There is no Schellman rate card
Schellman publishes no SOC 2 fee schedule. Neither does A-LIGN, Coalfire, Linford & Co, Johanson Group, Prescient Assurance, or any other CPA firm in this market. A SOC 2 examination is an attestation engagement performed under AICPA standards, scoped and priced per client after a scoping conversation, and fixed in an engagement letter. A fee table attributed to a named audit firm is a number that firm never published.
What you can know, and act on, is the mechanism. The fee is a function of auditor hours. Auditor hours are a function of the scope you define and the state of the evidence you hand over. You set both of those before you ask anyone for a number.
What actually sets the fee
- System boundary. Which products, environments, and supporting systems sit inside the description of the system.
- Trust Services Criteria in scope. Security, the Common Criteria, is the base. Availability, Confidentiality, Processing Integrity, and Privacy each bring more control points and more testing. See the criteria breakdown.
- Type 1 or Type 2. Design at a point in time, or operating effectiveness across a period. See Type 1 vs Type 2.
- Observation window. A longer Type 2 period means more samples to pull and test.
- Readiness state. The lever you control most directly. See readiness.
- Frameworks bundled into one engagement. SOC 2 and ISO 27001 share a substantial amount of control ground. A firm that can test the overlap once, rather than twice, spends fewer hours. See SOC 2 vs ISO 27001.
What is verifiable about Schellman
Schellman is a CPA firm headquartered in Tampa, Florida, specialising in IT audit and information security attestation. It carries a wide framework catalogue: SOC 1, SOC 2 and SOC 3 under the AICPA standards, plus ISO 27001, HITRUST, PCI DSS, and FedRAMP work. The firm's positioning is set out on its own site at schellman.com.
Two things genuinely matter to a buyer here: brand familiarity in enterprise procurement, and framework breadth. Procurement teams reviewing a vendor's SOC 2 report recognise the established specialist firms and rarely question the attestation itself. And where you expect to add ISO 27001 or another framework within the next couple of years, a firm that can carry both is worth having on the shortlist, because one evidence cycle is less internal work than two.
Where Schellman belongs on the shortlist
Schellman belongs on your shortlist when you are multi-framework today or expect to be soon, and when your enterprise buyers are the kind of procurement function that pattern-matches on the auditor's name. If you are a smaller company pursuing SOC 2 alone on the Security criterion, put boutique specialists such as Linford & Co and Johanson Group on the list as well. If you have a federal roadmap, add A-LIGN and Coalfire, both accredited 3PAOs. Then let the quotes, on an identical written scope, do the arguing.
Negotiation levers that actually exist
You cannot negotiate a discount off a list price that does not exist. You can shape the engagement. Tighten the system boundary. Drop criteria nobody has asked you for. Choose Type 1 or Type 2 deliberately rather than buying both in sequence. Bundle frameworks into a single engagement upfront rather than bolting them on serially, so the control overlap is tested once. Schedule outside the Q4 financial-audit crunch. Fix the year-two renewal at the same time as year one. And put competing quotes on an identical scope in front of the firm, because that is the only comparison a firm can actually respond to.