Thoropass Pricing and What the Audit Adds
Thoropass pricing starts at $8,700 a year for the platform plus $5,800 for a SOC 2 audit on AWS, and the median buyer pays $25,000. What moves your quote.
By the Scrutineer team
October 2026 · 8 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Thoropass pricing is quote-only on its website, but two list prices are public. Its AWS Marketplace listing sells the Compliance Platform from $8,700 per 12 months, including your first framework, and a SOC 2 Audit subscription from $5,800 per 12 months, billed separately. Vendr's February 2026 data puts the median buyer at $25,000 a year, with contracts from $1,145 to $50,880.
The difference between $14,500 and $25,000 is the useful part. It is made of extra frameworks, company size, onboarding and how the audit is scoped. This page puts every dated figure in one place, explains what each subscription covers, and lists the questions that move a Thoropass quote before you sign.
How much does Thoropass cost?
Thoropass costs about $25,000 a year for the median buyer, according to Vendr's February 2026 purchase data. The lowest published entry point is $14,500 a year on AWS Marketplace: $8,700 for the platform with one framework plus $5,800 for a SOC 2 audit. Thoropass's own pricing page shows no figures and routes every buyer to a tailored quote.
| Data point | Figure | Source and date | How to read it |
|---|---|---|---|
| Compliance Platform subscription | From $8,700 per 12 months, first framework included | Thoropass AWS Marketplace listing, read October 2026 | The software floor for one framework |
| SOC 2 Audit subscription | From $5,800 per 12 months | Thoropass AWS Marketplace listing, read October 2026 | The audit floor, billed as its own subscription |
| Platform plus SOC 2 audit | From $14,500 a year | Sum of the two listings | The cheapest published all-in starting point |
| Median annual contract | $25,000 | Vendr, February 2026 | What a typical buyer actually signs |
| Observed range | $1,145 to $50,880 | Vendr, February 2026 | The low end is likely an add-on or partial purchase, not a full program |
| Onboarding and implementation | $5,000 to $15,000, one time | Vendr buyer guidance, 2026 | A first-year cost outside the subscription |
The AWS listing also states that all fees are non-cancellable and non-refundable except where the law requires otherwise. That matters more on a bundled contract than on software alone, because the audit is prepaid with it.
What the two Thoropass subscriptions actually cover
Thoropass sells the software and the audit as two subscriptions that bill independently, and you need both for the connected workflow the company markets. The platform subscription covers readiness: policies, automated tests, evidence collection and your first framework. The audit subscription covers the attestation work itself, and on AWS it is listed specifically as a SOC 2 audit.
Three things follow from that structure. First, a second framework is not free. Adding ISO 27001, HIPAA or PCI DSS raises the platform line, and an ISO 27001 certification needs its own audit scope on top. Second, the audit price on the listing is a starting figure for SOC 2 only, and a Type 2 with a longer observation window or more systems in scope costs more. Third, you can buy the platform alone and use an outside CPA firm, which is how Vendr's guidance can list third-party auditor fees of $10,000 to $30,000 or more as a separate cost while Thoropass sells its own audit. Both are true; they describe different purchases.
Thoropass pricing by company size
Vendr publishes size bands for Thoropass. They are Vendr's estimates from purchase data, not Thoropass figures, so use them to sanity-check a quote rather than to anchor one.
| Company size | Scope | Vendr estimate per year |
|---|---|---|
| Under 50 employees | One framework | $20,000 to $45,000 |
| 50 to 200 employees | One or two frameworks | $40,000 to $80,000 |
| 50 to 200 employees | Several frameworks | $60,000 to $100,000 |
| Over 200 employees | Several frameworks | $80,000 to $150,000 or more |
Notice that the under-50 band starts above the $14,500 AWS floor. The gap is usually onboarding, a Type 2 audit rather than a Type 1, and more systems in scope than the starting price assumes.
What raises or lowers a Thoropass quote
Five things move the number. The count of frameworks you carry. The audit type and observation period. Headcount and the number of systems in scope, because both drive audit effort. Whether onboarding help is bundled. And contract length.
Vendr's 2026 guidance reports multi-year commitments earning discounts of 15 to 25 percent, competitive evaluations taking 20 to 30 percent off initial quotes, and renewals coming in 20 to 40 percent below the first year, mostly because implementation does not repeat. Treat these as ranges seen across buyers, not promises. The practical takeaway is that a first-year quote is the most negotiable number you will see, and a credible second quote from another vendor is the strongest lever you have.
Thoropass vs Scrutineer pricing
The two products are priced on different models, so compare them on what you would pay for the same scope. Scrutineer publishes its prices and sells software only; you choose and pay your auditor directly.
| Thoropass | Scrutineer | |
|---|---|---|
| Published price | No figures on its site; AWS listing from $8,700 platform plus $5,800 SOC 2 audit | Essentials $599 a month, Growth $1,200, Risk+ $2,500, on the pricing page |
| One framework, billed annually | From $8,700 a year for the platform | Essentials, $5,988 a year |
| Several frameworks | Each added framework raises the quote | Growth covers SOC 2, ISO 27001, HIPAA, GDPR and PCI DSS for $11,988 a year |
| Audit | Sold by Thoropass as its own subscription | Not included; you hire the CPA firm or certification body you want |
| Vendor risk management | Priced by quote | Risk+ adds third-party risk with unlimited vendor scoring for $24,996 a year |
| Security questionnaires | Priced by quote | Included from Growth, with no per-questionnaire fees |
Read the table honestly. If your priority is one vendor and one contract for both the software and the audit, Thoropass's bundle is a real advantage that a software-only price does not replicate, and you still have to pay an auditor on top of Scrutineer. If you carry more than one framework, need vendor risk in the same tool, or want your auditor chosen separately from your software vendor, the published plans are usually the cheaper and simpler path. Our Thoropass alternative comparison covers the feature side in more depth.
Is Thoropass worth it?
Thoropass is worth it for a first-time compliance team that wants readiness and the SOC 2 audit handled by one vendor on one timeline, and that would rather not run an auditor selection. That convenience is what the bundle sells, and it is a legitimate reason to pay for it.
It is a weaker fit in three situations. When a customer or board prefers an auditor with no commercial tie to the readiness software, which some enterprise procurement teams ask about. When you expect to add frameworks quickly, because each one raises the quote. And when your next problem is vendor risk rather than your own audit. If there is a chance you sell the company during a multi-year term, also check whether the contract assigns to a buyer, since acquirers of a small SaaS company review its compliance contracts alongside the verified revenue and churn metrics they are paying for.
Questions to ask before you sign a Thoropass quote
- Which frameworks does the platform line include, and what is the price of each one added later?
- Is the audit a SOC 2 Type 1 or Type 2, how long is the observation window, and which systems are in scope?
- Is onboarding included, and is it a one-time fee or part of the subscription?
- What is the renewal price, and is the annual increase capped in writing?
- If we move to an outside auditor in year two, what happens to the platform price?
- Can we see the auditor's independence arrangement in writing for our customers?
If you are still deciding between bundled and software-only models, our compliance automation software pricing comparison lays out what twelve platforms cost, and the SOC 2 audit cost breakdown shows what the audit alone runs when you buy it from a CPA firm. To see Scrutineer's numbers side by side, the pricing page lists every plan.
Scrutineer is compliance software for readiness and decision support. It does not issue SOC 2 reports or ISO 27001 certificates; an independent auditor does.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.