GetSOC2

Why bundled SOC 2 pricing is a red flag

A single flat number covering readiness, remediation, the audit and a penetration test is quoting work that nobody has looked at yet. Sometimes that is fine. Knowing which parts of the number are real and which are a guess is the difference.

Last reviewed 2026-09-18Written by Jacob Masse, TrazTech Inc.

A bundled SOC 2 price is one number covering work that is knowable and work that is not. Scoping, policy support, evidence collection and the audit itself can all be estimated before anyone starts. Remediation cannot, because remediation is whatever your gap assessment finds, and the gap assessment has not happened when the bundle is priced. The flat number therefore contains a guess, and the only question that matters is what happens when the guess is wrong.

That is not an argument against fixed prices. Fixed scope at a fixed price is usually better for a buyer than an hourly arrangement, because it moves the risk of an overrun onto the firm that can actually control it. The problem is a fixed price on unknown scope, which is a different thing wearing the same clothes.

What a bundle has to guess

Work through what an all-in SOC 2 quote is actually promising. Some of it is a known quantity on day one.

What can and cannot be priced before a gap assessment
Part of the workKnowable up front?Why
Scoping and system description Yes It is a defined deliverable and its size is set by how many products and environments you run.
Gap assessment Yes A fixed piece of work against a fixed set of criteria. This is the piece that produces the findings.
Policy set Mostly The number of policies is predictable. How much rewriting they need depends on what you already have.
Remediation No It is whatever the gap assessment finds. A company with SSO, MFA and logging already in place is a fraction of the work of one without.
Evidence collection through the window Partly The cadence is predictable. Whether your systems can produce the evidence at all is not.
The examination Yes A licensed CPA firm quotes it against scope and criteria. It is a separate contract with a separate party.
Penetration test Yes Priced off the attack surface, which you can describe before anyone starts.

Six of those seven can be quoted honestly on day one. The seventh is the one that moves, and in a first SOC 2 it is frequently the largest line. Published Canadian ranges for consultant-led readiness run from $15,000 to $60,000 CAD, and the spread inside that range is almost entirely remediation depth.

The test

Ask what the fee assumes about your current state, and ask for that assumption in writing. A firm that has thought about this can tell you: it assumes single sign-on exists, it assumes you have centralised logging, it assumes your infrastructure is in one cloud account. A firm that cannot name its assumptions has not made any, which means the number is a shape rather than an estimate.

The four numbers a bundle collapses into one

A first SOC 2 Type 2 in Canada is four separate purchases from up to four separate parties. Collapsing them into a single line is convenient, and it also removes your ability to tell whether any one of them is reasonable.

The four purchases behind a first SOC 2 Type 2, CAD, Security criteria only
PurchaseTypical rangeWho you buy it from
Readiness and remediation$15,000 to $60,000A consultant, or your own team
The examination$20,000 to $60,000 first yearA licensed CPA firm, independently
Compliance platform$8,000 to $30,000 per yearA software vendor, optional
Penetration test$8,000 to $40,000A testing firm
First year, all in, under 100 staff$40,000 to $90,000Across all parties

When those four arrive as one figure, three things become hard. You cannot compare the audit fee against other audit fees. You cannot drop the platform if you decide you do not need it. And you cannot take the readiness work to a different firm next year while keeping the auditor, which is the arrangement most companies settle into by year two.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The part a bundle cannot legitimately include

A SOC 2 examination is an attestation engagement performed under AICPA standards and issued by a licensed CPA firm. That firm has to be independent of the work it is examining. It cannot write your policies, design your controls, select your tooling, or perform your remediation and then issue an opinion on it.

So when a single price covers both the preparation and the report, the money is crossing two parties whatever the invoice looks like, and you should be able to see where the line falls. Ask directly: which entity signs the opinion, are they independent of the party doing the readiness work, and can you speak to them before you sign. A readiness firm with real auditor relationships answers that quickly and offers the introduction. There is more on what to ask in questions to ask a SOC 2 auditor.

The same logic applies to the penetration test. A test that exists to satisfy a control, performed by the firm that designed the control, is a weaker artifact in front of an enterprise security reviewer than one from a party with nothing at stake in the result. That does not make it improper. It does make it worth knowing, because the reviewer on the other side will ask.

Why two phases is the honest shape

The alternative to a bundle is not an open-ended hourly engagement. It is two fixed-price phases, where the second is scoped from the findings of the first.

  1. Phase 1, the gap assessment. A defined piece of work against the Trust Services Criteria you have selected, producing a findings register: what exists, what does not, what the evidence looks like today, and what each gap will take to close. This can be priced before it starts because its size depends on your architecture, which is visible.
  2. Phase 2, remediation. Priced from the register Phase 1 produced. By this point neither side is guessing, so the number is a real fixed price on real scope rather than a fixed price on a hope.

The practical consequence for a buyer is that you get a decision point. After Phase 1 you know your actual position, and you can take the findings and fix them internally, hand them to a different firm, or carry on. A bundle removes that decision, because the remediation was bought before anybody knew what it was.

It also changes what a low quote means. A firm quoting remediation before the assessment has either padded the number against the worst case you might turn out to be, or it has not padded it and will be back for a change order. Both are rational responses to pricing unknown work. Neither is something you want to discover in month four.

Where the money actually goes in an examination

One reason bundles are appealing is that the audit fee looks arbitrary from outside. It is not. The hours land in a fairly consistent pattern, and knowing the pattern tells you which of your own decisions move the fee.

Where the hours go on a first Type 2 examination
PhaseShare of the feeWhat the firm is doing
Planning and scoping10 to 15 percentAgreeing the system description, the criteria, the period, and which controls map where
Walkthroughs15 to 20 percentConfirming with your people that each control works the way the description says
Testing40 to 50 percentSampling evidence against each control across the period
Reporting and review20 to 25 percentDrafting, partner review, quality review, and issuing the signed opinion

Testing is nearly half, and testing is the block your evidence quality moves. Clean, complete, consistently produced evidence shortens it. Evidence that has to be chased, reconstructed or explained lengthens it, and most Canadian engagement letters allow additional fees when the client is not ready. Which means the readiness work is not a separate expense from the audit fee. It is partly a way of buying the audit fee down, and that relationship is invisible inside a bundle.

What to ask before signing a flat rate

None of this makes a fixed all-in price wrong. It makes it something to interrogate. These are the questions that separate a considered fixed price from a number picked to be easy to say yes to.

  • What does this fee assume about our current state? You want the assumptions written into the statement of work. SSO in place, MFA enforced, centralised logging, one production environment: each of those is worth real money and each is checkable.
  • What happens if the gap assessment finds more than the fee assumed? There are two honest answers. The firm absorbs it, in which case the fee was priced for the worst case and you are paying for somebody else's risk. Or there is a change order, in which case it is not really a flat rate and you should see the mechanism now.
  • Which entity signs the audit opinion, and are they independent? Name and licensing province. Ask whether you can speak to them before signing.
  • Can we buy the phases separately? A firm confident in its gap assessment will sell you the gap assessment. One that will only sell the bundle is telling you something about which half carries the margin.
  • What is excluded? A second round of testing on failed controls, bridge letters, the following year's surveillance, and support during a customer's security review are all commonly assumed and commonly excluded.
  • Which province's law governs the contract, and which entity signs it? This matters more than it sounds. It decides where a dispute is heard and, in practice, whether a reference call is even possible.
  • Where will our evidence live during the engagement? Policy drafts, architecture diagrams and access exports are a map of your environment. If they will sit outside Canada, that is a decision to make deliberately rather than discover, especially under Quebec Law 25, which requires a privacy impact assessment before personal information is communicated outside the province.

When a single price is the right answer

There are situations where one number is genuinely better for the buyer.

A company in its second or third year, with the controls already running and a known evidence position, has very little uncertainty left. Remediation there is maintenance rather than discovery, so a firm can price the whole year with confidence and you get the benefit of the certainty.

The same is true when the scope is genuinely small: one product, one cloud account, a handful of staff, Security criteria only. The range of what a gap assessment can find is narrow enough that a firm can price around it without much padding.

What both cases have in common is that the unknown part is small. The question to carry into the conversation is not whether the price is fixed. It is whether the person quoting it has seen enough of your environment to know what they are fixing it against.

Is an all-in SOC 2 package ever cheaper than buying the parts separately?

It can be, and for a small, clean scope it often is, because the firm saves on sales and coordination and some of that is passed on. The saving tends to disappear as scope grows, because the remediation guess inside the bundle has to widen to cover a wider range of outcomes.

Can one firm do both the readiness work and the SOC 2 audit?

No. The examination has to be issued by a licensed CPA firm that is independent of the preparation, so those are two parties whatever the commercial arrangement looks like. This is set out further in whether your SOC 2 firm has to be a CPA firm.

How much of the first-year cost is remediation?

It varies more than any other line. A company that already runs SSO, MFA, centralised logging and change management may need very little. One starting without those can spend more on remediation than on the examination. That variance is the whole reason it cannot be priced before it is assessed.

What should a gap assessment on its own cost in Canada?

Published Canadian ranges for a gap assessment without the remediation that follows run from $6,000 to $15,000 CAD, depending on scope and how many environments are in play. See what SOC 2 costs in Canada for how that sits inside the total.

Get quotes you can actually compare

Describe the scope once and it goes to Canadian firms that do this work, as separate quotes for separate phases rather than one number covering everything.

Get matched