Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How much does SOC 2 cost, and what drives the price?
Last verifiedCost has four parts: the CPA firm's examination fee, readiness and tooling, technical testing such as a penetration test, and internal time. Scope, the number of criteria categories, organisation size, and evidence maturity move each one. Only a firm's proposal is a price; nothing here is a quote.
How much SOC 2 costs, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
This is the cost structure, not YOUR price
Audience: a budget owner, founder, or compliance owner building a number for a board or a plan. This page names the drivers and separates one-time from recurring cost. It publishes no dollar figure as a fact, because a published figure presented as typical is a fabricated quote — the only price that exists is the one a licensed CPA firm puts in a proposal for your scope.
SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report, so none of this spend is a legal obligation. It is an investment tied to revenue you can name. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, and the Type I costs less — but a Type I that a buyer will not accept is the most expensive option on this page.
"SOC 2 certified" is a misnomer — there is no SOC 2 certificate being purchased. What you buy is an examination and the report that follows. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor, and its cost is not the examination fee. Last verified 10 September 2026. Not legal advice.
The four cost buckets
Ranges are given as order-of-magnitude bands and labelled market observation. They are what buyers of these services commonly report seeing, not a quote, not an average we computed, and not a promise.
| Bucket | What you are paying for | One-time or recurring | Kind of text |
|---|---|---|---|
| CPA firm examination fee | Planning, walkthroughs, testing, and the report. Commonly quoted in the low-to-mid five-figure range in US dollars for a first Type II at a small technology company, and materially higher as scope, criteria categories, entities, or locations grow. | Recurring — an annual examination is the normal rhythm once buyers rely on the report. | Market observation — bands only. Only the firm's proposal is a price. |
| Readiness and tooling | Gap assessment, advisory, and compliance-automation platform subscription. Commonly four to five figures annually depending on organisation size and how much advisory you buy. | Mixed — advisory is often one-time, platform subscription is recurring. | Market observation for the band; buying tooling is an SRM recommendation, never a requirement. |
| Technical testing | Penetration testing and related assessments, commonly expected by buyers and often used as evidence within the examination. | Recurring where you commit to an annual cadence. | Best practice and market observation — no attestation standard requires a penetration test. |
| Internal time | Engineering, IT, and compliance hours for remediation, evidence, walkthroughs, and the request list. Usually the largest real cost and the one least often budgeted. | Heavy one-time in the first cycle, lighter but real every year after. | Market observation — and the reason evidence automation is argued for on cost grounds. |
What moves the number
These are the variables a firm asks about before quoting. Knowing your answers shortens the proposal cycle and prevents a scope surprise mid-engagement.
- Report type. A Type I is cheaper than a Type II; a Type II is what most enterprise buyers expect. Market observation.
- Number of criteria categories. The common criteria are always in scope; each of Availability, Confidentiality, Processing Integrity, and Privacy added brings more criteria, more evidence, and more testing. Trust Services Criteria reference.
- System boundary. More products, environments, regions, or legal entities means more populations and more testing.
- Organisation size and headcount churn. Joiners and leavers drive the access populations that dominate sample counts.
- Subservice organisations, and whether they are carved in or carved out. Carve-in expands testing.
- Evidence maturity. A team producing dated evidence from systems of record costs a firm less effort than one reconstructing it, and firms price effort.
- Whether readiness work is bought from the same organisation, and whether independence forces a second firm. Attestation-standard requirement — independence is not optional.
- Repeat cycles. Second-year examinations commonly cost less internal time than the first, though the firm's fee does not usually drop much. Market observation.
One-time versus recurring
Boards approve a first-year number and then discover the annual one. Separate them from the start.
- One-time, first cycle: gap assessment, policy authorship, control implementation, the initial engineering remediation effort, and tool onboarding.
- Recurring annually: the examination fee, tooling subscription, technical testing if you commit to a cadence, access reviews and vendor reviews, training, and the internal time to support fieldwork.
- Recurring but invisible: keeping the observation period evidenced. This is where teams either spend a little continuously or a lot in a scramble. Market observation.
- Sometimes recurring, sometimes not: a bridge letter for buyers reviewing between report periods costs little but takes leadership attention.
- Not a cost of SOC 2, though frequently bundled into the same budget line: regulatory compliance work such as HIPAA or PCI DSS obligations, which exist independently of any SOC 2 decision.
Kinds of text on this page
Different sentences here carry different weight, and on this page the distinction matters most: every number is observation, never a quote.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination, including independence. | Not a statute, and it says nothing about price. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | Spend that experienced teams treat as worthwhile, such as technical testing. | Not required by any attestation standard. Skipping it is not an exception. |
| Market observation | Every band and range on this page — what buyers of these services commonly report seeing. | Not a quote, not an average we computed, not a guarantee, and not a promise about YOUR proposal. |
| SRM recommendation | Something this product suggests, including buying evidence automation. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
Get real numbers instead of estimates. Three proposals against a written scope beat any published range, including the bands on this page.
- Write the scope down first: report type, criteria categories, system boundary, entities, and subservice organisations. Firms quote scope, not intentions.
- Get proposals from at least three licensed CPA firms against that identical scope, and verify each licence with the relevant state board of accountancy.
- Ask each firm what would change the fee mid-engagement, and get that answer in writing.
- Budget internal time explicitly, in hours per team. It is the cost most often missing from the board slide.
- Separate first-year from annual cost in the budget line, and say so out loud when presenting it.
- Drop optional criteria categories no customer requires. That is the cheapest cost reduction available.
- Do not buy tooling expecting it to remove the examination fee. Only a licensed CPA firm can perform the examination and issue the report.
Checklist
A budget-readiness list, labelled by kind of text. Not a quote.
- Scope written down before requesting proposals? Attestation-standard requirement that scope be defined; writing it first is best practice.
- At least three proposals against identical scope? Best practice.
- Each firm's licence verified with the relevant board? Licensing requirement — the board's rules govern.
- Optional criteria categories justified by a named customer requirement? Trust Services Criteria reference.
- Internal hours budgeted per team, not assumed? Market observation — the most commonly missed line.
- First-year and recurring costs shown separately? Best practice.
- Technical testing cadence decided and priced? Best practice — not an attestation requirement.
- Nobody expecting tooling to replace the examination fee? Attestation-standard requirement — tooling is not the attestor.
Where this shows up in ShipReady Metrics
This product is in the readiness-and-tooling bucket above, and it is honest about which cost it affects. It does not reduce the CPA firm's fee, which is set by scope and effort. What evidence automation plausibly reduces is internal time — the largest and least-budgeted bucket — by collecting artefacts continuously instead of assembling them under deadline. We do not publish a saving figure, because a specific percentage would be a fabricated statistic.
If you already have a session: the bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set that is an illustrative readiness mapping to be tailored by a compliance owner. Evidence collection, evidence review with the met-verdict overlay, the policies library, the 24-framework crosswalk (criteria series references only, no Trust Services Criteria text reproduced), connector-sourced evidence, ShipReady Passport with the auditor share token, and the cyber risk register are the surfaces that carry that work. Pricing for this product is published on the pricing page and is not part of any examination fee.
Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
Scope drivers come from the AICPA sources below. Every band on this page is labelled market observation, and no figure here is a quote, an average, or a guarantee.
AICPA Trust Services Criteria, TSP section 100 — 2017 criteria with the 2022 revised points of focus, which determine how many criteria are in scope and therefore how much testing exists. Proprietary AICPA material: cited by reference and paraphrased, never reproduced. AICPA attestation standards SSAE 18, AT-C sections 105 and 205, including independence, which can force a second firm and therefore a second fee. AICPA SOC 2 guidance for service organisations. Cost bands are attributed to common market practice as reported by buyers of these services, not to the AICPA, which does not publish prices. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.