A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →There is no single best SOC 2 consultant, only the best fit for your stage and budget. This guide breaks down the four kinds of SOC 2 help you can hire in Canada, what each is good and bad at, and how to choose without overpaying.
Book a free readiness callSearching for a SOC 2 consultant in Canada turns up two kinds of company that do completely different jobs, and the pages that rank rarely tell you which is which. This guide separates them, sets out what to evaluate, names who is actually operating in this market, and says where each option including ours is the wrong call.
We are on this list. We have not put ourselves at the top, and every firm gets the same treatment: what they do well, who they suit, and what to watch for.
Key takeaway. SOC 2 is two purchases, not one. A licensed CPA firm issues the report and must stay independent of what it examines, so a separate readiness firm builds the controls and evidence. Compliance platforms are a third thing again, and buying one removes the need for neither.
A SOC 2 report is issued by a licensed CPA firm. That firm has to remain independent of what it examines, which means it cannot build your controls, write your policies or assemble your evidence. If it did, it would be auditing its own work and the report would be worth nothing.
So there are two roles, and you will end up buying both:
The audit firm examines and issues the opinion. Examples operating in Canada include Prescient Assurance, the Big 4, and a number of Canadian CPA firms specialising in cyber and privacy attestation. You cannot avoid this cost and you should not want to.
The readiness or prep firm gets you to the point where that examination goes well. Scope, control design, remediation, evidence, and managing the auditor relationship. This is what we do.
Buyers who do not know this typically make one of two mistakes. They hire an audit firm and are surprised when it will not tell them how to fix anything. Or they hire a consultant and assume a report comes out at the end. Establish which one you are talking to in the first five minutes.
There is a third category worth naming: compliance platforms such as Vanta and Drata. They hold your control set and evidence and automate part of the collection. They are neither auditor nor consultant, and buying one does not remove the need for either.
Key takeaway. Seven questions separate a firm that has run this before from one that is selling. Most come down to whether the scope, the auditor fee and the observation window are pinned down before any work starts, and whether the person who pitches is the person who delivers.
Hourly billing on a readiness engagement transfers all scope risk to you. A fixed scope with a fixed price means somebody has done this enough times to predict it.
It always is. A firm that lets you believe the quoted number covers the report is either careless or hoping you will not notice until it is too late to shop.
This is the single most common reason a SOC 2 programme slips. A Type II attests that controls operated across a period, so the period has to be chosen first and everything works backwards from it.
If ISO 27001 or HIPAA is anywhere in your future, mapping the overlap once is materially cheaper than doing the work twice a year apart.
At larger firms the person in the pitch is frequently not the person on the engagement. Ask directly.
Not every scope can be published. But a floor tells you the offering is productized rather than open-ended, and lets you compare without three discovery calls.
A firm that agrees your timeline is achievable without asking what evidence you already have is selling, not scoping.
| On this question | What good looks like | Red flag |
|---|---|---|
| Pricing basis | Fixed scope at a fixed price | Hourly billing that hands scope risk to you |
| Auditor fee | Stated plainly as separate from the quote | Left to look like the quote covers the report |
| Observation window | Chosen before any work begins | Work starts before the window is set |
| Frameworks | Can map the overlap across SOC 2, ISO 27001 or HIPAA | One framework only when others are in your future |
| Who delivers | The person in the pitch is on the engagement | The pitch team is not the delivery team |
| Prices | Publishes a floor you can compare against | No number without several discovery calls |
| Honesty on fit | Asks what evidence you have before agreeing a timeline | Agrees your timeline is achievable without asking |
Key takeaway. The firms below are grouped by what they actually do: audit, readiness, or platform. Match the group to where you are. If your controls are in order you need an auditor; if they are not, you need readiness first, because an auditor cannot fix anything for you.
Grouped by what they actually do. Facts from public pages, August 2026. Prices are shown where a firm publishes them.
| Firm | Role | Notes | Published price |
|---|---|---|---|
| Prescient Assurance | Audit firm | Licensed CPA firm, security-first background, SOC 2 and CSA STAR | Not disclosed |
| Canadian cyber and privacy CPA firms | Audit firm | Licensed practices focused on attestation rather than general accounting | Not disclosed |
| Big 4 | Audit and advisory | Deep bench, regulator-grade documentation, separate teams for each role | Not disclosed |
| Truvo Cyber | Readiness | Ottawa, CISSP and GIAC leadership, publishes floor pricing | From CAD $25K build |
| ISA Cybersecurity | Readiness, managed | Long-established Canadian security firm, broad managed services alongside advisory | Not published |
| Elastify | Readiness | Canadian consultancy positioning on senior delivery | Not published |
| Kobalt.io | Readiness, managed | Vancouver, managed programme model with platform included | Publishes programme pricing |
| Canadian Cyber | Readiness | Canadian consultancy covering SOC 1 and SOC 2 readiness | Not disclosed |
| Vanta / Drata | Platform | Control set and evidence automation, not a consultant or auditor | Subscription, typically annual |
| traztech | Readiness | Toronto, fixed scope, CVE-researcher led, free workspace included | Published, from $3,000 |
What they do well. Both are licensed CPA firms specialising in cyber and privacy attestation rather than general accounting practices that added it. For SaaS scope they are frequently more efficient than a Big 4 engagement at comparable rigour.
Best fit. When you need the report and already have your controls in order.
Caveats. They are auditors. Independence rules mean they cannot design your controls or fix your gaps, so if you are not ready, engaging them first simply tells you that at your expense.
What they do well. Bench depth, brand recognition that satisfies internal governance, and the ability to handle group structures and regulated entities.
Best fit. Large or regulated organisations, or where procurement requires the name.
Caveats. Pricing sits well above what most startups expect, and the partner who scopes the work is rarely the person delivering it. Their audit and advisory arms are separate for good reason, so you are still buying two engagements.
What they do well. Ottawa-based with CISSP and GIAC-credentialed leadership, publishing a floor price, which almost nobody in this market does. They write openly about the difference between a dashboard and a programme, which is the right critique.
Best fit. Buyers wanting a build-and-operate relationship rather than a one-off project.
Caveats. Their published entry point is materially higher than a fixed-price gap analysis, which suits a full programme and less so a company that needs a gap analysis first.
What they do well. One of the longer-established Canadian security firms, with managed services running alongside the advisory work. If you want compliance preparation and ongoing monitoring bought from one organisation, that combination is genuinely useful.
Caveats. A broad services business has a different centre of gravity than a firm that only does readiness. Ask who specifically will run your engagement and how many SOC 2 programmes they have personally taken through to a report.
What they do well. Positions on senior-level delivery rather than leveraged teams, which is the right axis to compete on for work of this kind.
Caveats. Less public detail on pricing and on framework coverage than several firms above, so both are worth establishing on the first call.
What they do well. Vancouver-based, running managed compliance programmes with a monthly cadence and a platform included, across SOC 2 and ISO 27001.
Best fit. Companies that want somebody to hold the programme continuously rather than deliver and leave.
Caveats. The managed model is a recurring commitment. If you want a defined piece of work with an end, say so early.
What they do well. Hold the control set, automate part of evidence collection from cloud and identity providers, and give you a dashboard that management can read.
Best fit. Organisations maintaining several frameworks continuously, with someone whose job includes compliance.
Caveats. Automation covers a minority of controls, and generally the ones you already pass. What fails audits is organisational: reviews that never ran, controls nobody owns. Most buyers end up paying for the platform and for help using it. A client who priced one and ran the programme without it.
What we do well. Fixed scope, published prices from $3,000, and the whole thing runs in traztech Workspace, which is free and which you keep afterwards. Our principal took a venture-backed company from no compliance programme at all to a SOC 2 Type II with zero exceptions, and the work is led by a researcher with five published CVEs including a CVSS 9.1 in the Mirai botnet. We run SOC 2 alongside ISO 27001 where both are needed, and we handle programmes where physical sites are in scope, not only software.
Best fit. Companies that want a number before committing, one accountable person rather than a rotating bench, and somebody who will say Type I is enough for now when it is.
Caveats, and we mean them. We are deliberately small. A hundred-person engagement across multiple business units is a Big 4 job and we will tell you so. We do not issue reports, so you are still engaging an audit firm. And we are not the cheapest option in this market; if price is the only variable, a platform subscription and your own effort will cost less, and for some companies that is genuinely the right answer.
Key takeaway. Four tiers, from boutique to Big 4, with the audit fee and optional tooling as separate lines. The figures are market ranges in Canadian dollars for a first-year programme, not our prices. Two things the ranges hide: the audit fee is not fixed by the market, and readiness changes the audit price rather than only adding to it.
Ranges below are drawn from Canadian firms and cost studies that publish them, in Canadian dollars, for a first-year SOC 2 programme. They are the market, not our prices. Ours are separate and published on the pricing page.
| Tier | First-year consulting | What you get | Where it fits |
|---|---|---|---|
| Boutique / specialist | CAD $15,000 to $40,000 | A small senior team, usually one named operator, fixed scope | Startups and SMEs on a first report |
| Full-service consultancy | CAD $40,000 to $85,000 | Assessment, build and first audit cycle, larger delivery team | Mid-market, several frameworks at once |
| Big 4 | CAD $80,000 to $200,000+ | Brand on the engagement letter, board-level reporting | Enterprises with procurement mandates |
| The audit itself | CAD $10,000 to $40,000 | Paid to the CPA firm, never to your readiness partner | Every path above |
| Compliance platform | CAD $5,000 to $25,000 per year | Evidence automation and a control dashboard | Optional, and optional for longer than vendors suggest |
Published all-in estimates for a Canadian SME of roughly 20 to 75 people put a first-year Type II somewhere between CAD $40,000 and $120,000 once consulting, audit, tooling and internal time are counted, settling to something like CAD $25,000 to $60,000 a year afterwards. Those figures assume the full-service tier. A boutique engagement with a right-sized audit firm lands well below them, which is the whole reason the boutique tier exists.
Two things those ranges hide. The first is that the audit fee is not fixed by the market: quotes from different firms for one identical scope can differ by a large multiple. The second is that readiness changes the audit price rather than merely adding to it: a firm looking at a documented readiness position and a confirmed prep firm has less uncertainty left to price, and its quote reflects that. Neither of those is visible to a first-time buyer comparing proposals side by side.
Key takeaway. Three separate numbers: readiness, the audit, and optional tooling. The audit is paid to the CPA firm, never to your readiness partner, and it is the number that varies most. Being demonstrably ready brings it down.
Three numbers, and they are separate.
Readiness. Ours starts at $3,000 for a gap analysis with the full SOC 2 track published on our pricing page. Truvo publishes from CAD $25K for a build. Most firms do not publish at all.
The audit. Paid to the CPA firm, never to your readiness partner. This is where buyers get surprised. Quotes from different firms for one identical scope can differ by a large multiple. That spread is almost never about quality; it is about what each firm assumed. What drives that spread.
Tooling. Optional. A compliance platform is typically a five-figure annual subscription. Our workspace is free, and if you already run a commercial platform we will work inside it.
One thing worth knowing because nobody advertises it: being demonstrably ready reduces the audit fee. An audit firm looking at an evidenced readiness position and a confirmed prep firm has less to allow for, and its estimate comes down. That is not a negotiated discount, it is a smaller estimate because there was less uncertainty to price. How that worked.
Key takeaway. The questions that come up most on a first SOC 2, answered in short. The recurring themes: readiness and audit are separate engagements, the observation window drives the timeline, and tooling is optional for longer than vendors suggest.
No, and you should avoid any arrangement that looks like it. The CPA firm issuing the report has to stay independent of what it examines, so it cannot design your controls or build your evidence. Readiness and audit are two engagements with two firms, by design.
Three separate costs: readiness, the audit itself, and optional tooling. Readiness starts from $3,000 with us and published floors elsewhere run considerably higher. The audit is billed by the CPA firm and varies widely; quotes from different firms for one identical scope can differ by a large multiple. Tooling is optional and typically a five-figure annual subscription.
Not for a first or second SOC 2. Automation covers a minority of controls, generally the ones you already pass, while what fails audits is organisational. If you maintain several frameworks continuously with dedicated staff, a commercial platform earns its money.
Type I for most first-time companies. It attests that controls are suitably designed at a point in time, so it is achievable now and unblocks the buyer conversation. The same control set then runs through an observation window and becomes the Type II, provided the controls were built to produce evidence.
SOC 2 Type I is commonly a few months from start to report, and Type II adds a 3, 6 or 12 month observation window. What drives it is the gaps the analysis finds, the observation period and the auditor's schedule. The binding constraint on a Type II is usually the observation period rather than the control work, which is why the window should be chosen before anything starts.
The observation window being chosen after the work begins. A Type II covers a period and evidence has to exist across it, so a control implemented last week cannot produce three months of history no matter how well designed it is.
Frequently yes, and it is usually cheaper than doing them a year apart. A large share of ISO 27001 Annex A maps onto the SOC 2 common criteria, so the control and evidence work is done once. What ISO adds is the management system: risk methodology, Statement of Applicability, internal audit and management review.
Yes. There is no minimum stage and no minimum headcount. What matters is whether security or compliance is on your critical path, which for some pre-seed companies it already is because an enterprise pilot is waiting on it.
No. SOC 2 is an attestation report issued by a licensed CPA firm under AICPA standards, not a certificate issued by a certifying body. There is no SOC 2 certificate and no organisation that grants one, which is why a firm advertising SOC 2 certification is worth a second look. The report states what the auditor observed about your controls over a point in time or a period.
Only a licensed CPA firm operating under AICPA rules. A cybersecurity consultancy cannot issue the report regardless of how much of the preparation it did, and independence rules prevent the firm that designed your controls from attesting to them. That separation is a requirement rather than a market convention.
Scopes which Trust Services Criteria your buyers need, runs a gap analysis against the real environment, writes the policies, fixes what is failing, stands up evidence collection so it accumulates across the observation window, and manages the auditor relationship through fieldwork. What they do not do is issue the report.
It depends on who is asking. North American enterprise buyers usually ask for SOC 2. European and international buyers, and public tenders, more often ask for ISO 27001. If both appear in your pipeline, running them together is materially cheaper than sequencing them, because a large share of Annex A maps onto the common criteria and the evidence is gathered once.
At the boutique tier, plan for consulting in the CAD $15,000 to $40,000 band, an audit fee of CAD $10,000 to $40,000 depending on scope and firm, and tooling only if you genuinely need it. Get the audit quote before committing to a readiness budget, because the audit is the number that varies most and it is the one you control least.
Key takeaway. Four steps, and the first two cost nothing. Decide the report and the observation window first, then send every audit firm the same package so their quotes are comparable, and choose the readiness partner on fit rather than the headline number.
Type I or Type II, which Trust Services Criteria beyond Security, and whether a specific buyer has already told you what they will accept.
Everything downstream is scheduled against it.
Written scope, system description, target window, in-scope systems, headcount including contractors with production access, and an honest statement of where your evidence stands. Then ask each what they assumed about anything you left out. Most of the price spread disappears at that point.
Ask who does the work, what the deliverable is, and what is excluded.
If you want to see where you stand before speaking to anybody, our auditor evidence request simulator runs the evidence request an auditor would send and gives you the gap list. How it works covers what an engagement involves phase by phase, and the cost hub has every cost breakdown we have written.
Most SOC 2 consultants expect you to arrive with a compliance platform already bought, or they resell you one. It is a separate annual number on top of the fee. Ours is not.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.