There is no A-LIGN rate card
A-LIGN publishes no SOC 2 fee schedule. Neither does Schellman, Coalfire, Linford & Co, Johanson Group, Prescient Assurance, or any other CPA firm in this market. A SOC 2 examination is an attestation engagement performed under AICPA standards, scoped and priced per client, and fixed in an engagement letter. Any fee table attributed to a named audit firm is a number that firm never published.
The useful thing to understand instead is the mechanism. The fee is a function of auditor hours, and auditor hours are a function of the scope you define and the state of the evidence you hand over. Both are yours to control before you ask for a quote.
What actually sets the fee
- System boundary. The products, environments, and supporting systems inside the description. This is the biggest single driver.
- Trust Services Criteria in scope. Security, the Common Criteria, is the base. Availability, Confidentiality, Processing Integrity, and Privacy each add control points and testing. See the criteria breakdown.
- Type 1 or Type 2. Design at a point in time, or operating effectiveness across a period. See Type 1 vs Type 2.
- Observation window. A longer Type 2 period means more samples and more testing.
- Readiness state. Organised, retrievable evidence takes fewer auditor hours. See readiness.
- Frameworks bundled into one engagement. Where a firm can test overlapping controls once and use the result for two frameworks, the combined engagement takes fewer hours than two separate ones. This is where A-LIGN's multi-framework and federal capability is commercially relevant.
What is verifiable about A-LIGN
A-LIGN is a CPA firm headquartered in Tampa, Florida, specialising in IT audit, information security attestation, and federal assessment work. Its positioning is set out on the firm's own site at a-lign.com.
Two things about the firm are a matter of public record and are worth weighing in a selection process. First, A-LIGN is an accredited FedRAMP 3PAO and a StateRAMP 3PAO. If your roadmap runs from SOC 2 through to federal or state government sales, that accreditation means one firm can carry both, and you avoid duplicating evidence collection across two firms and two timelines. Second, Warburg Pincus made a strategic investment in A-LIGN in August 2021, alongside existing investor FTV Capital. That is not a quality signal in either direction, but it is relevant at the procurement table, because it shapes the firm's posture on multi-year commitments.
Where A-LIGN belongs on the shortlist
A-LIGN belongs on your shortlist when a federal or state roadmap is real (FedRAMP Moderate or High, StateRAMP) and you would rather one firm carried both the SOC 2 attestation and the assessment, or when you are running several frameworks at once and want them tested against one evidence cycle. Where the federal assessment is the dominant workload rather than the secondary one, Coalfire is the other firm with deep accredited federal capability and belongs on the same shortlist.
If you are pure commercial SaaS with no federal roadmap, the accreditation you would be paying to have available is one you will never use. In that case put Schellman, Linford & Co, and Johanson Group on the list as well and let the quotes decide.
Negotiation levers that actually exist
You cannot negotiate against a rack rate, because there isn't one. You can negotiate the shape of the engagement. Tighten the system boundary before you ask for a quote. Take criteria out of scope that no customer has ever asked for. Decide deliberately between Type 1 and Type 2 rather than buying both in sequence. Book outside the Q4 financial-audit crunch, when audit teams are stretched. Agree the year-two renewal in writing at the same time as year one, so the renewal is not negotiated from a position of having no alternative. And bring genuine competing quotes on an identical scope, because a firm can only sharpen a number when it can see what it is being compared against.