logoalt Hacker News

shyetoday at 9:06 PM2 repliesview on HN

Last I chatted with some friends who were going through their first SOC2, they quoted a much lower number.


Replies

sethhochbergtoday at 10:03 PM

The details people gloss over when throwing SOC 2 or whatever other audit costs around are the complexity of the system being audited, the chosen criteria to audit (AICPA defines 5 families of criteria... Security is one, but you can optionally add Processing Integrity, Confidentiality, etc etc) and the reputation of the auditor.

A security-only audit for a small company with a narrow product focus can indeed be very inexpensive. A full SOC 2 examination for a large organization with a mix of legacy and modern systems by a name-recognizable public accounting firm can be many hundreds of thousands of dollars, or more if you need a Big 4 firm.

In my opinion, there's not much value to the "cheap" audits... If you're doing enterprise sales to a certain kind of client, your partners who demand an audit are going to want a reputable auditor or they're just going to put you through their own in-depth procurement due diligence regardless. The segment of the industry where a SOC 2 attestation is mandatory to participate but where any random auditor will do feels pretty narrow.

show 1 reply
tptacektoday at 10:21 PM

You can get a SOC2 done for mid to mid-high thousands.