Hael
Book a meeting
SOC 2 · Choosing support

SOC 2 consultancy services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • SOC 2 consultancy services cover six workstreams: scope, gap assessment, control implementation, policy, evidence framework, and project and audit management.
  • The last of those is usually the largest and the one that decides whether the deadline is met.
  • Consultancies prepare you for examination. Only a licensed accounting firm can issue the report.
  • Fees typically run $15,000 to $50,000 for a full first programme, with the auditor's fee separate.
  • Penetration testing, the platform subscription and legal review of contracts commonly sit outside the fee. Ask for exclusions in writing.

What SOC 2 consultancy services cover

SOC 2 consultancy services cover the work between deciding you need a report and the accounting firm arriving to examine you. That work divides into six workstreams. Understanding what each one delivers is the practical way to compare proposals, because two firms can quote very different numbers for what looks like the same engagement.

The six workstreams

Scoping. Deciding which systems, services and criteria are in the report, and which are excluded. This sets your fee, your timetable and whether the finished report answers the question your buyer actually asked. It is the highest-leverage decision in the programme.

Gap assessment. A requirement-by-requirement comparison of where you stand against each criterion in scope, stating what is met, what is not, and what closes each gap. This is our readiness and gap assessment, delivered as a fixed fee with a delivery call.

Control implementation. Configuring access management, change approval, logging, monitoring, vulnerability management, vendor oversight and incident response so that each control genuinely operates and leaves a record when it does. Covered by our implementation service.

Policy and documentation. Writing the policy set so it describes your actual company rather than a template company. This is where template-heavy engagements come apart, because the first engineer interviewed describes something different from the document.

Evidence framework. Establishing what gets collected, by whom, on what schedule, and in which system, so that evidence accumulates across the observation period instead of being assembled at the end.

Project and audit management. Holding the schedule, chasing evidence owners, selecting and managing the accounting firm, briefing the people who will be interviewed, and handling findings during fieldwork. This is normally the largest share of the effort and the one most often underestimated when a company decides to run the programme itself.

What consultancy services do not include

Three limits, all worth confirming before signing.

The report. Only a licensed accounting firm can issue it. Some groups offer both consulting and attestation through separate legal entities, which is a normal arrangement; ask which entity signs and how independence is maintained.

The operation of your controls. Access reviews, change approvals and vendor checks are performed by your people inside your business. A consultancy designs them, prepares them and chases them.

A shorter observation period. If the buyer wants a Type 2 in eight weeks and the shortest acceptable period is three months, no supplier closes that gap. A firm that tells you this on the first call is doing you a service.

Typical fees

ServiceTypical fee
Gap or readiness assessment alone$5,000 to $25,000
Full readiness programme, small to mid-sized company$15,000 to $50,000
Programme management through the observation periodRetainer, scope dependent
Independent practitioner day rate$800 to $2,000
Auditor fee, Type 2, quoted separately$15,000 to $60,000

Commonly outside the consultancy fee: penetration testing at $4,000 to $25,000, the compliance platform subscription at $7,500 to $25,000 a year, and legal review of customer contracts. Ask for exclusions listed explicitly, because these are real numbers and discovering them in month four is avoidable.

Advisory engagement or full programme?

The two are sold under similar names and produce very different experiences.

An advisory engagement gives you guidance. Someone experienced reviews your position, tells you what to do, and is available for questions. Your team does the work. This is good value when you have capable people who need direction rather than capacity.

A full programme means the firm does the work: writes the policies, configures what it can, runs the project, chases the evidence, manages the auditor. This costs more and is the right choice when nobody internal has protected time.

The question that separates them in a proposal is simple. Ask who writes the policies and who chases the evidence owners. The answer tells you which you are buying.

How consultancy fits with a compliance platform

They do different jobs and work well together. A platform connects to your systems, monitors configuration continuously and collects evidence automatically, which removes a great deal of manual work. What it produces is a list of what is missing.

Working through that list is the consultancy job: deciding what each item means for your architecture, writing the policy that fits, changing the engineering process, and getting the evidence to exist. We work inside whichever platform you already own and configure it properly. Where there is none, the engagement runs on the Hael platform, which is included and stays available to you afterwards.

What to do next

Write down three things before requesting proposals: what your buyer asked for, your real deadline, and who internally will be available. Those three facts turn vague quotes into comparable ones.

Our free readiness diagnostic gives a first view of where you stand, and the SOC 2 service page sets out how we run each workstream.

References

FAQ

What do SOC 2 consultancy services include?

Scoping, gap assessment, control implementation, policy and documentation, the evidence framework, and project and audit management.

How much do SOC 2 consultancy services cost?

Typically $15,000 to $50,000 for a full first programme at a small to mid-sized company, with the auditor's fee separate.

Can a consultancy issue my SOC 2 report?

No. Only a licensed accounting firm can. Some groups offer both through separate legal entities, so ask which entity signs.

What is normally excluded from the fee?

The audit fee, penetration testing, the compliance platform subscription and legal review of customer contracts. Ask for exclusions in writing.

Do I need consultancy if I have a compliance platform?

It depends who will work through what the platform identifies. The platform produces the list; someone still has to close it.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act. We are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.