Anyone who quotes you a SOC 2 audit cost before understanding your scope is guessing. The examination fee is a function of how much the auditor has to describe, test and document, and that varies enormously between a twelve-person API company running on one cloud account and a hundred-person platform with three products, two data centres and a Privacy criteria commitment.

So instead of a number, here are the levers. If you understand these, you can look at any quote and tell whether it is priced for your situation or for someone else’s. You can also reduce your own cost deliberately rather than by haggling.

Scope: what the report actually covers

Scope is the single biggest driver, and it is mostly your decision.

Scope means the systems, products, environments, locations and people the report describes. A SOC 2 covering one production platform in one cloud region is a fundamentally smaller examination than one covering three products with separate architectures, a legacy on-premise deployment and an offshore support team.

Every distinct environment adds its own set of things to describe and test: separate access provisioning, separate change pipelines, separate monitoring, separate infrastructure controls. Auditors do not get to assume the second environment works like the first — they test both.

The practical move: scope to the system your customers are actually buying. If your buyers care about the SaaS platform, do not sweep the internal analytics stack and the marketing site into the report because they happen to be yours. Narrow scope is not evasion; it is accuracy, and the report says plainly what it covers.

Number of trust services criteria

Security — the common criteria — is required in every SOC 2. Availability, Confidentiality, Processing Integrity and Privacy are optional, and each one you add brings its own criteria, its own controls and its own testing.

The increments are not equal. Availability and Confidentiality usually add a modest number of controls on top of what a decent Security programme already has: capacity monitoring, backup and recovery testing, data classification, retention and disposal. Processing Integrity requires you to demonstrate that processing is complete, accurate, timely and authorised, which means real evidence about how your system handles transactions and errors. Privacy is the heaviest — it reaches into notice, choice and consent, data subject requests, retention and disclosure to third parties, and it tends to touch teams outside engineering.

Adding a criterion you were not asked for is one of the most common self-inflicted cost increases we see. Ask your buyers what they need before you commit.

Observation window length (Type 2 only)

A Type 2 tests controls over a period. Longer periods mean larger populations, which means larger samples for the auditor to pull and larger evidence sets for you to assemble.

The relationship is not linear — going from three months to twelve does not quadruple the fee — but it is real. A twelve-month window means twelve months of change tickets, four quarters of access reviews and a full year of onboarding and offboarding records to sample from.

Shorter windows have their own hidden cost, though. Annual controls such as penetration testing, risk assessment, business continuity testing and policy review may not naturally fall inside a three-month period, which creates its own conversations. And a short first window means you are back in audit again sooner.

Subservice organizations and how you treat them

If your service relies on other providers — cloud hosting, a payments processor, a managed SOC, a data centre — the report has to address them. There are two methods, and they price differently.

Under the carve-out method, the subservice organization’s controls are excluded from your description and your opinion, but you must identify the provider, describe the functions it performs, and state the complementary subservice organization controls you assume it operates. You are also expected to have a real process for monitoring that provider, typically by reviewing its own SOC report annually. That monitoring becomes a control the auditor tests.

Under the inclusive method, the subservice organization’s relevant controls are pulled into your description and tested as part of your examination. This requires the provider’s cooperation and a written assertion from them. It is uncommon for large cloud vendors and materially more expensive when it happens.

Most companies carve out. The cost impact then shows up as vendor management work rather than testing work — but if you have twenty in-scope vendors and no vendor management process, that is real effort.

Control maturity and how much remediation you need

Two companies with identical scope can differ substantially in total spend because one has controls running and evidenced, and the other does not.

Cost shows up in three places when maturity is low:

  • Readiness and remediation before the examination — writing policies you do not have, standing up access reviews, implementing logging, formalising change approvals
  • Extra auditor time during fieldwork — chasing evidence that arrives incomplete, re-testing after a sample comes back short, re-explaining what the request meant
  • Exceptions in the report — which do not necessarily raise the fee, but often trigger a follow-up examination sooner than you planned

Evidence hygiene is the quiet driver here. A team where offboarding runs through a ticket with a timestamp and an approver can hand over a population in an afternoon. A team where offboarding happens in a private Slack thread spends a week reconstructing it, and the auditor spends longer reviewing what gets reconstructed.

Headcount, locations and complexity of the control environment

Population sizes scale with people. Sample sizes for access provisioning, onboarding, offboarding and security awareness training grow with headcount, and multiple offices or entities can mean multiple HR systems and multiple sets of records.

Regulated or unusual environments add work too — production systems handling protected health information or cardholder data, physical facilities you operate yourself, or manufacturing and OT environments all require testing that a pure cloud SaaS does not.

The parts people forget to budget

The examination fee is not the whole number. Depending on your situation, you may also need:

  • A readiness assessment or gap analysis before the examination
  • A penetration test, which many buyers expect and which several criteria are commonly satisfied by
  • Internal effort — typically the largest uncosted item, because a first SOC 2 will occupy an engineering lead and someone in operations for weeks
  • Tooling for logging, MDM, vulnerability scanning or evidence collection, if you do not already have it
  • Annual repetition, because a SOC 2 is not a one-time purchase; your buyers will expect a current report every year

What to do next

Before you ask anyone for a quote, write down four things: the exact system in scope, the trust services criteria your buyers have asked for, Type 1 or Type 2, and the observation window if it is a Type 2. Send those four things to every firm you approach. Quotes built on the same four inputs are comparable; quotes built on assumptions are not.

Then ask each firm what would make the fee go up mid-engagement. The honest answer is usually scope changes and evidence that does not arrive, and a firm that says so plainly is telling you how they work. Assurion is a licensed CPA firm and will scope an examination with you before quoting it.