Home/SOC 2 cost

Cost guide

How much does SOC 2 cost?

For a 5 to 100 person AWS-native SaaS startup, a first SOC 2 costs roughly $20,000 to $25,000 all-in through us, against a market where the same outcome commonly runs $30,000 to $65,000. The spread is not about the audit fee. It is about who does the remediation work and whether that cost is quoted or absorbed by your engineering team.

Updated 17 August 20269 min readFigures in USD

The full picture in one table

Line itemTypical market rangeWith AidaptivePaid to
Readiness or gap assessment$5,000 to $25,000$2,500, credited toward readinessReadiness provider
Remediation and readiness delivery$10,000 to $75,000, usually hourlyFrom $10,000, fixed, quoted with your gap reportReadiness provider
The SOC 2 examination$12,000 to $30,000 commonly published; small AWS startups sit well below itTypically $5,000 to $10,000 through partner firmsThe CPA firm, directly
Penetration test$5,000 to $15,000Partner-provided, contracted client-directThe testing firm
Compliance platformVaries widely by headcount and discountOptional. We work alongside whatever you haveThe platform
Type 2 window supportUsually hourly or out of scopeFrom $1,000/month for the windowReadiness provider
Your engineering timeRarely quoted. Commonly 0.25 to 0.5 FTE for 3 to 6 monthsTicketed, bounded, and scheduledYour payroll
The line that decides everything

Every row above except the last is cash. The last row is the one that quietly doubles the real cost. A quarter to a half of an engineer for three to six months, at loaded cost, is $20,000 to $50,000 of capacity that was going to ship product. Any comparison that omits it is not a comparison.

What the audit itself costs

The examination fee is what a licensed CPA firm charges to perform the attestation and issue the report. For a small AWS-native SaaS company with the Security category in scope, that fee is typically $5,000 to $10,000 through the firms we work with. A combined Type 1 and Type 2 arrangement usually costs less than the two purchased separately.

Published ranges are higher, often $12,000 to $30,000, for three reasons that all matter when you read a comparison article:

  • Scope. Adding Availability, Confidentiality, Processing Integrity, or Privacy adds criteria the auditor must test. A Security-only report is the cheapest report there is.
  • Size and complexity. More employees means larger populations to sample. More systems means more control points. A 12-person company on one AWS account is a very different engagement from a 300-person company with acquisitions.
  • Firm tier. A national brand charges brand pricing. For a seed-stage SaaS company selling to mid-market buyers, a competent regional firm with peer review in good standing produces a report that reads identically to the customer.

Two things the audit fee does not include: readiness work (the auditor cannot do it and stay independent, see readiness vs the audit), and remediation of anything they find.

What readiness costs, and why it varies most

Readiness is where the money and the variance live, because it is where the actual work is. The market splits into four shapes:

ModelCost shapeWhat you are really buying
Compliance platform aloneAnnual subscriptionMonitoring and templates. The work stays with your team
Hourly consultant$150 to $400 per hour, projects $10,000 to $75,000Advice, and an estimate that is not a commitment
Fixed-price readinessA number agreed before work startsTransferred risk. The provider absorbs their own estimation error
All-in-one (readiness plus audit, one firm)~$15,000 to $40,000 bundledSimplicity, at the cost of independence your enterprise buyers may question

Our number is from $10,000, fixed, quoted after we have scanned your environment and not before. That sequencing is the point. A fixed price quoted without a scan is either padded to cover the worst case or is going to become a change order in week five.

What actually drives your number

  • How many of the 35 controls fail, from the controls checklist. Eight or fewer is a clean profile. Seventeen or more is scoped individually.
  • How many failures need application changes rather than infrastructure we deploy alongside you. These carry ticket, wait, and rescan cycles, and they carry all of the schedule risk.
  • Whether you have infrastructure-as-code. A click-ops estate with no source of truth costs more to remediate and much more to evidence.
  • How many non-AWS critical tools you run. Each one needs SSO, MFA, access reviews, and offboarding coverage, and the ones that do not integrate become manual evidence for the whole window.
  • Whether anything requires a retrofit. Encryption-at-rest on existing production stores, or an AWS account restructure. Either one is a project with a maintenance window, and any honest provider re-scopes rather than swallowing it.

The costs nobody quotes you

  1. Engineering hours. The big one. Even with a provider doing the heavy lifting, your engineers apply the application-level fixes. Budget real sprint capacity for it rather than evenings.
  2. The observation window. Type 2 requires evidence across three to twelve months. Access reviews, policy re-approvals, tabletop exercises, and evidence collection all have to actually happen on schedule. Skip a quarter and you cannot backfill it.
  3. Security questionnaires. Once you have a report, customers send questionnaires. They arrive at your CTO by default. Ours are scope-capped at two per quarter, then a $400 flat fee each, never hourly, so the cost is knowable in advance.
  4. Additional AWS spend. Modest but real: CloudTrail data events, AWS Config recording, GuardDuty, VPC flow log storage, AWS Backup. Usually tens to low hundreds of dollars a month for a small estate, not thousands.
  5. Penetration testing. Not required by SOC 2. Frequently required by your customer's security questionnaire, which means it is a sales cost that shows up on the compliance budget.
  6. The renewal. A SOC 2 report covers a period and then expires from a buyer's perspective. This is an annual program, not a project.

Year two and beyond

Year two is materially cheaper. The controls exist, the policies exist, the baseline is deployed, and the evidence pipeline runs. What remains:

Ongoing itemCadenceWith Aidaptive
The annual examinationOnce per report periodPaid to the CPA firm, typically similar to year one
Evidence collection and cadence executionContinuousSteady-State Maintenance, from $1,000/month
Access reviewsQuarterlyFacilitated, records produced
Risk assessment, tabletop, policy re-approvalsAnnualIncluded in the retainer
Bridge letters between report periodsOn requestIncluded
Security questionnairesAs customers send themTwo per quarter included, then $400 flat each

How to compare quotes without being fooled

Normalize every quote to total spend until a report is in a customer's hands, then ask five questions:

  1. Is the readiness price fixed, and was it quoted after a scan? A number quoted from a sales call is a guess. A number quoted after a scan is a commitment.
  2. Who applies the fixes? If the answer is "we advise, you implement", the engineering line is yours and belongs in the comparison.
  3. Is the audit fee included, and is it the same firm? If one firm does both readiness and the examination, ask how they handle independence, and expect your enterprise customers to ask the same.
  4. What happens in the observation window? Readiness that ends at Type 1 leaves the harder half undone.
  5. What is out of scope? Ours: multi-cloud, on-premise estates, HIPAA and FedRAMP bundles, Privacy, and Processing Integrity. A provider with no exclusions list has not thought about it, or is not telling you.

Frequently asked questions

How much does a SOC 2 audit cost?

The examination itself, paid to the CPA firm, typically runs $5,000 to $10,000 for a small AWS-native startup through our partner firms. Published ranges run higher because they average in larger companies and broader scope. The audit fee is usually the smaller half of the total; readiness and remediation is the larger.

What is the total first-year cost?

Around $20,000 to $25,000 all-in with us: $2,500 gap assessment credited toward readiness from $10,000, the audit at $5,000 to $10,000 paid directly to the CPA firm, and Type 2 window support from $1,000 per month. Assembling the same outcome from hourly consultants and audit shopping commonly runs $30,000 to $65,000.

Why do published SOC 2 cost estimates vary so much?

They measure different things. Some quote only the audit fee, some include a platform subscription, and almost none include internal engineering time. Ranges also average across company sizes and scopes that have little to do with a seed-stage AWS SaaS company.

Can we do SOC 2 without spending anything on outside help?

You can do the readiness yourself. You cannot do the examination yourself: it requires a licensed CPA firm, and that fee is unavoidable. Doing readiness internally is a real option if you have a security-experienced engineer and no deadline pressure. It usually costs three to six months of elapsed time and a meaningful slice of that engineer, which is exactly the trade the deal on your desk is asking you to make.

Do you charge hourly for anything?

No. Fixed or flat only, everywhere. The gap assessment is $2,500. Readiness is a fixed number quoted with your gap report. Retainers are monthly. Extra security questionnaires beyond the included two per quarter are $400 flat each. There is no hourly rate to discover later.

Get a real number instead of a range

The $2,500 gap assessment scans your environment against all 35 controls and returns a fixed readiness quote with the gap report. Credited in full toward the engagement. If we are not a fit, you keep the report and the quote costs you nothing further.

Book a 30-minute scoping call

We name every cost in your journey up front, including the ones paid to other firms.