Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

The Costs of SOC 2 Nobody Quotes You

Direct answer: The two numbers you get quoted, readiness and the audit fee, are usually a bit over half the real cost. The rest is engineering time on remediation, a penetration test, any tooling you buy, and the internal hours spent collecting evidence. Budget for all five or the project stalls in month three.

The five real line items

Readiness. Gap analysis, policies, control build-out, evidence and audit coordination. Ours starts at $3,000 for the gap analysis, with remediation scoped after it, and the figures are on the pricing page.

The audit itself. Paid to an independent CPA firm, never to us, because the same firm cannot do both. This is a separate invoice and a separate relationship.

Engineering time. The one nobody budgets. Fixing what the gap analysis finds is real work: logging, access changes, an identity provider migration, encryption gaps. On a small team that is often several weeks of an engineer, and it lands on top of the roadmap.

A penetration test. Not formally mandatory, and expected in practice by auditors and buyers alike. From $1,000 depending on scope.

Evidence collection. Somebody has to gather screenshots, exports and tickets across the observation period. Done weekly it is minor. Left to the end it is a fortnight of somebody's life and it produces gaps that cannot be backfilled.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

The costs that only appear later

The observation period itself, if you want Type II, which means controls operating for months before you have a report to sell with. Renewal every year. A compliance platform subscription, if you buy one, which is annual and rarely cancelled. And the opportunity cost of whoever ends up owning this internally.

Where money gets wasted

Scoping too wide is the biggest. Every extra system in the boundary is more controls, more evidence and more audit hours. Buying tooling before you know your gaps is second: teams purchase a platform, then discover the work it automates was not their problem.

Third is arriving at the auditor unprepared. A disorganised client costs more to audit because it takes longer, and firms price that in. Arriving with a clean evidence package is worth real money. We took $11,000 off one client's quote that way, which is on our case studies.

A realistic total

For a small Canadian SaaS with a straightforward cloud stack, the honest answer is that readiness plus audit plus a pen test is the visible spend, and you should assume meaningful engineering time on top. Anyone quoting a single all-in number without seeing your environment is guessing at the part that varies most.

If you want the number for your situation rather than a range, tell us the shape of the environment and we will scope it.

When each invoice actually lands

Totals matter less than timing for a company watching runway, and the cash flow shape of a SOC 2 project surprises people. The gap analysis is paid up front, ours from $3,000, and it lands in month one. Remediation spend follows immediately behind it and is spread across months two and three, mostly as tooling subscriptions and engineering time you are already paying for. The penetration test is usually booked around the time remediation completes, from $1,000 depending on scope, and testing firms typically want payment on delivery of the report.

The auditor is the one that catches people. Many CPA firms invoice a deposit at engagement signature, before any fieldwork, and the balance on report delivery. For a Type II, that means you pay the deposit months before you receive anything you can send to a customer. If you buy a compliance platform, that is an annual invoice paid at signature regardless of when you use it. Laid out across a calendar, the profile is heavy at the start, quiet through the observation period, and heavy again at the end, with the actual revenue benefit arriving only once the report exists. Modelling it as a single lump in the month you sign is how teams end up short in month eight.

The SaaS upgrade bill nobody forecasts

This is the cost we most often watch land as a genuine surprise. A large share of SOC 2 remediation is about identity, access and audit trails, and the features that deliver those in your existing SaaS tools are almost always gated behind a higher pricing tier. Single sign-on, SCIM provisioning and de-provisioning, admin audit logs, role-based permissions beyond the basic set, longer log retention, and enforced session controls are the usual gated features.

Work through your application list before you start and price the upgrade for each. A dozen tools each moving up a tier, on annual commitments, adds up to a recurring cost that outlasts the audit and grows with headcount. There are decisions available here rather than just a bill. Some tools can be dropped entirely once you see them listed. Some can be consolidated. For a few, a documented compensating control with quarterly manual review is an acceptable answer to an auditor, and considerably cheaper than the enterprise tier. What you cannot do is discover this in month two and absorb it silently, because it is frequently the largest recurring line the project creates.

Choosing the auditor, and what moves their quote

Audit fees vary widely for the same work, and the drivers are knowable. Firm size and brand recognition carry a premium, and the question worth asking is whether any of your prospects have named a firm or a tier of firm, because most do not care as long as the firm is a licensed CPA practice with SOC 2 experience. Scope drives hours directly, through the number of systems, the number of trust services categories and the size of the populations they sample. Your level of preparedness drives hours too, which is the part you control.

Ask each firm the same set of questions and compare properly. What is included in the fee, and is the readiness assessment separate. How many hours are assumed, and what happens if they are exceeded. What is the turnaround from end of fieldwork to final report, since a firm that takes ten weeks to issue can cost you a quarter of selling time. Do they work through a compliance platform, and does that change the price. Is there a discount for engaging them for Type I and Type II together. And how many client-facing hours will be with a senior person versus a first-year associate, because the associate will ask you for things the senior would not.

Type I, Type II, and the cost of paying twice

A Type I is a point-in-time opinion on design. A Type II covers operating effectiveness over a period. Doing Type I first and Type II afterwards means two audit engagements and two fees, and it is often still the right call when a specific deal needs something in hand within weeks rather than months. The honest framing is that the Type I fee is money spent on sales enablement rather than on the compliance outcome, because the Type II supersedes it entirely.

Skip the Type I when no deal is waiting on it, when your buyers have not asked for anything yet, or when your observation period is short enough that the Type II lands soon anyway. Buy the Type I when a named contract is blocked on evidence and the customer has said they will accept it. That is a commercial decision with a number attached on both sides, and it should be made by whoever owns the revenue rather than by whoever owns the compliance project.

The observation period is a cost decision too

First-year Type II observation periods commonly run three, six or twelve months. Shorter costs less in elapsed time and gets a report into your sales process sooner. Longer produces a report that some enterprise reviewers prefer, and it reduces the awkwardness of a very short first window. The cost implication is not primarily the audit fee, which does not scale linearly with period length. It is the internal evidence collection burden, which does, and the delay before the report earns anything.

A three month first period followed by a twelve month second period is a common and sensible pattern. What it creates is a reporting gap, and covering that gap has its own small cost: a bridge letter, sometimes called a gap letter, in which management asserts that no material changes to the control environment occurred between the end of the report period and the current date. Some auditors provide one for a fee, and some expect management to write it. Buyers ask for these routinely once your report is more than three months old, so budget the time even where there is no invoice.

The legal and contractual spend it triggers

A SOC 2 programme reaches into your paperwork, and the bill for that arrives from a law firm rather than a consultancy. Your data processing agreement usually needs updating to match what the description says you actually do. Your subprocessor list needs publishing and maintaining, because you are now asserting vendor management as a control and a stale list contradicts it. Customer master agreements often need a security addendum that reflects the commitments in the report rather than the older, vaguer language. If you operate in Quebec or handle health information, the privacy obligations sit alongside this and are worth reviewing at the same time rather than separately.

None of these are large invoices individually, and together they are commonly a few hours of external counsel. What makes them worth forecasting is that they arrive late, usually once the description is drafted and someone reads it against the contracts, and they land on a founder who thought the spending was finished. Ask your lawyer for an estimate in month one, when the boundary is being defined, rather than in month nine.

The rework costs, which are the expensive ones

Everything above is planned spend. The unplanned spend comes from three situations. The first is exceptions in the report, meaning the auditor tested a control and found instances where it did not operate. Exceptions do not usually require a new audit, but they do require a management response and they hand your buyer's reviewer something to ask about, which costs sales time across every deal for a year.

The second is a control that was not operating at all during part of the period, discovered late. Access reviews that were never performed, a change management process nobody followed for two months, or logging that was not enabled until month four. Evidence for those periods cannot be created after the fact, and any attempt to do so is a much more serious problem than the gap itself. Depending on severity, the fix is a qualified opinion, a shortened period, or restarting the observation window, and the last of those means paying for the audit again and waiting again.

The third is changing auditors mid-engagement, which happens more than people admit, usually because of responsiveness or because the fee estimate turned out to be an opening bid. Assume you lose the deposit and repeat the onboarding effort. All three are avoided by the same discipline: check monthly that the controls you claimed are actually running, rather than assuming.

Year two is not half of year one

Budgets get built on the assumption that the second year is much cheaper, and it is cheaper, but less than expected. The audit fee falls modestly at best, because the auditor still performs the same testing over a longer period. The penetration test recurs annually and buyers expect it. The platform subscription renews, often with an uplift and a higher headcount band. Evidence collection is the same work, and now covers twelve months rather than three.

What genuinely gets cheaper is remediation, since the controls exist, and the internal learning curve, since somebody now knows how this works. What gets more expensive is anything you deferred in year one, and anything your growth added: more people, more systems, more vendors, sometimes a second product or region that widens the boundary. The steady-state annual cost of holding a SOC 2 report is a real line item in your operating budget rather than a project that finishes, and treating it as a project is why year two so often feels like a shock.

The internal ownership cost, stated plainly

Somebody inside the company owns this, and their time is the largest uncosted item in most SOC 2 projects. If that person is a founder, the cost is whatever they were otherwise doing, which at an early company is usually selling or building. If it is an engineering lead, the cost shows up as roadmap slippage that gets blamed on something else. The work itself is not glamorous: chasing evidence, nudging people to complete training, running access reviews, answering auditor requests, and keeping the description current.

There are three honest ways to handle it. Accept the cost, name the owner, and protect their time explicitly rather than pretending it fits around the edges. Hire for it, which rarely makes sense below a certain size. Or buy the ownership externally, which is what a fractional CISO engagement is, from $3,000 a month. The option that does not work is leaving it unassigned and hoping the platform handles it, because the platform collects evidence and does not chase people.

How to spend less without cutting corners

Four levers actually move the total. Narrow the boundary to production and the systems that touch customer data, which reduces controls, evidence, sample populations and audit hours simultaneously. Choose only the trust services categories your buyers ask for, which for the overwhelming majority is Security alone, with Availability and Confidentiality added cheaply where the controls already exist. Collect evidence weekly in small amounts rather than in one exhausting sprint at the end, which prevents the unfixable gaps described above. And arrive at the auditor organised, with the description agreed, the control matrix mapped and the evidence indexed, because a disorganised client is a slower audit and firms price for hours. That last lever is the one most firms underuse, and it is worth several thousand dollars on a typical quote. There are worked examples on our case studies.

Keeping the control set, evidence register and vendor list in one place makes the weekly rhythm sustainable, which is why the free Workspace exists in the shape it does. The point is not the tool. It is that ten minutes a week beats a fortnight in month eleven, and it produces a better report.

When SOC 2 is not worth buying yet

If one prospect is asking and no contract is signed, find out what they would accept instead. A completed security questionnaire, a current penetration test attestation letter, a documented policy set and a written roadmap with dates clears a surprising number of enterprise reviews, at a fraction of the cost, and buys you time to see whether a second buyer asks. If nobody else asks in six months, you saved the whole programme.

If your product has not found its market, do not spend a quarter of your remaining runway on an audit for customers you do not yet have. If your buyers are Canadian mid-market rather than US enterprise, check whether they want SOC 2 at all before assuming, because plenty will accept a security questionnaire and a conversation. If the request came from a procurement template rather than a security team, push back once politely and see whether it survives.

And if you do need it, the cheapest version is the one you scope tightly and run steadily, not the one you buy the most tooling for. We would rather scope you into a smaller engagement than sell you a wide one, partly because it is honest and partly because narrow projects finish and wide ones stall. If you want a number for your situation rather than a range, describe the environment and the deal that triggered this, and we will tell you what it takes, including when the answer is that it is too early. Ongoing ownership after the report exists is a separate and smaller conversation, which sits in a retainer rather than another project fee.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.