A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Every service, with the price it starts at. Your price is set on a short scoping call and confirmed in writing before any work starts.
Phase 1 is a fixed-price gap analysis. Phase 2 is scoped from what it finds. Both fixed price, no lock-in.
| SOC 2 (Type I or Type II)
End-to-end SOC 2 readiness: gap analysis, policies, controls, evidence repository, and auditor coordination. |
From $3,000 Phase 1 gap analysis |
| ISO 27001
ISMS build, Statement of Applicability, internal audit, and certification-body coordination. |
From $3,500 Phase 1 gap analysis |
| ISO 42001 (AI management system)
An AI management system built to ISO 42001, with the Annex A controls evidenced the way an auditor expects. |
From $3,500 Phase 1 gap analysis |
| CyberSecure Canada
Phase 1 gap analysis and Phase 2 remediation against CAN/DGSI 104, through to an accredited certification audit. |
From $2,500 Phase 1 gap analysis |
| CPCSC Level 1 (defence suppliers)
A check of the 13 Level 1 requirements for defence suppliers, and the work to meet them before the annual self-assessment. |
From $1,500 Level 1 check |
| HIPAA
Security Rule risk analysis, safeguard implementation, and business associate agreement hygiene. |
From $3,000 Phase 1 gap analysis |
| PCI DSS
Scope reduction, control implementation, and SAQ or ROC preparation. |
From $3,500 Phase 1 gap analysis |
| GDPR
Records of processing, lawful basis mapping, DPAs, transfer mechanisms, and data subject request workflow. |
From $3,000 Phase 1 gap analysis |
| PIPEDA
Privacy program build against the ten principles, with breach response and accountability records. |
From $2,500 Phase 1 gap analysis |
| Quebec Law 25
Four-week sprint covering data mapping, consent, privacy officer duties, and the confidentiality incident register. |
From $2,500 Phase 1 gap analysis |
| NIST CSF
Facilitated current and target profile assessment with a costed roadmap between the two. |
From $2,500 Phase 1 gap analysis |
| EU AI Act
Classification, technical documentation, risk management system, and conformity assessment preparation. |
From $3,000 Phase 1 gap analysis |
Go through Phase 1 and Phase 2 with us, the gap analysis and the remediation support, and if your audit or certification returns a qualified opinion, a major nonconformity (MNC), or the equivalent on a control we prepared, we provide the remediation support to resolve it at no charge.
Keep a programme running between audits, or add the piece you are missing.
| Continuous compliance (Phase 3 upkeep)
Ongoing monitoring: control health, policy review cycles, vendor reassessment, and your compliance calendar run for you. |
From $1,500/mo per month |
| Security and compliance programme build
A monthly retainer that builds your security and compliance programme, then steps down to upkeep. |
From $4,500/mo per month |
| Auditor management
We act as your point of contact with the auditor or certification body, from selection to the issued report. |
From $2,500 per audit |
| ISO 27001 internal audit
An independent clause 9.2 internal audit ahead of certification or surveillance: plan, fieldwork, report, and a check of corrective actions. |
From $3,000 per audit |
| Trust center (free for clients, hosted or managed)
A public trust page that answers the routine half of inbound security reviews. Run it yourself, or have TrazTech answer the questions and document requests and keep it current. |
From $149/mo per month hosted; free for clients |
| Vendor and third-party risk
Vendor inventory, tiering, questionnaire cycles, and an evidenced review record. |
From $750/mo per month, ongoing reviews |
| AI vendor risk assessment
Assess the model providers and AI tools in your supply chain against your obligations. |
From $2,000 per assessment |
| Outsourced privacy officer
A named privacy officer handling requests, the privacy programme, impact assessments and breach obligations. |
From $750/mo per month |
| AI acceptable use policy
A usable AI acceptable use policy plus the rollout and attestation record. |
From $750 tailored policy |
| Security awareness training
Onboarding and annual training, phishing simulations and completion records an auditor accepts. |
From $200/mo per month |
| Cloud cost audit
A review of your cloud spend with specific changes and estimated monthly savings. |
From $2,500 per cloud account |
Our own tooling, your environment on your terms, one standard report. Critical issues reported within 24 hours.
| Penetration testing (web, API, network, cloud)
An auditor-acceptable penetration test with the report and remediation evidence your framework expects. |
From $3,500 one app or API |
| Vulnerability assessment
Authenticated and unauthenticated scanning with every result verified by a person, in a risk-ranked report. |
From $1,500 verified scan and report |
| Vulnerability management
Scanning, triage, and a tracked remediation SLA so the control has a running record, not a one-off scan. |
From $450/mo per month |
| AI and LLM security
A security review of the AI systems you build on, covering the model, the data that reaches it, and the controls around both. |
From $4,000 scoped to what you built |
| LLM red teaming
Adversarial testing of prompt injection, jailbreaks, data leakage, and agent abuse paths. |
From $9,000 objective-based campaign |
| Vibe-coded app QA and security
A security and quality review of AI-generated code, against the failure modes that assistants reliably produce. |
From $600 launch check |
| Cloud security review
Configuration review across your cloud accounts against CIS benchmarks and your framework's technical controls. |
From $2,500 per platform |
One report you can act on, or the questions answered for you.
| Enterprise security review
A point-in-time review of your security programme across people, process and technology, with a risk-ranked roadmap. |
From $7,500 programme review |
| Threat and risk assessment (TRA)
A formal TRA in the shape procurement and public-sector buyers ask for: assets, threats, likelihood, impact and treatment. |
From $3,000 per system |
| Technical due diligence (investors and startups)
Architecture, code, security and compliance reviewed for investors, or for the company preparing to be reviewed. |
From $4,500 per company |
| Security questionnaire help
We answer the buyer questionnaire blocking your deal, accurately, and flag what to fix behind it. |
From $450 per questionnaire |
| Buyer security review support
We take a buyer's full security review through to sign-off: questionnaire, evidence pack and the calls. |
From $3,500 full review |
| Cyber insurance readiness
Close the control gaps underwriters price on, and answer the application accurately. |
From $2,000 per application |
| Shadow AI audit
Find the AI tools already in use across your org before an auditor or a customer does. |
From $2,000 AI tool inventory |
A named security lead, and help on call when it matters.
| vCISO (monthly block of hours)
Named security leadership to own the program, chair reviews, and sign off on customer questionnaires. |
From $2,500/mo per month |
| vCISO flexible (actual hours, full timesheet)
The same security lead without a monthly commitment, billed on actual hours with a full timesheet. |
From $275/hr per hour |
| Interim CISO
Full-time security leadership on a fixed term while you hire or close a deal. |
From $2,500/mo per month |
| Incident response retainer
24/7 on-call response with defined SLAs, plus the retainer letter insurers and auditors like to see. |
From $5,000/yr per year |
| Incident response tabletop
A one-day war-room exercise that produces the test record your framework asks for. |
From $3,000 per exercise |
| Continuity and DR testing
A business impact analysis, a continuity and recovery plan, and a tested exercise with evidence an auditor accepts. |
From $4,000 plan and tested exercise |
Priced into your proposal when you need them, so a small first engagement can grow without starting over.
Prices are in CAD before tax. MSPs and IT firms can deliver any of these to their own clients through our partner program.
Published ranges from other Canadian firms, each attributed to the source that published it. We include these because "what should this cost" is the question everybody asks first, and a page that only quotes its own prices does not answer it. Ranges are what each firm published, not what we would quote.
| Work | Published range | Source |
|---|---|---|
| Penetration test, small web application | C$5,000 to C$12,000 | Stingrai, and a Canadian pentest firm's published rate card |
| Penetration test, enterprise scope | C$20,000 to C$50,000+ | Canadian pentest firm, published rate card |
| Penetration testing, day rate | C$1,000 to C$2,000 per day | Canadian pentest firm, published rate card |
| Penetration testing as a service, annual | C$40,000 to C$120,000 | Stingrai |
| SOC 2 consulting, boutique | C$15,000 to C$40,000 | Truvo Cyber |
| SOC 2 consulting, full service | C$40,000 to C$85,000 | Truvo Cyber |
| SOC 2 consulting, Big 4 | C$80,000 to C$200,000+ | Truvo Cyber |
The audit fee is separate. Every range above is for consulting or testing. The CPA firm or certification body bills you directly, and no readiness quote includes it.
Most teams pricing a readiness programme have also been quoted a compliance platform to run it in. You do not need one to work with us: the workspace is free.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
The prices above are what we charge. The auditor or certification body bills you separately: why audit quotes vary, and how we help you pick the firm.
These are the longer answers: what drives the number, what an auditor or testing firm charges on top, and what the same work costs elsewhere in Canada.
Each figure is the smallest real scope we take on. Your price is set on a short scoping call, from what you actually have, and you see it in writing before anything starts.
No. The CPA firm or certification body bills you directly. We help you choose one, prepare you for the audit and manage the auditor if you want us to.
You keep the gap report and your workspace either way. If you continue, Phase 2 is scoped from the findings and carries them over with nothing re-entered. After the audit, continuous compliance keeps the programme current.
No. The compliance workspace is free, and clients on a live engagement get a self-managed trust center in it at no charge.
Yes. If a buyer or auditor needs proof before the report exists, we issue a letter confirming the engagement, and an attestation letter once the report is out.