Four of the five hide their price behind a demo, and none of them sells you the SOC 2 opinion. What each platform publishes about cost, the audit, frameworks and the tools a vibe-coded stack uses, read on each vendor's own site on 3 October 2026.
You have an enterprise buyer, a deadline, and five browser tabs that all say "get a demo." This page does one narrow job. It puts what each platform says on its own site next to the others, so you know what to ask before the first call.
Secureframe is the only one of the five that prints a number: its Fundamentals package is "starting at $7,500/year." Vanta, Drata, Sprinto and Thoropass publish plan names and feature lists but no dollar figures, and send you to a demo for a quote.
Here is what each pricing page actually shows:
Secureframe.Fundamentals says "Starting at $7,500/year." Complete and Defense show "Get a quote." Fundamentals and Complete both list one compliance framework.
Vanta.Four tiers (Essentials, Plus, Professional, Enterprise) and no price. The page says to "Request a free demo today to discuss your business needs and get personalized pricing." Essentials covers one framework.
Drata. There is no pricing page to read. A request for drata.com/pricing lands on the homepage. Its startup page mentions "plans built to fit today and scale tomorrow" and a demo form.
Sprinto.Two main plans, Foundation ("for startups on their first certification") and Growth, plus a track for mature GRC teams. No figures. Extra frameworks are an add-on.
Thoropass. No pricing page that we could find. Its SOC 2 page says audit costs "vary based on scope, company size, systems included," and offers a call.
Because the vendors won't say, the best public data is what buyers reported. Vendr is a software-buying marketplace that publishes ranges from contracts it handled:
Vendr buyer data, read 3 Oct 2026. Vendr customers only; the platform fee excludes the audit. · aliteq research
Vanta
Vendr median per year
$20,000
Low to high
$7,500 to $57,221
Sample
373 purchases
Drata
Vendr median per year
$25,000
Low to high
$9,415 to $68,250
Sample
235 purchases
Secureframe
Vendr median per year
$20,000
Low to high
$7,733 to $32,575
Sample
not stated
Thoropass
Vendr median per year
$25,000
Low to high
$1,145 to $50,880
Sample
not stated
Sprinto
Vendr median per year
$15,000
Low to high
$13,167 to $16,000
Sample
very few deals
Vendr median per year
Low to high
Sample
Vanta
$20,000
$7,500 to $57,221
373 purchases
Drata
$25,000
$9,415 to $68,250
235 purchases
Secureframe
$20,000
$7,733 to $32,575
not stated
Thoropass
$25,000
$1,145 to $50,880
not stated
Sprinto
$15,000
$13,167 to $16,000
very few deals
Read these with care. They come from Vendr's own customers, not all buyers. Vendr's Vanta page was last updated in February 2026, and its Drata low end moved a little in a week. Sprinto's narrow range suggests very few deals, so its median is thin. Thoropass's wide range may reflect that it sells audit services too, which we couldn't confirm. For a company with 1 to 50 employees on one framework, Vendr's own text for Vanta gives about $12,000 to $25,000 a year, and about the same for Drata. Our earlier guide used the same Vendr data in SOC 2 for AI startups.
Is the audit included?
For four of the five, no. Vanta, Drata, Secureframe and Sprinto each link you to partner audit firms, and the audit is its own engagement with its own fee. Thoropass is the exception: it sells an audit done by its own affiliated CPA firm. None of the pages we read says the audit fee is inside the subscription.
Vanta. Its startup FAQ is direct: "The audit is a separate engagement." It connects you to "AICPA peer-reviewed auditors from our partner network," and its SOC 2 page says "100+ trusted auditors." You can also bring your own auditor.
Drata. Describes an "Audit Hub" for auditor collaboration and "hundreds of technology partners and audit firms." We found no sentence saying an audit is included.
Secureframe. Lists "Access to the Secureframe Audit Partner Network." Nothing on the pages says the fee is covered.
Sprinto. Lists "Sprinto network auditor access" and "Bring your own auditor." Same: no fee claim.
Thoropass. Says "Our audit is completed by one of our in-house auditors." Its footer names "Laika Compliance, LLC dba Thoropass Assurance" as "a licensed certified public accounting firm registered with the American Institute of Certified Public Accountants (AICPA)." Whether that fee sits inside the platform price isn't stated on the pages we read, so ask.
That last point deserves a plain note. A platform and an auditor under one roof is a design choice some buyers like, because the same team sees the evidence and the audit. It also means the usual advice, to compare the platform price and the audit quote separately, gets harder to follow. Ask for the two as separate line items either way. Why that matters is in what a SOC 2 audit costs: the audit fee is the one part of the bill a platform can't make smaller on its own.
Why a platform vendor's audit number is a marketing number
Vanta's own cost page puts the audit fee at "$10,000 to $50,000" and calls it "the smallest and most predictable part" of the total. That may be true for a mid-sized company. But a platform has a reason to keep the audit line small next to its own subscription, which is why our audit guide puts independent bands first.
What no platform does
The software collects evidence, drafts policies, watches your systems and flags what is failing. It does not test your controls, form an opinion or issue the SOC 2 report. A licensed CPA firm does that. And you still fix the failing controls.
Who does what. The report always comes from the audit firm. · aliteq research
This is the same point the AICPA, the accountants' professional body, raised in May 2026. Its Journal of Accountancy quoted an AICPA ethics official saying "Some firms are leaning too heavily on third-party SOC platforms without applying the professional judgment required by our standards." The guidance names no company. Separately, in March 2026 an anonymous post alleged that Delve, a compliance startup, had produced hundreds of near-identical SOC 2 reports through a small set of audit firms. TechCrunch reported the allegations. Delve disputes them and says final reports are issued by independent licensed auditors, not by Delve. No court has ruled on them, and none of the five platforms here is part of that story. The lesson from our pillar guide applies to any of them: a very cheap, very fast report is a reason to look harder at the auditor, and you should be able to look up the firm.
The scorecard
Put side by side, the pages differ most on three things: whether a price is printed, whether the audit is separate, and which of your tools have a listed integration.
As each vendor's own pages read on 3 Oct 2026. 'Not seen' or 'not found' means the pages we could read didn't say. · aliteq research
Frameworks
All five name SOC 2, ISO 27001 and HIPAA. Vanta lists SOC 2, ISO 27001, GDPR, HIPAA, HITRUST, ISO 42001 and the NIST AI Risk Management Framework. Drata adds PCI DSS, DORA, FedRAMP and CMMC. Secureframe names SOC 2, ISO 27001, HIPAA, PCI DSS, CCPA, GDPR and CMMC. Sprinto says "25+ frameworks automated out of the box." Thoropass covers SOC 1, SOC 2, ISO 27001, PCI DSS, HIPAA and HITRUST. If your buyer later asks for ISO 42001, the AI-management standard, check it is in your tier. Several vendors sell a second framework as an add-on.
Integrations for a vibe-coded stack
This is where the pages are most uneven, and where a quick test saves you a bad demo. Does the platform have a listed integration for the tools you actually use?
Vanta has dedicated pages for Supabase, Vercel, GitHub, OpenAI, Anthropic, Netlify, Cloudflare and AWS. It has no page for Lovable, Cursor or Replit.
Drata's directory lists GitHub, Vercel, OpenAI, Anthropic, Cloudflare and AWS. We browsed its five pages of tiles and did not see Supabase, Lovable, Cursor or Replit.
Secureframe's page names GitHub and AWS, claims "300+ Native Integrations," and we didn't see Supabase, Vercel or Lovable on it.
Sprinto says "300+ integrations" and Thoropass says its integrations are "vetted and approved by auditors." We could not confirm Supabase, Vercel or GitHub on either, because their lists didn't load as readable text.
"Not seen" is not "unsupported." Many tools connect through a cloud account or an API. But if your app lives in Supabase and Vercel, the first question for each vendor is a plain one: is this a native integration, or a manual upload? Evidence you collect by hand is the cost you were trying to avoid. Our guide to which vibe-coding platforms hold SOC 2 covers what those platforms' own reports do and don't cover.
Startup programs and trials
Only Vanta says so on its own page: "a free production-level trial—typically five to seven days—where real work carries over if you become a customer," plus "startup-specific pricing" on request. We found no startup discount, trial or credit program on the Drata, Secureframe, Sprinto or Thoropass pages we read. That doesn't mean there isn't one. Ask.
Contract terms
None of the five publishes term length, renewal caps or cancellation terms on the pages we read. The only public data is Vendr's, and only for Vanta: "Annual contracts are standard; multi-year commitments often unlock discounting," and contracts "commonly include annual price escalation clauses (typically 5–10% per year)." Treat that as one marketplace's view of one vendor. For any of them, get the renewal terms in writing, with a cap on the annual increase, before you sign.
Who each fits
These are our readings of the public pages, not tested recommendations. The honest summary: for a team under about 20 people, the five are closer than their marketing suggests, and the deciding questions are your stack, your buyer's framework and who signs the audit.
If you want to know the entry price before a call: Secureframe is the only one that prints a figure. Fundamentals starts at $7,500 a year for one framework. That is a starting price, not a quote.
If your app runs on Supabase, Vercel and GitHub: Vanta is the only one with dedicated pages for all three, and the only one that publishes a trial. Ask the others for their equivalent list in writing.
If you want the auditor and the software from one company: Thoropass is the one that says so. Ask for the platform and the audit as separate quotes, and confirm the audit firm is a CPA firm you can look up.
If you expect to add frameworks later: Sprinto and Drata both advertise wide framework lists. Check which ones sit in your tier and which are add-ons.
If budget is the first filter: Vendr's lowest medians are Sprinto at $15,000 and Vanta and Secureframe at $20,000. Medians from different buyer mixes are not a ranking.
Whichever you pick, the platform is the cheaper half. Add a separate audit fee on top: our reuse of the published bands puts a Type 1 with a specialist firm at about $10,000 to $35,000, and the whole first year is modeled below.
SOC 2 cost + timeline estimator
Year one
$34.9k–$102k
Year two and later: roughly 40–70% of year one (vendor-reported).
Time to report
9–15 months
Includes the 6-month window. There is no AICPA minimum; 3 months is the practical floor.
Audit fee
specialist CPA, Type 2
$15.5k–$50k
Compliance platform
Vanta/Drata-class, per year
$12k–$28k
Pen test
basic
$5k–$15k
Readiness assessment
skipped
—
Stack upgrades
none selected
—
Your team's time
40–150 h × $60/h
$2.4k–$9k
Ranges from SOC2Auditors.org (directory), Vendr (buyer data), Drata, The Pun Group (CPA firm), Fractional CISO, SecureLeap and Cherry Bekaert (CPA firm); stack prices from Supabase, Vercel and Lovable pricing pages. Checked 27 Sep 2026. Most are published by companies that sell audits or compliance software. An estimate, not a quote.
Ten questions to ask on every demo call
A demo is where the missing price and the missing terms come out. Ask the same ten of every vendor and write the answers down.
What is the price for one framework, my headcount and my tier, in writing, for year one and year two?
Is the audit fee in that number? If not, which firms do you work with, and can I use my own?
Is the auditor a licensed CPA firm I can look up, and does it share any ownership with you?
Which of my tools are native integrations, and which need manual evidence? Name Supabase, Vercel and GitHub, or whatever you use.
What happens to the price if I add a second framework or cross the next headcount band?
What is the renewal increase cap, and what is the cancellation term?
Do you have a startup program or a trial, and does work carry over?
How long from signing to the auditor starting fieldwork, for a company my size?
Which questionnaire, trust-center and AI features are in my tier, and which are add-ons?
If my buyer wants a report by a date, what can you commit to in the contract?
Not sure SOC 2 is the right standard? How it compares with ISO 27001, which your buyers will ask for, and what each costs is in ISO 27001 vs SOC 2.
Quick answers
Is the SOC 2 audit included in Vanta, Drata or Secureframe?
Not on the pages we read. Vanta's own FAQ says "The audit is a separate engagement." Drata and Secureframe describe auditor partner networks and evidence tools, and don't say the audit fee is included. Budget the audit as its own bill and ask each vendor in writing.
Which compliance platform publishes its price?
Only Secureframe, which says its Fundamentals package starts at $7,500 a year. Vanta, Drata, Sprinto and Thoropass quote after a demo. Vendr's buyer data puts annual medians between $15,000 (Sprinto) and $25,000 (Drata and Thoropass).
Does Thoropass include the audit?
Thoropass says its audit is done by in-house auditors, and its footer names Thoropass Assurance as a licensed CPA firm. Whether that fee is inside the platform price isn't stated on the pages we read, so ask for platform and audit as separate line items.
Does Vanta integrate with Supabase and Vercel?
Yes. Vanta has dedicated integration pages for Supabase, Vercel and GitHub. Drata's directory lists Vercel and GitHub, and we did not see Supabase. None of the five lists Lovable where we could check.
Can a compliance platform issue my SOC 2 report?
No. The software collects evidence and flags gaps. A licensed CPA firm tests your controls and signs the opinion. Be wary of any report that arrives very cheaply or very fast, and check you can look up the auditor.
Is there a startup discount for any of these?
Vanta's page says it offers a free trial of typically five to seven days and startup-specific pricing on request. We found no startup program on the Drata, Secureframe, Sprinto or Thoropass pages we read, but that doesn't mean none exists. Ask.
The platform is a tool and the audit is a separate decision. Pick the one that fits your stack and your buyer's framework, get the price and renewal terms in writing, and keep the audit quote on its own line. The rest of the compliance map is on the Security & Compliance hub.
Use this in your own page
Teaching this? Paste the live version into your course, blog or answer. Free, no sign-up; the credit line links back here.