Buyer's toolkit
Requesting and comparing SOC 2 quotes
The lowest headline fee is rarely the lowest comparable proposal. Normalize every quote against the same scope first — then compare totals.
What to put in your RFP brief
Send every firm the same brief. Firms can't scope accurately — or price comparably — without it:
- Company snapshot: headcount, industry, cloud providers, revenue stage.
- Systems and entities in scope: which products, infrastructure, and legal entities the report covers.
- Trust Services Criteria: Security plus any of Availability, Confidentiality, Processing Integrity, Privacy.
- Report type and period: Type 1 or Type 2, and your desired observation window.
- Target report date — and why: a customer contract deadline changes how firms staff you.
- Current tooling: GRC platform, ticketing, IdP — evidence state matters for pricing.
- Readiness state: done, in progress, or needed (take our readiness quiz).
- Adjacent frameworks on the roadmap (ISO 27001, PCI, HIPAA) — bundling changes the proposal.
- Your decision timeline and budget range, if you have one.
Quote comparison worksheet
Fill in one column per proposal, then print or screenshot it for your decision file. Every row is a line item that changes the real total.
| Line item | Firm 1 | Firm 2 | Firm 3 |
|---|---|---|---|
| Quoted fee (Type 2 examination) | |||
| Report type & observation period | |||
| Trust Services Criteria in scope | |||
| Systems & entities in scope | |||
| Fieldwork window (kickoff to fieldwork end) | |||
| Report delivery date — in writing? | |||
| Readiness / gap work included? | |||
| Re-testing policy (what triggers extra fees) | |||
| Expenses & travel | |||
| Change-order rules | |||
| Year-2 pricing | |||
| Signing entity (licensed CPA?) | |||
| Named engagement team | |||
| Redacted sample report provided? |
Engagement-letter red flags
Read the engagement letter before you sign. Any of these is a reason to pause and ask questions:
- Vague scope. "SOC 2 audit" with no named criteria, systems, entities, or observation period.
- Hourly billing with no cap or estimate range — you can't budget against an open meter.
- No report delivery date or delivery window in writing.
- One-sided change orders: the firm can reprice for "additional work" but the triggers aren't defined.
- The signing entity isn't named — or differs from the brand with no explanation.
- Blurred independence: the same team sells you remediation consulting and the attestation, with no documented separation.
- Silent exclusions: no mention of penetration testing, readiness, travel, or extra criteria — assume they're extra until stated otherwise.
- Termination traps: heavy termination fees or auto-renewal you didn't negotiate.
- No sample report. A firm that issues SOC 2 reports should produce a redacted sample promptly. A glossy "certificate" image is not a report.
Skip the RFP paperwork
Answer four questions and matched auditors send scoped quotes — free, no obligation.