Scrutineer.ai
All posts
Comparison

Thoropass Pricing and What the Audit Adds

Thoropass pricing starts at $8,700 a year for the platform plus $5,800 for a SOC 2 audit on AWS, and the median buyer pays $25,000. What moves your quote.

By the Scrutineer team

October 2026 · 8 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

Thoropass pricing is quote-only on its website, but two list prices are public. Its AWS Marketplace listing sells the Compliance Platform from $8,700 per 12 months, including your first framework, and a SOC 2 Audit subscription from $5,800 per 12 months, billed separately. Vendr's February 2026 data puts the median buyer at $25,000 a year, with contracts from $1,145 to $50,880.

The difference between $14,500 and $25,000 is the useful part. It is made of extra frameworks, company size, onboarding and how the audit is scoped. This page puts every dated figure in one place, explains what each subscription covers, and lists the questions that move a Thoropass quote before you sign.

How much does Thoropass cost?

Thoropass costs about $25,000 a year for the median buyer, according to Vendr's February 2026 purchase data. The lowest published entry point is $14,500 a year on AWS Marketplace: $8,700 for the platform with one framework plus $5,800 for a SOC 2 audit. Thoropass's own pricing page shows no figures and routes every buyer to a tailored quote.

Data pointFigureSource and dateHow to read it
Compliance Platform subscriptionFrom $8,700 per 12 months, first framework includedThoropass AWS Marketplace listing, read October 2026The software floor for one framework
SOC 2 Audit subscriptionFrom $5,800 per 12 monthsThoropass AWS Marketplace listing, read October 2026The audit floor, billed as its own subscription
Platform plus SOC 2 auditFrom $14,500 a yearSum of the two listingsThe cheapest published all-in starting point
Median annual contract$25,000Vendr, February 2026What a typical buyer actually signs
Observed range$1,145 to $50,880Vendr, February 2026The low end is likely an add-on or partial purchase, not a full program
Onboarding and implementation$5,000 to $15,000, one timeVendr buyer guidance, 2026A first-year cost outside the subscription

The AWS listing also states that all fees are non-cancellable and non-refundable except where the law requires otherwise. That matters more on a bundled contract than on software alone, because the audit is prepaid with it.

What the two Thoropass subscriptions actually cover

Thoropass sells the software and the audit as two subscriptions that bill independently, and you need both for the connected workflow the company markets. The platform subscription covers readiness: policies, automated tests, evidence collection and your first framework. The audit subscription covers the attestation work itself, and on AWS it is listed specifically as a SOC 2 audit.

Three things follow from that structure. First, a second framework is not free. Adding ISO 27001, HIPAA or PCI DSS raises the platform line, and an ISO 27001 certification needs its own audit scope on top. Second, the audit price on the listing is a starting figure for SOC 2 only, and a Type 2 with a longer observation window or more systems in scope costs more. Third, you can buy the platform alone and use an outside CPA firm, which is how Vendr's guidance can list third-party auditor fees of $10,000 to $30,000 or more as a separate cost while Thoropass sells its own audit. Both are true; they describe different purchases.

Thoropass pricing by company size

Vendr publishes size bands for Thoropass. They are Vendr's estimates from purchase data, not Thoropass figures, so use them to sanity-check a quote rather than to anchor one.

Company sizeScopeVendr estimate per year
Under 50 employeesOne framework$20,000 to $45,000
50 to 200 employeesOne or two frameworks$40,000 to $80,000
50 to 200 employeesSeveral frameworks$60,000 to $100,000
Over 200 employeesSeveral frameworks$80,000 to $150,000 or more

Notice that the under-50 band starts above the $14,500 AWS floor. The gap is usually onboarding, a Type 2 audit rather than a Type 1, and more systems in scope than the starting price assumes.

What raises or lowers a Thoropass quote

Five things move the number. The count of frameworks you carry. The audit type and observation period. Headcount and the number of systems in scope, because both drive audit effort. Whether onboarding help is bundled. And contract length.

Vendr's 2026 guidance reports multi-year commitments earning discounts of 15 to 25 percent, competitive evaluations taking 20 to 30 percent off initial quotes, and renewals coming in 20 to 40 percent below the first year, mostly because implementation does not repeat. Treat these as ranges seen across buyers, not promises. The practical takeaway is that a first-year quote is the most negotiable number you will see, and a credible second quote from another vendor is the strongest lever you have.

Thoropass vs Scrutineer pricing

The two products are priced on different models, so compare them on what you would pay for the same scope. Scrutineer publishes its prices and sells software only; you choose and pay your auditor directly.

ThoropassScrutineer
Published priceNo figures on its site; AWS listing from $8,700 platform plus $5,800 SOC 2 auditEssentials $599 a month, Growth $1,200, Risk+ $2,500, on the pricing page
One framework, billed annuallyFrom $8,700 a year for the platformEssentials, $5,988 a year
Several frameworksEach added framework raises the quoteGrowth covers SOC 2, ISO 27001, HIPAA, GDPR and PCI DSS for $11,988 a year
AuditSold by Thoropass as its own subscriptionNot included; you hire the CPA firm or certification body you want
Vendor risk managementPriced by quoteRisk+ adds third-party risk with unlimited vendor scoring for $24,996 a year
Security questionnairesPriced by quoteIncluded from Growth, with no per-questionnaire fees

Read the table honestly. If your priority is one vendor and one contract for both the software and the audit, Thoropass's bundle is a real advantage that a software-only price does not replicate, and you still have to pay an auditor on top of Scrutineer. If you carry more than one framework, need vendor risk in the same tool, or want your auditor chosen separately from your software vendor, the published plans are usually the cheaper and simpler path. Our Thoropass alternative comparison covers the feature side in more depth.

Is Thoropass worth it?

Thoropass is worth it for a first-time compliance team that wants readiness and the SOC 2 audit handled by one vendor on one timeline, and that would rather not run an auditor selection. That convenience is what the bundle sells, and it is a legitimate reason to pay for it.

It is a weaker fit in three situations. When a customer or board prefers an auditor with no commercial tie to the readiness software, which some enterprise procurement teams ask about. When you expect to add frameworks quickly, because each one raises the quote. And when your next problem is vendor risk rather than your own audit. If there is a chance you sell the company during a multi-year term, also check whether the contract assigns to a buyer, since acquirers of a small SaaS company review its compliance contracts alongside the verified revenue and churn metrics they are paying for.

Questions to ask before you sign a Thoropass quote

  • Which frameworks does the platform line include, and what is the price of each one added later?
  • Is the audit a SOC 2 Type 1 or Type 2, how long is the observation window, and which systems are in scope?
  • Is onboarding included, and is it a one-time fee or part of the subscription?
  • What is the renewal price, and is the annual increase capped in writing?
  • If we move to an outside auditor in year two, what happens to the platform price?
  • Can we see the auditor's independence arrangement in writing for our customers?

If you are still deciding between bundled and software-only models, our compliance automation software pricing comparison lays out what twelve platforms cost, and the SOC 2 audit cost breakdown shows what the audit alone runs when you buy it from a CPA firm. To see Scrutineer's numbers side by side, the pricing page lists every plan.

Scrutineer is compliance software for readiness and decision support. It does not issue SOC 2 reports or ISO 27001 certificates; an independent auditor does.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.