How does the calculator turn prices into a budget?
The calculator estimates an audit-only shopping budget for a buyer comparing lower-cost specialists. Anonymized quote patterns help check the starting budget; scoped pricing guides help set allowances for larger teams. The result is a planning scenario, not an average paid price or a prediction for a particular firm.
Small-team specialist scenario
The reference is our Zero Day CPA directory record: $5,000–$7,000 for Type 1 and $7,000–$10,000 for Type 2. Pricing provenance: estimated. This record has documented startup fit and a lower-priced range; payment or placement does not enter the calculation. One firm's range is not evidence of what most startups pay.
Teams of up to 50 people share the starting range. These budgets assume Security-only scope, a simple system, and controls ready for testing before any further scope adjustment. The reference does not establish a Type 2 observation period, so the model applies no short-period discount.
How do real quotes inform the model?
The August 2026 review used anonymized patterns from firm offers received through our quote request flow. Type 1, Type 2, readiness, and combined packages were separated. Only firm-returned offers were included. Ambiguous currencies, conditional prices, and unclear mixed-service scopes were set aside. The calculator publishes rounded allowances, never individual offers or confidential firm rates.
These are quoted offers, not completed purchases. The usable sample is strongest for small teams and does not establish separate premiums for every criterion, platform, or report period. Larger-company observations are concentrated in too few buyers to fit a reliable price curve. Their allowances also draw on scoped pricing guides, including the team-size structure in Tempo's public pricing. Those GBP packages include support; they are not converted into USD audit-only observations.
Starting budgets by team size
One simple system, Security only, and controls ready for testing. The same lower-cost specialist assumption applies to every row.
| Team size | Type 1 budget | Type 2 budget |
|---|---|---|
| 1–10 employees | $5,000–$7,000 | $7,000–$10,000 |
| 11–50 employees | $5,000–$7,000 | $7,000–$10,000 |
| 51–200 employees | $7,500–$10,500 | $10,500–$15,000 |
| 201–500 employees | $10,000–$14,000 | $16,000–$22,500 |
The size allowances are planning choices, not measured increases at an employee threshold:
- 1–10 employees: Type 1 ×1.0; Type 2 ×1.0.
- 11–50 employees: Type 1 ×1.0; Type 2 ×1.0.
- 51–200 employees: Type 1 ×1.5; Type 2 ×1.5.
- 201–500 employees: Type 1 ×2.0; Type 2 ×2.25.
For full-service CPA and Big Four selections, request a firm-specific proposal. The guide's directory bands compare firm groups; they do not price your engagement.
The calculator's separate full-service comparison shows the middle half of firms' listed price-range midpoints, without size or scope adjustments. The guide's table instead runs from the median listed minimum to the median listed maximum. These are two summaries of directory estimates, not quote-derived budgets.
Scope allowances
The starting range is multiplied by the size allowance, the criteria allowance, and one system-footprint allowance. System footprint takes the largest of complexity, vendor count, or locations. These overlap, so multiplying all three would count some work more than once. Amounts round to the nearest $500.
- Security only: ×1.0.
- Security + 1 additional criterion: ×1.15.
- Security + 2 additional criteria: ×1.3.
- All 5 Trust Services Criteria: ×1.6.
System footprint uses these candidate allowances; only the largest applies:
- Simple SaaS (monolith, single region): ×1.0.
- Microservices (5–15 services): ×1.15.
- Distributed (multi-region or multi-cloud): ×1.3.
- Highly complex (100+ services, global): ×1.5.
- Fewer than 10 critical vendors: ×1.0.
- 10–24 critical vendors: ×1.15.
- 25+ critical vendors: ×1.3.
- 1 location or data center: ×1.0.
- 2–3 locations or data centers: ×1.15.
- 4+ locations or data centers: ×1.3.
Readiness never adds a preparation fee to the audit number. If work remains, the calculator flags it separately and assumes it is completed before fieldwork. For teams above 500 people or the most complex system option, the calculator asks for a scoped quote instead of showing a precise price.
Method revised August 31, 2026. Try your scope in the calculator or work out the rest of your budget.
Auditor organization-group ranges
Aggregate planning bands per (organization group × audit type), recomputed whenever we refresh our auditor directory. Each band runs from the median of the firms’ listed minimum estimates to the median of their listed maximum estimates. These are descriptive cohorts, not quality or capability scores, and individual proposals can fall outside the band.
Assurance specialist firms — SOC 2 Type 1
$10K–$35K
Computed from the assurance specialist firms in our auditor directory: the median of their directory-listed Type 1 minimum estimates through the median of their listed maximum estimates. These are planning values, not observed transaction prices or live quotes. Refreshed whenever we update our auditor directory.
Assurance specialist firms — SOC 2 Type 2
$16K–$50K
Median of the directory-listed Type 2 minimum estimates through the median of the listed maximum estimates across the assurance specialist firms in our auditor directory. These are planning values, not observed transaction prices or live quotes; proposals can fall outside the band in either direction. Refreshed whenever we update our auditor directory.
Full-service CPA firms — SOC 2 Type 1
$20K–$60K
Median of the directory-listed Type 1 minimum estimates through the median of the listed maximum estimates across generalist CPA firms (national networks through regional full-service shops) in our auditor directory. These are planning values, not observed transaction prices or live quotes. Refreshed whenever we update our auditor directory.
Full-service CPA firms — SOC 2 Type 2
$30K–$80K
Median of the directory-listed Type 2 minimum estimates through the median of the listed maximum estimates across generalist CPA firms in our auditor directory. These are planning values, not observed transaction prices or live quotes; proposals vary with scope. Refreshed whenever we update our auditor directory.
Big Four firms — SOC 2 Type 1
$40K–$140K
Big Four = Deloitte, PwC, KPMG, EY. Our entries cover the four firms across multiple regions and service lines, and the band is the median of their directory-listed Type 1 minimum estimates through the median of their listed maximum estimates. These are planning values, not observed transaction prices or live quotes; proposals vary sharply by office and engagement scope. Refreshed whenever we update our auditor directory.
Big Four firms — SOC 2 Type 2
$60K–$200K
Median of the directory-listed Type 2 minimum estimates through the median of the listed maximum estimates across the Big Four offerings in our auditor directory. These are planning values, not observed transaction prices or live quotes; proposals vary by office, scope, entity count, and region. Refreshed whenever we update our auditor directory.
Add-on costs
Costs that sit alongside the audit fee. Pen test, GRC platform, internal labor, scope creep, report amendments. Each entry identifies whether it comes from a vendor page, our GRC software directory, or a buyer-reported aggregate from this site.
External penetration test (SOC 2 evidence)
$8K–$30K
Reflects a single SOC 2-aligned external pen test (web app or external network). Cobalt's Starter and Pro tiers, plus comparable scopes from Bishop Fox and HackerOne services, cluster in this band. Highly variable for internal network, mobile, or red-team scopes.
GRC / compliance automation platform (annual)
$3.6K–$78.1K
Envelope from comparable annual USD prices observed in our GRC software directory. It mixes vendor-confirmed figures and clearly labeled third-party estimates; vendors without a published or quoted price are omitted. This is a planning span, not a typical price or a live quote.
Internal engineering and founder hours during audit prep
$25K–$90K
Reflects 300–600 hours of engineering, security, and founder time during a first SOC 2 Type 2 — buyer-reported. Range computed at $80–$150/hr loaded labor cost. Smaller teams with stronger baselines land at the low end; greenfield mid-market orgs at the high end.
Control remediation (tooling, vendors, hardware)
$5K–$50K
Covers tooling and vendor spend triggered by readiness gaps: MDM, IdP, logging or SIEM, vulnerability management, background-check service, security training. Highly dependent on starting maturity. Greenfield orgs land above this band.
Scope creep and change orders during audit
$10K–$30K
Triggered by mid-engagement additions: extra trust services criteria, additional in-scope systems, late-binding subservice organizations, or remediation that became audit work.
Report amendments and reissue fees
$2K–$5K
Charged when a buyer requests an updated report after issuance — for example, to add a subservice organization, fix a factual error, or refresh the system description for a customer that requires it.
Market mentions (reviewed third-party price points)
Single third-party price points — first-person buyer reports in public threads and figures published in auditor or compliance-platform guides. Each survived a manual review pass (duplicates, ambiguous amounts, and low-credibility sources rejected). Corroboration for the tier ranges above; never an input to them.
Buyer report — MSP, total SOC 2 spend
$20K
A buyer-reported total for SOC 2; the thread does not split audit fee from prep. Kept as an observed market datapoint (manual review, 2026-06).
Buyer report — SaaS audit fee
$12K
A SaaS founder reporting what their SOC 2 cost; audit type not stated. Kept as an observed market datapoint (manual review, 2026-06).
Buyer report — Type 2 audit fee
$15K
A buyer naming what they paid for a SOC 2 Type 2. Sits inside our specialist Type 2 band — the strongest single corroboration in the 2026-06 review batch.
Buyer report — Type 1 audit with Drata in place
$5.5K
A budget Type 1 quote for a company already running Drata — a useful observed low anchor below the bottom of our specialist band.
Buyer report — readiness consultant
$10K
A consultant quote for SOC 2 readiness work (not the audit itself). Matches the readiness band cited in our FAQ.
Auditor-published — readiness assessment
$13.5K
A licensed CPA firm publishing a typical readiness figure. The Pun Group is peer-review verified in our directory.
Auditor-published — typical audit figure
$27.5K
A CPA firm publishing a typical SOC 2 figure without splitting Type 1/Type 2. Falls mid-band for specialist/regional Type 2 in our directory data.
Auditor-published — upper-bound figure
$85K
One of the largest SOC 2 issuers stating how high engagements can run. Read as a ceiling: it corroborates the top of our mid-tier/Big Four bands, not a typical price.
Security-firm-published — Type 2 figure
$50K
An established security firm’s published Type 2 figure. Inside our mid-tier band.
Platform estimate — Type 1 (Drata)
$11.3K
Midpoint of the Type 1 estimate in Drata’s dedicated cost guide. A conflicting higher figure on their type-1-vs-type-2 marketing page was excluded after manual review.
Platform estimate — Type 1 (Sprinto)
$7.5K
The low end of published platform estimates for a Type 1 audit.
Platform estimate — Type 1 (Secureframe)
$12.5K
Secureframe’s Type 1 estimate. Their much higher Type 2 figure on the same page reads as total cost of compliance (tooling included) and was excluded after manual review.
Platform estimate — readiness (Sprinto)
$12.5K
A platform’s readiness-assessment estimate; consistent with the CPA-published readiness figure above.
Platform estimate — Type 2 (Vanta)
$45K
Vanta’s Type 2 estimate. Inside our mid-tier band; above the specialist p90.
Corrections and updates
Wrong range, stale source URL, a vendor that has since published clearer pricing? Email hello@soc2auditors.org. We respond within two business days and ship factual corrections within five, with a dated note on the affected entry.
The full methodology, including source-class tiers and verification cadence, is on our methodology page.