How much does a software audit cost in 2026?
Price follows the decision, access, and evidence. A cheap checklist can be expensive if it answers the wrong question.
GattyWorks software audit prices, cost drivers, scope differences, and a practical way to compare audit quotes.
GattyWorks software audits start at $399 for Surface, $999 for Deep, and $2,499 for Full. Those numbers are useful only with the scope beside them. The cost changes when the decision needs more systems, more evidence, or a specialist service that is outside the audit.
After reading the brief, we put the included systems, evidence, exclusions, fixed price, and delivery date in writing. A large product estate or unusual test requirement is quoted separately before work starts.
Four things move the price
1. The decision
Checking whether a five-page marketing site was delivered is smaller than deciding whether a company can operate a multi-tenant SaaS product after its vendor leaves. The second decision needs ownership, deployment, recovery, data, access, and dependency evidence.
2. The number of systems and dependencies
One repository and one cloud project are easier to trace than several applications, SaaS integrations, data stores, regions, and AI tools. The quote should name what is inside the boundary. Words like entire platform are too vague to price safely.
3. The access and evidence available
A Surface Audit can begin with public behavior and supplied claims. A Deep Audit needs authorized access to technical evidence. Poor documentation does not automatically make the audit invalid, but it adds discovery work and leaves more findings in Needs evidence.
4. The test and follow-up work
A configuration review, backup restore, permission test, cost analysis, and re-audit are different jobs. The quote should say which tests are included, who runs them, and whether agreed fixes get a second look.
Compare quotes line by line
Two audit quotes with the same price can buy different work. Ask each reviewer to complete this small record before you compare totals:
Decision: Accept delivery without vendor dependence
Included: app, repository, cloud project, domain account
Evidence: read-only access, runbooks, 30-day cost export
Tests: isolated restore, admin ownership, deployment replay
Excluded: penetration test, legal review, employee devices
Deliverable: findings + evidence + severity + fix order
Re-audit: included for agreed fixes
Fixed price and date: written before accessIf a quote cannot fill these lines, the lower price may mean a smaller scope rather than a better deal.
When each tier is usually enough
- Use Surface when the first question is whether the product and vendor claims deserve deeper inspection.
- Use Deep when the decision depends on security, restore evidence, data handling, or several external services.
- Use Full when architecture, AI behavior, governance, vendor continuity, and technology spend need one decision record.
Start smaller when the first review can answer the question. A Surface finding may show that the domain is already buyer-owned and the delivery is simple. It may also show that a Deep Audit is necessary because the vendor's recovery claim cannot be checked from outside.
Services that should be priced separately
A formal certification, regulated attestation, dedicated penetration test, legal opinion, financial audit, or large remediation project is not hidden inside these starting prices. Use the right specialist and ask the auditor to state the boundary plainly.
The same rule applies to fixes. The report can give your current vendor a fix order. If GattyWorks performs the remediation, that build is scoped and priced separately so the audit verdict is not tied to winning the repair work.
The next useful number
Write down the decision, target systems, and evidence you can authorize. Then read the synthetic sample report and the exact software audit scope. Send those three lines to hello@gattyworks.com. The written reply will recommend the lightest tier that can answer the decision.