GetSOC2

SOC 2 cost calculator, in CAD

Seven questions about your company and your scope, and an estimate broken into the four lines a first SOC 2 is actually made of. Nothing is emailed anywhere unless you ask for it at the end.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

Most published SOC 2 prices are a single number that describes somebody else's company. The four lines below move independently: the audit fee tracks scope and criteria, readiness tracks how much control work already exists, the platform tracks headcount, and the penetration test tracks your architecture. An estimate that does not separate them cannot tell you where to spend less.

Every figure is Canadian dollars. The answer appears on this page.

How many people work at the company?

Headcount drives the audit fee, the platform subscription and the volume of access evidence more than anything else does.

What does the production environment look like?

Infrastructure testing is priced on how many places the auditor has to look.

How many products go in the report?

Count only what the customer asking for the report considers part of what they bought. Everything else can usually be carved out.

Type 1 or Type 2?

If you do not know, pick the last option and the estimate will cover the usual route.

Which Trust Services Criteria are in scope?

Security is in every report and is already counted. Tick an optional category only if a customer named it in writing.

Where is the control work today?

This moves the readiness line further than anything else in this form.

When does the report have to exist?

How this estimate is built

The starting bands come from what Canadian companies pay for a first SOC 2: $20,000 to $35,000 CAD in audit fees at under twenty staff, rising with headcount, and $35,000 to $90,000 CAD all in for a typical small company. Those figures and their sources are set out on the cost page and, for the examination line specifically, the audit fee page.

From there the calculator applies the adjustments firms apply when they quote.

What each answer does to the estimate
AnswerEffectWhy
Optional criteriaAvailability or Confidentiality add roughly 15 percent each, Processing Integrity 28 percent, Privacy 25 percentEach category brings its own criteria, its own evidence and its own testing
Multiple accounts or cloudsAdds roughly 15 percent, hybrid infrastructure 25 percentInfrastructure testing is repeated per environment
More than one productAdds 20 to 35 percentSeparate architectures mean separate walkthroughs and separate control descriptions
Type 1 onlyRoughly 55 percent of a Type 2 feeDesign tested at a point in time rather than operation across a period
Type 1 then Type 2 in one yearRoughly 140 percent of a Type 2 feeTwo engagements, with the second reusing the first firm's planning
Control maturityReadiness ranges from 20 percent above the base to less than half of itYou are paying for the gap between where you are and what the criteria need
A blocked dealAdds roughly 20 percent to readinessCompressed timelines cost more because they buy other people's calendars

It is an estimate, not a quote. No firm can price an engagement without seeing your system description, and any that offers to is not going to hold the number. You get a budget of the right shape, and a sense of which line is worth attacking.

Where the estimate goes down

Three of these lines are negotiable and one is not. The audit fee falls when you narrow scope: fewer criteria, fewer environments, carving out a product nobody asked about. Readiness falls when you do more of the work internally, which trades money for your own team's hours. The platform line is optional under about twenty staff. Leave the penetration test alone. Your auditor is going to ask for it, and a cheap test that finds nothing has cost you the whole fee.

Turn the estimate into real quotes

Send your scope to Canadian firms and compare numbers priced against the same engagement.

Get matched

Common questions

How accurate is this SOC 2 cost estimate?

It puts you in the right band, which is what a budget needs. Real quotes vary with details this form does not ask about, such as how many subservice organisations you rely on and how long an observation window you choose. Treat the output as a range to plan against and get three written quotes before committing.

Why is readiness sometimes larger than the audit fee?

Because the audit tests controls that already exist, and readiness is the work of making them exist. A company with nothing written down is buying policies, control design, remediation and an evidence routine. A company that has been through an audit before is buying a review, which is a fraction of the price.

Does the estimate include our own team's time?

No, and that line is often the largest. A first SOC 2 consumes several hundred hours of engineering and management attention, concentrated in the weeks before fieldwork. Costed at a loaded engineering rate it frequently exceeds the audit fee.

What does this cost in year two?

Usually 60 to 80 percent of year one. The audit fee falls by roughly 15 to 25 percent as the firm rolls forward its working papers, readiness largely disappears if you kept the routine running, and the platform and penetration test recur in full.

Is anything I enter here sent anywhere?

No. The calculation runs in your browser and the estimate is rendered on this page. Nothing is sent to us unless you fill in the form below the result asking for the written version.