The collapse of SOC 2 cost: 2011 to 2026
- A SOC 2 fee bought hours, mostly: getting ready, collecting evidence, and typing the work up. The signature at the end was always the small part of the invoice.
- Two changes stripped those hours out. Your own AI can do the getting-ready work now, more accurately than the old screenshot chase, and the audit lost the collection and formatting that never needed a person.
- What remains is what could never be automated: how deep to test, whether a problem matters, independence, and the signature. That part holds its full value.
- A real audit at a small-company price is about to become ordinary. The economics that made cheap and real incompatible have gone.
- The combination to run from is a low fee attached to a methodology nobody will show you. If you cannot see what was tested, you cannot know that anything was.
The fee was always a bill for hours
A SOC 2 fee never bought you the signature at the end. It bought hours. Getting ready, collecting evidence, and typing the work up, which together made up most of the invoice for the entire history of the report.
Two changes have stripped those hours out. Getting ready moved into the AI you already use, and the audit lost the collection and formatting work that never needed a person. Everything else about the examination stayed exactly where it was.
Your AI can get you audit-ready now
Getting ready used to mean a project. Learn the standard, work out which controls apply to a company your size, write the policies, wire up the evidence, chase everyone for screenshots. It ate engineering time for months, at the moment a small company can least afford it. This was the bigger half of the cost.
The AI you already use is smart enough to do that work now. It knows your systems, it has your history and your access, and it works in plain English, so nothing has to be exported or re-explained to a tool that only understands what someone built a connector for. I went through what that does to the products that used to sell you this separately.
The part people miss is the quality gain. Evidence pulled from your live configuration beats a screenshot someone took three weeks ago, and nothing is lost between a person remembering and a person typing. The record comes out more complete and more current than the old process, which was rate-limited by human attention.
What it needs is guardrails. An AI left alone will hand you something that looks like evidence and falls apart on inspection: a policy nobody follows, a config that fails to prove what the control claims, a log covering the wrong window. It has to know what counts, what a control needs, and where an auditor will push. That knowledge comes from fieldwork. Give it that and it is genuinely good at this. Skip it and you get a very tidy pile of nothing.
You pay for the part that never could be automated
The audit changed too, more narrowly. Collection, transcription, and formatting were always the bulk of it: someone requesting evidence, someone finding it, someone typing it into a working paper, which is the auditor's written record of what was tested and what it showed. In 2011 that was most of the engagement. It is machine work now, and it should be.
| Went to machines | Stayed with the auditor |
|---|---|
| Collecting the evidence | Deciding how deep to test |
| Transcribing it into working papers | Judging whether a problem matters |
| Cross-referencing and formatting | Independence from the company paying you |
| Drafting the report | The second reviewer, and the signature |
That second column is the audit. Under the attestation standards, the rules an examination like this runs under, the auditor has to obtain sufficient appropriate evidence, meaning enough of the right kind, and carries sole responsibility for the opinion. Asking a question and taking the answer is never enough, and the profession has said openly that fast and easy may be coming at the expense of quality, with rushed or overly automated reports leaning too heavily on exactly that.
If anything the accountability side got heavier. Firms needed a formal system of quality management by December 15, 2025, and engagement quality review, the second reviewer who cannot be anyone who worked on the job, has its own standard now.
So the money now buys the part that never could be automated. A falling price and a discounted opinion are two different things. The opinion is not on sale.
The cost of looking collapsed
Put both changes on a timeline and you get the arc.
| Year | What changed | Roughly what it took, all in |
|---|---|---|
| 2011 | The report exists. Every hour is human. | About $80,000 |
| 2017 | The criteria modernize. The work stays manual. | About $50,000 |
| 2020 | Getting ready becomes software. | About $20,000 |
| 2026 | Getting ready happens inside your own AI. | As low as sub-$3,000 |
*Illustrative. These are my own estimates from working in this market, not survey data. No published price index for SOC 2 exists.*
The AICPA introduced the SOC reports in 2011, the same year the attestation standard for service auditors took effect, covering reports for periods ending on or after June 15, 2011. Every hour back then was human, and a five-figure fee was simple arithmetic. The two middle rows moved the criteria and then the collecting. Neither touched the judging.
The cost of looking has been falling for fifteen years and it will keep falling, which raises a question I took up separately: whether a once-a-year audit can keep up.
Affordable audits will go mainstream
The advice repeated for years, and still in plenty of buyer guides, is that a SOC 2 under about $5,000 is a warning sign. It deserves its due, because for most of the history above it was true. When a fee equals hours, a low fee means few hours, and few hours means someone did not look at much.
What changed is the hour count. The rate held and the standard held. A test that once took a day of coordination is set up in minutes now, over the same full set of items, with the same evidence inspected. So price stopped being a signal in either direction. The invoice only told you how many hours got billed, never what they went into. I went through how to tell separately.
Which means a real audit at a small-company price is about to become ordinary. The economics that once made cheap and real incompatible have gone, and every firm doing this work is going to feel it.
There are two better tells, and neither came from me. In 2026 the profession put the first in writing for peer reviewers, the accountants whose job is to inspect other firms' work: engagements that come out with identical reports, risk assessments, sample sizes, and testing procedures are not performed in accordance with professional standards in all material respects. Sameness is the signal.
The second is about who sets the number. The AICPA's ethics guidance says the examination fee must be set by the service auditor, the outside accountant doing the work, using its own professional judgment, and must not be influenced by a tool provider's services. A fee that is low because the auditor's own costs fell is that judgment working as intended. A fee someone else influenced is what the guidance addresses.
Audit methodology should be open
The criteria a SOC 2 measures you against are public. Anyone can read them. What stays private is the layer in between: what an auditor tests against each criterion, how deep they go, what they accept as evidence, and what makes a control fail. That is where all the real variation lives, and it sits inside each firm as private know-how.
Which sets up the one combination you should genuinely run from. A firm quotes you a low fee, call it anything under $5,000, and will not show you its methodology. You ask what they test and you get a brochure. You ask what evidence they accept and you get a process diagram. Money goes out, a report comes back, and you have no way of knowing what anybody looked at. That is an information problem before it is a suspicion. There is nothing there to check.
That combination is what produces a stamp audit, and the low fee is the least interesting half of it. Our own fees are low, and a low fee with the work shown is an honest price for labor that genuinely got cheaper. A low fee with the methodology sealed is a purchase you can never evaluate, and it stays unevaluable forever, because the closed box is the product. Buyers can only compare two engagements by brand and by number. Nobody outside can check the work. So the number floats to whatever the market will bear and never has to justify itself, and a report where the testing got skipped comes out looking exactly like a report where it did not.
Walk away from that. An auditor who will not tell you what they test in advance is asking for trust they have given you no way to verify, and that is the opposite of what an audit is for.
The fix is available to every firm today and it costs nothing to adopt. Publish what you test, what counts as evidence, and what makes a control fail. It gives away less than it sounds like, because the criteria were already public and the judgment is the part nobody can copy. Open methodologies exist in the wild already. More on that in why the method should not be a black box.
So here is the standard worth holding every auditor to, at any price. Show the work. An audit you can check is worth more than an audit you have to take on faith.
Frequently asked questions
How can you tell a stamp audit from a real one?
Why did SOC 2 audit costs fall so much?
Can AI really get you ready for a SOC 2 audit?
Is a cheap SOC 2 audit a red flag?
Does a lower audit fee mean the auditor tests less?
Keep reading
Your auditor gets punished for finding things
Auditors choose which handful of items to check, and finding a problem costs them their evening. What changes when nobody gets to choose.
Can your auditor just rely on the platform's evidence?
Some audits test nothing but what the platform hands over. The standards ask for more, and peer reviewers are now looking.
What should a SOC 2 report actually show you?
'No exceptions noted' can mean rigorous testing or none at all. What a report should disclose so you can tell.
Can a compliance platform's AI do your SOC 2?
Compliance platforms are adding AI assistants to their dashboards. The agent already in your terminal is better placed to do the work.
Sources
- The AICPA introduced the Service Organization Control (SOC) reports in 2011, five years before this June 2016 column.
- The attestation standard for service auditors, SSAE No. 16, is effective for service auditor's reports for periods ending on or after June 15, 2011.
- The 2017 trust services criteria, with points of focus revised in 2022, are the criteria used to evaluate and report on controls over security, availability, processing integrity, confidentiality, and privacy.
- The attestation standards governing a SOC 2 examination (the AT-C 200 series) require the practitioner to obtain sufficient appropriate evidence and give the practitioner sole responsibility for the opinion expressed.
- Firms must have a risk-based system of quality management in place by December 15, 2025 under SQMS No. 1.
- An engagement quality review is an objective evaluation of the significant judgments made by the engagement team, and the reviewer cannot be a member of the engagement team.
- Peer reviewer guidance flags firms leaning too heavily on third-party SOC platforms without applying professional judgment, and states that engagements with identical reports, risk assessments, sample sizes, and testing procedures are not performed in accordance with professional standards in all material respects.
- SOC professionals see indications that fast and easy may come at the expense of quality and objectivity, and a rushed or overly automated report may rely too heavily on inquiry, with the examiner taking the client's word on areas that require more thorough procedures.
- The examination fee must be set by the service auditor using professional judgment and must not be influenced by the tool provider's services, and arrangements limiting the auditor's ability to set scope and timing, obtain evidence, communicate deficiencies, or remain objective create ethics and independence threats.