COMPLIANCE COST ANALYSIS / THE FILTER

What Compliance Actually Costs

Sourced cost data for SOC 2, ISO 27001, PCI-DSS, HIPAA, NIST 800-171/CMMC, GDPR, EU AI Act · 25 sources · Updated August 2026

Every framework on this site has a dollar amount attached. This page breaks down what businesses actually pay — for single-framework compliance, multi-framework compliance, and the required infrastructure services that make compliance possible. The numbers come from vendor pricing pages, industry surveys, and compliance cost reports. No estimates without citation.

The thesis is simple: compliance cost is a regressive tax. A SOC 2 audit costs roughly the same whether you have 10 employees or 1,000. For a small AI startup, that's 6-12% of revenue. For a large enterprise, it's rounding error. This is how the market filters out small players and concentrates AI among the few who can afford the overhead.

COST SUMMARY — All Frameworks at a Glance

Year 1 total cost per framework by business size. Tap any section below for full breakdown including audit fees, implementation, recurring costs, and AI impact analysis.

FrameworkSmall (1-50 emp)Medium (51-500)Large (500+)Annual Recurring (Small)
SOC 2 Type II$47K-$79K$84K-$170K$210K-$650K$30K-$50K
ISO 27001$39K-$74K$99K-$200K$290K-$750K$15K-$30K
PCI-DSS v4.0$28K-$63K$68K-$160K$200K-$760K$12K-$30K
HIPAA Security Rule$5.5K-$24.8K$36K-$114K$144K-$550K$1K-$5K
NIST 800-171 / CMMC$31K-$113K$109K-$335K$335K-$1.2M$15K-$50K
MULTI: SOC 2 + PCI-DSS$60K-$120K$130K-$280K$350K-$1.2M$35K-$65K
MULTI: HIPAA + SOC 2 + ISO$80K-$160K$170K-$380K$500K-$1.8M$40K-$90K
MULTI: NIST + CMMC + SOC 2$70K-$170K$180K-$450K$500K-$1.8M$35K-$90K
MULTI: GDPR + EU AI Act + ISO + SOC 2$120K-$250K$250K-$600K$700K-$2.5M$60K-$140K
As % of RevenueSmall ($2M rev)Medium ($50M rev)Large ($500M rev)
SOC 2 alone2.4-4.0%0.17-0.34%0.04-0.13%
Combo D (EU+US AI)6.0-12.5%0.50-1.20%0.14-0.50%
Business Size Definitions Tiers
TierEmployeesAnnual Revenue
Small Business1-50Under $10M
Medium Business51-500$10M-$250M
Large Enterprise500+$250M+
SCENARIO 1 — BASIC COMPLIANCE (Single Framework)
SOC 2 Type II SaaS / Cloud

The most common compliance framework for SaaS and cloud companies. Required by most enterprise procurement teams before they'll sign a contract. A SOC 2 Type II report covers security, availability, processing integrity, confidentiality, and privacy over a 3-12 month observation period.

Cost ComponentSmallMediumLarge
Audit Fee$20K-$30K$30K-$50K$50K-$150K
Implementation$15K-$25K$30K-$60K$100K-$300K
Compliance Software$12K-$24K/yr$24K-$60K/yr$60K-$200K/yr
Year 1 Total$47K-$79K$84K-$170K$210K-$650K
Annual Recurring$30K-$50K$50K-$100K$120K-$400K
AI IMPACT — THE FILTER
A small AI startup must spend $47K-$79K in Year 1 for SOC 2 — before building product, before hiring engineers, before generating revenue. For a $2M revenue startup, that's 2.4-4% of gross revenue on a single compliance framework. Large enterprises spend the same amount but it represents 0.01-0.03% of their revenue. The fixed cost is the filter.

Sources: Comp AI (2025), Secureframe (2025), The SOC 2 (2025), SOC2ComplianceCost (2026). Big Four audits (Deloitte, EY, PwC, KPMG) trend to the high end; boutique firms trend lower.

ISO/IEC 27001 International

The global standard for information security management systems. Certifiable by accredited bodies. Required by many international and European enterprise procurement processes. More comprehensive than SOC 2 — covers the entire ISMS, not just controls.

Cost ComponentSmallMediumLarge
Certification Body Fee$12K-$20K$35K-$60K$80K-$150K
Implementation$15K-$30K$40K-$80K$150K-$400K
Compliance Software$12K-$24K/yr$24K-$60K/yr$60K-$200K/yr
Year 1 Total$39K-$74K$99K-$200K$290K-$750K
Annual Recurring$15K-$30K$40K-$80K$100K-$300K
AI IMPACT — DUAL CERTIFICATION BURDEN
Many AI companies need BOTH SOC 2 (for US enterprise) and ISO 27001 (for international/European enterprise). The two share ~70% of controls, but each requires its own audit and certification body. A small AI company serving global markets pays $86K-$153K in Year 1 for both — more than most early-stage companies can absorb.

Sources: DPO Consulting (2024), High Table (2026). Certification body fees vary by accredited registrar (BSI, DNV, Bureau Veritas, TUV).

PCI-DSS v4.0 Card Payments

Required for any business that processes, stores, or transmits cardholder data. v4.0 added new requirements around authentication, encryption, and continuous monitoring. Compliance level depends on transaction volume — Level 1 (6M+ transactions/year) requires onsite QSA assessment; Level 2-4 may use self-assessment questionnaires (SAQs).

Cost ComponentSmallMediumLarge
QSA Audit Fee$15K-$25K$30K-$60K$80K-$200K
Implementation$10K-$30K$30K-$80K$100K-$500K
ASV Scanning$3K-$8K/yr$8K-$20K/yr$20K-$60K/yr
Year 1 Total$28K-$63K$68K-$160K$200K-$760K
Annual Recurring$12K-$30K$30K-$70K$100K-$300K
AI IMPACT — FRAUD DETECTION MANDATE
PCI-DSS doesn't explicitly require AI fraud detection, but processors effectively mandate it through chargeback ratios. A small e-commerce business using AI for fraud detection (Stripe Radar, included with processing) pays effectively $0 additional. A business self-hosting AI fraud detection pays $10K-$50K+ in ML engineering — a cost that favors processor-included AI over custom AI. The framework pushes small business toward managed AI services.

Sources: Thoropass (2025), PCI Security Standards Council. QSA rates from Lazarus Alliance and industry surveys.

HIPAA Security Rule Healthcare

Required for covered entities and business associates handling protected health information (PHI). Unlike SOC 2 or ISO 27001, HIPAA has no formal certification — compliance is self-attested with the risk of HHS OCR audits and fines up to $1.5M/year per violation category. The low entry cost masks the high cost of a breach.

Cost ComponentSmallMediumLarge
Risk Assessment$2K-$8K$10K-$30K$40K-$150K
Implementation$3K-$15K$20K-$60K$80K-$300K
Compliance Software$468-$1,800/yr$6K-$24K/yr$24K-$100K/yr
Year 1 Total$5.5K-$24.8K$36K-$114K$144K-$550K
Annual Recurring$1K-$5K$15K-$40K$60K-$200K
AI IMPACT — HEALTHCARE AI GATEKEEPING
HIPAA's low entry cost ($5.5K-$24.8K for small practices) makes it seem accessible — but AI in healthcare changes the math. AI training on PHI requires BAA agreements with cloud providers, data de-identification, and audit trail documentation that most small practices can't implement alone. The result: small practices must use cloud AI (Azure OpenAI, AWS HealthLake) rather than self-hosted AI, because only the cloud providers have the compliance infrastructure. HIPAA doesn't mandate cloud — but the cost of self-hosting HIPAA-compliant AI makes it the only practical option.

Sources: AccountableHQ (2026), HIPAABinder (2026), DefendMyBusiness (2025), Patient-Protect (2026). Low end = DIY with compliance software; high end = consultant-led.

NIST 800-171 / CMMC Defense Contractor

Required for DoD contractors handling Controlled Unclassified Information (CUI). NIST 800-171 has 110 security requirements. CMMC 2.0 is DoD's enforcement layer — Level 1 (self-assessment) for basic CUI, Level 2 (third-party C3PAO assessment) for most CUI. Phase II (third-party assessments) was suspended July 2026, but self-assessment requirements remain active.

Cost ComponentSmallMediumLarge
Assessment$5K-$15K$31K-$75K$75K-$200K
Implementation (110 controls)$20K-$80K$60K-$200K$200K-$800K
Monitoring Tools$6K-$18K/yr$18K-$60K/yr$60K-$200K/yr
Year 1 Total$31K-$113K$109K-$335K$335K-$1.2M
Annual Recurring$15K-$50K$40K-$120K$120K-$400K
AI IMPACT — CUI AI PROCESSING BARRIER
A small defense contractor wanting to use AI for CUI analysis (e.g., automated document classification, predictive maintenance) must implement all 110 controls plus CMMC assessment. The $31K-$113K Year 1 cost is on top of the AI infrastructure itself. FIPS-validated encryption requirements (3.13.11) restrict which AI platforms can be used — most consumer AI services don't qualify. This pushes contractors toward a small set of approved cloud AI providers (AWS GovCloud, Azure Government) that have pre-existing FedRAMP/CMMC authorizations — concentrating defense AI spending among a few providers.

Sources: LegalClarity (2025), DataVirtualizer (2026), Blumira (2025). DoD cost model: 3-person assessment team, 120 hours, ~$260/hr = ~$31K base. Per-employee scaling: $100-$200/in-scope employee.

SCENARIO 2 — MULTI-POLICY COMPLIANCE (Multiple Frameworks)
Combo A: SOC 2 + PCI-DSS SaaS + Payments

A SaaS company processing payments needs both SOC 2 (for enterprise sales) and PCI-DSS (for card processing). ~60% control overlap — access control, encryption, monitoring, and vulnerability management are shared. Running both via a unified compliance program saves ~20% versus separate efforts.

SmallMediumLarge
Year 1 Total$60K-$120K$130K-$280K$350K-$1.2M
Annual Recurring$35K-$65K$65K-$150K$180K-$600K
Realistic for size?Yes, with automationYes, compliance managerYes, full GRC team
AI IMPACT — PAYMENTS AI GATEKEEPING
A small SaaS company using AI for payment fraud detection must comply with both frameworks. The compliance cost ($60K-$120K) exceeds the cost of the AI itself (Stripe Radar is included with processing). The framework cost, not the AI cost, is the barrier. This favors payment processors with built-in compliance (Stripe, Adyen, Square) over custom payment infrastructure — the compliance overhead makes self-hosted payment AI uneconomical for small business.
Combo B: HIPAA + SOC 2 + ISO 27001 Healthtech Enterprise

A healthtech company serving enterprise customers needs all three: HIPAA (healthcare data), SOC 2 (US enterprise procurement), and ISO 27001 (international enterprise procurement). ~55% overlap across all three — risk assessment, access control, encryption, incident response, and BAAs are shared.

SmallMediumLarge
Year 1 Total$80K-$160K$170K-$380K$500K-$1.8M
Annual Recurring$40K-$90K$80K-$200K$250K-$800K
Realistic for size?Difficult — 0.5-1 FTE + consultantYes, 1-2 FTE teamYes, GRC department
AI IMPACT — HEALTHCARE AI CONSOLIDATION
A small healthtech startup building AI for clinical decision support must absorb $80K-$160K in Year 1 compliance costs. For a $3M revenue startup, that's 2.7-5.3% of revenue on compliance alone. The BAA requirement (HIPAA) forces AI training infrastructure onto HIPAA-compliant cloud platforms — Azure OpenAI, AWS HealthLake, GCP Healthcare. Self-hosted AI for PHI is technically possible but the compliance overhead of proving FIPS-validated encryption, audit trails, and BAAs for every infrastructure component makes it impractical. Healthcare AI consolidates to the three cloud providers who can afford the compliance infrastructure.
Combo C: NIST 800-171 + CMMC + SOC 2 Defense SaaS

A defense contractor building SaaS for government clients needs NIST 800-171 (CUI protection), CMMC (DoD enforcement layer), and SOC 2 (commercial sales). NIST 800-171 and CMMC share 100% of controls — CMMC is built on 800-171. SOC 2 adds the commercial audit layer. Combined overlap: ~65%.

SmallMediumLarge
Year 1 Total$70K-$170K$180K-$450K$500K-$1.8M
Annual Recurring$35K-$90K$80K-$220K$200K-$700K
Realistic for size?Difficult — dual track CUI + commercialYes, 2-3 FTE + C3PAOYes, defense compliance division
AI IMPACT — DEFENSE AI VENDOR LOCK-IN
A small defense contractor wanting to build AI tools for CUI analysis faces $70K-$170K Year 1 — on top of AI infrastructure costs. The FIPS-validated encryption requirement (SP 800-171 3.13.11) restricts AI platforms to those with FedRAMP authorization. In practice this means AWS GovCloud or Azure Government — the only two platforms with the required authorizations. A small contractor cannot build their own AI infrastructure on these platforms cost-effectively; they must use managed AI services from AWS or Azure. Defense AI is locked to two vendors by compliance design.
Combo D: GDPR + EU AI Act + ISO 27001 + SOC 2 AI Company EU + US

An AI company serving both EU and US enterprise markets needs all four: GDPR (EU data protection), EU AI Act (AI-specific compliance), ISO 27001 (international security), and SOC 2 (US enterprise). This is the most expensive combination — four frameworks with AI-specific regulatory requirements on top. ~50% overall overlap.

SmallMediumLarge
Year 1 Total$120K-$250K$250K-$600K$700K-$2.5M
Annual Recurring$60K-$140K$120K-$300K$350K-$1.2M
Realistic for size?Very difficult — most cannot afford thisYes, 3-4 FTE + external DPOYes, legal + compliance + AI governance
AI IMPACT — THE KILLER COMBINATION
This is the combination that kills small AI companies. A startup building AI for EU + US enterprise markets must spend $120K-$250K in Year 1 on compliance — 6-12.5% of gross revenue for a $2M startup. The EU AI Act adds conformity assessment, risk management system, and technical documentation requirements that no existing compliance framework covers. GDPR requires a Data Protection Officer ($40K-$150K/yr per Vanta). ISO 27001 and SOC 2 each require separate audits. Most small AI startups cannot afford this combination — they either serve only one market (losing half their addressable market), get acquired by a larger company with existing compliance, or exit. The compliance cost is the market concentration mechanism in action.
REQUIRED SERVICES — The Infrastructure of Compliance

Compliance frameworks require specific infrastructure: backup, monitoring, vulnerability scanning, pen testing, IAM, encryption, incident response, and compliance management software. These are the real costs behind the compliance line items above.

AI for Credit Card Fraud Detection Service
OptionSmallMediumLarge
Processor-included (Stripe Radar, Square)$0 (included)$0.08/txnNegotiated
Enterprise platform (Featurespace, NICE)N/AN/A$100K-$500K/yr
Self-hosted ML$10K-$50K$50K-$200K$500K-$2M+

Self-hosted feasible? Small: No (included with processor). Medium: Possible but not cost-effective. Large: Yes, if transaction volume justifies ML team.

Compliance requirement: PCI-DSS v4.0 Req 6 requires vulnerability scanning. AI fraud detection is not required by PCI but is de facto required by processors to manage chargeback risk.

AI IMPACT
The economics push every business toward processor-included AI. Self-hosted fraud AI costs 100-1000x more than Stripe Radar's included service. Compliance frameworks don't mandate processor-included AI, but the cost structure makes it the only rational choice — concentrating AI fraud detection among payment processors.
Backup & Disaster Recovery Service
OptionSmallMediumLarge
Veeam$150-$450/mo$500-$2K/mo$5K-$20K/mo
Druva (SaaS)$200-$600/mo$1K-$5K/mo$5K-$30K/mo
AWS Backup$50-$200/mo$500-$3K/mo$3K-$15K/mo
Self-hosted (rsync)$0-$100/moDoes NOT meet audit requirements without policy documentation

Compliance requirement: SOC 2 CC9.1, HIPAA 164.308(a)(7), PCI-DSS Req 3, ISO 27001 A.12.3 all require backup and recovery. Self-hosted accepted IF documented and tested.

SIEM / Log Management Service
OptionSmallMediumLarge
Splunk$1.5K-$3K/mo$5K-$15K/mo$20K-$100K+/mo
Azure Sentinel$1K-$3K/mo$3K-$10K/mo$10K-$50K+/mo
ELK (self-hosted)$200-$500/mo$1K-$3K/mo$5K-$20K/mo
Graylog (open source)$0-$300/mo$500-$1K/mo$2K-$8K/mo

Self-hosted feasible? Small: Yes (ELK/Graylog). Medium: Yes, needs 0.5 FTE. Large: Yes, needs 2+ FTE. All frameworks accept self-hosted.

Compliance requirement: SOC 2 CC7.2, PCI-DSS Req 10, HIPAA 164.312(b), ISO 27001 A.12.4, NIST 800-171 3.3 all require log monitoring. Self-hosted accepted.

AI IMPACT
Splunk's per-GB pricing model ($1,500-$2,000/GB at low volume) makes it prohibitively expensive for small businesses generating significant log data — which AI workloads produce in volume. ELK self-hosted is the cost-effective alternative, but requires Linux expertise most small businesses don't have. The result: small AI companies either pay Splunk's premium or skip SIEM (non-compliance risk). Medium/large companies absorb the cost.
Vulnerability Scanning Service
OptionSmallMediumLarge
Nessus Professional$4K-$6K/yr$10K-$30K/yr$30K-$100K/yr
Qualys$2K-$5K/yr$10K-$25K/yr$30K-$100K/yr
OpenVAS (open source)$0 + server$1K-$3K/yr$5K-$15K/yr

Self-hosted feasible? Yes at all sizes. OpenVAS is free but requires maintenance time. All frameworks accept self-hosted scanning.

Compliance requirement: PCI-DSS Req 11.2-11.3, SOC 2 CC7.1, ISO 27001 A.12.6, NIST 800-171 3.11.2. PCI requires ASV-certified scanning for external.

Penetration Testing (Annual) Service
ScopeSmallMediumLarge
External pen test$5K-$10K$15K-$35K$50K-$100K
External + internal$10K-$15K$20K-$50K$80K-$200K
Comprehensive + red team$15K+$35K-$50K$100K-$200K+

Self-hosted feasible? Not recommended — pen testing should be done by independent third party for audit acceptance. Most frameworks require independence.

Compliance requirement: PCI-DSS Req 11.4 (annual + after changes), SOC 2 CC4.1, ISO 27001 A.12.6.1, NIST 800-171 3.11.3. Must be third-party.

Sources: QualySec (2025), CompassITC (2025), Uproot Security (2025).

Security Awareness Training Service
OptionSmall (50 users)Medium (500)Large (2000)
KnowBe4$1.8K/yr$18K-$30K/yr$72K-$120K/yr
SANS$40K-$75K/yr$400K-$750K/yrN/A (use KnowBe4)
Free (CISA/SANS Ouch + docs)$0$0 + staff time$0 + dedicated trainer

Self-hosted feasible? Small: Yes (free CISA/SANS resources + documentation). All frameworks accept self-hosted IF documented.

Compliance requirement: PCI-DSS Req 12.6, HIPAA 164.308(a)(5), ISO 27001 A.7.2.2, NIST 800-171 3.2.

Source: NTI Now (2025) — KnowBe4 pricing starts at $3/user/month.

Identity & Access Management Service
OptionSmallMediumLarge
Okta$1.2K-$2.4K/yr$24K-$48K/yr$48K-$288K/yr
Azure AD (Entra ID) P1/P2$3.6K/yr$54K/yr$108K+/yr
Self-hosted (FreeIPA/OpenLDAP)$500-$2K/yr$5K-$15K/yr$20K-$60K/yr

Self-hosted feasible? Small: Yes (FreeIPA). Medium: Possible but maintenance burden. Large: Yes if dedicated IAM team. All frameworks accept self-hosted.

Compliance requirement: SOC 2 CC6.1-6.3, PCI-DSS Req 7-8, HIPAA 164.312(a)(1), ISO 27001 A.9, NIST 800-171 3.5. MFA required by most frameworks.

Encryption & Key Management Service
OptionSmallMediumLarge
AWS KMS<$50/mo$200-$1K/mo$1K-$10K/mo
HashiCorp Vault (open source)$0-$300/mo$1K-$5K/mo$5K-$20K/mo
Enterprise HSMN/AN/A$10K-$30K/mo

Self-hosted feasible? Yes at all sizes (Vault open source). NIST 800-171 requires FIPS-validated crypto — restricts which self-hosted solutions qualify.

Compliance requirement: PCI-DSS Req 3, HIPAA 164.312(a)(2)(iv), SOC 2 CC6.7, ISO 27001 A.10, NIST 800-171 3.13. NIST 800-171 specifically requires FIPS-validated encryption.

Monitoring & Incident Response Service
OptionSmallMediumLarge
MSSP (co-managed)$2K-$3.5K/mo$7K-$15K/mo$15K-$50K+/mo
In-house SOCNot feasible$200K-$400K/yr$500K-$2M+/yr

Self-hosted feasible? Small: No (staffing). Medium: Possible with 2-3 FTE. Large: Yes, standard. MSSP or in-house both accepted by all frameworks.

Compliance requirement: SOC 2 CC7.3-7.4, PCI-DSS Req 12.10, HIPAA 164.308(a)(6), ISO 27001 A.16, NIST 800-171 3.6. Incident response capability required.

Source: CorsicaTech (2025) — MSSP clients typically pay $5K-$20K/month.

Compliance Automation Software Service
PlatformSmallMediumLarge
Vanta$8K-$15K/yr$20K-$50K/yrEnterprise pricing
Drata$10K-$24K/yr$24K-$60K/yrEnterprise pricing
Secureframe$8K-$18K/yr$18K-$40K/yrEnterprise pricing
Sprinto$5K-$12K/yr$12K-$30K/yrEnterprise pricing
Enterprise GRC (ServiceNow, AuditBoard)N/AN/A$80K-$200K/yr
Spreadsheets (DIY)$0$0 + 100+ hrsNot practical

Self-hosted feasible? Spreadsheets work for 1 framework but not multi-framework compliance. Not explicitly required by any framework, but dramatically reduces implementation and ongoing audit prep costs.

Sources: SOC2ComplianceCost (2026), vendor pricing pages. AWS Marketplace list prices verified July 2026.

THE FILTER — How Compliance Cost Concentrates the AI Market
The Regressive Tax of Compliance Analysis
ScenarioSmall ($2M rev)% of RevenueLarge ($500M rev)% of Revenue
SOC 2 alone (Year 1)$47K-$79K2.4-4.0%$210K-$650K0.04-0.13%
Combo D: EU+US AI (Year 1)$120K-$250K6.0-12.5%$700K-$2.5M0.14-0.50%
Combo D: Annual Recurring$60K-$140K3.0-7.0%$350K-$1.2M0.07-0.24%
AI IMPACT — THE CONCENTRATION MECHANISM

1. Large enterprises lobby for compliance frameworks (SOC 2, ISO 27001, FedRAMP, CMMC) as industry standards.

2. These frameworks become procurement requirements — you cannot sell without them.

3. The cost of compliance is fixed regardless of company size — a SOC 2 audit costs roughly the same for a 10-person startup as a 100-person company.

4. Small businesses spend 6-12% of revenue on compliance. Large enterprises spend 0.14-0.5%.

5. The fixed cost acts as a regressive tax — it disproportionately burdens smaller companies.

6. Small companies exit the market, are acquired, or never enter. The market consolidates.

7. AI amplifies this: AI-specific frameworks (EU AI Act, NIST AI RMF, ISO 42001) add new compliance layers on top of existing ones.

8. The "voluntary" frameworks (NIST AI RMF, SAFE RFC) become procurement requirements, adding cost without reducing it.

9. The result: AI markets consolidate to a handful of large providers who can afford the compliance overhead. Innovation narrows to what those providers choose to build.

Cost data from 25 sources including Comp AI (2025), Secureframe (2025), DPO Consulting (2024), Thoropass (2025), LegalClarity (2025), AccountableHQ (2026), HIPAABinder (2026), DefendMyBusiness (2025), Legiscope (2026), Vanta (2025), SIEMCostCalculator (2026), CostBench (2026), CorsicaTech (2025), QualySec (2025), SOC2ComplianceCost (2026), CyberSecManager (2025), NTI Now (2025), IBM/Ponemon (2024).

Cross-References Links

Framework pages with full text and AI impact annotations:

SOC 2 · ISO 27001 · PCI-DSS v4.0 · HIPAA · NIST 800-171 · CMMC 2.0 · GDPR · EU AI Act · NIST AI RMF · ISO 42001

Investigation tracks:

The Compliance Trap · The Asymmetry · The Narrative