The AICPA publishes the criteria for a SOC 2, not a price, and the Trust Services Criteria themselves are free with an AICPA account. What a company outside the US pays, whether it is a software firm in Germany, the UAE or Nigeria selling to American customers, is set by five decisions: what report the customer asking for it will accept, which trust services categories go in scope, Type 1 or Type 2, how long the period runs, and who signs the report. The last one is where being outside the US changes the arithmetic. In the United States a SOC 2 is performed by a licensed CPA under the AICPA attestation standards. Outside it, the AICPA says a CPA or equivalent licensed in another jurisdiction may perform one if local law permits, usually under ISAE 3000 (Revised), the international assurance standard.
That gives you a wider field of firms that can bid, and one question to settle before any of them do: will your US customer accept a report issued under ISAE 3000, or does it want one issued under the AICPA standards? The answer costs one email to get and decides which firms you can ask. The rest of this guide takes each cost driver in turn. What the report is, and the difference between the two types, is in our guide to SOC 2 Type 1 vs Type 2.
| Cost driver | What sets it | Where it comes from |
|---|---|---|
| Who can sign | A US licensed CPA under AT-C 105 and 205, or a non-US practitioner under ISAE 3000 (Revised) | AICPA SOC 2 FAQ and AICPA guidance on ISAEs |
| Scope | The common criteria plus each category you add | TSP section 100, 2017 Trust Services Criteria (revised points of focus, 2022) |
| System description | Management's description of the system | DC section 200, 2018 description criteria (revised implementation guidance, 2022) |
| Report type | Type 1 tests design; Type 2 adds operating effectiveness | AICPA SOC 2 guide |
| Period length | A management decision; no minimum is prescribed | AICPA SOC 2 FAQ, citing paragraph 2.46 of the guide |
| Distribution | SOC 2 is restricted use; a SOC 3 is general use | AICPA SOC reporting overview |
What does a SOC 2 cost a company outside the US?
Three lines, and only the reading material has a published price. The Trust Services Criteria and the description criteria are free with an AICPA account; the e-book of the AICPA's SOC 2 guide, the practitioner's handbook, is listed at USD 125 for non members. The practitioner's fee is a commercial quote. The internal line is your team's time to design controls against the criteria, write the system description, and, for a Type 2, operate the controls and keep the records for the whole period.
We found no fee guidance from the AICPA, and no AICPA equivalent of the ISO/IEC 27006-1 rule that turns headcount into audit time for ISO 27001. The practitioner prices its own judgement of the work. You narrow the spread by fixing the inputs before you ask: categories, type, period, and the systems in the description.
Who can issue a SOC 2 outside the US?
The AICPA's own FAQ answers it. "In the United States, a SOC 2 examination is performed by a licensed CPA in accordance with AT-C section 105 … and AT-C section 205." It continues that SOC 2 examinations "may also be performed by a CPA (or equivalent, such as a professional accountant in public practice) licensed in a jurisdiction outside the U.S., if permitted to do so by laws and regulations", and that these engagements "are usually performed in accordance with … ISAE 3000 Revised … or equivalent local country standards."
The AICPA's separate guidance on ISAEs sets the other boundaries. A non-US CPA may perform a SOC 2 examination in accordance with ISAE 3000 (Revised) and report accordingly, if local regulation does not preclude it. A US CPA may not perform a SOC 2 examination and report only in accordance with ISAE 3000 (Revised), but may report under both sets of standards in one report. So there are three shapes of report on offer: AICPA standards from a US licensed firm, ISAE 3000 from a local practitioner, and a dual report from a US licensed firm. Which one your customer accepts decides which firms can bid.
How do scope, report type and period change the fee?
Scope first. The 2017 Trust Services Criteria define five categories: security, availability, processing integrity, confidentiality and privacy. The common criteria apply to every category, so they are in every SOC 2; each additional category adds its own criteria on top. Every category you add is more controls to describe, test and evidence. Add one because a contract or a public commitment calls for it, not to look thorough.
Type second. A Type 1 reports on the description and the suitability of the design of controls. A Type 2 adds their operating effectiveness throughout a period, which means the practitioner samples evidence from across that period, and you have to have produced it. Period third. The AICPA FAQ says the SOC 2 guide "does not prescribe a minimum period of time", that the period is "a business decision made by service organization management", and that for a period of less than two months, as an example in paragraph 2.46 of the guide, the practitioner may conclude that sufficient evidence is unlikely to be obtainable. A longer period costs more internal effort, not necessarily a larger fee; a very short one can cost you the opinion.

Does ISO 27001 or GDPR work reduce the SOC 2 bill?
ISO 27001 work can reduce the internal line, because an access review, a change record or a supplier assessment that already exists for an ISMS can be offered as SOC 2 evidence if it covers the period and the systems in the description. It does not reduce the examination itself: the practitioner tests against the Trust Services Criteria, not against your certificate. If you are budgeting both, our guide to ISO 27001 certification cost covers the other half, and how to collect audit evidence covers evidence that serves both.
GDPR is a different matter. Regulation (EU) 2016/679 does not mention SOC 2. Its route to certification is Article 42, which encourages "data protection certification mechanisms and of data protection seals and marks" issued on criteria approved by a supervisory authority or the European Data Protection Board. A SOC 2 privacy category is not one of those mechanisms, and it does not replace any GDPR obligation.
What the other results get wrong
Page one for this query is mostly audit firms and compliance vendors, and four points are easy to get wrong. The first is calling the result a certification, as several result titles do. A SOC 2 is an examination report with a practitioner's opinion; there is no certificate and no register. The second is treating ISAE 3402 as the international SOC 2. ISAE 3402 covers controls at a service organisation relevant to user entities' internal control as it relates to financial reporting, which is SOC 1 territory under AT-C 320. The international route for a SOC 2 examination is ISAE 3000 (Revised).
The third is a minimum period stated as a rule. The AICPA says the guide prescribes none; a practitioner may still decline a very short one. The fourth is euro figures quoted without saying which standard the report is issued under, which categories are in scope, or how long the period is. Without those three inputs, a figure cannot be compared with your quote.
Where does your company stand?
Fill this in before you ask any firm for a quote. Every blank row is a variable the firm will price for you.
| Question | Your answer | Why it matters |
|---|---|---|
| Which customer is asking, and will it accept an ISAE 3000 report? | Decides whether local practitioners can bid. | |
| Which categories does the contract or your public commitments require? | The common criteria are in every report; each category adds criteria. | |
| Type 1 now, Type 2 later, or Type 2 only? | A Type 2 adds operating effectiveness across a period. | |
| How long a period, and when does it start? | No minimum is prescribed; very short periods risk the opinion. | |
| Which systems and services go in the description? | DC section 200 description criteria. | |
| Is the firm licensed to perform the examination in its jurisdiction? | The AICPA refers unlicensed practitioners to state boards of accountancy. | |
| Will you also need a SOC 3 for public use? | SOC 2 is restricted use; SOC 3 is general use. |
If most rows are blank, a free compliance check gives you a baseline, the SOC 2 readiness checklist lists what to map, and Venvera's SOC 2 module maps controls to the criteria and keeps evidence timestamped across the period.

Frequently asked questions
Can a non-US audit firm issue a SOC 2 report?
Yes, where local law permits. The AICPA says a CPA or equivalent licensed outside the US may perform a SOC 2 examination, usually under ISAE 3000 (Revised) or equivalent local standards.
Will a US customer accept an ISAE 3000 report?
That is the customer's decision, not a rule. Ask before you choose a firm. A US licensed firm can issue one report under both the AICPA standards and ISAE 3000 if you need both.
Is there a minimum Type 2 period?
No. The AICPA says the SOC 2 guide does not prescribe one and that the period is a management decision. Its example is that for a period under two months, sufficient evidence may be unlikely.
Does a SOC 2 help with GDPR?
It can evidence security controls, but GDPR does not mention SOC 2, and it is not an Article 42 certification mechanism.
Can we publish our SOC 2 report?
Not openly. The AICPA treats SOC 2 reports as restricted use. A SOC 3 is the general use report that can be freely distributed.
Primary sources
Who may perform a SOC 2 and the period rules are from the AICPA SOC 2 commonly asked questions and AICPA guidance on SOC 2 examinations under ISAEs (archived copies); restricted and general use from the AICPA service organization reporting page (archived copy) and the SOC 2 guide page; state board referral from the AICPA SOC suite of services; the criteria and guide editions from the 2017 Trust Services Criteria and the AICPA SOC 2 guide; the international standards from ISAE 3000 (Revised) and ISAE 3402; and Article 42 from Regulation (EU) 2016/679. Confirm acceptance terms with your customer and licensing with the firm before you sign an engagement letter.





