The short answer
Nobody publishes a price for either certification. The two inputs that decide an ISO 27001 fee are both unpublished. Third-party estimates put a SOC 2 Type II audit in Australia between A$20,000 and A$160,000 depending on the firm. For an ISO 27001 certification audit they run from A$7,500 to A$25,000 before readiness. Those ranges are too wide to budget against, so what follows separates the checkable from the estimated.
What is genuinely verifiable
- Only a licensed CPA firm can issue a SOC 2 report. A SOC 2 examination is an AICPA attestation engagement performed under AT-C sections 105 and 205. SSAE No. 21 is effective for reports dated on or after 15 June 2022. Source: AICPA, retrieved 18 September 2026.
- ISO 27001 audit days are set by the number of people in scope. Audit time is determined under the normative Annex C of ISO/IEC 27006-1:2024, which bases it on the effective number of personnel rather than on revenue. Accredited bodies were required to apply the 2024 edition to all clients by 31 March 2026. Source: ISO/IEC 27006-1:2024, via ANAB and the Standards Council of Canada transition notices, retrieved 18 September 2026.
- the certification body must be accredited, in Australia by JAS-ANZ. JAS-ANZ is the bi-national accreditation body established by treaty between the Australian and New Zealand governments in 1991. It accredits the bodies that certify, and publishes a register of accredited certifications. Source: Australian Department of Industry, Science and Resources, retrieved 18 September 2026.
The second point is the one that saves money. Audit days scale with the people inside your scope, so drawing a narrower scope is the biggest lever you hold before asking for a quote.
Published estimates, and whose they are
Every figure below belongs to the named source. None is ours, and none is independently verified by us.
| What | Published range | Whose figure |
|---|---|---|
| SOC 2 Type II, specialist firm, Australia | A$20,000 to A$45,000 | SOC2Auditors.org, AUD. Named example in a Sydney-based specialist listing. |
| SOC 2 Type II, mid-tier firm, Australia | A$30,000 to A$65,000 | SOC2Auditors.org, AUD. Directory estimate for the mid-tier band. |
| SOC 2 Type II, Big Four firm, Australia | A$50,000 to A$160,000 | SOC2Auditors.org, AUD. Directory estimate for the Big Four band. |
| SOC 2 Type II audit fee, small to midsize | US$12,000 to US$20,000 | Drata, USD. Audit fee only, United States market, not Australia. |
| ISO 27001 certification body audit, Stage 1 and Stage 2 | A$7,500 to A$25,000 | CyberNinja, AUD. Certification body fee only, excluding readiness and remediation. |
| ISO 27001 auditor day rate, Australia | A$1,200 to A$1,600 | CyberNinja, AUD. Per auditor day. Multiplied by audit days to give the fee. |
| ISO 27001 certification, 1 to 30 people in scope | A$7,000 to A$15,000 | PM Docs, AUD. Across 3 to 6 audit days. Presented as typical rather than sourced. |
| ISO 27001 certification, 31 to 100 people in scope | A$15,000 to A$25,000 | PM Docs, AUD. Across 6 to 10 audit days. Presented as typical rather than sourced. |
Two cautions. The Drata range is United States dollars for the United States market, so it is not an Australian figure. The SOC2Auditors.org bands are a directory's own estimates on a site that takes paid placements.
Why the audit fee is the smaller number
Buyers budget the auditor and are surprised by the rest. These usually cost more than the audit, and nobody quotes them up front.
- Readiness and gap work, before an auditor is engaged.
- Remediation, which is engineering rather than paperwork.
- Compliance tooling, usually an annual subscription.
- Internal time from the people who own the systems.
How to make a quote comparable
Ask every certification body the same four questions, then compare the answers rather than the totals.
- How many audit days, and on what basis were they determined?
- What is the day rate, and the Stage 1 and Stage 2 split?
- What do surveillance years one and two cost, and recertification?
- Which scheme are you accredited for, on the JAS-ANZ register?
For SOC 2, confirm the report will be issued by a licensed CPA firm. Whether the customer wants Type I or Type II moves the cost more than the choice of auditor, which is covered in SOC 2 Type I vs Type II.
What we do not publish
Our own fees are not on this page, because a number without your scope attached would mislead. SOC 2 readiness and ISO 27001 readiness set out what the work covers and excludes, and scope and fee are agreed in writing before anything starts. Sorami prepares you for the body that certifies or attests, and is not that body.
Sources
- SOC2Auditors.org, independent directory of SOC 2 audit firms. Retrieved 18 September 2026. Discloses paid placements for labelled listings and states its figures are a mix of firm-confirmed numbers, public sources and its own estimates.
- Drata, compliance platform vendor. Retrieved 18 September 2026. A vendor writing about a market it sells into. Figures are US dollars and not Australia-specific.
- CyberNinja, Australian consultancy. Retrieved 18 September 2026. A consultancy that sells readiness work. Its audit-fee and day-rate figures are its own estimates.
- PM Docs, Australian template and documentation vendor. Retrieved 18 September 2026. Undated. Figures are presented as typical rather than sourced.
Every figure above was read from the named source on 18 September 2026 and is reproduced as that source published it.