A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →People say "we need to hire someone for our SOC 2" as if it is one purchase. It is two, and by design they cannot be the same firm. Understanding the split is how you avoid overpaying and choose the right help for each half.
Book a free readiness callA SOC 2 report is only worth something because an independent party vouches for it. That independence is the whole point. So the standard splits the work in two. One party helps you get ready, which means finding your gaps, writing policies, fixing controls, and organising evidence. A separate party, a licensed CPA firm, examines the result and issues the report. The firm that prepares you is not allowed to be the firm that judges you.
The practical takeaway: you are going to hire two things. A prep partner to do the readiness work, and an audit firm to sign the report. Confusing the two, or trying to buy them from one place, is where budgets and timelines go wrong.
| Audit prep partner | Full audit firm (the auditor) | |
|---|---|---|
| Job | Gets you audit-ready: gap assessment, policies, remediation, evidence | Independently examines your controls and issues the SOC 2 report |
| Signs the report | No, and is not allowed to | Yes, this is the whole point of them |
| Where the effort is | Most of it, this is the heavy lifting | A defined examination once you are ready |
| Hands-on with your systems | Yes, closes real gaps with your team | No, observes and tests from the outside |
| Typical cost | Fixed fee, sized to scope | Often USD 10,000 to 30,000 or more, priced in USD |
| Best value for a startup | A boutique specialist, fast and focused | A reputable licensed CPA firm your buyers accept |
Large national and Big 4 firms can do SOC 2 readiness advisory, and for a very large or complex multi-framework program at enterprise scale they are a reasonable choice. The trap is using them for a first SOC 2 at a startup. You tend to pay premium rates for junior staff, move slowly, and get a process built for a 5,000-person company applied to your 30-person one.
For the readiness half, a specialist prep partner is usually faster and far less expensive for the same outcome. For the audit half, you do not need the biggest name, you need a reputable licensed CPA firm whose report your buyers will accept. Spending Big 4 money on a first SOC 2 is the most common way startups overpay.
People assume the risk of going straight to an audit firm is a bad report. Bad reports do exist: an adverse opinion and a disclaimer are both real outcomes, and ISO 27001 will withhold a certificate outright for a major nonconformity at Stage 2, then charge you for the additional audit days it takes to verify the fix. But the outcome that actually catches unprepared companies is a stall. The auditor gets into fieldwork, works the document request list, finds that a meaningful share of the evidence does not exist in a form they can test, and recommends stopping.
That is worse than a qualified opinion in every direction, because a qualified report is at least a document you can hand a buyer. A stall gives you nothing.
The fee is spent against quotes that commonly run USD 10,000 to 30,000 and up, and re-entering fieldwork means paying again. A Type II gap can add a fresh three to twelve month window. Your engineers spend the same weeks twice. And the readiness work is still ahead of you, on a shorter runway with a smaller budget.
Which is why the split is not just a rule. The independence requirement means your auditor is barred from fixing the thing they found. They can tell you a control will not pass; they cannot rebuild it for you. Somebody has to do that work, and doing it before fieldwork is the cheap version. What auditors see most, and what it costs.
traztech is a prep partner, not an auditor. We do the readiness and remediation, we handle auditor management and advocacy so the examination goes smoothly, and we bring real security depth to the controls. Our principal is a published security researcher with five CVEs, so what we build survives a buyer's technical reviewer, not just the audit. We quote fixed scope, so you know the readiness number before you commit, see our pricing for the specific engagements, and we are honest that the audit itself is a separate cost you pay the CPA firm.
Tell us your scope and deadline and we will quote the readiness work fixed, then help you pick an auditor that fits. No Big 4 markup, no invented numbers.
Book a free readiness callAudit prep is the work of getting ready: closing control gaps, writing policies, and collecting evidence. The audit is the independent examination that produces the SOC 2 report. They are two separate jobs, and by the rules of the standard they must be done by two independent parties. A prep partner gets you ready, and a licensed CPA firm issues the report.
Because the standard requires the auditor to be independent of the work they are examining. If the same firm built your controls and then judged them, the report would not be trustworthy. This is why you hire a prep partner and a separate CPA audit firm. A good prep partner coordinates with your auditor but never signs the report.
For a startup or mid-market company, usually not for the prep. The Big 4 are built for large, complex engagements and price accordingly, often with junior staff doing the work. For the readiness itself, a specialist prep partner is typically faster and far less expensive for the same outcome. For the audit signature, choose a reputable licensed CPA firm that fits your buyers' expectations.
Bad reports are possible, since adverse opinions and disclaimers both exist, and for ISO 27001 a major nonconformity at Stage 2 withholds the certificate until you remediate and pay for the verification days. But the usual outcome is a stall, which is worse. The firm reaches fieldwork, finds the evidence is not testable, and recommends pausing. You have paid for an audit that produced no report, so nothing goes to the buyer who asked, re-entering fieldwork means paying a firm again against quotes that commonly run USD 10,000 to 30,000 and up, a Type II gap can cost a fresh three to twelve month observation window, and the readiness work is still ahead of you. More on what actually goes wrong.
Most of the time and effort is in readiness, not the audit, so that is where good help pays off. Budget a fixed fee for a prep partner to close the gaps, a separate fee for the independent auditor, and optionally a compliance platform subscription. Avoid paying enterprise-firm rates for a first SOC 2 that a boutique can deliver faster.
Preparation and the audit are two separate bills, and there is usually a third: the platform you are told to run the programme in. That one is avoidable.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.