Worked example · 2026 pricing
SOC 2 cost for a 10-person startup
"How much is SOC 2 going to cost us?" is almost always asked by a founder with a ten-person team, one enterprise deal stuck in security review, and no line in the budget for it. This page answers it with an itemised example rather than a range, using the same cost model as our SOC 2 calculator.
The scenario
A ten-person B2B SaaS company: six engineers, two go-to-market, two founders. Single production AWS account, a managed Postgres database, Google Workspace for identity, no on-premise infrastructure and no dedicated security hire. Some hygiene is already in place — MFA is on, laptops are managed loosely, there is a Notion page that calls itself a security policy — but there is no risk register, no access-review cadence and no evidence anyone could hand an auditor. In our model this is a micro company (1–25 employees) with partial maturity, buying a compliance automation platform. Security Trust Services criterion only; Availability and Confidentiality are excluded.
The itemised budget
Both columns are first-year totals. The Type 1 column is the cost of getting a point-in-time report issued; the Type 2 column is the cost of running a three-month observation window and getting the report that enterprise buyers actually accept.
| Cost line | Type 1 | Type 2 |
|---|---|---|
| Auditor fees (CPA firm)Boutique or mid-market firm, single criterion, small scope. Type 2 covers the observation window plus report issuance. | $5,000 – $9,000 | $10,000 – $18,000 |
| Compliance automation platformTwelve-month subscription at the smallest headcount tier. Priced the same whichever report you pursue. | $8,000 – $14,000 | $8,000 – $14,000 |
| Penetration testSingle web application plus its API. Not mandated by the AICPA, but requested by nearly every enterprise buyer who reads the report. | $4,000 – $9,000 | $4,000 – $9,000 |
| Internal time (readiness + audit support)180–380 hours at $85 per fully-loaded hour. Type 2 sits at the upper end because controls must be operated and evidenced across the whole window. | $15,300 – $27,200 | $18,000 – $32,300 |
| Security tooling gap-fill (optional)MDM for ten laptops, centralised logging, background checks, awareness training. Skip only if you genuinely have these already. | $3,000 – $8,000 | $3,000 – $8,000 |
| First-year total | $35,300 – $67,200 | $43,000 – $81,300 |
The number that surprises founders is not the auditor's invoice — it is the internal time line. At ten people, roughly 200 to 380 hours of engineering and founder attention goes into a first SOC 2: writing policies you will actually follow, wiring integrations, fixing the access-control findings the platform surfaces in week two, running the first access review, and then answering the auditor's evidence requests. Costed at a realistic $85 per fully-loaded hour — salary plus payroll taxes, benefits and overhead, not the salary figure alone — that is frequently the largest single line in the budget, and it is the one nobody puts in the board deck.
What drives the number up
- Extra Trust Services criteria. Adding Availability and Confidentiality to Security typically raises auditor fees 20–40% and adds evidence obligations (capacity monitoring, formal SLAs, data-classification handling). Add them only if a named customer contract requires it.
- Complex or multi-cloud infrastructure. Two cloud providers, a self-managed Kubernetes estate, or third-party subservice organisations all extend fieldwork hours and the carve-out language in the report.
- Starting from zero. Our "no maturity" setting pushes internal hours to 320–640 and adds a tooling gap-fill line. A team with nothing written down should budget closer to the top of both columns.
- Compressed timelines. Auditors charge for expedited scheduling, and a rushed readiness phase converts directly into exceptions in the report — the expensive kind of saving.
- A second framework mid-year. Adding ISO 27001 or HIPAA after signing typically costs more than scoping it in at the start; our ISO 27001 calculator prices the combined path.
What drives the number down
- Ruthless scoping. One product, one production environment, Security criterion only. Scope is the cheapest lever you have and the one most teams forget to pull.
- Choosing the auditor before the platform. Audit firms quote lower when evidence arrives in a format they already work with, and several will tell you which tools make their fieldwork faster. Get three quotes; spread on identical scopes is wide.
- Annual platform billing and a multi-year term — but only after confirming what adding a second framework mid-term costs. Compare the vendors first with Vanta vs Drata and Drata vs Secureframe.
- One owner, not a committee. The single largest reducer of internal hours is naming one person accountable for the programme. Split ownership across three engineers and the hours roughly double through context-switching alone.
- Reusing the penetration test. One well-scoped annual test satisfies the auditor, the enterprise security questionnaire and, usually, your cyber insurer — see the cyber insurance calculator for how controls evidence affects premiums.
Timeline expectation
For this profile, a realistic path is: weeks 1–2 to select a platform and an auditor and connect integrations; weeks 3–10 for readiness — policies, risk assessment, access reviews, vendor list, remediating whatever the platform flags; week 8 or so to run the penetration test so findings can be fixed before the window opens. A Type 1 can then be issued around month 3 to 4. A Type 2 needs an observation window on top: three months is the shortest window most auditors will accept for a first report, so realistically month 6 to 8 before the report lands, and a further two to four weeks for the auditor to draft and issue it.
The common mistake is promising a prospect a Type 2 in eight weeks. It cannot be done — the window has to elapse. What you can do is issue a Type 1 quickly to unblock the deal and commit contractually to a Type 2 within the following two quarters, which most enterprise security teams will accept from a company this size. The Type 1 vs Type 2 guide covers exactly how to position that with a buyer.
What year two looks like
SOC 2 is a subscription, not a purchase. Year two drops the readiness spike but keeps the recurring lines: the auditor engagement repeats (usually at a similar or slightly lower fee for a twelve-month window), the platform renews, the penetration test repeats annually, and internal time falls to perhaps 80–150 hours if the controls have genuinely been operating. Budget roughly $30,000 to $55,000 for a steady-state second year at this headcount — then add for growth, because every rating input in the model scales with headcount.
To price your own situation rather than this one, change the inputs in the SOC 2 cost calculator. If you want to understand where each figure comes from, the methodology page documents the model, its sources and its assumptions in full.