Independent reference.Not affiliated with the AICPA or any audit firm.See methodology.
Pillar / Real cost drivers (pre-audit)

SOC 2 readiness: what you are actually paying for.

Most readiness quotes mix three different things into one number: gap analysis, readiness assessment proper, and the remediation engagement. They are not the same work, they are not the same size, and the third one is usually the largest and the least discussed. Consultants quote per engagement and publish nothing, so the useful skill here is not knowing a price. It is knowing what you are buying.
Section 01

Three things buyers conflate

When a vendor or consultant quotes a "readiness fee", they are pricing one or more of three distinct workstreams. Recognising which is the most useful budget skill on this page, because it is what lets you compare two quotes that look nothing alike.

WorkstreamWhat it producesHow it is priced
Gap analysisControls inventory, gap log with severity ratings. No roadmap, no evidence map.Often included in a GRC platform subscription. Sold standalone by consultants as a short engagement.
Readiness assessment properThe gap log, plus an evidence map, a recommended remediation order, and a timeline that fits inside the audit window.A scoped consultancy engagement, quoted in days. Day rates are not published by anyone.
Remediation engagementHands-on work: policy authoring, control build, evidence collection set up and running.Quoted only once the gap log exists, because nobody can size it before then. Usually the largest of the three.

GRC platforms usually include the gap analysis. They sometimes include a light readiness assessment. They almost never include serious remediation work, which sits with the platform's partner consultant network and is priced separately. A platform quote and a consultancy quote are therefore rarely comparable without unpicking which of the three each one covers.

Section 02

What a readiness deliverable should contain

A defensible readiness deliverable is not a slide deck. It is a controls inventory listing every Trust Services Criterion in scope and the corresponding control. It is a gap log with severity rated against the audit firm's expected criteria. It is an evidence map showing where each piece of evidence will live and how it will be collected. It is a recommended remediation order, prioritised by audit risk, and a calendar timeline that fits inside the audit window.

If the deliverable lacks the evidence map, the engagement was a gap analysis dressed as readiness. If it lacks the remediation order, the consultant is handing the prioritisation problem back to you, which is the part you were paying them for. Press for both before signing a readiness SOW, and the quote will tell you what it really covers.

Section 03

The remediation problem

Remediation is where readiness budgets break, and the reason is structural rather than commercial: it cannot be sized until the gap log exists, and the gap log is the output of the engagement you have already bought. So the largest of the three workstreams is the one you commit to knowing least about.

What drives it is existing maturity, and the spread is enormous. A team with no formal controls, no policies and ad-hoc access management is building the entire control set from scratch: policies, access reviews, change management, vendor management, incident response. A team with an existing security programme, or a prior ISO 27001, is mostly doing mapping and evidence work, because the controls already exist and the only question is whether they are auditable. Those two are not variations of the same engagement.

Section 04

What teams underestimate

Re-readiness after remediation is often cut for economy. It is the wrong line item to cut. Controls that were remediated on paper but are not operating end to end are exactly what a Type 2 tests for, and surprise findings in the audit cost more in calendar time than a re-readiness pass costs in cash. Build a small re-readiness budget into the readiness SOW from the start, and use it.

The internal half is also missed. Readiness is not something done to you by a consultant: every gap closed is someone internal writing a policy, changing a process, or standing up a review that has never happened before. The consultant's days are the visible cost. Your team's hours are the larger one.

Where the readiness work is heavier on the Type 2 path, see the Type 1 vs Type 2 page. Where platform-included readiness is the right call, see the GRC platforms page. Where scope drives the gap count, see the Trust Services Criteria page.

Section 05

FAQ

What is the difference between a gap analysis and a readiness assessment?+
A gap analysis is a controls-inventory review that identifies what is missing or weak. A readiness assessment is a more structured engagement: the gap analysis plus a remediation roadmap, an evidence map, and a recommended remediation order. GRC platforms usually include the gap analysis in the subscription. The distinction matters commercially, because the two are quoted as if they were the same thing and they are not.
Can the audit firm do the readiness?+
Yes, subject to safeguards, and many CPA firms sell readiness assessments openly. Under the AICPA Code of Professional Conduct, readiness work is a nonattest service. The Code permits nonattest services for an attest client provided the client assumes all management responsibilities, designates an individual with suitable skills, knowledge and experience to oversee the work, evaluates the adequacy and results of it, and accepts responsibility for the outcome. The understanding has to be documented in writing before the work begins. The firm also has to manage the self-review threat, since it cannot rely on its own recommendations as audit evidence. Ask a firm how it handles those safeguards rather than assuming the arrangement is closed to you.
How long does a SOC 2 readiness assessment take?+
Standalone readiness typically runs 4 to 8 weeks for a small to mid-sized SaaS, depending on how much documentation already exists. Platform-led readiness compresses because much of the inventory work is automated. Remediation afterwards is the variable one: it runs from a few weeks to a couple of quarters depending entirely on the size of the gap, which is the thing you do not know until the gap log exists.
Should we re-assess after remediation?+
Yes, even briefly. A re-readiness pass before audit fieldwork catches the controls that were remediated on paper but are not operating end to end, which is a distinction the auditor will certainly make. It is a small engagement next to the cost of surprise findings in the audit itself, and it is the wrong line item to cut for economy.

Updated 2026-07-15