the total at any plausible rate, that is worth a conversation before signature rather than after.
Firm tiers: what the choice actually turns on
The tiers are real market segments even though their prices are not published. Big 4, mid-tier and regional firms, and boutiques specialising in SOC 2 all issue the same attestation under the same AICPA standards. A boutique's SOC 2 report is not a lesser instrument than a Big 4's.
So the choice is rarely about the report. It is about whether a downstream buyer requires a particular signatory by name, which some banks, defence counterparties and regulated insurers do, and about engagement style. A boutique expects you to ship evidence on schedule. A Big 4 firm expects you to run your project around its methodology. A mid-tier firm usually sits between the two. For a first-time SOC 2 with no named-signatory requirement, the segment that fits how your team actually works is the right one.
Where a firm is running SOC 2 alongside adjacent attestation work, asking about a combined engagement is worth doing. Whether that produces a discount, and how much, is between you and the firm. Nobody publishes bundle pricing either, and a SOC 2 report has to come from a CPA firm while an ISO 27001 certificate has to come from an accredited certification body, so a single provider covering both is a question to put rather than an assumption to budget on.
Cross-reference
Trust Services Criteria scope is the lever you control most directly; the Trust Services Criteria page sets out what each one adds. The platform decision interacts with the audit but does not include it; see the GRC platforms page, where real published prices do exist. For the year 2 shape, see the ongoing cost page. To put a modelled number on any of this, use the calculator.