How to Choose a SOC 2 Auditor: What Sets the Quote, and How to Compare Firms
The audit is the largest line in a SOC 2 budget that you cannot look up. No CPA firm publishes a rate card, so this page does not have a fee table on it. What it has instead is more useful: the mechanism that actually sets your number, and how to run a process that makes three firms compete on it.
Every driver below is something you control before you ask for a quote.
Why no firm publishes a price
A SOC 2 report is not a product with a SKU. It is an attestation engagement performed under AICPA standards, in which a licensed CPA firm examines a system you defined against criteria you selected, over a period you chose. The work cannot be priced until that scope exists, and the scope is different for every client. So the fee is set per engagement and fixed in an engagement letter, and there is nothing for a firm to publish.
This matters because the internet is full of confident SOC 2 fee tables attributed to named firms. Every one of them is a number the firm never published. The honest version of this page is the mechanism, not a table, and the mechanism is more actionable anyway: a fee table tells you what to expect, and the drivers below tell you what to change.
What actually sets the fee
The fee is a function of auditor hours. Auditor hours are a function of how much you put in scope and how well organised the evidence is when it arrives. Both are yours.
System boundary
Which products, environments and supporting systems sit inside the description. The single biggest driver, and the one most often set too wide by default. Everything inside the boundary gets tested.
Criteria in scope
Security, the Common Criteria, is the base. Availability, Confidentiality, Processing Integrity and Privacy each add control points and testing hours. See the criteria breakdown.
Type 1 or Type 2
Design at a point in time, or operating effectiveness across a period. Type 2 requires sampling and testing that Type 1 does not. See Type 1 vs Type 2.
Observation window
A longer Type 2 period means more samples and more testing. Shorter windows cost less and carry less weight with some buyers. See the timeline.
Systems and locations
More environments, more cloud accounts, more physical sites, more entities in the description all mean more walkthroughs and more evidence to test.
Evidence maturity
Organised, retrievable, complete evidence takes fewer auditor hours than a scramble, and exceptions found mid-fieldwork cost more than gaps closed beforehand. See readiness.
The firm tiers, without a price attached
The tiers are a real feature of this market, but what separates them is capacity, accreditation and brand rather than a posted price. Use the tier as a shortlist filter, then let the quotes decide.
Boutique CPA firms
Quoted per engagement
Specialist SOC examination practices, small teams. Examples: Linford & Co, Prescient Assurance, Johanson Group.
Strengths
Deep SOC 2 focus, faster scheduling, senior people actually on your engagement rather than supervising it from a distance.
Limits
No federal accreditations, so a FedRAMP or CMMC roadmap means a second firm. Brand recognition may matter to some enterprise buyers.
When it fits
Startups and scale-ups with no federal roadmap and no procurement team naming acceptable auditors.
Mid-tier and specialist firms
Quoted per engagement
National practices with dedicated compliance and IT audit teams. Examples: Schellman, A-LIGN, Coalfire, BDO, Grant Thornton, Moss Adams.
Strengths
Wider framework capability under one engagement, stronger procurement brand recognition, and in some cases federal accreditations that boutiques do not hold.
Limits
Longer scheduling lead times and less flexibility on engagement shape.
When it fits
Multi-framework programmes, or a real federal or state roadmap, or enterprise buyers who care whose name is on the report.
Big 4
Quoted per engagement
Deloitte, PwC, EY, KPMG. Examples: Deloitte, PwC, EY, KPMG.
Strengths
Maximum brand credibility and global reach, alongside the other services a listed or listing company needs.
Limits
A small SOC 2 engagement is not their core business and will not be their priority.
When it fits
Genuinely required rather than chosen: an IPO process, a regulator, or a customer that names them specifically.
Firm-specific detail, including the accreditations that are a matter of public record, is on the individual pages: A-LIGN, Schellman, Coalfire, Linford & Co, Johanson Group, Prescient Assurance.
How to run a three-quote process
Since there is no rack rate, the only way to find out what your audit costs is to make firms tell you, on terms that make their answers comparable. This is the whole method.
- 1.Write the scope down once. System boundary, criteria in scope, report type, observation window, report deadline. One document. This is the single most important step, because quotes against different scopes are not comparable and comparing them tells you nothing.
- 2.Send the identical document to three firms. Ideally across tiers, so the spread tells you something about the market rather than about one segment of it. Tell each firm it is competing; a firm can only sharpen a number when it knows what it is being compared against.
- 3.Compare what is included, not the headline. Readiness or gap assessment priced separately, the examination itself, rounds of report review, bridge letters, and the year-two renewal. Two quotes with the same number can contain very different amounts of work.
- 4.Fix year two before you sign year one. This is the lever nearly everyone gives away. Once your evidence lives in a firm's process, the renewal is negotiated from a position of having no alternative. Agree it in writing while you still have three firms interested.
Questions to ask before signing
1. How many SOC 2 examinations does your team complete a year?
A specialist moves faster and raises fewer false issues than a generalist practice doing a handful.
2. Have you audited companies with our tech stack and in our industry?
AWS versus Azure versus GCP experience matters. So does SaaS versus fintech versus healthcare.
3. Is the fee fixed or hourly?
Insist on fixed. Hourly means your cost rises when the auditor works slowly, which is the wrong incentive on both sides.
4. What is in the fee, and what is extra?
Readiness review, management letter, follow-up calls, report revisions. Clarify every deliverable before signing.
5. What is your timeline from engagement to report?
Good firms commit to dates. Vague answers mean scheduling risk, and scheduling risk means your deal slips.
6. Who is the engagement lead, and who does the fieldwork?
You want an experienced manager, not a team learning SOC 2 on your audit while the partner appears twice.
7. Which GRC platforms do you work with directly?
If your platform and the auditor already have a working evidence flow, fieldwork is materially less painful.
8. What does clean evidence look like to you?
Their expectations, understood upfront, are the difference between a smooth fieldwork and six weeks of follow-ups.
9. What is the year-two renewal fee?
Ask now, in writing, while you still have leverage and other firms are still in the process.
10. Can you support the frameworks on our roadmap?
Switching firms for a second framework is expensive. If ISO 27001 or HIPAA is coming, ask before you commit.
Red flags
The same firm does your readiness and your audit
Independence is the foundation of an attestation engagement, and a firm evaluating work it helped you prepare sits in a different position from one that did not. Not automatically disqualifying, but ask how they handle it and be ready to explain the answer to a procurement team.
They will not quote a fixed fee
A firm that can scope the work can price it. Resistance to a fixed fee usually means they expect scope creep, and hourly billing puts the cost of that entirely on you.
A quote far below the others on identical scope
This is exactly why you send the same scope to three firms: the spread is the signal. A number well outside the others means someone has understood the scope differently, and finding out which one during fieldwork is expensive.
No references from comparable companies
Ask for two or three references at your size, in your industry, on your stack. Inability to produce any is a warning worth heeding.
Negotiation levers that actually exist
You cannot negotiate against a rack rate, because there is not one. You negotiate the shape of the engagement, and the levers below are real because each one changes the number of hours the work takes.
Tighten the boundary before you ask
The cheapest hour is the one nobody bills. Scope reduction is the only lever that lowers the fee without asking anyone for a favour, and it is the one buyers reach for last.
Drop criteria nobody asked for
Optional criteria bought speculatively add testing you pay for every year thereafter. Add them when a customer actually asks, not in case one does.
Book outside the Q4 crunch
Audit teams are stretched from October through January by year-end financial work. A Q2 or Q3 engagement gets you more attention and more scheduling flexibility.
Agree year two at year one
Your leverage is highest before your evidence lives in one firm's process. A renewal negotiated later is negotiated from a weaker position, whatever the firm.