About Cost of Compliance

Independent, vendor-neutral cost research for security compliance programs.

Why this site exists

Ask what a SOC 2 costs and you get one of two answers: a vendor landing page that quotes only the part they sell, or a forum thread with a number and no context. Neither helps when you have to defend a budget line to a finance team that has never heard of a trust services criterion.

Cost of Compliance exists to give that budget conversation a defensible starting point. The calculators break a compliance program into its actual components — auditor fees, tooling, testing and internal hours — and show a range for each with the assumptions written down. You can disagree with an assumption and adjust; you cannot do that with a single number in a sales deck.

Who writes this

The site is produced by a small independent editorial team with hands-on experience taking B2B software companies through SOC 2 and ISO 27001 audits, on both the buying and the implementing side. Every page is written specifically for this site. Nothing here is syndicated vendor content or a rewritten press release.

How the site is funded

Cost of Compliance is funded by display advertising. Ad units are clearly labelled "Advertisement", kept visually distinct from editorial content, and never placed to be confused with navigation, buttons or calculator results. We limit ad units per page rather than maximising them.

What we do not do:

  • We do not accept payment for favourable coverage or placement in comparisons.
  • We do not use vendor affiliate or referral links.
  • We do not sell or broker reader contact details as sales leads.
  • We do not gate calculators behind an email form.

If that changes, the disclosure will appear here and on the affected pages before the change takes effect.

Editorial standards

  • Show the model. Every calculator's formula and assumptions are documented on the methodology page.
  • Say "we do not know". Where a vendor's current price is not publicly verifiable, we mark it for verification instead of inventing a figure.
  • Correct in public. Corrections are applied and dated rather than quietly edited away.
  • No fear marketing. Compliance is a commercial requirement, not a catastrophe. We write about it as a budget decision.

Contributing data

The most useful thing a reader can send is the structure of a real quote: framework, audit type, headcount band, region and total. We treat submissions as confidential, never name the sender or their employer, and use them only in aggregate to refine the bands. Details are on the contact page.

Scope

Current coverage is SOC 2, ISO 27001, penetration testing and cyber insurance, with US market pricing as the default. Coverage expands as the underlying pricing data becomes reliable enough to publish — we would rather ship four accurate calculators than twelve speculative ones.