GintiCalcEvery calculation

AuditPath

SOC 2 and ISO 27001 Cost Calculator

The auditor's quote is the visible number. Readiness work is usually the bigger one.

SOC 2 and ISO 27001 cost by how many controls you already meet

All rows assume 90 controls in scope, 8 hours to close one gap at an internal rate of 95 dollars an hour, a 30,000 dollar auditor fee, 12,000 dollars of annual compliance tooling, a surveillance audit at 60 percent of the original fee, and a three-year horizon. Only the starting coverage changes, which is the single input that moves the total most.

Controls already met (of 90)CoverageReadiness effort (hr)Year-one costAnnualised over 3 years
00%720$110,400$56,800
1517%600$99,000$53,000
3033%480$87,600$49,200
4550%360$76,200$45,400
6067%240$64,800$41,600
7280%144$55,680$38,560
8594%40$45,800$35,267

Every later year costs the same $30,000 in every row - a $18,000 surveillance audit at 60 percent of the fee plus $12,000 of tooling - because readiness work happens once and the recurring commitment does not depend on where you started. That is why the annualised column compresses: the difference between starting from nothing and starting from 94 percent coverage is $64,600 in year one but only $21,533 a year across three years. It is also why the annualised figure, not the year-one headline, is the number for a budget conversation. Scope, trust criteria and control applicability are decisions made with an auditor, and widening scope multiplies both readiness and audit effort. This prices effort and fees under assumptions you supply; it cannot tell you whether you would pass. Illustrative only, and not legal or assurance advice.

A SOC 2 and ISO 27001 cost calculator estimates what certification actually costs across its full lifecycle, rather than just the auditor's quote. That quote is the most visible number and rarely the largest one, because most of the spend is internal readiness work closing the gap between how you operate today and what the framework expects.

The model starts from controls in scope minus controls already met, which gives the real gap. Multiplying that gap by the hours needed to close one control, then by an internal rate, produces the readiness cost, usually the dominant first-year figure for an organisation starting from a low base. Adding the auditor fee and annual compliance tooling gives the first-year total. Later years drop the readiness work but keep tooling and a surveillance audit, priced as a percentage of the original fee. Totalling across the period and dividing gives an annualised cost, which is the honest number for a budget conversation.

Framing certification as recurring rather than one-off is the correction most teams need. A surveillance audit happens every year and full recertification comes round on a cycle, so the commitment continues indefinitely. An organisation that budgets only for year one is surprised annually thereafter. The other lever is starting coverage: an organisation already running access reviews, change management and logging may meet a large share of controls before starting, and every control already met removes its readiness hours entirely, which is why coverage moves the total more than the auditor's price does.

Scope drives everything and is not a calculation. Which systems, which trust criteria, which locations and which control set applies are decisions made with an auditor, and a wider scope multiplies both readiness and audit effort. This prices effort under assumptions you provide. It cannot tell you whether you would pass, and does not substitute for a qualified assessor or legal review.

Certification is a subscription, not a purchase

A surveillance audit recurs annually and full recertification comes round on a cycle, so the commitment continues indefinitely. Budgeting only for year one guarantees an unpleasant surprise every year after, which is why the annualised figure is the honest number to take into a budget conversation.

Existing coverage moves the total more than the auditor's price

Every control already met removes its readiness hours entirely. An organisation already running access reviews, change management and logging can start with a large share of controls satisfied, and that starting coverage typically shifts the first-year total far more than negotiating the audit fee does.

Frequently asked questions

90 controls with 40 already met, 8 hours per gap, a $30k auditor and $12k tooling - what is year one?

Fifty gaps at 8 hours is 400 hours, about $38,000 of readiness at $95/hr. Adding the $30,000 auditor fee and $12,000 tooling gives roughly $80,000 in year one. Later years run about $30,000, so across three years it annualises to around $46,700.

Which is cheaper, SOC 2 or ISO 27001?

It depends far more on your scope and starting coverage than on the framework. SOC 2 is common for US SaaS buyers and ISO 27001 for international ones, and many organisations eventually do both because the underlying control work overlaps heavily. Model your own control gap rather than assuming one is cheaper.

Why is readiness usually bigger than the audit fee?

Because the audit only checks what already exists. If your controls, policies and evidence are not in place, an auditor cannot certify them, so the work of building and documenting them lands on you first. Organisations with mature practices see this reverse, since their readiness gap is small.

Does this predict whether I will pass?

No. It prices the effort and fees under assumptions you supply. Whether you pass depends on how controls are implemented and evidenced, and on the auditor's judgement. Scope, trust criteria and control applicability should be set with a qualified assessor.

Related Business calculators

You might also like

Last updated: September 6, 2026