Methodology and sources.
Every figure on this site is either a price a vendor publishes or an output of a model whose assumptions are listed below. This page tells you which is which, and what this site refuses to publish at all.
The two kinds of number on this site
There are exactly two, and they are never blended. The first is a published price: a figure a vendor states publicly, reproduced here in the vendor's own currency, unit and band, with the date it was checked. Every published price on this site is a GRC platform price, because the GRC vendors are the only participants in this market who publish anything.
The second is a modelled figure: an output of the model set out below, built from assumptions we chose and rates you supply. It is labelled as modelled wherever it appears. It is not a market rate, and it should never be quoted as one.
Anything that could be neither is not published. That is a real constraint with real consequences: it is why this site has no audit-firm fee table, no auditor rate card, no per-tier fee bands, and no all-in cost claim on its homepage.
What this site is and is not
soc2certificationcost.com is a research surface from Digital Signet. It is not an audit firm. It does not perform attestations. It does not sell audits. It is not affiliated with the AICPA or any audit firm.
SOC 2 is an attestation performed by CPA firms licensed by state boards of accountancy, under professional standards published by the AICPA. Use of the term "SOC 2" on this site is descriptive only. We do not claim SOC 2 attestation of our own and we do not represent the AICPA.
This site takes no referral or affiliate fees from GRC platforms (such as Vanta, Drata, Secureframe, Sprinto) or from audit firms. No vendor pays for placement, and no figure on this site is influenced by a commercial relationship. The platform ranking on the GRC platforms page falls where the published prices put it.
Sources
Primary sources only: the AICPA's own published standards, and list prices the vendors themselves publish. This site does not use price aggregators, buyer-survey pools, review sites, or vendor marketing content, because self-reported figures pooled by a third party cannot be checked back to anything. It also does not cite other sites owned by Digital Signet as evidence for its own figures.
The criteria themselves: the five categories, Security as the common criteria, and the 2017 criteria with the 2022 revised points of focus. Published free by the AICPA. Everything this site says about what SOC 2 is comes from here.
Governs who may issue a SOC 2 report and how a CPA firm may provide nonattest services to an attest client. A SOC 2 report is issued by a CPA firm licensed by a state board of accountancy and subject to AICPA peer review. The AICPA does not accredit firms, and this site does not say that it does.
The seven GRC vendors priced on this site publish full annual list prices here, per dimension, in US dollars, including the separate per-framework line items several of them bill on top of the platform subscription. Each figure is read off the listing and carries the date it was checked. This is the only place their list prices are published in full: most of the vendors' own pricing pages name tiers without prices.
The individual vendor listings, checked 15 July 2026: Sprinto, Scytale, Vanta, Secureframe, Scrut, Strike Graph, Drata.
The model, in full
Nobody publishes SOC 2 audit fees. Not the Big 4, not the mid-tier firms, not the boutiques. Readiness consultants do not publish day rates. There is no register and no filing. So this site does not print a market rate. It publishes a model instead, and the model works bottom-up: it assumes an hour or day count from your scope, you supply the rates, and the total is the arithmetic of the two. Nothing is reverse-engineered from a headline figure.
Every assumption below is ours. None is an observed market figure, and none should be quoted as one. They are listed so you can disagree with any of them and re-run the sum yourself.
Assumed from the company size band for a Type 2 with Security only in scope, as a wide range, because the real spread is wide. Scope and audit type then adjust it.
A Type 1 is assumed to take 60 percent of the Type 2 hours for identical scope, because it has no observation window and no sample testing. Running a Type 1 then a Type 2 in one year is assumed to take 145 percent, sharing the planning and walkthrough work rather than repeating it. This single factor is why the site quotes one Type 1 to Type 2 relationship everywhere rather than a different one per page.
Each optional criterion is assumed to add between 10 and 25 percent to auditor hours. This is deliberately a bracket rather than a single percentage. Adding a criterion adds controls to test, so it adds hours; how many depends on the criterion, the environment and the firm, and no published figure exists. The model widens its range as scope grows instead of asserting a precision it does not have.
Assumed from the company size band, then adjusted by maturity. A mature programme does not make the auditor's testing cheaper, so maturity is applied to readiness and internal time only, never to the audit fee.
Assumed from the size band, adjusted by maturity, and reduced to 60 percent where a GRC platform is in the scenario, on the basis that automation absorbs the evidence-collection rhythm but not the judgement work.
The model applies none. Platforms market a reduction in audit fees and it is plausible that well-organised evidence saves auditor hours, but no firm publishes a platform discount, so the model does not invent one. If your auditor offers one in writing, subtract it yourself.
The audit repeats in full, because SOC 2 has no surveillance audit. Readiness drops out. The platform renews at whatever you are paying. Internal time falls to 50 percent of year 1, because the evidence rhythm already exists.
£190 per hour blended for the auditor, £75 per hour fully loaded for internal time, and £900per day for readiness consultancy. All three are starting points meant to be overwritten. The auditor rate in particular: divide your engagement letter's fee by its quoted hours and use that, because it is the only auditor rate that can be verified.
The model works in pounds. The published platform prices are US dollars, as the vendors publish them. The two are never mixed and nothing is converted, which is why the calculator asks you to enter your platform contract in pounds rather than doing the exchange arithmetic for you. An FX-converted figure presented as a vendor's price would be our arithmetic carrying their name.
What we do not publish
- · Audit-firm fee tables by tier. No firm publishes fees, so any such table is an estimate presented as data.
- · Auditor rate cards by grade. Firm rates are confidential. A partner-manager-senior-staff grid implies a precision nobody outside the engagement has.
- · Big 4 SOC 2 pricing. It is not published anywhere, by anyone.
- · A single control-overlap percentage between SOC 2 and ISO 27001. Published mappings disagree wildly depending on method, so there is no one number to give.
- · Bundle or concurrent-engagement discount percentages, or year-over-year fee ratios. Both are derived from data that does not exist publicly.
- · Summed vendor totals presented as published prices. Where two published dimensions are added, the sum is labelled as our arithmetic, because AWS publishes the dimensions and publishes no combined figure.
- · Exchange-rate conversions of vendor list prices.
Update cadence
Figures update when the underlying reality changes. There are no cosmetic date bumps. The triggers:
- · A vendor changes a published SKU on its AWS Marketplace listing.
- · A material change to AICPA SOC 2 attestation standards.
- · A material change to the Trust Services Criteria.
- · A change to any assumption in the model above.
- · A correction we receive and verify.
The published platform prices carry the date they were last read off the listing, currently 15 July 2026. AWS Marketplace shows no price-effective date, so that checked-on date is the strongest claim available and it travels with every figure. Substantive updates are logged on the updated page.
What we do not do
- · Take referral or affiliate fees from GRC platforms or audit firms.
- · Recommend a specific GRC platform by name.
- · Sell SOC 2 services or attestation work.
- · Gate the calculator behind an email signup.
- · Run display advertising on cost-reference pages.
Author and contact
soc2certificationcost.com is compiled by Digital Signet, an independent research practice. Corrections are welcome and taken seriously: if a figure here is wrong, or a vendor has changed a published price, tell us and we will check the listing and log the change. Contact hello@digitalsignet.com. Inquiries are answered by a person, not a chatbot, within five working days.