Softmax is once per token per a layer, and growing linearly with context window size (therefore quadratic over full input).
But softmax sampling, where you pick a single output token at the end and feed it back in to generate the next one, is branchy, so you need to do some extra encrypted computation to avoid leaking which token was sampled.