How much should a CPA firm charge for a SOC 2 audit?

Every page ranking for SOC 2 cost tells your client what to expect to pay, and none of them state what one engagement costs your practice to run.

How much should a CPA firm charge for a SOC 2 audit? Start from hours. The one published practitioner breakdown cited below reasons from staffing to an hours range and a floor, and it is quoted in full with the date it was read. Price above the floor those hours produce.

The harder question is the one underneath it. What does a single engagement cost your practice to run, and which part of it quietly consumes the margin you already quoted away?

Search the query your clients search and every result is written for them, which makes the whole corpus useless to you as a costing exercise. Quote off it and you are pricing against a buyer’s expectation instead of your own hours. The fee is usually not the mistake. The mistake is assuming the unpredictable part of the work is the testing.

Start from hours, not from what the market will bear

A fee you cannot decompose into hours is a guess wearing a rate card. The breakdown below is worth reading even where you disagree with the rates it assumes, because it works up from staffing rather than back from a market rate.

  • One published practitioner breakdown puts a Security-only Type 2 at 60 to 80 auditor hours, at partner rates of $250 to $350 per hour and staff rates of $100 to $175, giving a stated floor near $9,000. Source, checked 2026-07-30.

Read that as a floor, not as a target. It assumes one Trust Services Criteria category,1 a cooperative client, and a scope that does not expand after the engagement letter is signed. Add categories and the hours move. Add a client who has never been examined before and they move again, in the one direction you cannot bill for. What the buyer side of that fee is told to expect is set out in what the auditor fee actually covers, which is worth reading mainly because your prospect has probably read something like it already.

Where the hours actually go

Break a small engagement into the work it genuinely contains. The last four items are the ones an estimate gets right. The first three are where the optimism lives.

Scoping and planning
System description, boundary, subservice carve-outs, criteria selection. Cheap when the client knows their own architecture. Expensive when they do not, and you find that out in week three rather than week one.
The request list
Building a prepared-by-client list is fast. Making it legible to an engineer who has never seen one is not. Every ambiguous request line becomes two emails later.
Evidence chasing
Requesting, receiving the wrong artifact, explaining, requesting again. Unbounded in theory, unbillable in practice, and the largest single source of variance on a small engagement.
Testing
Sampling, inspection, reperformance, exception handling. This is the part your estimate is usually right about, which is exactly why it is the wrong thing to worry about.
Workpaper documentation
Tying evidence to criteria so a reviewer, a peer reviewer, or your successor can follow the conclusion without you in the room to narrate it. That bar comes from the attestation standards.2
Review and sign-off
Partner time at partner rates. Compressed review is where documentation errors survive all the way to issuance.
Report drafting and issuance
Narrative, exceptions, dates, management letters. Mechanical when the workpapers are clean. A rewrite when they are not.

Realization leaks in the chasing, not in the testing

A complex control is bounded work: you scope it, test it, document it, and then it is finished whether it took two hours or six. A client who sends the wrong screenshot three times is unbounded. Each round trip costs a reply, a context switch, and a re-read of the request you already wrote, and none of that is defensible on a fee note.

Firms price for the testing and lose the year on the wrangling.

So price the client, not only the control set. Two engagements with identical scope will not consume the same hours, and what separates them is almost entirely how the evidence arrives. You can tell which one you have inside the first two weeks. Ask for three specific artifacts before you quote, because how they come back tells you more than the questionnaire ever will.

Year two is a different engagement, so price it differently

A roll-forward year is not last year at a discount. Some of the work genuinely disappears. Some of it only looks like it did, and setting year two as a flat percentage of year one gets both halves wrong at once.

WorkYear oneRoll-forward year
Scoping and system descriptionBuilt from nothingUpdate and confirm, unless the architecture moved
Control narrative and workpaper structureAuthoredCarried forward, then retested
TestingPopulation and sampling decisions made freshSame decisions, new period, new samples
Evidence chasingUnpredictableUnpredictable, and usually unchanged from last year
Review and issuanceFullFull. This one does not compress
Ask what moved before you quote year two

A new subprocessor, a cloud migration, a first enterprise customer, headcount that doubled, or one added criteria category will each undo part of the carry forward. A roll-forward price agreed before you know the answer is a price you set blind, and the client has no reason to volunteer it.

When to decline

Declining is a pricing decision, and it is the cheapest one available to you. Three cases are worth a firm no.

  1. No infrastructure ownership. If the client cannot change the control environment they are describing, because it belongs to a parent, a managed provider, or a platform they resell, you are being asked to opine on somebody else’s system.
  2. A report date that cannot be reached. Work backwards from the period, the fieldwork, the review, and the issuance. If the date the client already promised their buyer sits inside that arithmetic, say so before the engagement letter, not during fieldwork.
  3. A client who cannot produce evidence. Test this before you sign. Send the three-artifact request above, set a deadline, and treat what comes back as the most reliable data you will ever get about the engagement.

There is a fourth case, which is quoting so far below your own floor that the only way to deliver is to stop doing the work. The reputational mechanics of that are documented rather than hypothetical.

  • Linford and Company warns buyers to be careful when a compliance tool has a partner audit firm with a set fee far below other bids, citing a case where one firm issued the same form report to every client with only the names changed. Source, checked 2026-07-30.

That warning is written for buyers and should be read by firms. The buyer-facing version of the same argument sits at is a cheap audit legitimate, which tells a client what to ask you to prove. Being asked those questions is good for you.

What the platform fee is

Stated once, plainly. $600 per engagement, billed when the engagement is created. Free to join. No seats, no monthly fee, no annual commitment. Ten engagements bought together are $5,000 and stay valid for twelve months, which saves $1,000 against buying them one at a time.

$600Per engagement, billed at creation
$5,000Ten engagements, valid twelve months
$1,000Saved against buying them singly

The fee is uniform. It is charged identically for every engagement, and it does not move with your findings, your conclusions, or whether the report you issue ends up qualified. The fee buys software, not introductions. Your fee, your scope decisions, and your opinion are not ours to influence.

What it buys is the file: workpapers tied to criteria, sampling, the sign-off chain, and the gates that stop an unreviewed report reaching issuance, engagement quality review among them. Roll-forward carries year one into year two, and any engagement exports as a single file you can take with you when you leave. It was built with advisors out of Big Four practices, which is the only credibility claim worth making about tooling that sits this close to an opinion. The rest you should verify by running an engagement on it.

The line the software does not cross

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.3

The conclusions and the issuance decision are yours. The system records who reached them and when, which is the part a peer reviewer will ask about.4

The feature list and the signup are on the Enterprise page. If you want to see the client side of this before you decide anything, the consumer SOC 2 pricing is published in full, which is the same standard we are asking you to hold us to.

Questions

How much should a CPA firm charge for a SOC 2 audit?
Build the number from hours rather than from a market rate. Take the published practitioner breakdown cited and dated on this page, apply your own partner and staff rates to the hours it reasons from, and quote above the floor that produces. Then add for the evidence chasing the client will generate.
Why does year two cost less to run than year one?
Scoping, the system description and most of the workpaper structure already exist, so a roll forward year is largely retest and update. The saving is real but smaller than most firms assume, because evidence chasing does not roll forward. A client who was slow in year one is usually slow again in year two.
When should a firm decline a SOC 2 engagement?
Decline when the client does not own the infrastructure in scope, when the report date they need cannot be reached from the period they can actually cover, and when they cannot produce evidence on request. The third one is the expensive failure, because it does not surface until you are already committed.
What does Polara charge an audit firm?
Joining is free. No seats, no monthly fee, no annual commitment. The platform fee is $600 per engagement, billed when the engagement is created. Ten engagements are $5,000, valid for twelve months, which saves $1,000 against buying them singly. The fee is uniform. It does not move with your findings, your conclusions, or whether the report you issue is qualified.
Does the platform issue the opinion?
No. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms. The conclusions and the issuance decision belong to the licensed firm on the engagement, and the record shows who made them.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  4. AICPA Peer Review Program AICPA. Enrollment and scope for firms performing attest engagements. Checked 1 August 2026.

Bring one engagement.

$0 to join. $600 when you create an engagement. Run one, start to seal, and judge the binder that comes out.

Book a working session
polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty