NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
SOC 2 Cost for Companies Outside the US
Learn

SOC 2 Cost for Companies Outside the US

·Alexander Sverdlov

The AICPA publishes the criteria for a SOC 2, not a price, and the Trust Services Criteria themselves are free with an AICPA account. What a company outside the US pays, whether it is a software firm in Germany, the UAE or Nigeria selling to American customers, is set by five decisions: what report the customer asking for it will accept, which trust services categories go in scope, Type 1 or Type 2, how long the period runs, and who signs the report. The last one is where being outside the US changes the arithmetic. In the United States a SOC 2 is performed by a licensed CPA under the AICPA attestation standards. Outside it, the AICPA says a CPA or equivalent licensed in another jurisdiction may perform one if local law permits, usually under ISAE 3000 (Revised), the international assurance standard.

That gives you a wider field of firms that can bid, and one question to settle before any of them do: will your US customer accept a report issued under ISAE 3000, or does it want one issued under the AICPA standards? The answer costs one email to get and decides which firms you can ask. The rest of this guide takes each cost driver in turn. What the report is, and the difference between the two types, is in our guide to SOC 2 Type 1 vs Type 2.

Cost driverWhat sets itWhere it comes from
Who can signA US licensed CPA under AT-C 105 and 205, or a non-US practitioner under ISAE 3000 (Revised)AICPA SOC 2 FAQ and AICPA guidance on ISAEs
ScopeThe common criteria plus each category you addTSP section 100, 2017 Trust Services Criteria (revised points of focus, 2022)
System descriptionManagement's description of the systemDC section 200, 2018 description criteria (revised implementation guidance, 2022)
Report typeType 1 tests design; Type 2 adds operating effectivenessAICPA SOC 2 guide
Period lengthA management decision; no minimum is prescribedAICPA SOC 2 FAQ, citing paragraph 2.46 of the guide
DistributionSOC 2 is restricted use; a SOC 3 is general useAICPA SOC reporting overview
Where the SOC 2 price is set: AT-C 205 examinations, ISAE 3000 outside the US, the TSP 100 criteria, the DC 200 description criteria, the Type 2 period and the SOC 3 general use report

What does a SOC 2 cost a company outside the US?

Three lines, and only the reading material has a published price. The Trust Services Criteria and the description criteria are free with an AICPA account; the e-book of the AICPA's SOC 2 guide, the practitioner's handbook, is listed at USD 125 for non members. The practitioner's fee is a commercial quote. The internal line is your team's time to design controls against the criteria, write the system description, and, for a Type 2, operate the controls and keep the records for the whole period.

We found no fee guidance from the AICPA, and no AICPA equivalent of the ISO/IEC 27006-1 rule that turns headcount into audit time for ISO 27001. The practitioner prices its own judgement of the work. You narrow the spread by fixing the inputs before you ask: categories, type, period, and the systems in the description.

Who can issue a SOC 2 outside the US?

The AICPA's own FAQ answers it. "In the United States, a SOC 2 examination is performed by a licensed CPA in accordance with AT-C section 105 … and AT-C section 205." It continues that SOC 2 examinations "may also be performed by a CPA (or equivalent, such as a professional accountant in public practice) licensed in a jurisdiction outside the U.S., if permitted to do so by laws and regulations", and that these engagements "are usually performed in accordance with … ISAE 3000 Revised … or equivalent local country standards."

The AICPA's separate guidance on ISAEs sets the other boundaries. A non-US CPA may perform a SOC 2 examination in accordance with ISAE 3000 (Revised) and report accordingly, if local regulation does not preclude it. A US CPA may not perform a SOC 2 examination and report only in accordance with ISAE 3000 (Revised), but may report under both sets of standards in one report. So there are three shapes of report on offer: AICPA standards from a US licensed firm, ISAE 3000 from a local practitioner, and a dual report from a US licensed firm. Which one your customer accepts decides which firms can bid.

Who can sign a SOC 2 report: a US CPA under AICPA AT-C standards, a non-US practitioner under ISAE 3000 where local law allows, a US CPA issuing a dual report under both, but not a US CPA reporting under ISAE 3000 alone

How do scope, report type and period change the fee?

Scope first. The 2017 Trust Services Criteria define five categories: security, availability, processing integrity, confidentiality and privacy. The common criteria apply to every category, so they are in every SOC 2; each additional category adds its own criteria on top. Every category you add is more controls to describe, test and evidence. Add one because a contract or a public commitment calls for it, not to look thorough.

Type second. A Type 1 reports on the description and the suitability of the design of controls. A Type 2 adds their operating effectiveness throughout a period, which means the practitioner samples evidence from across that period, and you have to have produced it. Period third. The AICPA FAQ says the SOC 2 guide "does not prescribe a minimum period of time", that the period is "a business decision made by service organization management", and that for a period of less than two months, as an example in paragraph 2.46 of the guide, the practitioner may conclude that sufficient evidence is unlikely to be obtainable. A longer period costs more internal effort, not necessarily a larger fee; a very short one can cost you the opinion.

Five decisions that set a SOC 2 fee, in order: ask what the buyer accepts, pick the trust services categories, choose Type 1 or Type 2, set the period, choose the practitioner
Venvera SOC 2 Type 2 dashboard showing categories in scope, controls operating effectively, open findings and criteria coverage for availability, confidentiality, privacy, processing integrity and security

Does ISO 27001 or GDPR work reduce the SOC 2 bill?

ISO 27001 work can reduce the internal line, because an access review, a change record or a supplier assessment that already exists for an ISMS can be offered as SOC 2 evidence if it covers the period and the systems in the description. It does not reduce the examination itself: the practitioner tests against the Trust Services Criteria, not against your certificate. If you are budgeting both, our guide to ISO 27001 certification cost covers the other half, and how to collect audit evidence covers evidence that serves both.

GDPR is a different matter. Regulation (EU) 2016/679 does not mention SOC 2. Its route to certification is Article 42, which encourages "data protection certification mechanisms and of data protection seals and marks" issued on criteria approved by a supervisory authority or the European Data Protection Board. A SOC 2 privacy category is not one of those mechanisms, and it does not replace any GDPR obligation.

What the other results get wrong

Page one for this query is mostly audit firms and compliance vendors, and four points are easy to get wrong. The first is calling the result a certification, as several result titles do. A SOC 2 is an examination report with a practitioner's opinion; there is no certificate and no register. The second is treating ISAE 3402 as the international SOC 2. ISAE 3402 covers controls at a service organisation relevant to user entities' internal control as it relates to financial reporting, which is SOC 1 territory under AT-C 320. The international route for a SOC 2 examination is ISAE 3000 (Revised).

The third is a minimum period stated as a rule. The AICPA says the guide prescribes none; a practitioner may still decline a very short one. The fourth is euro figures quoted without saying which standard the report is issued under, which categories are in scope, or how long the period is. Without those three inputs, a figure cannot be compared with your quote.

An illustrative view of a SOC 2 Type 2 period under way: common criteria with evidence, access reviews on schedule, days left in the period and exceptions to explain

Where does your company stand?

Fill this in before you ask any firm for a quote. Every blank row is a variable the firm will price for you.

QuestionYour answerWhy it matters
Which customer is asking, and will it accept an ISAE 3000 report?Decides whether local practitioners can bid.
Which categories does the contract or your public commitments require?The common criteria are in every report; each category adds criteria.
Type 1 now, Type 2 later, or Type 2 only?A Type 2 adds operating effectiveness across a period.
How long a period, and when does it start?No minimum is prescribed; very short periods risk the opinion.
Which systems and services go in the description?DC section 200 description criteria.
Is the firm licensed to perform the examination in its jurisdiction?The AICPA refers unlicensed practitioners to state boards of accountancy.
Will you also need a SOC 3 for public use?SOC 2 is restricted use; SOC 3 is general use.

If most rows are blank, a free compliance check gives you a baseline, the SOC 2 readiness checklist lists what to map, and Venvera's SOC 2 module maps controls to the criteria and keeps evidence timestamped across the period.

Venvera SOC 2 gap assessment scoping the Trust Services Criteria against the current state
The bottom line on SOC 2 cost outside the US: ask the buyer what report they accept before you price the audit

Frequently asked questions

Can a non-US audit firm issue a SOC 2 report?

Yes, where local law permits. The AICPA says a CPA or equivalent licensed outside the US may perform a SOC 2 examination, usually under ISAE 3000 (Revised) or equivalent local standards.

Will a US customer accept an ISAE 3000 report?

That is the customer's decision, not a rule. Ask before you choose a firm. A US licensed firm can issue one report under both the AICPA standards and ISAE 3000 if you need both.

Is there a minimum Type 2 period?

No. The AICPA says the SOC 2 guide does not prescribe one and that the period is a management decision. Its example is that for a period under two months, sufficient evidence may be unlikely.

Does a SOC 2 help with GDPR?

It can evidence security controls, but GDPR does not mention SOC 2, and it is not an Article 42 certification mechanism.

Can we publish our SOC 2 report?

Not openly. The AICPA treats SOC 2 reports as restricted use. A SOC 3 is the general use report that can be freely distributed.

Primary sources

Who may perform a SOC 2 and the period rules are from the AICPA SOC 2 commonly asked questions and AICPA guidance on SOC 2 examinations under ISAEs (archived copies); restricted and general use from the AICPA service organization reporting page (archived copy) and the SOC 2 guide page; state board referral from the AICPA SOC suite of services; the criteria and guide editions from the 2017 Trust Services Criteria and the AICPA SOC 2 guide; the international standards from ISAE 3000 (Revised) and ISAE 3402; and Article 42 from Regulation (EU) 2016/679. Confirm acceptance terms with your customer and licensing with the firm before you sign an engagement letter.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING