A SOC 2 is not one invoice but five. There is the opinion a licensed CPA firm signs, the readiness read that comes before it, a penetration test where your buyer asks for one, the tooling you subscribe to, and the hours your team spends gathering the evidence each quarter.
A SOC 2 is five bills, not one.
A SOC 2 is five bills, not one - and the largest is usually your own team. What each line is, and what moves it.
Our promise
“A price you cannot compare is a guess.”
The readiness fee is published. The opinion is a licensed CPA firm’s to sign, and their fee is never folded into ours. The fee is fixed at $12,500, and nothing is charged until you approve it.
Request this readiness scanThe SOC 2 bill, in three chapters
Two quotes for the same report can differ several times over, and usually they are quoting different things. What moves the number is how many criteria you elected, how much sits inside the boundary, whether the report is Type I or Type II, and how long the observation window runs.
Our job is the read before the audit. We settle the boundary, check which controls already produce their own evidence, cost what is missing, and hand you the questions that make two quotes comparable. We issue no opinion and sell no software, so nothing we find earns us a fee.
Two invoices. Only one is ours.
The opinion is signed by a licensed CPA firm. The read before it is ours.
- The opinion - signed, and theirs alone to issue
- Fieldwork - testing your controls across the window
- The report - description, tests, results and exceptions
- Re-tests - priced separately when a control fails
- Tooling - annual, and per seat more often than not
- Hour counts - what each control costs you every quarter
- Remediation - unknowable until the gap read is done
- Renewal - annually, plus a bridge letter between
The opinion is theirs. The bill is yours.
The opinion, and its fee
A SOC 2 is an attestation opinion signed by a licensed CPA firm. That fee is theirs to set and ours to stay out of - we are not a CPA firm and do not issue the report. It is commonly the single largest external line on the whole budget, and it is quoted against your own scope rather than off any price list.
The read before the audit
What the fieldwork will actually ask for, checked before the meter starts. Ours is a published fixed fee that never moves with what we find, and it exists because arriving at an audit unready is the most expensive way to find a gap - the CPA firm bills that discovery either way, then bills the re-test.
The line nobody budgets
Your own people. Evidence gathering, screenshots, policy drafting, answering the auditor's questions - commonly hundreds of hours, spread right across the quarter, billed to no one and therefore budgeted for by no one. It routinely comes to more than every other invoice on this page put together.
“We just need a SOC 2. Ten thousand, right?”
That is one line of five. Ask for the other four.
It is the most common finding we write up.
- Who it is for
- SaaS & platform vendors
- Startups selling upmarket
- Security & GRC leads
- Finance & procurement
- Founders answering an RFP
Two firms can quote the same report and differ several times over, because they are quoting different scopes, windows and testing depths.
A Type II covers a period you choose. Nobody bills you for the window, and it is the line that decides when you can answer the buyer.
The report expires with its period. Budget SOC 2 as a subscription rather than a project, or year two arrives as a surprise.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your cost check
Four moments, and the longest one is yours.
The middle two are work you control. The last one is elapsed time, and no amount of effort makes a window pass faster than it passes.
-
Scoped
Week zeroThe boundary and the elected criteria are settled in writing, and nothing is charged until you approve.
-
Read
Weeks 1-4The readiness review: what the criteria ask, what your controls produce, and where the two do not meet.
-
Observed
3 to 12 monthsA Type II watches controls operate across a window you choose. The window is a cost, and it is yours.
-
Renewed
Every 12 monthsThe report covers a period and then stops. Budget it as a subscription rather than as a project.
Teams budget the audit fee and stop there. The line that actually dominates is not on any invoice — it is the hours your own team spends collecting evidence, every quarter the window runs.
What the bill contains, what we do about it
12 things to settle, and the artefact that answers each one. Paired, so every claim on this page can be checked against the requirement beside it.
- The CPA firm's opinion Their fee, quoted on your scope - not ours to set
- Named as a separate line before you commit, so two quotes can be compared like for like instead of one bundled number.
- The readiness review Ours, fixed and published - the one exact figure here
- The gap read itself: boundary, elected criteria, and whether each control named actually produces its own evidence.
- Type I or Type II A point in time, or a period - the choice moves everything
- Which one your buyer actually asked for, in writing, before you pay for the more expensive answer to the wrong question.
- The observation window Commonly three to twelve months, and you choose it
- What a shorter window costs you in credibility and a longer one costs you in time, set against who is asking for the report.
- Penetration testing Commonly asked for, priced by the tester and not by us
- Whether your buyer or your auditor actually requires one, at what depth, and what the report has to show to count.
- Compliance tooling Annual, and per seat more often than the pricing page says
- Whether a platform earns its licence against what you already run, or whether it is automating a spreadsheet you could keep.
- Security tooling MDM, logging, scanning - mostly things already in place
- Which criteria your existing stack already satisfies, so the gap list is what you must buy rather than what a vendor sells.
- Policy and documentation Written once, then kept current - the second part is the cost
- Which policies the criteria actually require, and which of yours are describing a process nobody follows any more.
- Evidence collection The hours nobody puts in the budget, every single time
- Which controls throw off their own evidence and which need a human with a screenshot tool every quarter, named one by one.
- Remediation Unknowable until the gap read - and quoted as such
- Ranked by what the audit will actually stop on, so the spend goes where the opinion is at risk rather than where it is easy.
- Your own staff hours Commonly the largest line, and it appears on no invoice
- An honest hour count per control owner, so the internal cost is a number in the plan instead of a surprise in the quarter.
- Renewal and the bridge Annual, plus a bridge letter to cover the gap between
- What holding the report costs every year after the first, which is the line that decides whether SOC 2 was worth starting.
Your control set, independently read
From a first Type I to a renewed Type II.
-
Scope
What is in the system boundary, which criteria you elect, and what that costs.
-
Read
Your controls against the criteria, and the evidence each one does or does not produce.
-
Price and sign off
You see the draft first. Then the gap list, the shortlist and the costed plan - dated.
Why teams ask iDharma what it will really cost
We sell no software
No platform to license, no seats to grow, and no reason to call your spreadsheet a gap.
We do not issue the SOC 2
A licensed CPA firm signs that opinion. We read you before it, and we say so on every page.
One fixed fee, published
The readiness price is published on this page and in the checkout, and no finding we make changes it.
Costed, not just listed
Every gap arrives with what closing it takes in money and hours, so the plan is a budget not a wish.
Four marks, struck on every readiness report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Costed readiness report
The whole assessment in one document: what sits inside the system boundary, which trust services criteria you have elected, which controls already produce their own evidence and which do not, what each remaining gap takes to close in money and in hours, and what to expect the CPA firm to ask for.
Cost model workbook
Every line on this page as a row you can edit - the ranges, your hour counts and the quotes you collect, totalling as you go.
Criteria gap report
Each elected criterion set against the control you actually run, with the evidence it produces named and the gap stated.
Evidence index
Which controls throw off their own evidence, which need a person each quarter, and what that costs across a Type II window.
Scope memo
What sits inside the boundary and what was deliberately left out, with the reason for each call written down rather than assumed.
Remediation shortlist
What to fix before fieldwork and what can wait, ranked by what the opinion is at risk on rather than what is quickest.
Auditor question sheet
What to ask a CPA firm so two quotes can be compared - scope, window, testing depth, what a re-test costs and what is excluded.
Real numbers, upfront.
- Scope
- Set by the criteria you elect
- Input
- Your controls, policies, evidence
- Re-read
- Annually, or on a scope change - a new system, a new criterion, a new buyer asking.
The scope is fixed before the meter starts, so the fee is flat - and nothing is charged until you approve it.
Request your scan- Independent readiness report, costed
- Pipeline trace, transform by transform
- Vendor-clause review included
- A dated evidence trail you keep
Four lines you have to put a number against
Good faith is not a document. Each of these is either in your hand on the day somebody asks, or it is not.
The opinion,
bought
The CPA firm's fee for the attestation itself, quoted against your boundary and elected criteria. It is their number, and no readiness review shrinks it.
The readiness,
read
What fieldwork will ask for, checked while changing it is still cheap. Arriving unready does not avoid this cost - it moves it onto the clock of the firm billing you.
The window,
chosen
A Type II covers a period you pick, commonly three to twelve months. Nobody quotes it as a cost, and it is the line that decides when you can answer the buyer.
The renewal,
dated
The report covers its window and then expires. What it costs to hold in year two, and the bridge letter for the gap between reports, belong in the first budget.
Four lines, and only one of them is ours to quote.
Plain answers
Scope, timing, and the cost of getting it wrong. Answered straight.
Request your scanHow much does the SOC 2 audit itself cost?
That fee belongs to the licensed CPA firm that signs the opinion, and it is quoted against your boundary, your elected criteria and your window - not off a price list. We are not a CPA firm, so we will not quote theirs.
What does the whole thing cost, readiness and audit together?
Five lines, not one: the CPA firm's opinion, the readiness read, testing, tooling and your own hours. Only the readiness fee is ours to state - it is $9,000, published, and the same number the checkout charges.
Are there ongoing costs after the first report?
Yes. A SOC 2 covers a period and then expires, so the tooling, the testing and the audit recur annually - and a bridge letter usually covers the gap between one report ending and the next beginning.
Can we prepare for SOC 2 without buying compliance software?
Yes. Software buys automation, not compliance - it collects evidence you could collect yourself. Whether it earns its licence depends on how many controls you run and how much of your stack already produces evidence.
What does iDharma charge?
The readiness review is a published fixed fee of $9,000. It is the same number in the checkout, it does not move with what we find, and it does not include the CPA firm's fee for the opinion.
Request your readiness review
Tell us what you generate and where it goes, and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which systems sit inside the boundary
- Where that content is published, and who gets to see it
- Any documentation - policies, prior reports
- Whether you host the model, buy it, or fine-tune one
- A published asset or two, exactly as your readers get them
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- AICPA Trust Services Criteria (2017, rev. 2022)
- AICPA SSAE No. 18, AT-C section 205
- Criteria
- TSC 2017, rev. 2022
- Last read
- 14 September 2026
What it means
- General information about what the criteria ask — not legal or accounting advice, and no professional relationship arises from reading it. It determines nothing about your own systems.
- Where a scope question is arguable, our reports say so rather than the convenient one.
Scope & limitation
- Every range here is an indicative market observation, not survey data.
- Only the $9,000 readiness fee is ours - the opinion is a CPA firm's fee.
- Do not rest a binding decision on it; engage qualified counsel.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.