upvote
The details people gloss over when throwing SOC 2 or whatever other audit costs around are the complexity of the system being audited, the chosen criteria to audit (AICPA defines 5 families of criteria... Security is one, but you can optionally add Processing Integrity, Confidentiality, etc etc) and the reputation of the auditor.

A security-only audit for a small company with a narrow product focus can indeed be very inexpensive. A full SOC 2 examination for a large organization with a mix of legacy and modern systems by a name-recognizable public accounting firm can be many hundreds of thousands of dollars, or more if you need a Big 4 firm.

In my opinion, there's not much value to the "cheap" audits... If you're doing enterprise sales to a certain kind of client, your partners who demand an audit are going to want a reputable auditor or they're just going to put you through their own in-depth procurement due diligence regardless. The segment of the industry where a SOC 2 attestation is mandatory to participate but where any random auditor will do feels pretty narrow.

reply
Unless you have a very good reason (I compare notes with people at dozens of firms and have never heard one), the only criteria you ever want to get SOC2'd on is Security.

My experience is the opposite of yours: having a security SOC2 ends the vendorsec process it any enterprise buyer, and enterprise buyers virtually never read anything in the SOC2 other than a glance at the exceptions. A very large, very security-intensive vendor we have all heard of told me a story about a vendor they had that gave them several years of repeated Type 1 reports. Went fine.

reply
You can get a SOC2 done for mid to mid-high thousands.
reply