Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Pricing

Every service, with the price it starts at. Your price is set on a short scoping call and confirmed in writing before any work starts.

Compliance programmes

Phase 1 is a fixed-price gap analysis. Phase 2 is scoped from what it finds. Both fixed price, no lock-in.

SOC 2 (Type I or Type II)
End-to-end SOC 2 readiness: gap analysis, policies, controls, evidence repository, and auditor coordination.
From $3,000 Phase 1 gap analysis
ISO 27001
ISMS build, Statement of Applicability, internal audit, and certification-body coordination.
From $3,500 Phase 1 gap analysis
ISO 42001 (AI management system)
An AI management system built to ISO 42001, with the Annex A controls evidenced the way an auditor expects.
From $3,500 Phase 1 gap analysis
CyberSecure Canada
Phase 1 gap analysis and Phase 2 remediation against CAN/DGSI 104, through to an accredited certification audit.
From $2,500 Phase 1 gap analysis
CPCSC Level 1 (defence suppliers)
A check of the 13 Level 1 requirements for defence suppliers, and the work to meet them before the annual self-assessment.
From $1,500 Level 1 check
HIPAA
Security Rule risk analysis, safeguard implementation, and business associate agreement hygiene.
From $3,000 Phase 1 gap analysis
PCI DSS
Scope reduction, control implementation, and SAQ or ROC preparation.
From $3,500 Phase 1 gap analysis
GDPR
Records of processing, lawful basis mapping, DPAs, transfer mechanisms, and data subject request workflow.
From $3,000 Phase 1 gap analysis
PIPEDA
Privacy program build against the ten principles, with breach response and accountability records.
From $2,500 Phase 1 gap analysis
Quebec Law 25
Four-week sprint covering data mapping, consent, privacy officer duties, and the confidentiality incident register.
From $2,500 Phase 1 gap analysis
NIST CSF
Facilitated current and target profile assessment with a costed roadmap between the two.
From $2,500 Phase 1 gap analysis
EU AI Act
Classification, technical documentation, risk management system, and conformity assessment preparation.
From $3,000 Phase 1 gap analysis
Clean Audit Guarantee

Go through Phase 1 and Phase 2 with us, the gap analysis and the remediation support, and if your audit or certification returns a qualified opinion, a major nonconformity (MNC), or the equivalent on a control we prepared, we provide the remediation support to resolve it at no charge.

Compliance support and ongoing programmes

Keep a programme running between audits, or add the piece you are missing.

Continuous compliance (Phase 3 upkeep)
Ongoing monitoring: control health, policy review cycles, vendor reassessment, and your compliance calendar run for you.
From $1,500/mo per month
Security and compliance programme build
A monthly retainer that builds your security and compliance programme, then steps down to upkeep.
From $4,500/mo per month
Auditor management
We act as your point of contact with the auditor or certification body, from selection to the issued report.
From $2,500 per audit
ISO 27001 internal audit
An independent clause 9.2 internal audit ahead of certification or surveillance: plan, fieldwork, report, and a check of corrective actions.
From $3,000 per audit
Trust center (free for clients, hosted or managed)
A public trust page that answers the routine half of inbound security reviews. Run it yourself, or have TrazTech answer the questions and document requests and keep it current.
From $149/mo per month hosted; free for clients
Vendor and third-party risk
Vendor inventory, tiering, questionnaire cycles, and an evidenced review record.
From $750/mo per month, ongoing reviews
AI vendor risk assessment
Assess the model providers and AI tools in your supply chain against your obligations.
From $2,000 per assessment
Outsourced privacy officer
A named privacy officer handling requests, the privacy programme, impact assessments and breach obligations.
From $750/mo per month
AI acceptable use policy
A usable AI acceptable use policy plus the rollout and attestation record.
From $750 tailored policy
Security awareness training
Onboarding and annual training, phishing simulations and completion records an auditor accepts.
From $200/mo per month
Cloud cost audit
A review of your cloud spend with specific changes and estimated monthly savings.
From $2,500 per cloud account

Security testing

Our own tooling, your environment on your terms, one standard report. Critical issues reported within 24 hours.

Penetration testing (web, API, network, cloud)
An auditor-acceptable penetration test with the report and remediation evidence your framework expects.
From $3,500 one app or API
Vulnerability assessment
Authenticated and unauthenticated scanning with every result verified by a person, in a risk-ranked report.
From $1,500 verified scan and report
Vulnerability management
Scanning, triage, and a tracked remediation SLA so the control has a running record, not a one-off scan.
From $450/mo per month
AI and LLM security
A security review of the AI systems you build on, covering the model, the data that reaches it, and the controls around both.
From $4,000 scoped to what you built
LLM red teaming
Adversarial testing of prompt injection, jailbreaks, data leakage, and agent abuse paths.
From $9,000 objective-based campaign
Vibe-coded app QA and security
A security and quality review of AI-generated code, against the failure modes that assistants reliably produce.
From $600 launch check
Cloud security review
Configuration review across your cloud accounts against CIS benchmarks and your framework's technical controls.
From $2,500 per platform

Assessments and buyer support

One report you can act on, or the questions answered for you.

Enterprise security review
A point-in-time review of your security programme across people, process and technology, with a risk-ranked roadmap.
From $7,500 programme review
Threat and risk assessment (TRA)
A formal TRA in the shape procurement and public-sector buyers ask for: assets, threats, likelihood, impact and treatment.
From $3,000 per system
Technical due diligence (investors and startups)
Architecture, code, security and compliance reviewed for investors, or for the company preparing to be reviewed.
From $4,500 per company
Security questionnaire help
We answer the buyer questionnaire blocking your deal, accurately, and flag what to fix behind it.
From $450 per questionnaire
Buyer security review support
We take a buyer's full security review through to sign-off: questionnaire, evidence pack and the calls.
From $3,500 full review
Cyber insurance readiness
Close the control gaps underwriters price on, and answer the application accurately.
From $2,000 per application
Shadow AI audit
Find the AI tools already in use across your org before an auditor or a customer does.
From $2,000 AI tool inventory

Leadership and incident response

A named security lead, and help on call when it matters.

vCISO (monthly block of hours)
Named security leadership to own the program, chair reviews, and sign off on customer questionnaires.
From $2,500/mo per month
vCISO flexible (actual hours, full timesheet)
The same security lead without a monthly commitment, billed on actual hours with a full timesheet.
From $275/hr per hour
Interim CISO
Full-time security leadership on a fixed term while you hire or close a deal.
From $2,500/mo per month
Incident response retainer
24/7 on-call response with defined SLAs, plus the retainer letter insurers and auditors like to see.
From $5,000/yr per year
Incident response tabletop
A one-day war-room exercise that produces the test record your framework asks for.
From $3,000 per exercise
Continuity and DR testing
A business impact analysis, a continuity and recovery plan, and a tested exercise with evidence an auditor accepts.
From $4,000 plan and tested exercise

Add-ons

Priced into your proposal when you need them, so a small first engagement can grow without starting over.

Retests and additional retestsExtra applications, APIs, environments or rolesExtra cloud accounts or platformsExtra Trust Services Criteria or frameworks mapped onceTesting confirmation and attestation lettersExecutive or board readoutsPolicy packsPhishing simulationsExtra vendors reviewedAdditional vCISO hoursManaged trust center request handlingRush delivery

Prices are in CAD before tax. MSPs and IT firms can deliver any of these to their own clients through our partner program.

What the rest of the market charges

Published ranges from other Canadian firms, each attributed to the source that published it. We include these because "what should this cost" is the question everybody asks first, and a page that only quotes its own prices does not answer it. Ranges are what each firm published, not what we would quote.

WorkPublished rangeSource
Penetration test, small web applicationC$5,000 to C$12,000Stingrai, and a Canadian pentest firm's published rate card
Penetration test, enterprise scopeC$20,000 to C$50,000+Canadian pentest firm, published rate card
Penetration testing, day rateC$1,000 to C$2,000 per dayCanadian pentest firm, published rate card
Penetration testing as a service, annualC$40,000 to C$120,000Stingrai
SOC 2 consulting, boutiqueC$15,000 to C$40,000Truvo Cyber
SOC 2 consulting, full serviceC$40,000 to C$85,000Truvo Cyber
SOC 2 consulting, Big 4C$80,000 to C$200,000+Truvo Cyber

The audit fee is separate. Every range above is for consulting or testing. The CPA firm or certification body bills you directly, and no readiness quote includes it.

The line item that is not on this page

Most teams pricing a readiness programme have also been quoted a compliance platform to run it in. You do not need one to work with us: the workspace is free.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote A documented readiness position the audit firm can scope and price against Nothing. The audit firm prices your readiness, not your tooling

Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.

What this work costs, in detail

The prices above are what we charge. The auditor or certification body bills you separately: why audit quotes vary, and how we help you pick the firm.

These are the longer answers: what drives the number, what an auditor or testing firm charges on top, and what the same work costs elsewhere in Canada.

Questions

Why "From" prices?

Each figure is the smallest real scope we take on. Your price is set on a short scoping call, from what you actually have, and you see it in writing before anything starts.

Is the auditor or certification body included?

No. The CPA firm or certification body bills you directly. We help you choose one, prepare you for the audit and manage the auditor if you want us to.

What happens after Phase 1?

You keep the gap report and your workspace either way. If you continue, Phase 2 is scoped from the findings and carries them over with nothing re-entered. After the audit, continuous compliance keeps the programme current.

Do you charge for the workspace?

No. The compliance workspace is free, and clients on a live engagement get a self-managed trust center in it at no charge.

Can you provide a letter while testing is booked?

Yes. If a buyer or auditor needs proof before the report exists, we issue a letter confirming the engagement, and an attestation letter once the report is out.

Book a free 30-minute call