SOC 2 compliance: what it is, what it costs, how long it takes

There is no such thing as being SOC 2 certified. SOC 2 produces a report in which a licensed CPA firm gives an opinion on your controls. No software vendor can grant it, including us. What a platform can do is remove the evidence work, which is where nearly all of the cost and the calendar time actually sits.

Diagram of what SOC 2 compliance consists of: your controls, the evidence that they operated, and a licensed CPA firm's opinion, with the note that only the CPA can issue the report

On this page: what it actually is · Type 1 or Type 2 · the five categories · what gets examined · cost · timeline · what a platform can and cannot do

What SOC 2 compliance actually is

SOC 2 is an attestation engagement performed under the AICPA’s attestation standards. A CPA firm examines the controls at a service organization against the Trust Services Criteria and issues a report containing its opinion. The AICPA’s own SOC materials describe the output as a report throughout.

There is no certificate

This is the single most common misunderstanding, and it shapes everything else. ISO 27001 has a certification body and issues a certificate. SOC 2 does not. There is no accreditation scheme, no registry, and no pass mark. There is a report, and inside it an opinion that is unqualified, qualified, adverse, or a disclaimer.

That matters commercially. When a buyer asks for “your SOC 2 certificate”, what they will accept is the report, usually under NDA. If a vendor sends you a one-page certificate with a logo on it, they have sent you marketing.

Who is allowed to issue the report

Only a CPA firm licensed by a state board of accountancy, subject to NASBA and state licensure rules and to AICPA peer review. This is not a formality. It is the reason the market is structured the way it is: the firm signing the opinion has to be independent of the systems it is auditing, so it cannot also sell you the compliance software or do the remediation work it is opining on.

An attestation engagement requires the practitioner to be independent of the responsible party.

Any vendor telling you they will “get you SOC 2 compliant” end to end, including the audit, is describing an arrangement that independence rules do not permit. The honest version of that sentence is that they do the preparation and an independent CPA does the audit.

Type 1 or Type 2

SOC 2 is one report in the AICPA’s SOC suite of services, alongside SOC 1 for financial reporting controls and SOC 3 for a public summary. Within SOC 2 the two report types answer different questions, and the difference is months of calendar time.

Type 1Type 2
Question answeredAre the controls suitably designed?Did the controls actually operate?
Time coveredA single point in timeA stated period (the observation window)
Typical windown/a3 to 12 months
Realistic timeline4 to 8 weeks4 to 6 months for a first 3-month window
What buyers wantAccepted as an interimThe one enterprise security teams ask for

The observation window is your calendar

Nothing about a Type 2 can be compressed below its window. The auditor is testing whether controls operated over a period, so the period has to elapse. A 3-month window is the shortest most firms will sign, and 12 months is the steady state once you are renewing.

Timeline showing the SOC 2 Type 2 observation window and where testing evidence has to land to count

This is also the trap in the sales conversation. A deal that needs a Type 2 report in six weeks cannot have one, no matter what you spend. What you can do is issue a Type 1 now and commit contractually to the Type 2 date, which is a normal and accepted move.

The five categories, and why you need one

SOC 2 has five Trust Services Categories, described in the AICPA’s SOC 2 guidance. Scope is a choice, and most companies over-scope it.

CategoryRequired?Add it when
Security (common criteria)AlwaysEvery SOC 2 engagement includes it
AvailabilityOptionalYou have signed uptime commitments
Processing integrityOptionalYou process transactions where correctness is the product
ConfidentialityOptionalA contract names confidential data handling specifically
PrivacyOptionalYou handle personal information and a customer requires it

Security is the only category you certainly need

The common criteria, numbered CC1 through CC9, cover the control environment, communication, risk assessment, monitoring, control activities, logical access, system operations, change management, and risk mitigation. That is the set every SOC 2 report contains.

Each extra category widens the scope, extends fieldwork, and increases the fee with no commercial return unless a customer actually asked for it. Start with security only. Add categories when a contract makes you.

What the auditor actually examines

Not your intentions. Evidence that a control operated, repeatedly, across the window. Access reviews with dates and reviewers. Change tickets tied to approvals. Vulnerability and patch records. Onboarding and offboarding trails. Incident records. Vendor reviews.

The evidence problem is the real cost

Controls are usually not the hard part. Most engineering teams already do code review, use SSO, and patch. The expensive part is proving each of those ran on a schedule, for months, in a form an auditor accepts.

The auditor tests whether controls operated effectively throughout the specified period, not whether they exist today.

That is why auditor hours balloon on first engagements. When evidence is scattered across Slack threads, spreadsheets, and cloud consoles, the auditor bills for the archaeology.

Penetration testing sits inside this. No Trust Services Criterion requires a pentest, and we say so plainly in does SOC 2 require a penetration test, but auditors expect one and buyers ask for the report itself. The timing rule matters: the test has to land inside the window to count as evidence for it. It is also a separate purchase almost everywhere, by market convention rather than by rule: which platforms include a pentest covers who bundles what.

What SOC 2 compliance costs in 2026

Three separate line items, and vendors routinely blur them.

Line itemWho bills youTypical range
Compliance platformThe software vendor$0 to $25,000 per year
Penetration testA security firm$4,000 to $25,000 per engagement
The audit itselfAn independent CPA firm$7,000 to $50,000 per report

The audit fee has a hard floor. A CPA firm carries licensure, peer review, and liability, and the opinion takes real hours. Anyone advertising a complete SOC 2 for a few hundred dollars is not paying for a real audit.

Our SOC 2 audit cost breakdown takes each of those three lines apart: what sets the CPA’s floor hour by hour, the five scope levers that legitimately cut the fee, what year two costs, and why the published $30,000 to $50,000 ranges come from people whose subscription looks cheaper beside a large audit number.

Where our own numbers sit

We publish ours, which most of this market does not. Pricing is $299 a month under ten people and $499 at ten or more, or $2,990 and $4,990 paid annually. The CPA attestation starts at $2,500 and is paid directly to the independent firm, never through us, because routing it through us is exactly what would compromise the independence the report depends on. A human-validated penetration test is $2,999 per engagement, a one-time add-on rather than a monthly figure.

For the wider market, our penetration testing cost breakdown shows where day rates come from, and PCI DSS penetration testing requirements covers the framework with the strictest testing language, which is useful contrast if you are scoping for more than SOC 2.

How long it takes

For a first Type 2 with a 3-month window, 4 to 6 months from a standing start is realistic: 2 to 6 weeks to stand up controls and connect evidence sources, 3 months of window, then 3 to 6 weeks of fieldwork and report drafting. A Type 1 collapses that to 4 to 8 weeks because there is no window to wait out.

The variable that moves this most is not audit speed. It is how long you take to close the gaps found in readiness, because the window cannot start until the controls it will observe are actually running.

What a platform can and cannot do

A compliance platform cannot make you compliant and cannot issue an opinion. What it can do is remove the evidence work: connect to your cloud, code hosting, and identity provider, map what it finds to the criteria, and keep collecting for the whole window so the auditor gets an organized package instead of a shoebox.

That is the honest boundary, and it is worth insisting on when you evaluate vendors. The question to ask is not “will you make us compliant”. It is “what percentage of my evidence will you collect without me touching it, and which controls will still be manual”.

Our own answer to why security and compliance belong in one product is on the SOC 2 page, and what lands in your evidence library after each run is on compliance.

How to start

  1. Pick the report type your buyer actually needs. Type 1 unblocks a deal now.
  2. Scope security only unless a contract names another category.
  3. Run a readiness assessment and fix the gaps before opening the window.
  4. Choose the CPA firm early. Their calendar, not yours, sets the end date.
  5. Open the window and let evidence collect for the full period.

Reviewed against the 2017 Trust Services Criteria with revised 2022 points of focus.

Frequently asked questions

Is SOC 2 a certification?

No, and the distinction matters when a customer asks for your certificate. SOC 2 produces an attestation report containing a licensed CPA firm's opinion on your controls. There is no certificate, no certification body, and no pass or fail stamp. A vendor claiming to be SOC 2 certified is either speaking loosely or does not understand what they bought.

Can a software platform make me SOC 2 compliant?

No. Only a licensed CPA firm can examine your controls and issue the report, and AICPA independence rules stop that firm from also selling you the software or the remediation work. What a platform genuinely does is collect and organize the evidence, which is where most of the cost and calendar time actually sits. Be suspicious of anyone who says otherwise, including us.

Do I need all five Trust Services Categories?

Almost certainly not. Security, the common criteria, is the only category required in every SOC 2 engagement. The other four (availability, processing integrity, confidentiality, privacy) are optional and you add them only when a contract or a real customer commitment requires it. Adding categories you do not need widens the scope, lengthens the audit, and raises the fee for no commercial return.

How long does SOC 2 compliance take?

A Type 1 can be done in roughly 4 to 8 weeks because it examines control design at a single point in time. A Type 2 is governed by the observation window, which runs 3 to 12 months, and the report cannot be issued until that window closes and the auditor completes fieldwork. First-time Type 2 in a 3-month window realistically lands 4 to 6 months from the day you start.

How can HackZero do this so cheaply when the usual stack costs 30,000 dollars or more?

The published price is 299 dollars a month under ten people and 499 at ten or more, or 2,990 and 4,990 paid annually, with the CPA attestation from 2,500 dollars paid directly to the independent firm. A human-validated pentest is 2,999 dollars per engagement, a one-time add-on and never a monthly figure. The 30,000-dollar number is three vendors at retail: a compliance platform, a separate pentest firm, and an auditor who spends most billed hours chasing evidence that nobody organized. We own the whole stack, the attack agents, the exploitation tooling, and the reporting, all built in-house, so the marginal cost of a run is compute plus senior review rather than tester-weeks. AI does the continuous coverage, hackers stay in the loop to confirm findings actually exploit and to write the report, and because the same product carries the controls and the monitoring, evidence arrives pre-organized and the CPA audits a standardized security-only scope in a fraction of the usual hours. The customer pays the CPA directly, which is what keeps the opinion independent.

What happens after the first report?

SOC 2 is a recurring obligation, not a one-time project. Reports cover a stated period, so a buyer reading a report whose window closed 11 months ago is looking at stale assurance. Most companies run a rolling 12-month Type 2 window and renew every year, which is why the ongoing cost of evidence collection matters far more than the one-time cost of getting the first report.