Fixed-price plans

Powered by ValueMentor

Demonstrate that your security controls work in practice.

Prepare your control environment, operate your controls through the review period, complete an independent CPA examination and receive your SOC 2 Type 2 report through one coordinated engagement with Secusy, powered by ValueMentor.

Guided planFrom $8,500 (CPA audit included)
Complete plan$14,500 (CPA audit included)
Standard observation period3 months
Delivered byValueMentor

The definition

What is a SOC 2 Type 2 report?

A SOC 2 Type 2 report results from an independent CPA examination that evaluates both the design and the operating effectiveness of a service organization's relevant controls over a specified period, assessed against the AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality or privacy. That evaluation of operating effectiveness over a period is the key difference from a Type 1 examination, which evaluates controls only as of a specified date. Because Type 2 requires evidence that controls actually operated consistently, it's the version most commonly requested during enterprise vendor security reviews.
  • Guided plan

    From $8,500 (CPA audit included)

  • Complete plan

    $14,500 (CPA audit included)

  • Standard observation period

    3 months

  • Delivered by

    ValueMentor

SOC 2 Type 2 plans

Choose a fixed-price plan based on the size and scope of your organization — both include a three-month observation period, the independent CPA examination and the SOC 2 Type 2 report.

Guided

Startups and smaller service organizations with an internal compliance owner

$8,500one-time

Package scope
  • Employees within scopeUp to 50
  • Legal entities1
  • Physical locations1
  • Systems/services in scope1 defined system/service
  • Trust Services Category includedSecurity
  • Readiness supportUp to 3 months
  • Standard observation period3 months

Timeline depends on your readiness, scope complexity and team availability.

Enterprise

Larger or complex organizations

Custom pricing

Everything in Complete, plus
  • Employees within scope251+
  • Legal entitiesMultiple / Custom
  • Physical locations4+ / Custom
  • Systems/services in scopeMultiple / Custom
  • Trust Services Category includedCustom
  • Readiness supportCustom
  • Standard observation periodCustom

Timeline depends on your readiness, scope complexity and team availability.

Compare plans

FeatureGuidedCompleteEnterprise
Best forStartups and smaller service organizations with an internal compliance ownerGrowing companies wanting hands-on SOC 2 supportLarger or complex organizations
Employees within scopeUp to 50Up to 250251+
Legal entities11Multiple / Custom
Physical locations1Up to 34+ / Custom
Systems/services in scope1 defined system/service1 defined system/serviceMultiple / Custom
Trust Services Category includedSecuritySecurityCustom
Readiness supportUp to 3 monthsUp to 4 monthsCustom
Standard observation period3 months3 monthsCustom

All plans include a readiness assessment, control mapping, control implementation guidance, evidence review throughout the observation period, a pre-audit readiness review and coordination of the independent CPA examination.

SOC 2 Type 2 for larger or more complex environments

Choose Enterprise when your scope includes:

  • More than 250 employees
  • More than three physical locations
  • Multiple legal entities
  • Multiple materially different systems or services
  • Multiple Trust Services Categories
  • Longer or complex examination periods
  • Complex subservice organizations
  • Significant additional CPA testing requirements

The implementation, observation period, CPA examination scope and pricing are customized around your requirements.

SOC 2 Type 1 vs Type 2

A Type 2 examination evaluates both the design and operating effectiveness of relevant controls over a specified period — the key difference from a Type 1 examination, which evaluates controls as of a specified date. You do not necessarily need to purchase a new Type 1 report before starting Type 2 — organizations with a sufficiently mature and implemented control environment may proceed directly.

Type 1Type 2
Controls evaluatedAt a specified dateOver a specified period
Control designEvaluatedEvaluated
Operating effectivenessNot examined over a periodExamined
Evidence requirementPoint-in-time focusedEvidence throughout period
Best suited forOrganizations beginning their SOC 2 journeyOrganizations needing evidence that controls operate consistently
Standard Secusy starting price$6,500$8,500
CPA examination
CPA report

Start Type 2 directly, or continue from Type 1

  • New to SOC 2?

    Readiness → Type 1 → Type 2. Organizations completing SOC 2 for the first time may benefit from Type 1 as an earlier assurance milestone.

  • Controls already implemented?

    Readiness → Type 2 observation period → CPA examination. Proceed directly toward Type 2 without first obtaining a Type 1 report.

  • Already completed Type 1 with Secusy?

    Continue directly into the Type 2 program and reuse the controls, documentation and implementation work already completed.

How it works

How SOC 2 Type 2 works

  1. Step 1

    Define your scope

    Confirm the system or service, organizational boundaries, Trust Services Categories, locations, relevant infrastructure and third-party dependencies.

  2. Step 2

    Complete your readiness assessment

    We assess existing controls and identify gaps before the observation period begins.

  3. Step 3

    Implement the required controls

    Your organization implements missing or incomplete technical and organizational controls.

  4. Step 4

    Begin the observation period

    Once the applicable controls are ready, the agreed Type 2 examination period begins. The standard Secusy package includes three months.

  5. Step 5

    Operate your controls

    Your organization performs recurring control activities throughout the period.

  6. Step 6

    Retain evidence

    Evidence is collected and retained to demonstrate how applicable controls operated.

  7. Step 7

    Review readiness

    Our consultants review available evidence and identify potential gaps before CPA testing.

  8. Step 8

    Complete the CPA examination

    The independent CPA firm performs examination procedures over the defined period.

  9. Step 9

    Receive your Type 2 report

    Following completion of the examination, the CPA firm issues the applicable SOC 2 Type 2 report.

Why evidence matters more in Type 2

Having a policy does not demonstrate that a control operated consistently. For Type 2, organizations must be able to provide evidence supporting applicable control activities throughout the examination period. For example, if your control states that access is reviewed quarterly, the CPA may test whether the review actually occurred and evaluate relevant evidence. This is why Type 2 requires ongoing control operation rather than a one-time compliance exercise.

Attestation

SOC 2 Type 2 is a report — not a certification

You may see terms such as "SOC 2 certified" or "SOC 2 certification" used informally. SOC 2 is an attestation examination resulting in a SOC 2 report — not a certification issued by a certification body.

The examination is conducted by an independent CPA firm in accordance with the applicable AICPA attestation requirements. ValueMentor provides SOC 2 readiness assessment, control implementation guidance, documentation and evidence review. The independent CPA firm performs the examination and issues the report.

Security included. Add other Trust Services Categories.

The standard Guided and Complete plans include the Security category. Additional categories increase implementation, evidence and CPA examination effort and are separately priced.

  • Availability

    For organizations that make commitments about system availability, resilience and recovery.

  • Confidentiality

    For organizations handling information designated as confidential.

  • Processing Integrity

    For systems where processing must be complete, valid, accurate, timely and authorized.

  • Privacy

    For organizations whose SOC 2 scope needs to address applicable privacy criteria.

Choose your observation period

  • 3 months

    Included in Guided and Complete

    A streamlined starting option for organizations entering their first Type 2 engagement where the agreed CPA examination scope supports the selected period.

  • 6 months

    Add-on

    Extend the examination period and demonstrate control operation across a longer period.

  • 12 months

    Custom

    Suitable where customers, procurement requirements or the organization's assurance strategy require a longer reporting period.

The examination period must ultimately be agreed with the independent CPA firm.

Your role

What you need to provide

Successful Type 2 completion requires active participation throughout the engagement. Requested actions and information should normally be completed within five business days. Customer delays may affect the examination and report timeline but do not increase the consulting effort included in the package.

You will normally provide

  • Appoint an internal SOC 2 owner
  • Confirm the SOC 2 scope
  • Make relevant stakeholders available
  • Review and approve documentation
  • Implement required technical and organizational controls
  • Operate applicable controls throughout the observation period
  • Complete recurring control activities when required
  • Collect and retain evidence
  • Upload requested evidence
  • Respond to ValueMentor and CPA requests
  • Document control exceptions
  • Address identified gaps
  • Provide required management representations

Scope boundaries

What is not included

Unless specifically purchased, standard packages do not include — these services can be separately scoped where required:

  • Technical implementation or configuration of security controls
  • ValueMentor operating controls on the customer's behalf
  • Collection of evidence directly from customer systems
  • Security software licenses
  • Penetration testing
  • Vulnerability assessments
  • Additional Trust Services Categories
  • Additional systems outside the agreed scope
  • Multiple legal entities
  • Additional locations outside package limits
  • Observation periods longer than three months
  • Work outside the included readiness support period
  • Legal advice
  • Onsite consulting or travel

What's included in the price?

There is no separate base CPA examination fee for customers remaining within the standard package boundaries.

  • Guided

    $8,500

    SOC 2 Type 2 readiness and implementation guidance + 3-month observation period + evidence preparation and review support + independent CPA examination + SOC 2 Type 2 report

  • Complete

    $14,500

    Hands-on implementation support + up to 15 customized policies and procedures + recurring control and evidence planning + 3-month observation period + ongoing evidence review + independent CPA examination + SOC 2 Type 2 report

Compliance

Reuse your SOC 2 controls.

Use Secusy OneCSF to map implemented controls against other cybersecurity and compliance requirements. Cross-framework mapping identifies reusable controls and additional gaps — it does not by itself demonstrate compliance with another framework.

  • ISO 27001

    Information security management

  • HIPAA

    Healthcare privacy & security

  • PCI DSS

    Payment card data protection

  • NIST CSF

    Cybersecurity framework

  • NIS2

    EU network & information security

  • DORA

    Digital operational resilience

  • Add continuous SOC 2 management

    SOC 2 Type 2 is most effective as an ongoing control program rather than an annual audit project. Add a SOC 2 Continuous Compliance subscription for control tracking, evidence schedules, recurring evidence reviews, risk register updates, policy reviews and annual CPA coordination.

  • Add penetration testing

    Many SOC 2 customers also need independent security testing for customer assurance or as part of their wider security program — web application, API, mobile application and external infrastructure testing, plus vulnerability assessments.

  • Security awareness with Cywareness

    Support people-related security controls with ongoing employee cybersecurity awareness through Cywareness. Track employee participation and maintain relevant awareness evidence for your SOC 2 program.

Why Secusy + ValueMentor?

One journey from implementation to Type 2 report. Most organizations approaching SOC 2 need to coordinate consultants, compliance tools and a CPA auditor separately — Secusy brings the process together.

Fixed-price starting packages

Understand your standard SOC 2 Type 2 cost before starting.

CPA examination included

The standard package includes the independent CPA examination and report.

Independent assurance

An independent licensed CPA firm performs the SOC 2 examination and issues the applicable SOC 2 report.

Expert-led readiness

ValueMentor cybersecurity and compliance professionals help prepare your control environment.

Digital compliance management

Use Secusy to manage activities, controls, evidence and related compliance requirements.

Designed for ongoing compliance

Continue after your report with recurring SOC 2 management and annual examination support.

Questions

Frequently asked questions