SOC 2 (AICPA)
Estimate the audit fees, tooling spend, internal effort, and timeline for SOC 2 Type I or II.
Security (Common Criteria) is mandatory; every additional criterion adds audit scope and cost.