Docket No. 054 · Compliance Audit Budgeting
Docket
Pick the framework, size the engagement, and price the full audit cycle — not just year one.
SOC 2 Type II
ISO 27001
PCI DSS
HIPAA
GDPR
Custom
Real audit cycles vary by regulator and scope — the days below are editable starting estimates, not a quote.
01 Auditor fees
02 Internal & one-time costs
03 The audit cycle — three years
Year 1
Initial audit
— days
—
—
Year 2
Surveillance
— days
—
—
Year 3
Surveillance / renewal
— days
—
—
Year 1 total
—
Audit fee, travel, internal time, cert & remediation.
Avg. annual (years 2–3)
—
Typical ongoing surveillance year.
3-year program total
—
Full initial + surveillance cycle.
04 Full breakdown
Copied to clipboard