SOC 2 · COST GUIDE · READINESS FROM $9,000

A SOC 2 is five bills, not one.

A SOC 2 is five bills, not one - and the largest is usually your own team. What each line is, and what moves it.


A reviewer with curly dark hair, in a charcoal blazer, a closed notebook at the edge of the desk, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Independent means no stake in the answer
The CPA fee Readiness $9,000 Pen test Tooling Your hours

Our promise

“A price you cannot compare is a guess.”

The readiness fee is published. The opinion is a licensed CPA firm’s to sign, and their fee is never folded into ours. The fee is fixed at $12,500, and nothing is charged until you approve it.

Request this readiness scan
The case file

The SOC 2 bill, in three chapters

The Law

A SOC 2 is not one invoice but five. There is the opinion a licensed CPA firm signs, the readiness read that comes before it, a penetration test where your buyer asks for one, the tooling you subscribe to, and the hours your team spends gathering the evidence each quarter.

The Gap

Two quotes for the same report can differ several times over, and usually they are quoting different things. What moves the number is how many criteria you elected, how much sits inside the boundary, whether the report is Type I or Type II, and how long the observation window runs.

The Office

Our job is the read before the audit. We settle the boundary, check which controls already produce their own evidence, cost what is missing, and hand you the questions that make two quotes comparable. We issue no opinion and sell no software, so nothing we find earns us a fee.

The Act, split

Two invoices. Only one is ours.

The opinion is signed by a licensed CPA firm. The read before it is ours.

What the CPA firm is paid for № 01
  • The opinion - signed, and theirs alone to issue
  • Fieldwork - testing your controls across the window
  • The report - description, tests, results and exceptions
  • Re-tests - priced separately when a control fails
SOC 2 · iDharma · Presented for assay
What you carry yourself № 02
  • Tooling - annual, and per seat more often than not
  • Hour counts - what each control costs you every quarter
  • Remediation - unknowable until the gap read is done
  • Renewal - annually, plus a bridge letter between
SOC 2 · iDharma · Presented for assay
Know your role

The opinion is theirs. The bill is yours.

The CPA firm

The opinion, and its fee

A SOC 2 is an attestation opinion signed by a licensed CPA firm. That fee is theirs to set and ours to stay out of - we are not a CPA firm and do not issue the report. It is commonly the single largest external line on the whole budget, and it is quoted against your own scope rather than off any price list.

The readiness

The read before the audit

What the fieldwork will actually ask for, checked before the meter starts. Ours is a published fixed fee that never moves with what we find, and it exists because arriving at an audit unready is the most expensive way to find a gap - the CPA firm bills that discovery either way, then bills the re-test.

The catch

The line nobody budgets

Your own people. Evidence gathering, screenshots, policy drafting, answering the auditor's questions - commonly hundreds of hours, spread right across the quarter, billed to no one and therefore budgeted for by no one. It routinely comes to more than every other invoice on this page put together.

What most teams assume

“We just need a SOC 2. Ten thousand, right?”

What the contract says

That is one line of five. Ask for the other four.

It is the most common finding we write up.

  • Who it is for
  • SaaS & platform vendors
  • Startups selling upmarket
  • Security & GRC leads
  • Finance & procurement
  • Founders answering an RFP
Where the money goes
A long black archive box closed on a dark desk under a low warm light, a blank brass label plate screwed to its front with a single stud, a fountain pen and reading glasses beside it, and a small card propped in front reading EVIDENCE OVER PROMISES above a pair of scales.
01 The largest line on most SOC 2 budgets is not an invoice at all. It is your own people gathering evidence, every quarter, for the length of the window.
02

Two firms can quote the same report and differ several times over, because they are quoting different scopes, windows and testing depths.

03

A Type II covers a period you choose. Nobody bills you for the window, and it is the line that decides when you can answer the buyer.

04

The report expires with its period. Budget SOC 2 as a subscription rather than a project, or year two arrives as a surprise.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

Headcount -

It is not the headline number. What counts is how many people hold access the criteria make you review, and how many systems come with them - a lean company with nine production systems can cost more than a large one with two.

Report -

Most enterprise buyers mean Type II. Paying for a Type I when the contract wanted a period covered is the most common wasted spend on this page, and it is avoidable with one email.

Evidence -

This is the hours line. A control that throws off its own evidence costs nothing each quarter. The rest cost a person with a screenshot tool, every quarter, for the length of the window.

The calendar

Four moments, and the longest one is yours.

The middle two are work you control. The last one is elapsed time, and no amount of effort makes a window pass faster than it passes.

  1. Scoped

    Week zero

    The boundary and the elected criteria are settled in writing, and nothing is charged until you approve.

  2. Read

    Weeks 1-4

    The readiness review: what the criteria ask, what your controls produce, and where the two do not meet.

  3. Observed

    3 to 12 months

    A Type II watches controls operate across a window you choose. The window is a cost, and it is yours.

  4. Renewed

    Every 12 months

    The report covers a period and then stops. Budget it as a subscription rather than as a project.

The trap

Teams budget the audit fee and stop there. The line that actually dominates is not on any invoice — it is the hours your own team spends collecting evidence, every quarter the window runs.

Requirement & coverage

What the bill contains, what we do about it

12 things to settle, and the artefact that answers each one. Paired, so every claim on this page can be checked against the requirement beside it.

The CPA firm's opinion Their fee, quoted on your scope - not ours to set
Named as a separate line before you commit, so two quotes can be compared like for like instead of one bundled number.
The readiness review Ours, fixed and published - the one exact figure here
The gap read itself: boundary, elected criteria, and whether each control named actually produces its own evidence.
Type I or Type II A point in time, or a period - the choice moves everything
Which one your buyer actually asked for, in writing, before you pay for the more expensive answer to the wrong question.
The observation window Commonly three to twelve months, and you choose it
What a shorter window costs you in credibility and a longer one costs you in time, set against who is asking for the report.
Penetration testing Commonly asked for, priced by the tester and not by us
Whether your buyer or your auditor actually requires one, at what depth, and what the report has to show to count.
Compliance tooling Annual, and per seat more often than the pricing page says
Whether a platform earns its licence against what you already run, or whether it is automating a spreadsheet you could keep.
Security tooling MDM, logging, scanning - mostly things already in place
Which criteria your existing stack already satisfies, so the gap list is what you must buy rather than what a vendor sells.
Policy and documentation Written once, then kept current - the second part is the cost
Which policies the criteria actually require, and which of yours are describing a process nobody follows any more.
Evidence collection The hours nobody puts in the budget, every single time
Which controls throw off their own evidence and which need a human with a screenshot tool every quarter, named one by one.
Remediation Unknowable until the gap read - and quoted as such
Ranked by what the audit will actually stop on, so the spend goes where the opinion is at risk rather than where it is easy.
Your own staff hours Commonly the largest line, and it appears on no invoice
An honest hour count per control owner, so the internal cost is a number in the plan instead of a surprise in the quarter.
Renewal and the bridge Annual, plus a bridge letter to cover the gap between
What holding the report costs every year after the first, which is the line that decides whether SOC 2 was worth starting.
The engagement

Your control set, independently read

From a first Type I to a renewed Type II.

  1. Scope

    What is in the system boundary, which criteria you elect, and what that costs.

  2. Read

    Your controls against the criteria, and the evidence each one does or does not produce.

  3. Price and sign off

    You see the draft first. Then the gap list, the shortlist and the costed plan - dated.

Request your readiness review
An auditor in a forest-green trouser suit and cream blouse, with braided hair in a high bun, standing against a warm pale wall and pointing into the open space alongside.
The record is what you are buying.
Struck in your favour

Why teams ask iDharma what it will really cost

We sell no software

No platform to license, no seats to grow, and no reason to call your spreadsheet a gap.

We do not issue the SOC 2

A licensed CPA firm signs that opinion. We read you before it, and we say so on every page.

One fixed fee, published

The readiness price is published on this page and in the checkout, and no finding we make changes it.

Costed, not just listed

Every gap arrives with what closing it takes in money and hours, so the plan is a budget not a wish.

Four marks, struck on every readiness report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Costed readiness report

The whole assessment in one document: what sits inside the system boundary, which trust services criteria you have elected, which controls already produce their own evidence and which do not, what each remaining gap takes to close in money and in hours, and what to expect the CPA firm to ask for.

Workbook

Cost model workbook

Every line on this page as a row you can edit - the ranges, your hour counts and the quotes you collect, totalling as you go.

Report

Criteria gap report

Each elected criterion set against the control you actually run, with the evidence it produces named and the gap stated.

Index

Evidence index

Which controls throw off their own evidence, which need a person each quarter, and what that costs across a Type II window.

Memo

Scope memo

What sits inside the boundary and what was deliberately left out, with the reason for each call written down rather than assumed.

Ranked

Remediation shortlist

What to fix before fieldwork and what can wait, ranked by what the opinion is at risk on rather than what is quickest.

Templates

Auditor question sheet

What to ask a CPA firm so two quotes can be compared - scope, window, testing depth, what a re-test costs and what is excluded.

Format & fee

Real numbers, upfront.

Scope
Set by the criteria you elect
Input
Your controls, policies, evidence
Re-read
Annually, or on a scope change - a new system, a new criterion, a new buyer asking.

The scope is fixed before the meter starts, so the fee is flat - and nothing is charged until you approve it.

Request your scan
SOC 2 · Readiness review $12,500 flat
  • Independent readiness report, costed
  • Pipeline trace, transform by transform
  • Vendor-clause review included
  • A dated evidence trail you keep
Show your hand

Four lines you have to put a number against

Good faith is not a document. Each of these is either in your hand on the day somebody asks, or it is not.

The opinion,
bought

The CPA firm's fee for the attestation itself, quoted against your boundary and elected criteria. It is their number, and no readiness review shrinks it.

The readiness,
read

What fieldwork will ask for, checked while changing it is still cheap. Arriving unready does not avoid this cost - it moves it onto the clock of the firm billing you.

The window,
chosen

A Type II covers a period you pick, commonly three to twelve months. Nobody quotes it as a cost, and it is the line that decides when you can answer the buyer.

The renewal,
dated

The report covers its window and then expires. What it costs to hold in year two, and the bridge letter for the gap between reports, belong in the first budget.

Four lines, and only one of them is ours to quote.

FAQ

Plain answers

Scope, timing, and the cost of getting it wrong. Answered straight.

Request your scan
How much does the SOC 2 audit itself cost?

That fee belongs to the licensed CPA firm that signs the opinion, and it is quoted against your boundary, your elected criteria and your window - not off a price list. We are not a CPA firm, so we will not quote theirs.

What does the whole thing cost, readiness and audit together?

Five lines, not one: the CPA firm's opinion, the readiness read, testing, tooling and your own hours. Only the readiness fee is ours to state - it is $9,000, published, and the same number the checkout charges.

Are there ongoing costs after the first report?

Yes. A SOC 2 covers a period and then expires, so the tooling, the testing and the audit recur annually - and a bridge letter usually covers the gap between one report ending and the next beginning.

Can we prepare for SOC 2 without buying compliance software?

Yes. Software buys automation, not compliance - it collects evidence you could collect yourself. Whether it earns its licence depends on how many controls you run and how much of your stack already produces evidence.

What does iDharma charge?

The readiness review is a published fixed fee of $9,000. It is the same number in the checkout, it does not move with what we find, and it does not include the CPA firm's fee for the opinion.

Get started

Request your readiness review

Tell us what you generate and where it goes, and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Which systems sit inside the boundary
  2. Where that content is published, and who gets to see it
  3. Any documentation - policies, prior reports
  4. Whether you host the model, buy it, or fine-tune one
  5. A published asset or two, exactly as your readers get them

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • AICPA Trust Services Criteria (2017, rev. 2022)
  • AICPA SSAE No. 18, AT-C section 205
Criteria
TSC 2017, rev. 2022
Last read
14 September 2026

What it means

  • General information about what the criteria ask — not legal or accounting advice, and no professional relationship arises from reading it. It determines nothing about your own systems.
  • Where a scope question is arguable, our reports say so rather than the convenient one.

Scope & limitation

  • Every range here is an indicative market observation, not survey data.
  • Only the $9,000 readiness fee is ours - the opinion is a CPA firm's fee.
  • Do not rest a binding decision on it; engage qualified counsel.

Something on this page out of date?

Tell us