Guided plan
From $6,500 (CPA audit included)
Fixed-price plans
Powered by ValueMentor
Prepare your controls, complete your independent CPA examination and obtain your SOC 2 Type 1 report with Secusy, powered by ValueMentor. No need to separately find a consultant and CPA firm — we coordinate the complete journey from readiness assessment through the independent CPA examination.
The definition
From $6,500 (CPA audit included)
$11,500 (CPA audit included)
Remote, delivered globally
ValueMentor
Choose a fixed-price plan based on the size and scope of your organization — both include the independent CPA examination and the SOC 2 Type 1 report.
Startups and smaller SaaS/service organizations
$6,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Growing organizations wanting hands-on support
$11,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Larger or complex organizations
Custom pricing
Timeline depends on your readiness, scope complexity and team availability.
| Feature | Guided | Complete | Enterprise |
|---|---|---|---|
| Best for | Startups and smaller SaaS/service organizations | Growing organizations wanting hands-on support | Larger or complex organizations |
| Employees in scope | Up to 50 | Up to 250 | 251+ |
| Legal entities | 1 | 1 | Multiple / Custom |
| Physical locations | 1 | Up to 3 | 4+ / Custom |
| Systems/services in report scope | 1 defined system/service | 1 defined system/service | Multiple / Custom |
| Trust Services Category included | Security | Security | Custom |
| Support period | Up to 3 months | Up to 4 months | Custom |
All plans include a readiness assessment, SOC 2 control mapping, control implementation guidance, evidence review, pre-audit readiness review and coordination of the independent CPA examination.
Choose Enterprise when your scope includes:
We define the implementation scope, CPA examination scope, delivery model and pricing around your requirements.
Attestation
You may see terms such as "SOC 2 certified" or "SOC 2 certification" used informally. SOC 2 is an attestation examination resulting in a SOC 2 report — not a certification issued by a certification body.
The examination is conducted by an independent CPA firm in accordance with the applicable AICPA attestation requirements. ValueMentor provides SOC 2 readiness assessment, control implementation guidance, documentation and evidence review. The independent CPA firm performs the examination and issues the report.
The standard Guided and Complete packages include the Security Trust Services Category. Depending on your customer requirements and services, you can expand the CPA examination to additional Trust Services Categories — this increases the implementation and CPA examination scope and is priced separately.
For organizations whose customers depend on system availability and resilience.
For organizations that process or store information designated as confidential.
For services where complete, valid, accurate, timely and authorized system processing is important.
For organizations that need the SOC 2 examination to address applicable privacy criteria.
How it works
Select Guided or Complete based on your organization size and the amount of implementation support you need.
We identify the system, service, infrastructure, people, processes and locations relevant to the engagement.
We compare your current controls against the applicable SOC 2 criteria and identify gaps.
Develop policies, risk management activities and organizational controls required for the scope. Your team implements the required controls.
Build the control documentation, system description and evidence package required for examination.
We review your evidence and outstanding gaps before the engagement moves to the CPA firm.
The independent CPA firm performs the SOC 2 Type 1 examination.
After completing the examination process, the CPA firm issues the applicable SOC 2 Type 1 report.
Your role
Successful SOC 2 completion requires active participation from your organization. Requested actions and information should normally be completed within five business days. Customer delays can extend the project timeline but do not increase the consulting effort included within the package.
You will normally provide
Scope boundaries
Unless specifically stated or purchased as an add-on, the standard packages do not include — these services can be separately scoped where required:
Unlike many SOC 2 services, our published package price includes both readiness support and the independent CPA examination — there is no separate base CPA audit fee for customers remaining within the standard package scope.
$6,500
SOC 2 readiness and implementation guidance + independent CPA Type 1 examination + SOC 2 Type 1 report
$11,500
Hands-on SOC 2 implementation support + independent CPA Type 1 examination + SOC 2 Type 1 report
Compliance
Your SOC 2 controls can also contribute to other cybersecurity and compliance requirements. Use Secusy OneCSF to map your controls against additional frameworks and identify the remaining gaps. Cross-framework mapping identifies common controls and remaining requirements — it does not by itself demonstrate compliance with the additional framework.
Information security management
Healthcare privacy & security
Payment card data protection
Cybersecurity framework
EU network & information security
Digital operational resilience
A Type 1 report is often the first step in an organization's SOC 2 journey. After completing Type 1, continue with a SOC 2 Type 2 program to demonstrate how relevant controls operated during an examination period — maintaining your control environment, tracking recurring control activities, collecting ongoing evidence and coordinating the independent CPA examination.
Strengthen your people-related security controls with ongoing cybersecurity awareness through Cywareness. Add a subscription to deliver and track cybersecurity awareness activities across your organization.
One journey from readiness to CPA report. Most organizations approaching SOC 2 need to coordinate consultants, compliance tools and a CPA auditor separately — Secusy brings the process together.
Know the cost of the standard implementation and CPA examination before you start.
You do not need to separately source an auditor for the standard package.
An independent licensed CPA firm performs the SOC 2 examination and issues the applicable SOC 2 report.
ValueMentor cybersecurity and compliance professionals prepare your organization for examination.
Manage activities, documentation, evidence and progress through Secusy.
Progress to Type 2 and reuse your controls across ISO 27001 and other compliance requirements.
Questions