Compliance pricing you can actually budget for
Most platforms in this category will not publish a number. Here is ours, what it includes, and what it does not, so there are no surprises at signature.
Plans
Priced on scope and framework, never on headcount.
Early Stage
10-100 employees, Seed to Series A
- One framework (SOC 2 or ISO 27001)
- Named compliance lead, weekly check-ins
- Pre-built control library and policies
- Automated evidence collection
- Trust center
- Audit-ready in 8-12 weeks
Growth
100-500 employees, multi-framework
- Multiple frameworks on one shared control library
- No per-framework licence fee
- Vendor risk and questionnaire automation
- Risk register and policy lifecycle
- Priority support
Enterprise
500+ employees, regulated or multi-entity
- All frameworks including ISO 42001 and EU AI Act
- AI governance module
- Multi-entity and regional scoping
- SSO / SCIM
- Dedicated compliance team
Pay at signoff
The platform fee falls due when your audit is signed off, not on the day you sign the contract. It keeps the incentive where it belongs: on getting you certified, not on renewing software you never managed to roll out.
What compliance actually costs
The platform is one line item. Here is the honest full picture for a first SOC 2.
| Line item | Typical range | With Certifyi |
|---|---|---|
| Compliance platform | $8,000 - $50,000/yr | From Minimal inital cost |
| Additional framework | $3,000 - $15,000 each | Included, shared control library |
| Implementation / onboarding | $2,000 - $10,000 | Included |
| External auditor | $8,000 - $20,000 | Paid directly to auditor |
| Penetration test | $4,000 - $12,000 | Separate, scoped only if required |
| Internal headcount | 0.5 - 1 FTE | Replaced by your named lead |
Questions we get before signing
What exactly is "pay at signoff"?
You pay the platform fee once your audit is signed off, not upfront. If we do not get you audit-ready, you are not paying for a year of software you could not use.
Does the price include the auditor?
No. The audit opinion must come from an independent CPA firm or certification body, so their fee is separate and paid directly to them. We will introduce you to auditors in our network, or work with yours. Budget roughly $8K-$20K for a first SOC 2 Type 2 audit depending on scope.
What about penetration testing?
Pen testing is separate and typically $4K-$12K depending on scope. Many frameworks expect it annually. We will tell you upfront whether your scope needs it.
Do you charge per framework?
No. Adding ISO 27001 alongside SOC 2 does not trigger a new licence fee, because the control library is shared. This is the single biggest difference from vendors charging $3K-$15K per additional framework.
Does pricing scale with headcount?
No. We price on scope and framework, not employee count. Hiring should not increase your compliance bill mid-contract.
What if we already started with another platform?
That is common. We can usually reuse existing policies and evidence rather than starting over, which shortens the timeline.
Is there a long-term contract?
Annual terms. No multi-year lock-in required to get a reasonable rate.