Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Case Study: Two Quotes, Same Scope, Very Different Numbers

The client went out to four firms for the same audit and got back quotes that were nowhere near each other. Same framework, same stated scope, same company. The highest was 2.1 times the lowest.

That surprises people the first time. It should not. Audit pricing is not a rate card, and a spread of that size tells you something useful once you know what drives it. It is rarely that one firm is twice as good, or twice as greedy.

What actually moves the number

How much work the firm expects to do. This is the big one. A quote is an estimate of effort, and effort depends almost entirely on the state you are in when they arrive. A firm quoting a company with a written system description and a populated evidence register is estimating a different job to one quoting a company that has not scoped anything yet. Same framework, different work.

What the firm assumed when it quoted. Two quotes for the same scope frequently are not for the same scope at all. One assumed a single environment, the other assumed the subsidiaries were in. One assumed you would provide evidence in a usable form, the other priced in the chasing. One assumed a three-month observation window, the other assumed twelve. Comparing headline numbers without comparing assumptions is comparing nothing.

Type I against Type II. A point-in-time attestation and a period-of-time attestation are different amounts of work, and if one firm quoted each, the comparison is meaningless.

Firm size and where you sit in their book. A large firm carries overheads that show up in the price and a process built around a certain size of client. A smaller specialist may price lower and give you more attention, or may be at capacity and slot you in months out. Neither is automatically better, but you should know which trade you are making.

Sector experience. Familiarity is speed, and speed is the cost.

Whether the framework is being run alongside another. If you are doing two standards, a firm that has seen that combination before will scope the overlap efficiently. One that has not will price them as two separate engagements, because for them it would be.

How to make quotes comparable

Most of a 2.1x spread disappears once you normalise the inputs, and you can do that yourself. On this engagement the gap narrowed substantially the moment every firm was answering the same question.

Send every firm the same package: the scope you intend to audit, written down; a system or ISMS description; the observation window you are targeting; a list of in-scope systems and environments; your headcount including contractors with production access; and an honest statement of where you are with evidence.

Then ask each of them, in writing, what they assumed about anything you did not specify. The differences that survive that exercise are real price differences. The ones that do not survive it were scope differences wearing a price tag.

Why the cheapest quote is frequently the expensive one

The failure mode is not that the low quote came from a bad firm. It is that a low quote often reflects a narrow set of assumptions, and assumptions get revisited during fieldwork.

The costs that hurt are not on the invoice. They are the deal that slipped a quarter because the report was late. The exception on the report that you now explain in every security review for a year, to buyers who did not read the context. The second engagement to fix what the first one surfaced. The internal time, which nobody counts and which is usually the largest number of all.

An exception in particular is worth more attention than it gets. It is not a fail. It is a note on a document you will hand to prospects for the next twelve months, and it invites a question in every review. Removing the conditions that cause one is preparation work, and it happens before the audit or not at all.

The argument for spending on preparation

Here is the part clients find counterintuitive. If you are already committed to spending on an audit, the preparation spend is the part that protects it.

The audit fee buys you an opinion. It does not buy you the controls, the evidence, or somebody making sure what you hand over is what the firm will accept. Arrive underprepared and you have paid full price for an opinion you may not like, on a report you then have to explain.

It also shows up directly in the quote. On one engagement the audit firm took $11,000 off its number once the client's readiness position was set out and it was confirmed that a prep firm was running the programme, which is covered in the piece on vetting an auditor.

Preparation changes that equation three ways. It reduces the auditor's effort, which is the thing their price is made of. It removes the most common causes of an exception before anybody is sampling for them. And it means the scope you are being quoted on is one somebody defined deliberately rather than one that emerged during fieldwork.

There is a fourth point, and it is the structural one. A prep firm has an incentive the audit firm cannot have. We do not issue the opinion, so nothing stops us telling you plainly that a control will not pass and then building one that will. An auditor is barred from doing that by the independence rules that make their report worth having. That division is covered properly in the piece on vetting an auditor.

What we did for the client

We read all four quotes against each other, established what each firm had assumed, and worked out which differences were scope and which were genuinely price. Then we chose on fit rather than on the headline number, and the firm we picked came down $11,000 once the readiness position was set out.

The comparison was worth doing on its own merits. Not because the cheapest option won, but because the client understood what they were buying in each case, which is not the position most companies are in when they sign an audit engagement letter.

our cost breakdowns covers what each framework runs to. Our own prices are fixed and published, which is a deliberate response to exactly this problem: you should be able to see the number before you talk to anybody.

Note. The client is unnamed. Figures are described by what drives them rather than quoted, because audit pricing is specific to scope and we will not publish another firm's numbers.

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
15+
Penetration testing engagements delivered

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.