What happens if I cancel a SOC 2 audit mid-engagement?
You typically owe for work already performed and lose any prepaid deposit, per your engagement letter — there is no standard cancellation fee. Terms vary by firm, so the contract, not an industry rule, decides what you pay.
The full answer
There is no formal AICPA rule on cancelling a SOC 2 audit mid-engagement — what happens is governed entirely by the engagement letter you signed with the CPA firm. That contract defines the fee structure, deposit, and termination terms, so read it before you sign and again before you cancel.
In practice, most firms bill for professional time already spent. If the engagement is milestone- or deposit-based, you generally forfeit the deposit and owe for completed phases such as the readiness review or planning. If it is hourly, you owe for hours worked to date. A fixed-fee contract may still specify a cancellation or kill fee.
Where you are in the timeline matters. A SOC 2 Type 1 covers a point in time and typically runs one to three months; a Type 2 observes controls over a window, usually three to twelve months, with three months the shortest most auditors accept. Cancelling early in planning usually costs less than cancelling after fieldwork or evidence testing has begun.
If your goal is to switch firms rather than abandon the audit, ask whether completed readiness work or evidence can transfer, since that reduces sunk cost. Because there is no market-wide standard, the safest move is to negotiate clear termination terms up front. Request a fresh scoped quote with transparent milestones before committing to a new engagement.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Can I negotiate a SOC 2 audit price?
Yes. SOC 2 audit fees are quotes, not fixed prices, so scope, timing, and multi-year commitments are all negotiable. The biggest lever is narrowing scope; bundling readiness or future audits and comparing firms also moves the number.
Do SOC 2 auditors charge for a readiness assessment?
Usually yes — a readiness assessment is a separate, billed engagement, priced below the audit itself. Some firms bundle or credit it toward the audit; others quote it standalone. Independence rules limit how much remediation the same auditor can do.
Do SOC 2 audits have hidden fees?
Sometimes. The audit fee itself is usually fixed, but total SOC 2 cost can include readiness assessments, GRC tooling, penetration testing, remediation, extra Trust Services Criteria, and bridge letters — get an itemized quote to avoid surprises.
Do auditors discount multi-year SOC 2 contracts?
Often yes. Because SOC 2 is an annual attestation, many firms offer a discount or locked rate for a two- or three-year commitment in exchange for recurring revenue. There is no standard discount; terms are negotiated firm by firm.
Does company size change the price of a SOC 2 audit?
Yes, but scope drives price more than headcount. Bigger companies usually have more systems, locations, and controls to test, which raises fees. A small startup with tight scope can pay far less than a large firm with sprawling infrastructure.
Does using a GRC platform lower my SOC 2 audit fee?
Sometimes, modestly. A GRC platform like Vanta, Drata, or Secureframe mainly cuts your prep time and internal effort, not the auditor's base fee. Fees drop most when your auditor has a confirmed integration and pulls evidence directly.
Sources: AICPA SSAE No. 18 attestation standards; AICPA SOC 2 Type 1 and Type 2 guidance (market practice), 2025. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.