Every framework on this site has a dollar amount attached. This page breaks down what businesses actually pay — for single-framework compliance, multi-framework compliance, and the required infrastructure services that make compliance possible. The numbers come from vendor pricing pages, industry surveys, and compliance cost reports. No estimates without citation.
The thesis is simple: compliance cost is a regressive tax. A SOC 2 audit costs roughly the same whether you have 10 employees or 1,000. For a small AI startup, that's 6-12% of revenue. For a large enterprise, it's rounding error. This is how the market filters out small players and concentrates AI among the few who can afford the overhead.
Year 1 total cost per framework by business size. Tap any section below for full breakdown including audit fees, implementation, recurring costs, and AI impact analysis.
| Framework | Small (1-50 emp) | Medium (51-500) | Large (500+) | Annual Recurring (Small) |
|---|---|---|---|---|
| SOC 2 Type II | $47K-$79K | $84K-$170K | $210K-$650K | $30K-$50K |
| ISO 27001 | $39K-$74K | $99K-$200K | $290K-$750K | $15K-$30K |
| PCI-DSS v4.0 | $28K-$63K | $68K-$160K | $200K-$760K | $12K-$30K |
| HIPAA Security Rule | $5.5K-$24.8K | $36K-$114K | $144K-$550K | $1K-$5K |
| NIST 800-171 / CMMC | $31K-$113K | $109K-$335K | $335K-$1.2M | $15K-$50K |
| MULTI: SOC 2 + PCI-DSS | $60K-$120K | $130K-$280K | $350K-$1.2M | $35K-$65K |
| MULTI: HIPAA + SOC 2 + ISO | $80K-$160K | $170K-$380K | $500K-$1.8M | $40K-$90K |
| MULTI: NIST + CMMC + SOC 2 | $70K-$170K | $180K-$450K | $500K-$1.8M | $35K-$90K |
| MULTI: GDPR + EU AI Act + ISO + SOC 2 | $120K-$250K | $250K-$600K | $700K-$2.5M | $60K-$140K |
| As % of Revenue | Small ($2M rev) | Medium ($50M rev) | Large ($500M rev) |
|---|---|---|---|
| SOC 2 alone | 2.4-4.0% | 0.17-0.34% | 0.04-0.13% |
| Combo D (EU+US AI) | 6.0-12.5% | 0.50-1.20% | 0.14-0.50% |
| Tier | Employees | Annual Revenue |
|---|---|---|
| Small Business | 1-50 | Under $10M |
| Medium Business | 51-500 | $10M-$250M |
| Large Enterprise | 500+ | $250M+ |
The most common compliance framework for SaaS and cloud companies. Required by most enterprise procurement teams before they'll sign a contract. A SOC 2 Type II report covers security, availability, processing integrity, confidentiality, and privacy over a 3-12 month observation period.
| Cost Component | Small | Medium | Large |
|---|---|---|---|
| Audit Fee | $20K-$30K | $30K-$50K | $50K-$150K |
| Implementation | $15K-$25K | $30K-$60K | $100K-$300K |
| Compliance Software | $12K-$24K/yr | $24K-$60K/yr | $60K-$200K/yr |
| Year 1 Total | $47K-$79K | $84K-$170K | $210K-$650K |
| Annual Recurring | $30K-$50K | $50K-$100K | $120K-$400K |
Sources: Comp AI (2025), Secureframe (2025), The SOC 2 (2025), SOC2ComplianceCost (2026). Big Four audits (Deloitte, EY, PwC, KPMG) trend to the high end; boutique firms trend lower.
The global standard for information security management systems. Certifiable by accredited bodies. Required by many international and European enterprise procurement processes. More comprehensive than SOC 2 — covers the entire ISMS, not just controls.
| Cost Component | Small | Medium | Large |
|---|---|---|---|
| Certification Body Fee | $12K-$20K | $35K-$60K | $80K-$150K |
| Implementation | $15K-$30K | $40K-$80K | $150K-$400K |
| Compliance Software | $12K-$24K/yr | $24K-$60K/yr | $60K-$200K/yr |
| Year 1 Total | $39K-$74K | $99K-$200K | $290K-$750K |
| Annual Recurring | $15K-$30K | $40K-$80K | $100K-$300K |
Sources: DPO Consulting (2024), High Table (2026). Certification body fees vary by accredited registrar (BSI, DNV, Bureau Veritas, TUV).
Required for any business that processes, stores, or transmits cardholder data. v4.0 added new requirements around authentication, encryption, and continuous monitoring. Compliance level depends on transaction volume — Level 1 (6M+ transactions/year) requires onsite QSA assessment; Level 2-4 may use self-assessment questionnaires (SAQs).
| Cost Component | Small | Medium | Large |
|---|---|---|---|
| QSA Audit Fee | $15K-$25K | $30K-$60K | $80K-$200K |
| Implementation | $10K-$30K | $30K-$80K | $100K-$500K |
| ASV Scanning | $3K-$8K/yr | $8K-$20K/yr | $20K-$60K/yr |
| Year 1 Total | $28K-$63K | $68K-$160K | $200K-$760K |
| Annual Recurring | $12K-$30K | $30K-$70K | $100K-$300K |
Sources: Thoropass (2025), PCI Security Standards Council. QSA rates from Lazarus Alliance and industry surveys.
Required for covered entities and business associates handling protected health information (PHI). Unlike SOC 2 or ISO 27001, HIPAA has no formal certification — compliance is self-attested with the risk of HHS OCR audits and fines up to $1.5M/year per violation category. The low entry cost masks the high cost of a breach.
| Cost Component | Small | Medium | Large |
|---|---|---|---|
| Risk Assessment | $2K-$8K | $10K-$30K | $40K-$150K |
| Implementation | $3K-$15K | $20K-$60K | $80K-$300K |
| Compliance Software | $468-$1,800/yr | $6K-$24K/yr | $24K-$100K/yr |
| Year 1 Total | $5.5K-$24.8K | $36K-$114K | $144K-$550K |
| Annual Recurring | $1K-$5K | $15K-$40K | $60K-$200K |
Sources: AccountableHQ (2026), HIPAABinder (2026), DefendMyBusiness (2025), Patient-Protect (2026). Low end = DIY with compliance software; high end = consultant-led.
Required for DoD contractors handling Controlled Unclassified Information (CUI). NIST 800-171 has 110 security requirements. CMMC 2.0 is DoD's enforcement layer — Level 1 (self-assessment) for basic CUI, Level 2 (third-party C3PAO assessment) for most CUI. Phase II (third-party assessments) was suspended July 2026, but self-assessment requirements remain active.
| Cost Component | Small | Medium | Large |
|---|---|---|---|
| Assessment | $5K-$15K | $31K-$75K | $75K-$200K |
| Implementation (110 controls) | $20K-$80K | $60K-$200K | $200K-$800K |
| Monitoring Tools | $6K-$18K/yr | $18K-$60K/yr | $60K-$200K/yr |
| Year 1 Total | $31K-$113K | $109K-$335K | $335K-$1.2M |
| Annual Recurring | $15K-$50K | $40K-$120K | $120K-$400K |
Sources: LegalClarity (2025), DataVirtualizer (2026), Blumira (2025). DoD cost model: 3-person assessment team, 120 hours, ~$260/hr = ~$31K base. Per-employee scaling: $100-$200/in-scope employee.
A SaaS company processing payments needs both SOC 2 (for enterprise sales) and PCI-DSS (for card processing). ~60% control overlap — access control, encryption, monitoring, and vulnerability management are shared. Running both via a unified compliance program saves ~20% versus separate efforts.
| Small | Medium | Large | |
|---|---|---|---|
| Year 1 Total | $60K-$120K | $130K-$280K | $350K-$1.2M |
| Annual Recurring | $35K-$65K | $65K-$150K | $180K-$600K |
| Realistic for size? | Yes, with automation | Yes, compliance manager | Yes, full GRC team |
A healthtech company serving enterprise customers needs all three: HIPAA (healthcare data), SOC 2 (US enterprise procurement), and ISO 27001 (international enterprise procurement). ~55% overlap across all three — risk assessment, access control, encryption, incident response, and BAAs are shared.
| Small | Medium | Large | |
|---|---|---|---|
| Year 1 Total | $80K-$160K | $170K-$380K | $500K-$1.8M |
| Annual Recurring | $40K-$90K | $80K-$200K | $250K-$800K |
| Realistic for size? | Difficult — 0.5-1 FTE + consultant | Yes, 1-2 FTE team | Yes, GRC department |
A defense contractor building SaaS for government clients needs NIST 800-171 (CUI protection), CMMC (DoD enforcement layer), and SOC 2 (commercial sales). NIST 800-171 and CMMC share 100% of controls — CMMC is built on 800-171. SOC 2 adds the commercial audit layer. Combined overlap: ~65%.
| Small | Medium | Large | |
|---|---|---|---|
| Year 1 Total | $70K-$170K | $180K-$450K | $500K-$1.8M |
| Annual Recurring | $35K-$90K | $80K-$220K | $200K-$700K |
| Realistic for size? | Difficult — dual track CUI + commercial | Yes, 2-3 FTE + C3PAO | Yes, defense compliance division |
An AI company serving both EU and US enterprise markets needs all four: GDPR (EU data protection), EU AI Act (AI-specific compliance), ISO 27001 (international security), and SOC 2 (US enterprise). This is the most expensive combination — four frameworks with AI-specific regulatory requirements on top. ~50% overall overlap.
| Small | Medium | Large | |
|---|---|---|---|
| Year 1 Total | $120K-$250K | $250K-$600K | $700K-$2.5M |
| Annual Recurring | $60K-$140K | $120K-$300K | $350K-$1.2M |
| Realistic for size? | Very difficult — most cannot afford this | Yes, 3-4 FTE + external DPO | Yes, legal + compliance + AI governance |
Compliance frameworks require specific infrastructure: backup, monitoring, vulnerability scanning, pen testing, IAM, encryption, incident response, and compliance management software. These are the real costs behind the compliance line items above.
| Option | Small | Medium | Large |
|---|---|---|---|
| Processor-included (Stripe Radar, Square) | $0 (included) | $0.08/txn | Negotiated |
| Enterprise platform (Featurespace, NICE) | N/A | N/A | $100K-$500K/yr |
| Self-hosted ML | $10K-$50K | $50K-$200K | $500K-$2M+ |
Self-hosted feasible? Small: No (included with processor). Medium: Possible but not cost-effective. Large: Yes, if transaction volume justifies ML team.
Compliance requirement: PCI-DSS v4.0 Req 6 requires vulnerability scanning. AI fraud detection is not required by PCI but is de facto required by processors to manage chargeback risk.
| Option | Small | Medium | Large |
|---|---|---|---|
| Veeam | $150-$450/mo | $500-$2K/mo | $5K-$20K/mo |
| Druva (SaaS) | $200-$600/mo | $1K-$5K/mo | $5K-$30K/mo |
| AWS Backup | $50-$200/mo | $500-$3K/mo | $3K-$15K/mo |
| Self-hosted (rsync) | $0-$100/mo | Does NOT meet audit requirements without policy documentation | |
Compliance requirement: SOC 2 CC9.1, HIPAA 164.308(a)(7), PCI-DSS Req 3, ISO 27001 A.12.3 all require backup and recovery. Self-hosted accepted IF documented and tested.
| Option | Small | Medium | Large |
|---|---|---|---|
| Splunk | $1.5K-$3K/mo | $5K-$15K/mo | $20K-$100K+/mo |
| Azure Sentinel | $1K-$3K/mo | $3K-$10K/mo | $10K-$50K+/mo |
| ELK (self-hosted) | $200-$500/mo | $1K-$3K/mo | $5K-$20K/mo |
| Graylog (open source) | $0-$300/mo | $500-$1K/mo | $2K-$8K/mo |
Self-hosted feasible? Small: Yes (ELK/Graylog). Medium: Yes, needs 0.5 FTE. Large: Yes, needs 2+ FTE. All frameworks accept self-hosted.
Compliance requirement: SOC 2 CC7.2, PCI-DSS Req 10, HIPAA 164.312(b), ISO 27001 A.12.4, NIST 800-171 3.3 all require log monitoring. Self-hosted accepted.
| Option | Small | Medium | Large |
|---|---|---|---|
| Nessus Professional | $4K-$6K/yr | $10K-$30K/yr | $30K-$100K/yr |
| Qualys | $2K-$5K/yr | $10K-$25K/yr | $30K-$100K/yr |
| OpenVAS (open source) | $0 + server | $1K-$3K/yr | $5K-$15K/yr |
Self-hosted feasible? Yes at all sizes. OpenVAS is free but requires maintenance time. All frameworks accept self-hosted scanning.
Compliance requirement: PCI-DSS Req 11.2-11.3, SOC 2 CC7.1, ISO 27001 A.12.6, NIST 800-171 3.11.2. PCI requires ASV-certified scanning for external.
| Scope | Small | Medium | Large |
|---|---|---|---|
| External pen test | $5K-$10K | $15K-$35K | $50K-$100K |
| External + internal | $10K-$15K | $20K-$50K | $80K-$200K |
| Comprehensive + red team | $15K+ | $35K-$50K | $100K-$200K+ |
Self-hosted feasible? Not recommended — pen testing should be done by independent third party for audit acceptance. Most frameworks require independence.
Compliance requirement: PCI-DSS Req 11.4 (annual + after changes), SOC 2 CC4.1, ISO 27001 A.12.6.1, NIST 800-171 3.11.3. Must be third-party.
Sources: QualySec (2025), CompassITC (2025), Uproot Security (2025).
| Option | Small (50 users) | Medium (500) | Large (2000) |
|---|---|---|---|
| KnowBe4 | $1.8K/yr | $18K-$30K/yr | $72K-$120K/yr |
| SANS | $40K-$75K/yr | $400K-$750K/yr | N/A (use KnowBe4) |
| Free (CISA/SANS Ouch + docs) | $0 | $0 + staff time | $0 + dedicated trainer |
Self-hosted feasible? Small: Yes (free CISA/SANS resources + documentation). All frameworks accept self-hosted IF documented.
Compliance requirement: PCI-DSS Req 12.6, HIPAA 164.308(a)(5), ISO 27001 A.7.2.2, NIST 800-171 3.2.
Source: NTI Now (2025) — KnowBe4 pricing starts at $3/user/month.
| Option | Small | Medium | Large |
|---|---|---|---|
| Okta | $1.2K-$2.4K/yr | $24K-$48K/yr | $48K-$288K/yr |
| Azure AD (Entra ID) P1/P2 | $3.6K/yr | $54K/yr | $108K+/yr |
| Self-hosted (FreeIPA/OpenLDAP) | $500-$2K/yr | $5K-$15K/yr | $20K-$60K/yr |
Self-hosted feasible? Small: Yes (FreeIPA). Medium: Possible but maintenance burden. Large: Yes if dedicated IAM team. All frameworks accept self-hosted.
Compliance requirement: SOC 2 CC6.1-6.3, PCI-DSS Req 7-8, HIPAA 164.312(a)(1), ISO 27001 A.9, NIST 800-171 3.5. MFA required by most frameworks.
| Option | Small | Medium | Large |
|---|---|---|---|
| AWS KMS | <$50/mo | $200-$1K/mo | $1K-$10K/mo |
| HashiCorp Vault (open source) | $0-$300/mo | $1K-$5K/mo | $5K-$20K/mo |
| Enterprise HSM | N/A | N/A | $10K-$30K/mo |
Self-hosted feasible? Yes at all sizes (Vault open source). NIST 800-171 requires FIPS-validated crypto — restricts which self-hosted solutions qualify.
Compliance requirement: PCI-DSS Req 3, HIPAA 164.312(a)(2)(iv), SOC 2 CC6.7, ISO 27001 A.10, NIST 800-171 3.13. NIST 800-171 specifically requires FIPS-validated encryption.
| Option | Small | Medium | Large |
|---|---|---|---|
| MSSP (co-managed) | $2K-$3.5K/mo | $7K-$15K/mo | $15K-$50K+/mo |
| In-house SOC | Not feasible | $200K-$400K/yr | $500K-$2M+/yr |
Self-hosted feasible? Small: No (staffing). Medium: Possible with 2-3 FTE. Large: Yes, standard. MSSP or in-house both accepted by all frameworks.
Compliance requirement: SOC 2 CC7.3-7.4, PCI-DSS Req 12.10, HIPAA 164.308(a)(6), ISO 27001 A.16, NIST 800-171 3.6. Incident response capability required.
Source: CorsicaTech (2025) — MSSP clients typically pay $5K-$20K/month.
| Platform | Small | Medium | Large |
|---|---|---|---|
| Vanta | $8K-$15K/yr | $20K-$50K/yr | Enterprise pricing |
| Drata | $10K-$24K/yr | $24K-$60K/yr | Enterprise pricing |
| Secureframe | $8K-$18K/yr | $18K-$40K/yr | Enterprise pricing |
| Sprinto | $5K-$12K/yr | $12K-$30K/yr | Enterprise pricing |
| Enterprise GRC (ServiceNow, AuditBoard) | N/A | N/A | $80K-$200K/yr |
| Spreadsheets (DIY) | $0 | $0 + 100+ hrs | Not practical |
Self-hosted feasible? Spreadsheets work for 1 framework but not multi-framework compliance. Not explicitly required by any framework, but dramatically reduces implementation and ongoing audit prep costs.
Sources: SOC2ComplianceCost (2026), vendor pricing pages. AWS Marketplace list prices verified July 2026.
| Scenario | Small ($2M rev) | % of Revenue | Large ($500M rev) | % of Revenue |
|---|---|---|---|---|
| SOC 2 alone (Year 1) | $47K-$79K | 2.4-4.0% | $210K-$650K | 0.04-0.13% |
| Combo D: EU+US AI (Year 1) | $120K-$250K | 6.0-12.5% | $700K-$2.5M | 0.14-0.50% |
| Combo D: Annual Recurring | $60K-$140K | 3.0-7.0% | $350K-$1.2M | 0.07-0.24% |
1. Large enterprises lobby for compliance frameworks (SOC 2, ISO 27001, FedRAMP, CMMC) as industry standards.
2. These frameworks become procurement requirements — you cannot sell without them.
3. The cost of compliance is fixed regardless of company size — a SOC 2 audit costs roughly the same for a 10-person startup as a 100-person company.
4. Small businesses spend 6-12% of revenue on compliance. Large enterprises spend 0.14-0.5%.
5. The fixed cost acts as a regressive tax — it disproportionately burdens smaller companies.
6. Small companies exit the market, are acquired, or never enter. The market consolidates.
7. AI amplifies this: AI-specific frameworks (EU AI Act, NIST AI RMF, ISO 42001) add new compliance layers on top of existing ones.
8. The "voluntary" frameworks (NIST AI RMF, SAFE RFC) become procurement requirements, adding cost without reducing it.
9. The result: AI markets consolidate to a handful of large providers who can afford the compliance overhead. Innovation narrows to what those providers choose to build.
Cost data from 25 sources including Comp AI (2025), Secureframe (2025), DPO Consulting (2024), Thoropass (2025), LegalClarity (2025), AccountableHQ (2026), HIPAABinder (2026), DefendMyBusiness (2025), Legiscope (2026), Vanta (2025), SIEMCostCalculator (2026), CostBench (2026), CorsicaTech (2025), QualySec (2025), SOC2ComplianceCost (2026), CyberSecManager (2025), NTI Now (2025), IBM/Ponemon (2024).
Framework pages with full text and AI impact annotations:
SOC 2 · ISO 27001 · PCI-DSS v4.0 · HIPAA · NIST 800-171 · CMMC 2.0 · GDPR · EU AI Act · NIST AI RMF · ISO 42001
Investigation tracks: