SOC 2 Compliance Services
- There are four ways to get SOC 2 done: in-house, platform-led, consultancy-led, or a full-service accounting group. Each suits a different situation.
- Cost is not the deciding factor. Available internal capacity usually is.
- Whichever model you choose, the examination must come from a licensed accounting firm, and that fee is separate.
- The most expensive arrangement is the implicit one, where nobody has formally been given the programme.
- Ask every provider the same two questions: who writes the policies, and who chases the evidence owners.
The four ways to buy
SOC 2 compliance services are bought in four broad ways. The right one depends far more on how much internal capacity you genuinely have than on which model looks cheapest on paper. This guide sets out what each delivers, what it costs, and where each one tends to struggle.
Whichever route you take, one thing does not change: only a licensed accounting firm can perform the examination and issue the report, and that engagement is always separate.
| Model | What you get | Typical cost | Best suited to |
|---|---|---|---|
| In-house | Your own team runs everything, usually with a compliance platform | Platform subscription plus internal time | A company with prior SOC 2 experience in-house and protected hours |
| Platform-led | Software first, with advisory hours attached | $7,500 to $25,000 a year plus advisory | A straightforward single-cloud environment and someone internal to drive it |
| Consultancy-led | A firm runs the readiness programme and prepares you for examination | $15,000 to $50,000, audit fee separate | A fixed deadline and no in-house compliance function |
| Full-service accounting group | Consulting and attestation from one group, through separate legal entities | Varies widely | Boards that want a recognised name on the report |
In-house
The cheapest model in cash terms and the most expensive in attention. It works when someone internal has run a SOC 2 programme before and has several protected hours a week for six months.
Where it fails is not technical knowledge. It is that the programme belongs to someone whose main job is something else, so the tasks wait. The audit date does not move, and the last six weeks get bought at emergency rates from whoever is available.
If you are considering this route, the honest test is whether you can name the person and point to the hours in their week. If you cannot do both, you are choosing the implicit model, which is the most expensive of all.
Platform-led
A compliance platform connects to your cloud accounts, identity provider and code repositories, monitors configuration continuously, and collects evidence automatically. Most vendors attach advisory hours or a customer success layer.
This removes a large amount of manual work and is worth the subscription for most companies. What it produces is a list of what is missing.
The limitation is the same in every case: deciding what each item means for your architecture, writing a policy that fits your company rather than a template, and changing an engineering process are jobs a person does. A small team with a long list and a fixed date often finds the list itself was never the hard part.
We work inside whichever platform you already own and configure it properly. Where there is none, the engagement runs on the Hael platform, which is included and remains available to you afterwards.
Consultancy-led
A firm takes the programme: scope, gap assessment, control implementation, policies, evidence framework, project management and examination support. The detail of what that covers is in SOC 2 consultancy services.
This costs more up front and is the usual fit when a deadline is fixed and no one internal has capacity. The variation between firms is mostly in the last workstream. Some deliver a readiness assessment and stop; some run the programme through the observation period to the report. Those are very different products at similar headline prices.
Full-service accounting group
Some groups offer both the consulting and the attestation, delivered through separate legal entities so independence is preserved. This is a normal and accepted arrangement, and it appeals to boards that want a recognised name on the report.
Ask which entity signs the opinion, how the two are kept apart, and whether choosing one for consulting commits you to the other for the audit. All of those have reasonable answers. You should simply know them before you choose.
The two questions that separate any proposal
Ask every provider these, in writing.
Who writes the policies? If the answer is that a library is provided and your team adapts it, that is an advisory engagement. If the firm writes them from how your company actually works, that is a delivery engagement. Both are legitimate; they are not the same price of effort for you.
Who chases the evidence owners? This is the work that decides whether the deadline is met, and it is the workstream most often assumed rather than assigned. If the answer is your team, make sure your team knows.
Working out which model fits
Answer three questions honestly.
Do you have someone internal with prior SOC 2 experience? If yes, platform-led is likely enough. If no, the learning happens on your deadline.
Do they have protected hours, written into their week? If not, treat in-house as unavailable rather than cheap.
Is the deadline fixed by a customer contract? If yes, buy the model that includes project management, because that is the workstream deadlines fail on.
What to do next
Get your buyer's requirement in writing, then get a view of your actual starting position before choosing a model. Companies that pick a delivery model before knowing their gaps frequently pick the wrong one.
Our free readiness diagnostic gives a first view, our readiness and gap assessment gives the detailed one for a fixed fee, and the SOC 2 service page sets out how we deliver.
References
FAQ
What are SOC 2 compliance services?
The work of preparing a company for SOC 2 examination: scope, gap assessment, control implementation, policies, evidence, project management and audit support. The examination itself is a separate engagement with an accounting firm.
Which model is cheapest?
In-house is cheapest in cash and most expensive in attention. The genuinely cheapest route is whichever one gets you to a clean report first time without emergency spending in the final weeks.
Can one provider do everything including the audit?
Some groups offer both through separate legal entities. Ask which entity issues the opinion and how independence is maintained.
Do compliance services include the audit fee?
Almost never. Budget $15,000 to $60,000 separately for a Type 2 examination.
How do I compare two proposals fairly?
Make both quote against the same written scope, then compare the responsibility split and the exclusions before comparing the fees.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act. We work inside whichever compliance platform you already own, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.