Guided plan
From $8,500 (CPA audit included)
Fixed-price plans
Powered by ValueMentor
Prepare your control environment, operate your controls through the review period, complete an independent CPA examination and receive your SOC 2 Type 2 report through one coordinated engagement with Secusy, powered by ValueMentor.
The definition
From $8,500 (CPA audit included)
$14,500 (CPA audit included)
3 months
ValueMentor
Choose a fixed-price plan based on the size and scope of your organization — both include a three-month observation period, the independent CPA examination and the SOC 2 Type 2 report.
Startups and smaller service organizations with an internal compliance owner
$8,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Growing companies wanting hands-on SOC 2 support
$14,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Larger or complex organizations
Custom pricing
Timeline depends on your readiness, scope complexity and team availability.
| Feature | Guided | Complete | Enterprise |
|---|---|---|---|
| Best for | Startups and smaller service organizations with an internal compliance owner | Growing companies wanting hands-on SOC 2 support | Larger or complex organizations |
| Employees within scope | Up to 50 | Up to 250 | 251+ |
| Legal entities | 1 | 1 | Multiple / Custom |
| Physical locations | 1 | Up to 3 | 4+ / Custom |
| Systems/services in scope | 1 defined system/service | 1 defined system/service | Multiple / Custom |
| Trust Services Category included | Security | Security | Custom |
| Readiness support | Up to 3 months | Up to 4 months | Custom |
| Standard observation period | 3 months | 3 months | Custom |
All plans include a readiness assessment, control mapping, control implementation guidance, evidence review throughout the observation period, a pre-audit readiness review and coordination of the independent CPA examination.
Choose Enterprise when your scope includes:
The implementation, observation period, CPA examination scope and pricing are customized around your requirements.
A Type 2 examination evaluates both the design and operating effectiveness of relevant controls over a specified period — the key difference from a Type 1 examination, which evaluates controls as of a specified date. You do not necessarily need to purchase a new Type 1 report before starting Type 2 — organizations with a sufficiently mature and implemented control environment may proceed directly.
| Type 1 | Type 2 | |
|---|---|---|
| Controls evaluated | At a specified date | Over a specified period |
| Control design | Evaluated | Evaluated |
| Operating effectiveness | Not examined over a period | Examined |
| Evidence requirement | Point-in-time focused | Evidence throughout period |
| Best suited for | Organizations beginning their SOC 2 journey | Organizations needing evidence that controls operate consistently |
| Standard Secusy starting price | $6,500 | $8,500 |
| CPA examination | ||
| CPA report |
Readiness → Type 1 → Type 2. Organizations completing SOC 2 for the first time may benefit from Type 1 as an earlier assurance milestone.
Readiness → Type 2 observation period → CPA examination. Proceed directly toward Type 2 without first obtaining a Type 1 report.
Continue directly into the Type 2 program and reuse the controls, documentation and implementation work already completed.
How it works
Confirm the system or service, organizational boundaries, Trust Services Categories, locations, relevant infrastructure and third-party dependencies.
We assess existing controls and identify gaps before the observation period begins.
Your organization implements missing or incomplete technical and organizational controls.
Once the applicable controls are ready, the agreed Type 2 examination period begins. The standard Secusy package includes three months.
Your organization performs recurring control activities throughout the period.
Evidence is collected and retained to demonstrate how applicable controls operated.
Our consultants review available evidence and identify potential gaps before CPA testing.
The independent CPA firm performs examination procedures over the defined period.
Following completion of the examination, the CPA firm issues the applicable SOC 2 Type 2 report.
Having a policy does not demonstrate that a control operated consistently. For Type 2, organizations must be able to provide evidence supporting applicable control activities throughout the examination period. For example, if your control states that access is reviewed quarterly, the CPA may test whether the review actually occurred and evaluate relevant evidence. This is why Type 2 requires ongoing control operation rather than a one-time compliance exercise.
Attestation
You may see terms such as "SOC 2 certified" or "SOC 2 certification" used informally. SOC 2 is an attestation examination resulting in a SOC 2 report — not a certification issued by a certification body.
The examination is conducted by an independent CPA firm in accordance with the applicable AICPA attestation requirements. ValueMentor provides SOC 2 readiness assessment, control implementation guidance, documentation and evidence review. The independent CPA firm performs the examination and issues the report.
The standard Guided and Complete plans include the Security category. Additional categories increase implementation, evidence and CPA examination effort and are separately priced.
For organizations that make commitments about system availability, resilience and recovery.
For organizations handling information designated as confidential.
For systems where processing must be complete, valid, accurate, timely and authorized.
For organizations whose SOC 2 scope needs to address applicable privacy criteria.
A streamlined starting option for organizations entering their first Type 2 engagement where the agreed CPA examination scope supports the selected period.
Extend the examination period and demonstrate control operation across a longer period.
Suitable where customers, procurement requirements or the organization's assurance strategy require a longer reporting period.
The examination period must ultimately be agreed with the independent CPA firm.
Your role
Successful Type 2 completion requires active participation throughout the engagement. Requested actions and information should normally be completed within five business days. Customer delays may affect the examination and report timeline but do not increase the consulting effort included in the package.
You will normally provide
Scope boundaries
Unless specifically purchased, standard packages do not include — these services can be separately scoped where required:
There is no separate base CPA examination fee for customers remaining within the standard package boundaries.
$8,500
SOC 2 Type 2 readiness and implementation guidance + 3-month observation period + evidence preparation and review support + independent CPA examination + SOC 2 Type 2 report
$14,500
Hands-on implementation support + up to 15 customized policies and procedures + recurring control and evidence planning + 3-month observation period + ongoing evidence review + independent CPA examination + SOC 2 Type 2 report
Compliance
Use Secusy OneCSF to map implemented controls against other cybersecurity and compliance requirements. Cross-framework mapping identifies reusable controls and additional gaps — it does not by itself demonstrate compliance with another framework.
Information security management
Healthcare privacy & security
Payment card data protection
Cybersecurity framework
EU network & information security
Digital operational resilience
SOC 2 Type 2 is most effective as an ongoing control program rather than an annual audit project. Add a SOC 2 Continuous Compliance subscription for control tracking, evidence schedules, recurring evidence reviews, risk register updates, policy reviews and annual CPA coordination.
Many SOC 2 customers also need independent security testing for customer assurance or as part of their wider security program — web application, API, mobile application and external infrastructure testing, plus vulnerability assessments.
Support people-related security controls with ongoing employee cybersecurity awareness through Cywareness. Track employee participation and maintain relevant awareness evidence for your SOC 2 program.
One journey from implementation to Type 2 report. Most organizations approaching SOC 2 need to coordinate consultants, compliance tools and a CPA auditor separately — Secusy brings the process together.
Understand your standard SOC 2 Type 2 cost before starting.
The standard package includes the independent CPA examination and report.
An independent licensed CPA firm performs the SOC 2 examination and issues the applicable SOC 2 report.
ValueMentor cybersecurity and compliance professionals help prepare your control environment.
Use Secusy to manage activities, controls, evidence and related compliance requirements.
Continue after your report with recurring SOC 2 management and annual examination support.
Questions