Cost guide
How much does SOC 2 cost?
For a 5 to 100 person AWS-native SaaS startup, a first SOC 2 costs roughly $20,000 to $25,000 all-in through us, against a market where the same outcome commonly runs $30,000 to $65,000. The spread is not about the audit fee. It is about who does the remediation work and whether that cost is quoted or absorbed by your engineering team.
The full picture in one table
| Line item | Typical market range | With Aidaptive | Paid to |
|---|---|---|---|
| Readiness or gap assessment | $5,000 to $25,000 | $2,500, credited toward readiness | Readiness provider |
| Remediation and readiness delivery | $10,000 to $75,000, usually hourly | From $10,000, fixed, quoted with your gap report | Readiness provider |
| The SOC 2 examination | $12,000 to $30,000 commonly published; small AWS startups sit well below it | Typically $5,000 to $10,000 through partner firms | The CPA firm, directly |
| Penetration test | $5,000 to $15,000 | Partner-provided, contracted client-direct | The testing firm |
| Compliance platform | Varies widely by headcount and discount | Optional. We work alongside whatever you have | The platform |
| Type 2 window support | Usually hourly or out of scope | From $1,000/month for the window | Readiness provider |
| Your engineering time | Rarely quoted. Commonly 0.25 to 0.5 FTE for 3 to 6 months | Ticketed, bounded, and scheduled | Your payroll |
Every row above except the last is cash. The last row is the one that quietly doubles the real cost. A quarter to a half of an engineer for three to six months, at loaded cost, is $20,000 to $50,000 of capacity that was going to ship product. Any comparison that omits it is not a comparison.
What the audit itself costs
The examination fee is what a licensed CPA firm charges to perform the attestation and issue the report. For a small AWS-native SaaS company with the Security category in scope, that fee is typically $5,000 to $10,000 through the firms we work with. A combined Type 1 and Type 2 arrangement usually costs less than the two purchased separately.
Published ranges are higher, often $12,000 to $30,000, for three reasons that all matter when you read a comparison article:
- Scope. Adding Availability, Confidentiality, Processing Integrity, or Privacy adds criteria the auditor must test. A Security-only report is the cheapest report there is.
- Size and complexity. More employees means larger populations to sample. More systems means more control points. A 12-person company on one AWS account is a very different engagement from a 300-person company with acquisitions.
- Firm tier. A national brand charges brand pricing. For a seed-stage SaaS company selling to mid-market buyers, a competent regional firm with peer review in good standing produces a report that reads identically to the customer.
Two things the audit fee does not include: readiness work (the auditor cannot do it and stay independent, see readiness vs the audit), and remediation of anything they find.
What readiness costs, and why it varies most
Readiness is where the money and the variance live, because it is where the actual work is. The market splits into four shapes:
| Model | Cost shape | What you are really buying |
|---|---|---|
| Compliance platform alone | Annual subscription | Monitoring and templates. The work stays with your team |
| Hourly consultant | $150 to $400 per hour, projects $10,000 to $75,000 | Advice, and an estimate that is not a commitment |
| Fixed-price readiness | A number agreed before work starts | Transferred risk. The provider absorbs their own estimation error |
| All-in-one (readiness plus audit, one firm) | ~$15,000 to $40,000 bundled | Simplicity, at the cost of independence your enterprise buyers may question |
Our number is from $10,000, fixed, quoted after we have scanned your environment and not before. That sequencing is the point. A fixed price quoted without a scan is either padded to cover the worst case or is going to become a change order in week five.
What actually drives your number
- How many of the 35 controls fail, from the controls checklist. Eight or fewer is a clean profile. Seventeen or more is scoped individually.
- How many failures need application changes rather than infrastructure we deploy alongside you. These carry ticket, wait, and rescan cycles, and they carry all of the schedule risk.
- Whether you have infrastructure-as-code. A click-ops estate with no source of truth costs more to remediate and much more to evidence.
- How many non-AWS critical tools you run. Each one needs SSO, MFA, access reviews, and offboarding coverage, and the ones that do not integrate become manual evidence for the whole window.
- Whether anything requires a retrofit. Encryption-at-rest on existing production stores, or an AWS account restructure. Either one is a project with a maintenance window, and any honest provider re-scopes rather than swallowing it.
The costs nobody quotes you
- Engineering hours. The big one. Even with a provider doing the heavy lifting, your engineers apply the application-level fixes. Budget real sprint capacity for it rather than evenings.
- The observation window. Type 2 requires evidence across three to twelve months. Access reviews, policy re-approvals, tabletop exercises, and evidence collection all have to actually happen on schedule. Skip a quarter and you cannot backfill it.
- Security questionnaires. Once you have a report, customers send questionnaires. They arrive at your CTO by default. Ours are scope-capped at two per quarter, then a $400 flat fee each, never hourly, so the cost is knowable in advance.
- Additional AWS spend. Modest but real: CloudTrail data events, AWS Config recording, GuardDuty, VPC flow log storage, AWS Backup. Usually tens to low hundreds of dollars a month for a small estate, not thousands.
- Penetration testing. Not required by SOC 2. Frequently required by your customer's security questionnaire, which means it is a sales cost that shows up on the compliance budget.
- The renewal. A SOC 2 report covers a period and then expires from a buyer's perspective. This is an annual program, not a project.
Year two and beyond
Year two is materially cheaper. The controls exist, the policies exist, the baseline is deployed, and the evidence pipeline runs. What remains:
| Ongoing item | Cadence | With Aidaptive |
|---|---|---|
| The annual examination | Once per report period | Paid to the CPA firm, typically similar to year one |
| Evidence collection and cadence execution | Continuous | Steady-State Maintenance, from $1,000/month |
| Access reviews | Quarterly | Facilitated, records produced |
| Risk assessment, tabletop, policy re-approvals | Annual | Included in the retainer |
| Bridge letters between report periods | On request | Included |
| Security questionnaires | As customers send them | Two per quarter included, then $400 flat each |
How to compare quotes without being fooled
Normalize every quote to total spend until a report is in a customer's hands, then ask five questions:
- Is the readiness price fixed, and was it quoted after a scan? A number quoted from a sales call is a guess. A number quoted after a scan is a commitment.
- Who applies the fixes? If the answer is "we advise, you implement", the engineering line is yours and belongs in the comparison.
- Is the audit fee included, and is it the same firm? If one firm does both readiness and the examination, ask how they handle independence, and expect your enterprise customers to ask the same.
- What happens in the observation window? Readiness that ends at Type 1 leaves the harder half undone.
- What is out of scope? Ours: multi-cloud, on-premise estates, HIPAA and FedRAMP bundles, Privacy, and Processing Integrity. A provider with no exclusions list has not thought about it, or is not telling you.
Frequently asked questions
How much does a SOC 2 audit cost?
The examination itself, paid to the CPA firm, typically runs $5,000 to $10,000 for a small AWS-native startup through our partner firms. Published ranges run higher because they average in larger companies and broader scope. The audit fee is usually the smaller half of the total; readiness and remediation is the larger.
What is the total first-year cost?
Around $20,000 to $25,000 all-in with us: $2,500 gap assessment credited toward readiness from $10,000, the audit at $5,000 to $10,000 paid directly to the CPA firm, and Type 2 window support from $1,000 per month. Assembling the same outcome from hourly consultants and audit shopping commonly runs $30,000 to $65,000.
Why do published SOC 2 cost estimates vary so much?
They measure different things. Some quote only the audit fee, some include a platform subscription, and almost none include internal engineering time. Ranges also average across company sizes and scopes that have little to do with a seed-stage AWS SaaS company.
Can we do SOC 2 without spending anything on outside help?
You can do the readiness yourself. You cannot do the examination yourself: it requires a licensed CPA firm, and that fee is unavoidable. Doing readiness internally is a real option if you have a security-experienced engineer and no deadline pressure. It usually costs three to six months of elapsed time and a meaningful slice of that engineer, which is exactly the trade the deal on your desk is asking you to make.
Do you charge hourly for anything?
No. Fixed or flat only, everywhere. The gap assessment is $2,500. Readiness is a fixed number quoted with your gap report. Retainers are monthly. Extra security questionnaires beyond the included two per quarter are $400 flat each. There is no hourly rate to discover later.
Get a real number instead of a range
The $2,500 gap assessment scans your environment against all 35 controls and returns a fixed readiness quote with the gap report. Credited in full toward the engagement. If we are not a fit, you keep the report and the quote costs you nothing further.
Book a 30-minute scoping callWe name every cost in your journey up front, including the ones paid to other firms.