Hael
Book a meeting
SOC 2 · Services

SOC 2 Compliance Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • There are four ways to get SOC 2 done: in-house, platform-led, consultancy-led, or a full-service accounting group. Each suits a different situation.
  • Cost is not the deciding factor. Available internal capacity usually is.
  • Whichever model you choose, the examination must come from a licensed accounting firm, and that fee is separate.
  • The most expensive arrangement is the implicit one, where nobody has formally been given the programme.
  • Ask every provider the same two questions: who writes the policies, and who chases the evidence owners.

The four ways to buy

SOC 2 compliance services are bought in four broad ways. The right one depends far more on how much internal capacity you genuinely have than on which model looks cheapest on paper. This guide sets out what each delivers, what it costs, and where each one tends to struggle.

Whichever route you take, one thing does not change: only a licensed accounting firm can perform the examination and issue the report, and that engagement is always separate.

ModelWhat you getTypical costBest suited to
In-houseYour own team runs everything, usually with a compliance platformPlatform subscription plus internal timeA company with prior SOC 2 experience in-house and protected hours
Platform-ledSoftware first, with advisory hours attached$7,500 to $25,000 a year plus advisoryA straightforward single-cloud environment and someone internal to drive it
Consultancy-ledA firm runs the readiness programme and prepares you for examination$15,000 to $50,000, audit fee separateA fixed deadline and no in-house compliance function
Full-service accounting groupConsulting and attestation from one group, through separate legal entitiesVaries widelyBoards that want a recognised name on the report

In-house

The cheapest model in cash terms and the most expensive in attention. It works when someone internal has run a SOC 2 programme before and has several protected hours a week for six months.

Where it fails is not technical knowledge. It is that the programme belongs to someone whose main job is something else, so the tasks wait. The audit date does not move, and the last six weeks get bought at emergency rates from whoever is available.

If you are considering this route, the honest test is whether you can name the person and point to the hours in their week. If you cannot do both, you are choosing the implicit model, which is the most expensive of all.

Platform-led

A compliance platform connects to your cloud accounts, identity provider and code repositories, monitors configuration continuously, and collects evidence automatically. Most vendors attach advisory hours or a customer success layer.

This removes a large amount of manual work and is worth the subscription for most companies. What it produces is a list of what is missing.

The limitation is the same in every case: deciding what each item means for your architecture, writing a policy that fits your company rather than a template, and changing an engineering process are jobs a person does. A small team with a long list and a fixed date often finds the list itself was never the hard part.

We work inside whichever platform you already own and configure it properly. Where there is none, the engagement runs on the Hael platform, which is included and remains available to you afterwards.

Consultancy-led

A firm takes the programme: scope, gap assessment, control implementation, policies, evidence framework, project management and examination support. The detail of what that covers is in SOC 2 consultancy services.

This costs more up front and is the usual fit when a deadline is fixed and no one internal has capacity. The variation between firms is mostly in the last workstream. Some deliver a readiness assessment and stop; some run the programme through the observation period to the report. Those are very different products at similar headline prices.

Full-service accounting group

Some groups offer both the consulting and the attestation, delivered through separate legal entities so independence is preserved. This is a normal and accepted arrangement, and it appeals to boards that want a recognised name on the report.

Ask which entity signs the opinion, how the two are kept apart, and whether choosing one for consulting commits you to the other for the audit. All of those have reasonable answers. You should simply know them before you choose.

The two questions that separate any proposal

Ask every provider these, in writing.

Who writes the policies? If the answer is that a library is provided and your team adapts it, that is an advisory engagement. If the firm writes them from how your company actually works, that is a delivery engagement. Both are legitimate; they are not the same price of effort for you.

Who chases the evidence owners? This is the work that decides whether the deadline is met, and it is the workstream most often assumed rather than assigned. If the answer is your team, make sure your team knows.

Working out which model fits

Answer three questions honestly.

Do you have someone internal with prior SOC 2 experience? If yes, platform-led is likely enough. If no, the learning happens on your deadline.

Do they have protected hours, written into their week? If not, treat in-house as unavailable rather than cheap.

Is the deadline fixed by a customer contract? If yes, buy the model that includes project management, because that is the workstream deadlines fail on.

What to do next

Get your buyer's requirement in writing, then get a view of your actual starting position before choosing a model. Companies that pick a delivery model before knowing their gaps frequently pick the wrong one.

Our free readiness diagnostic gives a first view, our readiness and gap assessment gives the detailed one for a fixed fee, and the SOC 2 service page sets out how we deliver.

References

FAQ

What are SOC 2 compliance services?

The work of preparing a company for SOC 2 examination: scope, gap assessment, control implementation, policies, evidence, project management and audit support. The examination itself is a separate engagement with an accounting firm.

Which model is cheapest?

In-house is cheapest in cash and most expensive in attention. The genuinely cheapest route is whichever one gets you to a clean report first time without emergency spending in the final weeks.

Can one provider do everything including the audit?

Some groups offer both through separate legal entities. Ask which entity issues the opinion and how independence is maintained.

Do compliance services include the audit fee?

Almost never. Budget $15,000 to $60,000 separately for a Type 2 examination.

How do I compare two proposals fairly?

Make both quote against the same written scope, then compare the responsibility split and the exclusions before comparing the fees.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act. We work inside whichever compliance platform you already own, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.