Methodology

Every figure on this site is a modelled estimate, not a quote. This page explains exactly how each number is produced so you can judge whether it applies to you.

Principles

  • Ranges, never single numbers. Compliance pricing is negotiated. A single figure would be false precision.
  • Internal time is a real cost. Most published estimates omit it, which is why real programs feel twice as expensive as the blog posts promised.
  • No invented vendor prices. Where a specific vendor's current price is not publicly verifiable, we label the cell "verify current pricing" rather than guess.
  • No paid placement. No vendor pays to appear, rank higher, or be described favourably here.

Size bands

Every calculator maps headcount into one of five bands, because auditors, certification bodies and platforms all price from headcount in similar steps.

BandEmployeesTypical characteristics
Micro1–25One product, one cloud account, founder-led security
Small26–100First dedicated security or compliance owner
Mid101–250Multiple environments, formal change management
Large251–1,000Several products, possibly multiple sites
Enterprise1,000+Multi-entity scope, internal audit function

Auditor and certification body fees

SOC 2 auditor fees are anchored to 2026 US CPA firm pricing: $5,000–$25,000 for a Type 1 and $10,000–$60,000 for a Type 2, banded by size. Each additional framework covered in the same engagement multiplies the auditor line by 1.3, reflecting shared fieldwork rather than a full second audit.

ISO 27001 is modelled from audit days rather than flat fees, following the sizing logic in ISO/IEC 27006, at day rates of roughly $1,200–$2,200. Surveillance audits in years two and three are modelled at 50–60% of the initial certification total combined, and ISO 27701 adds a 35% uplift when certified in the same cycle.

Compliance automation platforms

Modelled at $8,000–$30,000 per year, banded by headcount, with a 15–20% uplift per additional framework. This band reflects publicly reported list and negotiated pricing across the category as a whole. It is not a claim about any individual vendor's price — all of them quote privately.

Penetration testing

Priced from estimated tester-days at $1,800–$2,800 per day, producing an overall $4,000–$30,000 band. Multipliers: black box 0.9, grey box 1.0, white box 1.25. Each additional distinct target adds 55% of the base. Reporting is shown at 8–12% of the test cost and a remediation retest at 15–25%.

Internal time

Costed at a blended $85 per fully-loaded hour, which approximates a US engineering and operations mix including benefits and overhead. Hour estimates run from 90–200 hours at mature security posture to 320–640 hours starting from nothing, and are multiplied by 1.5–1.6 when no automation platform is in place because evidence collection becomes manual. If your loaded cost per hour is different, scale that line linearly.

What these estimates are not

  • They are not quotes. No auditor or vendor is bound by anything shown here.
  • They are not legal, accounting or assurance advice. Nothing here substitutes for a licensed practitioner's judgement.
  • They are US-market centric. European and APAC pricing differs, often downward for audit days and upward for specialist testing.

Review cadence and corrections

Bands are reviewed each quarter against publicly available pricing, published benchmark reports and anonymised figures readers share with us. If a number here looks wrong against a real quote you hold, tell us on the contact page — corrections with evidence are applied and the change is dated. Read more about who runs this site on the about page.