Get audit-ready.Priced up front.
The ISAE 3402 environment, built and set up on your Veritise Full Suite subscription. Your team operates it from day one; an external audit firm tests it and signs the report.
€4,000
excluding VAT
* Final price may depend on your organisation size and how much of your compliance environment is already in place. Scope is confirmed on a 30-minute discovery call before any work starts. Full Suite subscription runs the ongoing work on the platform.
Five work products.One engagement.
Each artefact is written for your organisation, signed off by a certified compliance specialist, and delivered on your Veritise Full Suite platform. Your team operates the environment from day one; the auditor tests it.
Control library
Mapped one-to-one to the ISAE 3402 control objectives your auditor will test, anchored to the services actually in scope.
Evidence-collection scaffolding
Sampling cadence, storage, and owners set up on Full Suite so the Type II observation period runs on its own rails.
Policies and procedures
One per in-scope control. Drafted for your product and your team, then signed off by a certified compliance specialist.
Walkthrough documentation
Written in the format the audit firm reads, so their first onsite opens straight into testing.
Remediation plan
For every control gap we surface in Discovery. Ordered by priority and effort so nothing lands in fieldwork by surprise.
Why the setup is €4,000, not €40,000.
Because we don't rebuild what you already have.
Traditional readiness quotes hide behind 'contact us' pricing and start well into five or six figures. That is what it costs when the provider rebuilds the control environment from scratch and bills every hour of it. We don't. Existing SOC 1 work, your ROPA, prior policies, security controls already in place for GDPR — all of it feeds the engagement. Two variables move the price: how many services are in scope, and how much of the environment is already documented.
And we don't sign the report.
An external audit firm signs the ISAE 3402 report — a service organisation cannot audit itself. We build the environment they test, set it up on Full Suite, and stay on call through their fieldwork. Your team operates the environment day to day. If you already have an audit firm we brief them; if not, we introduce you to firms we have worked with.
When this is not the right engagement.
The Veritise ISAE 3402 readiness engagement is not for organisations that need a SOC 1 report (that is the AICPA standard, tested by a different auditor — different rulebook), or that expect the readiness provider to also sign the assurance report (that is not how ISAE 3402 works). If you need controls documented on paper but no continuous evidence collection, a template library is cheaper than the Full Suite subscription. If you are large enough to run an in-house ISAE 3402 programme end-to-end, hire in — this engagement is priced for teams that would rather not.
Read the honest side-by-side: Veritise vs a traditional Big-Four readiness quote →
ISAE 3402 is issued by the International Auditing and Assurance Standards Board (IAASB) .
Three phases.Roughly four to five weeks.
The build runs on your Full Suite platform. Type II monitoring picks up from handoff — your team on the platform, under our support. Longer if you're starting from a thin evidence base; we flag that in Discovery.
Discovery
Thirty minutes to map services in scope, the SOC 1 work, ROPA, and security controls you already have, and the audit firm that will run the engagement. By the end of the call, scope, price, and timeline are agreed in writing.
Build
We build the missing controls, draft the policies, and set up the evidence-collection scaffolding on your Veritise Full Suite platform. Existing Full Suite work — GDPR, security, vendors — is aligned around the ISAE 3402 environment. A certified compliance specialist signs off every artefact before it reaches you.
Handoff
The environment goes live on Full Suite; your team operates it from day one. We brief your audit firm on how it was built, walk them through the controls, and stay on call through their fieldwork.
Three moments that put ISAE 3402 on the table.
Your customer's auditor asked for it.
A large customer's audit firm is placing reliance on your controls for their financial reporting and needs an ISAE 3402 report before they can sign off.
Procurement is blocking a renewal.
Vendor security cannot see an assurance report on file. The renewal is stuck until they can.
A European buyer will not accept SOC 1.
You have a SOC 1. Their auditor tests against ISAE 3402, not SSAE 18, and specifically asks for the international standard.
Read the full guide on when customers ask for ISAE 3402 →
Confused about SOC 1 vs ISAE 3402? See the side-by-side comparison →
Everything worth asking before you book.
- What does the 30,000 DKK cover?
- The readiness setup: the ISAE 3402 environment, controls, evidence, policies, procedures, and walkthrough documentation delivered on your Full Suite subscription. Type I — which confirms the design of controls at a point in time — is what most organisations publish in year one; that is what the setup gets you to. Type II tests operating effectiveness over a six- to twelve-month observation period; that runs on Full Suite afterwards, with your team on the platform under our support, and enterprise customers usually require it at renewal.
- Do I need a Veritise subscription?
- Yes — the Full Suite subscription. The ISAE 3402 environment lives on it: the controls, evidence storage, tasks, and vendor register your team operates day to day. The readiness engagement builds the environment; the subscription runs it, and is what makes the Type II observation period practical to sustain.
- How long until we have a signed report?
- The readiness setup runs four to five weeks on average from discovery to handoff. The audit firm's fieldwork then adds a few more weeks. Total time from first call to a signed report is commonly two to three months. It can extend if you're starting from a thin evidence base — we flag that in Discovery so nothing surprises you later.
- Why does the price vary per customer?
- Two variables move the number: how many services are in scope, and how much of your control environment is already documented. A small organisation with existing SOC 1 work or a mature GDPR programme lands at the lower end. A larger organisation building from scratch lands higher. You get a fixed scope and price after the discovery call — no time-and-materials meter.
- What if we already have an audit firm lined up?
- Better. We brief them, adapt to their preferred evidence formats, and stay out of your commercial relationship. If you don't yet have one, we can introduce you to firms we have worked with. The engagement contract is between you and them.
- Where does Veritise stop and the auditor start?
- We build the environment on Full Suite, keep the wider compliance work aligned around it, and stay on call through fieldwork. Your team operates the environment day to day. The external audit firm tests the environment and issues the report. Their fieldwork opens straight into testing because the walkthroughs and evidence are already in place — that is what 'readiness' means.
Deeper on ISAE 3402.
The full library on the framework. No pricing pitch, just the standard.
Scope it in a call,not a quote.
Thirty minutes. Scope, price, and timeline agreed on the call. Nothing starts before then.
Or write to info@veritise.dk