SOC 2 readiness: what you are actually paying for.
Three things buyers conflate
When a vendor or consultant quotes a "readiness fee", they are pricing one or more of three distinct workstreams. Recognising which is the most useful budget skill on this page, because it is what lets you compare two quotes that look nothing alike.
| Workstream | What it produces | How it is priced |
|---|---|---|
| Gap analysis | Controls inventory, gap log with severity ratings. No roadmap, no evidence map. | Often included in a GRC platform subscription. Sold standalone by consultants as a short engagement. |
| Readiness assessment proper | The gap log, plus an evidence map, a recommended remediation order, and a timeline that fits inside the audit window. | A scoped consultancy engagement, quoted in days. Day rates are not published by anyone. |
| Remediation engagement | Hands-on work: policy authoring, control build, evidence collection set up and running. | Quoted only once the gap log exists, because nobody can size it before then. Usually the largest of the three. |
GRC platforms usually include the gap analysis. They sometimes include a light readiness assessment. They almost never include serious remediation work, which sits with the platform's partner consultant network and is priced separately. A platform quote and a consultancy quote are therefore rarely comparable without unpicking which of the three each one covers.
What a readiness deliverable should contain
A defensible readiness deliverable is not a slide deck. It is a controls inventory listing every Trust Services Criterion in scope and the corresponding control. It is a gap log with severity rated against the audit firm's expected criteria. It is an evidence map showing where each piece of evidence will live and how it will be collected. It is a recommended remediation order, prioritised by audit risk, and a calendar timeline that fits inside the audit window.
If the deliverable lacks the evidence map, the engagement was a gap analysis dressed as readiness. If it lacks the remediation order, the consultant is handing the prioritisation problem back to you, which is the part you were paying them for. Press for both before signing a readiness SOW, and the quote will tell you what it really covers.
The remediation problem
Remediation is where readiness budgets break, and the reason is structural rather than commercial: it cannot be sized until the gap log exists, and the gap log is the output of the engagement you have already bought. So the largest of the three workstreams is the one you commit to knowing least about.
What drives it is existing maturity, and the spread is enormous. A team with no formal controls, no policies and ad-hoc access management is building the entire control set from scratch: policies, access reviews, change management, vendor management, incident response. A team with an existing security programme, or a prior ISO 27001, is mostly doing mapping and evidence work, because the controls already exist and the only question is whether they are auditable. Those two are not variations of the same engagement.
What teams underestimate
Re-readiness after remediation is often cut for economy. It is the wrong line item to cut. Controls that were remediated on paper but are not operating end to end are exactly what a Type 2 tests for, and surprise findings in the audit cost more in calendar time than a re-readiness pass costs in cash. Build a small re-readiness budget into the readiness SOW from the start, and use it.
The internal half is also missed. Readiness is not something done to you by a consultant: every gap closed is someone internal writing a policy, changing a process, or standing up a review that has never happened before. The consultant's days are the visible cost. Your team's hours are the larger one.
Where the readiness work is heavier on the Type 2 path, see the Type 1 vs Type 2 page. Where platform-included readiness is the right call, see the GRC platforms page. Where scope drives the gap count, see the Trust Services Criteria page.