| ▲ | shye 2 hours ago | |||||||
Last I chatted with some friends who were going through their first SOC2, they quoted a much lower number. | ||||||||
| ▲ | sethhochberg 39 minutes ago | parent | next [-] | |||||||
The details people gloss over when throwing SOC 2 or whatever other audit costs around are the complexity of the system being audited, the chosen criteria to audit (AICPA defines 5 families of criteria... Security is one, but you can optionally add Processing Integrity, Confidentiality, etc etc) and the reputation of the auditor. A security-only audit for a small company with a narrow product focus can indeed be very inexpensive. A full SOC 2 examination for a large organization with a mix of legacy and modern systems by a name-recognizable public accounting firm can be many hundreds of thousands of dollars, or more if you need a Big 4 firm. In my opinion, there's not much value to the "cheap" audits... If you're doing enterprise sales to a certain kind of client, your partners who demand an audit are going to want a reputable auditor or they're just going to put you through their own in-depth procurement due diligence regardless. The segment of the industry where a SOC 2 attestation is mandatory to participate but where any random auditor will do feels pretty narrow. | ||||||||
| ||||||||
| ▲ | tptacek 21 minutes ago | parent | prev [-] | |||||||
You can get a SOC2 done for mid to mid-high thousands. | ||||||||