How much should a CPA firm charge for a SOC 2 audit?
Every page ranking for SOC 2 cost tells your client what to expect to pay, and none of them state what one engagement costs your practice to run.
How much should a CPA firm charge for a SOC 2 audit? Start from hours. The one published practitioner breakdown cited below reasons from staffing to an hours range and a floor, and it is quoted in full with the date it was read. Price above the floor those hours produce.
The harder question is the one underneath it. What does a single engagement cost your practice to run, and which part of it quietly consumes the margin you already quoted away?
Search the query your clients search and every result is written for them, which makes the whole corpus useless to you as a costing exercise. Quote off it and you are pricing against a buyer’s expectation instead of your own hours. The fee is usually not the mistake. The mistake is assuming the unpredictable part of the work is the testing.
Start from hours, not from what the market will bear
A fee you cannot decompose into hours is a guess wearing a rate card. The breakdown below is worth reading even where you disagree with the rates it assumes, because it works up from staffing rather than back from a market rate.
- One published practitioner breakdown puts a Security-only Type 2 at 60 to 80 auditor hours, at partner rates of $250 to $350 per hour and staff rates of $100 to $175, giving a stated floor near $9,000. Source, checked 2026-07-30.
Read that as a floor, not as a target. It assumes one Trust Services Criteria category,1 a cooperative client, and a scope that does not expand after the engagement letter is signed. Add categories and the hours move. Add a client who has never been examined before and they move again, in the one direction you cannot bill for. What the buyer side of that fee is told to expect is set out in what the auditor fee actually covers, which is worth reading mainly because your prospect has probably read something like it already.
Where the hours actually go
Break a small engagement into the work it genuinely contains. The last four items are the ones an estimate gets right. The first three are where the optimism lives.
- Scoping and planning
- System description, boundary, subservice carve-outs, criteria selection. Cheap when the client knows their own architecture. Expensive when they do not, and you find that out in week three rather than week one.
- The request list
- Building a prepared-by-client list is fast. Making it legible to an engineer who has never seen one is not. Every ambiguous request line becomes two emails later.
- Evidence chasing
- Requesting, receiving the wrong artifact, explaining, requesting again. Unbounded in theory, unbillable in practice, and the largest single source of variance on a small engagement.
- Testing
- Sampling, inspection, reperformance, exception handling. This is the part your estimate is usually right about, which is exactly why it is the wrong thing to worry about.
- Workpaper documentation
- Tying evidence to criteria so a reviewer, a peer reviewer, or your successor can follow the conclusion without you in the room to narrate it. That bar comes from the attestation standards.2
- Review and sign-off
- Partner time at partner rates. Compressed review is where documentation errors survive all the way to issuance.
- Report drafting and issuance
- Narrative, exceptions, dates, management letters. Mechanical when the workpapers are clean. A rewrite when they are not.
Realization leaks in the chasing, not in the testing
A complex control is bounded work: you scope it, test it, document it, and then it is finished whether it took two hours or six. A client who sends the wrong screenshot three times is unbounded. Each round trip costs a reply, a context switch, and a re-read of the request you already wrote, and none of that is defensible on a fee note.
Firms price for the testing and lose the year on the wrangling.
So price the client, not only the control set. Two engagements with identical scope will not consume the same hours, and what separates them is almost entirely how the evidence arrives. You can tell which one you have inside the first two weeks. Ask for three specific artifacts before you quote, because how they come back tells you more than the questionnaire ever will.
Year two is a different engagement, so price it differently
A roll-forward year is not last year at a discount. Some of the work genuinely disappears. Some of it only looks like it did, and setting year two as a flat percentage of year one gets both halves wrong at once.
| Work | Year one | Roll-forward year |
|---|---|---|
| Scoping and system description | Built from nothing | Update and confirm, unless the architecture moved |
| Control narrative and workpaper structure | Authored | Carried forward, then retested |
| Testing | Population and sampling decisions made fresh | Same decisions, new period, new samples |
| Evidence chasing | Unpredictable | Unpredictable, and usually unchanged from last year |
| Review and issuance | Full | Full. This one does not compress |
A new subprocessor, a cloud migration, a first enterprise customer, headcount that doubled, or one added criteria category will each undo part of the carry forward. A roll-forward price agreed before you know the answer is a price you set blind, and the client has no reason to volunteer it.
When to decline
Declining is a pricing decision, and it is the cheapest one available to you. Three cases are worth a firm no.
- No infrastructure ownership. If the client cannot change the control environment they are describing, because it belongs to a parent, a managed provider, or a platform they resell, you are being asked to opine on somebody else’s system.
- A report date that cannot be reached. Work backwards from the period, the fieldwork, the review, and the issuance. If the date the client already promised their buyer sits inside that arithmetic, say so before the engagement letter, not during fieldwork.
- A client who cannot produce evidence. Test this before you sign. Send the three-artifact request above, set a deadline, and treat what comes back as the most reliable data you will ever get about the engagement.
There is a fourth case, which is quoting so far below your own floor that the only way to deliver is to stop doing the work. The reputational mechanics of that are documented rather than hypothetical.
- Linford and Company warns buyers to be careful when a compliance tool has a partner audit firm with a set fee far below other bids, citing a case where one firm issued the same form report to every client with only the names changed. Source, checked 2026-07-30.
That warning is written for buyers and should be read by firms. The buyer-facing version of the same argument sits at is a cheap audit legitimate, which tells a client what to ask you to prove. Being asked those questions is good for you.
What the platform fee is
Stated once, plainly. $600 per engagement, billed when the engagement is created. Free to join. No seats, no monthly fee, no annual commitment. Ten engagements bought together are $5,000 and stay valid for twelve months, which saves $1,000 against buying them one at a time.
The fee is uniform. It is charged identically for every engagement, and it does not move with your findings, your conclusions, or whether the report you issue ends up qualified. The fee buys software, not introductions. Your fee, your scope decisions, and your opinion are not ours to influence.
What it buys is the file: workpapers tied to criteria, sampling, the sign-off chain, and the gates that stop an unreviewed report reaching issuance, engagement quality review among them. Roll-forward carries year one into year two, and any engagement exports as a single file you can take with you when you leave. It was built with advisors out of Big Four practices, which is the only credibility claim worth making about tooling that sits this close to an opinion. The rest you should verify by running an engagement on it.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.3
The conclusions and the issuance decision are yours. The system records who reached them and when, which is the part a peer reviewer will ask about.4
The feature list and the signup are on the Enterprise page. If you want to see the client side of this before you decide anything, the consumer SOC 2 pricing is published in full, which is the same standard we are asking you to hold us to.
Questions
How much should a CPA firm charge for a SOC 2 audit?
Why does year two cost less to run than year one?
When should a firm decline a SOC 2 engagement?
What does Polara charge an audit firm?
Does the platform issue the opinion?
Sources
Bring one engagement.
$0 to join. $600 when you create an engagement. Run one, start to seal, and judge the binder that comes out.
Book a working session