Fixed-price plans

Powered by ValueMentor

Get audit-ready and receive your SOC 2 Type 1 report through one engagement.

Prepare your controls, complete your independent CPA examination and obtain your SOC 2 Type 1 report with Secusy, powered by ValueMentor. No need to separately find a consultant and CPA firm — we coordinate the complete journey from readiness assessment through the independent CPA examination.

Guided planFrom $6,500 (CPA audit included)
Complete plan$11,500 (CPA audit included)
DeliveryRemote, delivered globally
Delivered byValueMentor

The definition

What is a SOC 2 Type 1 report?

A SOC 2 Type 1 report results from an independent CPA examination of a service organization's system and relevant controls as of a specified date, evaluated against the AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality or privacy. It's commonly used by organizations that need an independent report on the design of their controls without first completing the longer observation period required for a Type 2 examination. The examination also considers management's description of the system using the applicable SOC 2 Description Criteria.
  • Guided plan

    From $6,500 (CPA audit included)

  • Complete plan

    $11,500 (CPA audit included)

  • Delivery

    Remote, delivered globally

  • Delivered by

    ValueMentor

SOC 2 Type 1 plans

Choose a fixed-price plan based on the size and scope of your organization — both include the independent CPA examination and the SOC 2 Type 1 report.

Guided

Startups and smaller SaaS/service organizations

$6,500one-time

Package scope
  • Employees in scopeUp to 50
  • Legal entities1
  • Physical locations1
  • Systems/services in report scope1 defined system/service
  • Trust Services Category includedSecurity
  • Support periodUp to 3 months

Timeline depends on your readiness, scope complexity and team availability.

Enterprise

Larger or complex organizations

Custom pricing

Everything in Complete, plus
  • Employees in scope251+
  • Legal entitiesMultiple / Custom
  • Physical locations4+ / Custom
  • Systems/services in report scopeMultiple / Custom
  • Trust Services Category includedCustom
  • Support periodCustom

Timeline depends on your readiness, scope complexity and team availability.

Compare plans

FeatureGuidedCompleteEnterprise
Best forStartups and smaller SaaS/service organizationsGrowing organizations wanting hands-on supportLarger or complex organizations
Employees in scopeUp to 50Up to 250251+
Legal entities11Multiple / Custom
Physical locations1Up to 34+ / Custom
Systems/services in report scope1 defined system/service1 defined system/serviceMultiple / Custom
Trust Services Category includedSecuritySecurityCustom
Support periodUp to 3 monthsUp to 4 monthsCustom

All plans include a readiness assessment, SOC 2 control mapping, control implementation guidance, evidence review, pre-audit readiness review and coordination of the independent CPA examination.

SOC 2 for larger or more complex organizations

Choose Enterprise when your scope includes:

  • More than 250 employees
  • More than three physical locations
  • Multiple legal entities
  • Multiple products or materially different systems requiring broader examination scope
  • Multiple Trust Services Categories
  • Complex organizational or governance requirements
  • Significant additional CPA examination requirements

We define the implementation scope, CPA examination scope, delivery model and pricing around your requirements.

Attestation

SOC 2 Type 1 is a report — not a certification

You may see terms such as "SOC 2 certified" or "SOC 2 certification" used informally. SOC 2 is an attestation examination resulting in a SOC 2 report — not a certification issued by a certification body.

The examination is conducted by an independent CPA firm in accordance with the applicable AICPA attestation requirements. ValueMentor provides SOC 2 readiness assessment, control implementation guidance, documentation and evidence review. The independent CPA firm performs the examination and issues the report.

Security included. Add other Trust Services Categories when needed.

The standard Guided and Complete packages include the Security Trust Services Category. Depending on your customer requirements and services, you can expand the CPA examination to additional Trust Services Categories — this increases the implementation and CPA examination scope and is priced separately.

  • Availability

    For organizations whose customers depend on system availability and resilience.

  • Confidentiality

    For organizations that process or store information designated as confidential.

  • Processing Integrity

    For services where complete, valid, accurate, timely and authorized system processing is important.

  • Privacy

    For organizations that need the SOC 2 examination to address applicable privacy criteria.

How it works

How the SOC 2 Type 1 process works

  1. Step 1

    Choose your plan

    Select Guided or Complete based on your organization size and the amount of implementation support you need.

  2. Step 2

    Define the SOC 2 scope

    We identify the system, service, infrastructure, people, processes and locations relevant to the engagement.

  3. Step 3

    Complete the readiness assessment

    We compare your current controls against the applicable SOC 2 criteria and identify gaps.

  4. Step 4

    Prepare your controls

    Develop policies, risk management activities and organizational controls required for the scope. Your team implements the required controls.

  5. Step 5

    Prepare documentation and evidence

    Build the control documentation, system description and evidence package required for examination.

  6. Step 6

    Complete the readiness review

    We review your evidence and outstanding gaps before the engagement moves to the CPA firm.

  7. Step 7

    Complete the independent CPA examination

    The independent CPA firm performs the SOC 2 Type 1 examination.

  8. Step 8

    Receive your SOC 2 Type 1 report

    After completing the examination process, the CPA firm issues the applicable SOC 2 Type 1 report.

Your role

What you need to provide

Successful SOC 2 completion requires active participation from your organization. Requested actions and information should normally be completed within five business days. Customer delays can extend the project timeline but do not increase the consulting effort included within the package.

You will normally provide

  • Appoint an internal SOC 2 owner
  • Confirm the system and organizational scope
  • Make appropriate business and technical stakeholders available
  • Attend implementation workshops
  • Review and approve policies and procedures
  • Implement required controls
  • Collect and upload requested evidence
  • Prepare and approve management information required for the examination
  • Respond to consultant and CPA information requests
  • Address identified control gaps
  • Provide management representations required as part of the examination

Scope boundaries

What is not included

Unless specifically stated or purchased as an add-on, the standard packages do not include — these services can be separately scoped where required:

  • Technical implementation or configuration of security controls
  • Collection of evidence from customer systems
  • Penetration testing
  • Vulnerability assessment
  • Security software licenses
  • Additional Trust Services Categories
  • Multiple independent systems or services outside the agreed report scope
  • Additional legal entities
  • Work outside the included implementation period
  • Legal advice
  • Onsite consulting or travel
  • SOC 2 Type 2 examination and report
  • Remediation that requires ValueMentor to operate customer systems

What's included in the price?

Unlike many SOC 2 services, our published package price includes both readiness support and the independent CPA examination — there is no separate base CPA audit fee for customers remaining within the standard package scope.

  • Guided

    $6,500

    SOC 2 readiness and implementation guidance + independent CPA Type 1 examination + SOC 2 Type 1 report

  • Complete

    $11,500

    Hands-on SOC 2 implementation support + independent CPA Type 1 examination + SOC 2 Type 1 report

Compliance

Reuse the controls you already built.

Your SOC 2 controls can also contribute to other cybersecurity and compliance requirements. Use Secusy OneCSF to map your controls against additional frameworks and identify the remaining gaps. Cross-framework mapping identifies common controls and remaining requirements — it does not by itself demonstrate compliance with the additional framework.

  • ISO 27001

    Information security management

  • HIPAA

    Healthcare privacy & security

  • PCI DSS

    Payment card data protection

  • NIST CSF

    Cybersecurity framework

  • NIS2

    EU network & information security

  • DORA

    Digital operational resilience

  • Add SOC 2 Type 2

    A Type 1 report is often the first step in an organization's SOC 2 journey. After completing Type 1, continue with a SOC 2 Type 2 program to demonstrate how relevant controls operated during an examination period — maintaining your control environment, tracking recurring control activities, collecting ongoing evidence and coordinating the independent CPA examination.

  • Security awareness with Cywareness

    Strengthen your people-related security controls with ongoing cybersecurity awareness through Cywareness. Add a subscription to deliver and track cybersecurity awareness activities across your organization.

Why Secusy + ValueMentor?

One journey from readiness to CPA report. Most organizations approaching SOC 2 need to coordinate consultants, compliance tools and a CPA auditor separately — Secusy brings the process together.

One fixed price

Know the cost of the standard implementation and CPA examination before you start.

CPA examination included

You do not need to separately source an auditor for the standard package.

Independent examination

An independent licensed CPA firm performs the SOC 2 examination and issues the applicable SOC 2 report.

Expert-led implementation

ValueMentor cybersecurity and compliance professionals prepare your organization for examination.

Digital delivery

Manage activities, documentation, evidence and progress through Secusy.

Continue beyond Type 1

Progress to Type 2 and reuse your controls across ISO 27001 and other compliance requirements.

Questions

Frequently asked questions