Independent reference.Not affiliated with the AICPA or any audit firm.See methodology.
Pillar / Budget sanity check by company size

SOC 2 cost for scale-ups: Series B and beyond.

At 100 to 500 employees, SOC 2 is neither optional nor new. The cost question stops being "how much" and becomes what scope, what auditor tier, and what concurrent standards. It also stops tracking headcount: at this size the fee is driven by how complicated you are, not how many people you employ.
Section 01

Headcount is the wrong variable

The instinct at this stage is to budget SOC 2 as a function of company size. It is a poor predictor. A 400-person company running one product on one cloud account with one security team is a simpler audit than a 120-person company with three acquired subsidiaries, two clouds and a dozen vendors holding customer data. The auditor is testing controls across an environment, and the environment is what scales.

The drivers that actually move the number at scale-up size are the number of legal entities in scope, the number of regions and cloud estates, the number of in-scope services, the number of vendors with material data access, and the Trust Services Criteria you have agreed to. Each of those adds auditor hours, and hours are the fee. None of it is published by any firm, which is why this page carries no bracket table: a fee band by headcount would be inventing a relationship that does not hold in the first place.

Section 02

Multi-entity scoping

A holding company with multiple operating entities, multiple products under separate brands, or international subsidiaries faces a scoping decision before it faces a pricing one. There are three workable patterns, and the choice between them moves the cost more than any negotiation will.

Single combined report covering all entities under one parent engagement. The cost-efficient option where entities genuinely share infrastructure and management, because the shared controls are tested once. Each additional entity still brings its own walkthroughs and control owner interviews, so it is cheaper than separate reports rather than free.

Separate reports per entity. Necessary where entities operate under different brands and serve different customer bases. Each report carries its own full engagement, so this is close to paying for two audits and should be chosen for a commercial reason rather than defaulted into.

Carve-out method, with one parent report and named entities excluded. Useful where some entities are genuinely out of scope: a different jurisdiction, a different product, a recent acquisition not yet integrated. The carve-out has to be documented in the report and accepted by your customers, which is the catch. Complex carve-outs are a common source of unbudgeted cost, because the documentation and the customer conversations both take longer than anyone plans.

Section 03

Concurrent-standard pattern

At scale-up size, SOC 2 is rarely the only standard pursued. ISO 27001 follows for international customers, GDPR obligations come with EU customers, HIPAA with US healthcare, PCI DSS where card payments are processed. Running them as one programme costs less than running them one after another, because the control sets overlap and the evidence is largely the same evidence.

The saving is conditional, and the conditions are where it usually fails. The engagements have to be run as one programme rather than two. Readiness has to be a single workstream. The platform, if there is one, has to support both. Where a GRC platform is involved the multi-framework economics are visible in the published prices: the marginal listed cost of a second framework is small next to the first, and in some packaged tiers it is nothing at all. That part is on the GRC platforms page, where the figures are real.

Section 04

What scale-ups consistently get right

Multi-year budgets. Scale-up finance teams approve three-year compliance budgets rather than annual ones, which is the correct frame for a standard that re-audits in full every year. Surprise year-3 spend is rare in companies that budget this way.

Auditor relationships. By Series B, most scale-ups have a named partner who has run their SOC 2 across several cycles. That continuity is worth real money: the firm already understands the environment, and scope-creep conversations happen early instead of arriving as a change order in month eight.

Section 05

What they get wrong

Scope drift across entities. The subsidiary acquired in year 2 is not in the year-1 scope statement, and nobody notices until a customer asks whether it is covered. Re-scoping mid-cycle is the expensive way to find out.

Treating the compliance programme as separable line items. Fintech and payments scale-ups in particular run SOC 2 alongside KYC, AML, GDPR and often PCI DSS, and the same evidence, the same vendor reviews and the same policies serve several of them. Budgeting each as an independent programme both overstates the total and understates the coordination work.

Cross-reference

For why no fee table appears on this site, and what to ask a firm instead, see the audit firm fees page. For the GRC platform prices that are genuinely published, see the GRC platforms page. For the concurrent SOC 2 and ISO 27001 decision, see the SOC 2 vs ISO 27001 page.

Section 06

FAQ

When does SOC 2 require Big 4 instead of mid-tier CPA?+
Only where downstream buyers explicitly require it: tier-one banks, defence and intelligence, certain regulated insurers, and a small subset of listed-enterprise procurement. Outside those, mid-tier and boutique firms issue the same attestation under the same AICPA standards, and the report is not a lesser instrument for it. No firm at any tier publishes its fees, so the premium cannot be quoted at you as a fact. Get quotes from both tiers on identical scope and you will have your own answer.
How does multi-entity scope change the cost?+
Each additional entity brings its own walkthroughs, its own control owner interviews and its own sample testing, so it adds auditor hours rather than a percentage surcharge. How many depends on whether the entities share infrastructure and management: two entities on one platform with one security team are close to one audit, and two genuinely separate businesses are close to two. Multi-entity scope is also where Big 4 process discipline starts to earn its premium.
Should scale-ups run SOC 2 alongside ISO 27001?+
For most scale-ups with international customers, yes, and the reason is that the control sets overlap heavily enough that readiness, evidence and policies can be shared. The saving is real but it is not automatic: it depends on running one programme rather than two, and it evaporates if two firms run separate engagements to separate calendars. No firm publishes a bundle discount, so ask for both quotes, combined and separate.
Is there a SOC 2 cost benefit at scale?+
Per-employee cost falls, because the audit fee does not scale with headcount. Much of the work is fixed: the control set is the control set whether you have 50 people or 500. What does scale is complexity, and complexity is the thing that grows faster than headcount at this stage: more entities, more regions, more in-scope services, more vendors with data access. That is why absolute cost still rises and gets harder to forecast, not easier.

Updated 2026-07-15