The client went out to four firms for the same audit and got back quotes that were nowhere near each other. Same framework, same stated scope, same company. The highest was 2.1 times the lowest.
That surprises people the first time. It should not. Audit pricing is not a rate card, and a spread of that size tells you something useful once you know what drives it. It is rarely that one firm is twice as good, or twice as greedy.
What actually moves the number
How much work the firm expects to do. This is the big one. A quote is an estimate of effort, and effort depends almost entirely on the state you are in when they arrive. A firm quoting a company with a written system description and a populated evidence register is estimating a different job to one quoting a company that has not scoped anything yet. Same framework, different work.
What the firm assumed when it quoted. Two quotes for the same scope frequently are not for the same scope at all. One assumed a single environment, the other assumed the subsidiaries were in. One assumed you would provide evidence in a usable form, the other priced in the chasing. One assumed a three-month observation window, the other assumed twelve. Comparing headline numbers without comparing assumptions is comparing nothing.
Type I against Type II. A point-in-time attestation and a period-of-time attestation are different amounts of work, and if one firm quoted each, the comparison is meaningless.
Firm size and where you sit in their book. A large firm carries overheads that show up in the price and a process built around a certain size of client. A smaller specialist may price lower and give you more attention, or may be at capacity and slot you in months out. Neither is automatically better, but you should know which trade you are making.
Sector experience. Familiarity is speed, and speed is the cost.
Whether the framework is being run alongside another. If you are doing two standards, a firm that has seen that combination before will scope the overlap efficiently. One that has not will price them as two separate engagements, because for them it would be.
How to make quotes comparable
Most of a 2.1x spread disappears once you normalise the inputs, and you can do that yourself. On this engagement the gap narrowed substantially the moment every firm was answering the same question.
Send every firm the same package: the scope you intend to audit, written down; a system or ISMS description; the observation window you are targeting; a list of in-scope systems and environments; your headcount including contractors with production access; and an honest statement of where you are with evidence.
Then ask each of them, in writing, what they assumed about anything you did not specify. The differences that survive that exercise are real price differences. The ones that do not survive it were scope differences wearing a price tag.
Why the cheapest quote is frequently the expensive one
The failure mode is not that the low quote came from a bad firm. It is that a low quote often reflects a narrow set of assumptions, and assumptions get revisited during fieldwork.
The costs that hurt are not on the invoice. They are the deal that slipped a quarter because the report was late. The exception on the report that you now explain in every security review for a year, to buyers who did not read the context. The second engagement to fix what the first one surfaced. The internal time, which nobody counts and which is usually the largest number of all.
An exception in particular is worth more attention than it gets. It is not a fail. It is a note on a document you will hand to prospects for the next twelve months, and it invites a question in every review. Removing the conditions that cause one is preparation work, and it happens before the audit or not at all.
The argument for spending on preparation
Here is the part clients find counterintuitive. If you are already committed to spending on an audit, the preparation spend is the part that protects it.
The audit fee buys you an opinion. It does not buy you the controls, the evidence, or somebody making sure what you hand over is what the firm will accept. Arrive underprepared and you have paid full price for an opinion you may not like, on a report you then have to explain.
It also shows up directly in the quote. On one engagement the audit firm took $11,000 off its number once the client's readiness position was set out and it was confirmed that a prep firm was running the programme, which is covered in the piece on vetting an auditor.
Preparation changes that equation three ways. It reduces the auditor's effort, which is the thing their price is made of. It removes the most common causes of an exception before anybody is sampling for them. And it means the scope you are being quoted on is one somebody defined deliberately rather than one that emerged during fieldwork.
There is a fourth point, and it is the structural one. A prep firm has an incentive the audit firm cannot have. We do not issue the opinion, so nothing stops us telling you plainly that a control will not pass and then building one that will. An auditor is barred from doing that by the independence rules that make their report worth having. That division is covered properly in the piece on vetting an auditor.
What we did for the client
We read all four quotes against each other, established what each firm had assumed, and worked out which differences were scope and which were genuinely price. Then we chose on fit rather than on the headline number, and the firm we picked came down $11,000 once the readiness position was set out.
The comparison was worth doing on its own merits. Not because the cheapest option won, but because the client understood what they were buying in each case, which is not the position most companies are in when they sign an audit engagement letter.
our cost breakdowns covers what each framework runs to. Our own prices are fixed and published, which is a deliberate response to exactly this problem: you should be able to see the number before you talk to anybody.
Note. The client is unnamed. Figures are described by what drives them rather than quoted, because audit pricing is specific to scope and we will not publish another firm's numbers.
Read the engagement letter, not the quote
The quote is a marketing document. The engagement letter is the contract, and the difference between two firms usually lives in clauses the quote never mentions. Four of them are worth reading closely before anybody signs.
What triggers additional fees. Most letters contain language allowing the firm to bill beyond the fixed fee if the engagement takes materially more effort than assumed. That is reasonable in principle. What matters is how the trigger is defined. A clause tied to specific, checkable conditions, for example evidence not delivered within a stated window or a scope change requested by you, is one you can manage. A clause that says additional effort will be billed at standard rates, with no definition of additional, converts your fixed price into an estimate.
What counts as a deliverable. Ask whether the fee includes the draft report, management's responses being incorporated, a bridge letter later in the year, and reissue of the report if a factual error is found. Bridge letters in particular are frequently a separate line item, and you will want one, because your customers will ask for coverage of the gap between your period end and the date they are reviewing you.
Who actually does the work. A quote priced on a senior name and staffed with first-year associates is a different engagement to the one you thought you bought. Ask for the staffing mix and the name of the person who will run fieldwork, and ask what happens to your engagement if that person leaves. Continuity matters more in year two than year one, because a fresh team re-learns your environment at your expense.
Timing commitments. Look for a stated date for fieldwork start, draft report, and final report, and for what happens if the firm misses them. Most letters bind you to dates and bind the firm to nothing. You will not always win that negotiation, but asking reveals how the firm thinks about your deadline, and their answer is information whether or not the clause changes.
The questions that separate firms once the price is normalised
After you have equalised the scope, the remaining decision is fit, and fit is testable. We put the same set of questions to every firm on this engagement and the answers ranked them far more clearly than the numbers did.
Ask how many clients like you they have audited in the last year, and define "like you" precisely: same framework, same rough size, same architecture. Ask what their most common finding is for companies at your stage, because a firm that answers immediately and specifically has genuinely seen a lot of them, and a firm that gives you a generic answer has not. Ask how they handle a control that is well designed but has one operating failure in the period, since that judgement call is the difference between a clean report and an exception you explain for a year. Ask what their evidence request process looks like and whether it comes through a portal or a spreadsheet, and how many rounds of requests they typically run. Ask directly what would make them walk away from the engagement.
Then ask the scheduling question, because capacity is the constraint nobody prices in. Audit firms have a peak, and if your desired period end lands inside it, the firm that quoted lowest may also be the one that slots your fieldwork three months out. A cheaper number attached to a report that arrives after your renewal date is not cheaper. Ask for the fieldwork window in writing during the quote stage, not after signature.
Finally, ask for a reference from a client of similar size and actually call them. The question worth asking that reference is not whether they were happy. It is whether the final invoice matched the quote, and if it did not, why.
What a change order actually looks like mid-engagement
The cheap quote turning expensive is rarely dramatic. It happens in three or four small increments, each individually defensible.
The first is a scope discovery. Fieldwork reveals a second production environment, or a subsidiary that shares the identity provider, or a data flow into a system nobody mentioned during scoping. The firm is not wrong to raise it. But the effort estimate was built without it, and the increment gets billed.
The second is evidence quality. The firm asked for access review records for the period and received a screenshot of the current user list. That is not the requested artefact, so the request goes back, and back again, and each round costs the firm hours it will eventually charge for. This is the increment most within your control, and it is precisely what preparation removes.
The third is sample expansion. When testing a sample turns up a deviation, the firm frequently expands the sample to determine whether the failure is isolated or systemic. A larger sample is more hours, and it usually arrives at the worst point in the calendar.
The fourth is remediation and retesting inside the period. If a control has to be fixed and then observed operating, you have extended the timeline and added a testing round. On a Type II with a short window that can push the report past the date you promised a customer.
None of these are bad faith. They are the normal shape of an audit meeting an unprepared organisation, and the reason a spread of quotes at the outset tells you less than you think. What you are really comparing at quote stage is four firms' guesses about how much of this will happen to you.
Choosing the observation window, which is a cost decision as well as a timing one
For a Type II, the period length is a lever most companies pull without realising it is a lever. A short initial window, commonly three months, gets you a report sooner and costs less, because there is less history to sample. The trade is that some enterprise buyers push back on a three-month window and ask when the next report covering a full year will be available. A twelve-month window costs more, takes longer, and satisfies almost everybody.
The pragmatic pattern for a company with a deal on the line is a short first window followed by a full-year window that starts the day the first one ends, so coverage is continuous and the second report arrives without a gap. Continuity is the part that gets missed. A company that runs a three-month report, waits six months, and then starts a twelve-month period has created a hole in its coverage that every future buyer will notice, and no bridge letter fixes a gap of that size.
Decide the window against the named accounts you need to close and their stated requirements, not against a general sense that longer is more credible. And put the question to your prospect's security team directly, because they will usually tell you what they accept, and their answer is the only one that matters.
When you should not hire a prep firm, including us
The argument for preparation spend has limits, and it is worth being plain about where they sit.
If you already have someone who has done this before, you do not need us to run it. A security or compliance lead who has taken a company through a first audit knows the shape of the work. What they usually want is a second pair of eyes on scope and on the evidence set before fieldwork, plus somebody to argue with about the controls they are unsure of. That is a few days of work, not a programme, and we would rather sell you the few days.
If you are very small and genuinely simple, the audit firm's own readiness view may be enough. A ten-person company with one product, one cloud environment, and no acquisitions can often go straight to an auditor, take the Stage 1 or readiness feedback, and act on it. Adding a prep firm to that adds a coordination layer for a job with little coordination in it.
If you have not confirmed the requirement, do nothing yet. We have told founders to go back to the buyer and ask, in writing, whether the report is a contractual condition of signature or a preference, and what they would accept in the interim. Some of the time the answer changes the plan entirely, and asking costs nothing.
If your problem is a single stalled security review rather than an audit, buy the smaller thing. Answering a questionnaire properly and standing up a trust page is a fraction of the cost of a readiness programme and may clear the blockage on its own.
Where preparation earns its keep is the case this client was in: multiple frameworks or a complicated scope, a deadline attached to revenue, and nobody internally who has done it before. That is worth paying for, and it is why our own numbers for readiness work are published on the pricing page and our compliance practice is scoped as fixed deliverables rather than open-ended hours. If what you need afterwards is somebody keeping the programme running between audits rather than rebuilding it every year, that is a different arrangement again, and a retainer is the honest way to buy it.
Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.
See SOC 2 in 75 DaysOr talk about a retainerWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.