Hael
Book a meeting
SOC 2 · Support

What a SOC 2 consultant does, and when you need one

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • A SOC 2 consultant prepares you for the examination. They cannot issue the report, which only a licensed CPA firm can do.
  • The work is scope, control design, policies, evidence, project management and audit preparation. The largest part is usually project management.
  • Consultancy fees for a first SOC 2 programme typically run $15,000 to $50,000, separate from the auditor's fee.
  • A compliance platform and a consultant do different jobs. The platform produces the list. Someone still has to work through it.
  • The clearest signal you need help is a fixed audit date, no named internal owner, and a list of outstanding tasks that is not shrinking.

What a SOC 2 consultant is for

A SOC 2 consultant prepares your company for examination by a CPA firm. That means agreeing what is in scope, designing and implementing the controls, writing policies that match how your company actually works, assembling the evidence, preparing the people who will be interviewed, and running the project to the audit date. What a consultant cannot do is issue the report. Only a licensed CPA firm can do that, and the opinion stays entirely with them.

The word "consultancy" covers a wide range of arrangements, from a few days of advice to a firm that runs the whole programme. It is worth being precise about which you are buying, because the difference in outcome is large.

What SOC 2 consultancy services actually include

Most SOC 2 readiness and compliance services cover six things. In our experience the sixth is the one that decides whether the deadline is met.

WorkstreamWhat it involves
ScopeDeciding which systems, services and criteria are in the report. This sets both the cost and whether the report answers your buyer's question.
Gap assessmentComparing your current position against each criterion and stating what is met, what is not, and what closes each gap.
Control design and implementationConfiguring access control, change management, logging, monitoring, vendor oversight and incident handling so they operate in practice.
Policies and documentationWriting the policy set so it describes your actual company, not a template company.
EvidenceEstablishing what gets collected, by whom, on what schedule, and making sure it accumulates across the observation period rather than at the end.
Project management and audit supportHolding the schedule, chasing evidence owners, briefing the people who will be interviewed, managing the audit firm and handling findings.

The technical side of that work, meaning the configuration that makes each control actually run, is covered separately in SOC 2 - Security Consultants.

What a SOC 2 consultant cannot do

Three limits are worth stating plainly, because they affect who you hire.

A consultant cannot issue your report. If a firm offers both consulting and the audit itself, ask how independence is preserved. In most cases the two are delivered by separate legal entities, which is a normal and accepted arrangement, but you should understand which entity is signing.

A consultant cannot make the controls run for you. Access reviews, change approvals and vendor checks happen inside your business, performed by your people. A consultant designs them, prepares them and chases them, but the work sits with your team.

A consultant cannot fix an unrealistic date. If the buyer wants a Type 2 report in eight weeks and the observation period alone is three months, no amount of help closes that gap. What a good adviser does is tell you that on the first call rather than the fifth month.

Is a consultant the same as a compliance platform?

No, and the two are complements rather than alternatives. A platform such as Vanta, Drata or Secureframe connects to your systems, monitors configuration continuously and collects evidence automatically. That removes a very large amount of manual work and is worth having.

What the platform produces is a list of what is missing. Working through that list is a separate job: deciding what each item means for your architecture, writing the policy that fits your company, changing the engineering process, and getting the evidence to exist. A small team with a fixed audit date and a long list often finds that the list is the easy part.

We work inside whichever platform you already own and configure it properly. Where there is none, the engagement runs on the Hael platform, which is included and stays available to you afterwards.

What does a SOC 2 consultant cost?

Consultancy fees are separate from the auditor's fee and are usually the larger of the two.

Engagement typeTypical fee
Gap or readiness assessment only$5,000 to $25,000
Full readiness programme, small to mid-sized company$15,000 to $50,000
Ongoing programme management through the observation periodMonthly or annual retainer, varies with scope
Independent day rate, experienced practitioner$800 to $2,000

How to read a fee proposal

Fixed-fee proposals are generally preferable to day rates for a first programme, because a fixed fee forces the scope conversation to happen before the work starts rather than in month four. Ask for the fee to be itemised, and ask specifically whether the auditor's fee is included or separate. It is almost always separate.

When is it worth hiring one?

Hiring makes sense when one or more of these is true:

  • You have a fixed audit date driven by a customer, and no named person inside the company owns the programme with real hours protected for it.
  • You have bought a compliance platform, the outstanding task list is long, and it has not shrunk in a month.
  • Your architecture is anything other than a straightforward single-cloud deployment, so template controls do not map cleanly.
  • You need SOC 2 alongside ISO 27001, ISO/IEC 42001 or GDPR work, and you want one control set serving all of them rather than three parallel programmes.
  • You have been through an examination before and picked up exceptions you do not want repeated.

Doing it in-house is entirely reasonable when you have someone with prior SOC 2 experience, a simple environment and a timeline with slack in it. The variable that predicts the outcome is not internal versus external. It is whether one named person owns it and has the time.

Where the need is ongoing rather than a single deadline, a monthly arrangement often fits better than a project fee. See SOC 2 vCISO Services.

If you are working out the sequence rather than the supplier, see How best to proceed with SOC 2.

What to do next

Get a written view of where you actually stand before you commission anything. Our free readiness diagnostic takes a few minutes. Our readiness and gap assessment gives you a requirement-by-requirement breakdown with a fixed fee and a delivery call.

If you are already choosing between firms, the questions worth asking are set out in how to choose a SOC 2 compliance consultant.

References

FAQ

How much do SOC 2 consultancy services cost?

Typically $15,000 to $50,000 for a full first programme at a small to mid-sized company, with the auditor's fee separate. A standalone gap assessment usually runs $5,000 to $25,000.

Can the same firm do my consulting and my audit?

Some groups offer both, delivered through separate legal entities to preserve independence. Ask which entity signs the report and how the two are kept apart, then decide whether you are comfortable.

Do I still need a consultant if I have Vanta or Drata?

Not automatically. The platform handles monitoring and evidence collection. Whether you need help depends on who is going to work through what the platform identifies, and whether they have the time and the experience.

What is a SOC 2 readiness assessment?

A structured comparison of your current position against each criterion in scope, stating what is met, what is not, and what closes each gap. It is the normal first step and it is what the auditor's fee assumes you have already done.

How long does a consultant stay involved?

Through preparation and the examination at minimum. Many companies keep support in place across the observation period, because that is where programmes most often drift.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act. We are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.