What SOC 2 and ISO 27001 actually cost in Australia

Neither has a published price. Here is what sets the number, and whose estimates are whose.

Last reviewed: · 4 min read

The short answer

Nobody publishes a price for either certification. The two inputs that decide an ISO 27001 fee are both unpublished. Third-party estimates put a SOC 2 Type II audit in Australia between A$20,000 and A$160,000 depending on the firm. For an ISO 27001 certification audit they run from A$7,500 to A$25,000 before readiness. Those ranges are too wide to budget against, so what follows separates the checkable from the estimated.

What is genuinely verifiable

  • Only a licensed CPA firm can issue a SOC 2 report. A SOC 2 examination is an AICPA attestation engagement performed under AT-C sections 105 and 205. SSAE No. 21 is effective for reports dated on or after 15 June 2022. Source: AICPA, retrieved 18 September 2026.
  • ISO 27001 audit days are set by the number of people in scope. Audit time is determined under the normative Annex C of ISO/IEC 27006-1:2024, which bases it on the effective number of personnel rather than on revenue. Accredited bodies were required to apply the 2024 edition to all clients by 31 March 2026. Source: ISO/IEC 27006-1:2024, via ANAB and the Standards Council of Canada transition notices, retrieved 18 September 2026.
  • the certification body must be accredited, in Australia by JAS-ANZ. JAS-ANZ is the bi-national accreditation body established by treaty between the Australian and New Zealand governments in 1991. It accredits the bodies that certify, and publishes a register of accredited certifications. Source: Australian Department of Industry, Science and Resources, retrieved 18 September 2026.

The second point is the one that saves money. Audit days scale with the people inside your scope, so drawing a narrower scope is the biggest lever you hold before asking for a quote.

Published estimates, and whose they are

Every figure below belongs to the named source. None is ours, and none is independently verified by us.

Third-party cost estimates, retrieved 18 September 2026. Currencies differ by source.
WhatPublished rangeWhose figure
SOC 2 Type II, specialist firm, AustraliaA$20,000 to A$45,000SOC2Auditors.org, AUD. Named example in a Sydney-based specialist listing.
SOC 2 Type II, mid-tier firm, AustraliaA$30,000 to A$65,000SOC2Auditors.org, AUD. Directory estimate for the mid-tier band.
SOC 2 Type II, Big Four firm, AustraliaA$50,000 to A$160,000SOC2Auditors.org, AUD. Directory estimate for the Big Four band.
SOC 2 Type II audit fee, small to midsizeUS$12,000 to US$20,000Drata, USD. Audit fee only, United States market, not Australia.
ISO 27001 certification body audit, Stage 1 and Stage 2A$7,500 to A$25,000CyberNinja, AUD. Certification body fee only, excluding readiness and remediation.
ISO 27001 auditor day rate, AustraliaA$1,200 to A$1,600CyberNinja, AUD. Per auditor day. Multiplied by audit days to give the fee.
ISO 27001 certification, 1 to 30 people in scopeA$7,000 to A$15,000PM Docs, AUD. Across 3 to 6 audit days. Presented as typical rather than sourced.
ISO 27001 certification, 31 to 100 people in scopeA$15,000 to A$25,000PM Docs, AUD. Across 6 to 10 audit days. Presented as typical rather than sourced.

Two cautions. The Drata range is United States dollars for the United States market, so it is not an Australian figure. The SOC2Auditors.org bands are a directory's own estimates on a site that takes paid placements.

Why the audit fee is the smaller number

Buyers budget the auditor and are surprised by the rest. These usually cost more than the audit, and nobody quotes them up front.

  • Readiness and gap work, before an auditor is engaged.
  • Remediation, which is engineering rather than paperwork.
  • Compliance tooling, usually an annual subscription.
  • Internal time from the people who own the systems.

How to make a quote comparable

Ask every certification body the same four questions, then compare the answers rather than the totals.

  • How many audit days, and on what basis were they determined?
  • What is the day rate, and the Stage 1 and Stage 2 split?
  • What do surveillance years one and two cost, and recertification?
  • Which scheme are you accredited for, on the JAS-ANZ register?

For SOC 2, confirm the report will be issued by a licensed CPA firm. Whether the customer wants Type I or Type II moves the cost more than the choice of auditor, which is covered in SOC 2 Type I vs Type II.

What we do not publish

Our own fees are not on this page, because a number without your scope attached would mislead. SOC 2 readiness and ISO 27001 readiness set out what the work covers and excludes, and scope and fee are agreed in writing before anything starts. Sorami prepares you for the body that certifies or attests, and is not that body.

Sources

  • SOC2Auditors.org, independent directory of SOC 2 audit firms. Retrieved 18 September 2026. Discloses paid placements for labelled listings and states its figures are a mix of firm-confirmed numbers, public sources and its own estimates.
  • Drata, compliance platform vendor. Retrieved 18 September 2026. A vendor writing about a market it sells into. Figures are US dollars and not Australia-specific.
  • CyberNinja, Australian consultancy. Retrieved 18 September 2026. A consultancy that sells readiness work. Its audit-fee and day-rate figures are its own estimates.
  • PM Docs, Australian template and documentation vendor. Retrieved 18 September 2026. Undated. Figures are presented as typical rather than sourced.

Every figure above was read from the named source on 18 September 2026 and is reproduced as that source published it.

Questions before you book

Practical answers.

How much does SOC 2 cost in Australia?

There is no published price. The SOC2Auditors.org directory, retrieved on 18 September 2026, estimates a Type II audit in Australia at about A$20,000 for a specialist firm rising to A$160,000 at the Big Four end. That directory discloses paid placements and describes its figures as estimates. Treat the spread as a starting point for quotes rather than a rate card.

How much does ISO 27001 certification cost in Australia?

The certification body fee is audit days multiplied by a day rate. CyberNinja estimates A$1,200 to A$1,600 per auditor day in Australia and A$7,500 to A$25,000 for Stage 1 and Stage 2 combined, retrieved on 18 September 2026. Neither input is officially published, which is why quotes vary so widely.

Why will not anyone quote a fixed price?

Because the two inputs are not public. ISO sells the standard that determines audit days, and no accredited certification body publishes its day rate. A real number needs your scope, the people in it and your current evidence.

What is usually missing from a cost estimate?

The audit fee is the smaller line. Readiness, remediation, tooling and internal labour usually dominate first-year spend. An estimate covering only the auditor understates the total.

Does Sorami publish its prices?

Not on this page. Scope changes the answer enough that a published number would mislead, so scope and fee are confirmed in writing before any work starts.

Let’s scope it

Need a number for your actual scope?

Tell us what the customer asked for and what you already run. We will confirm scope and fee in writing before anything starts.

Request a quote