Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →There is no single best SOC 2 consultant, only the best fit for your stage and budget. This guide breaks down the four kinds of SOC 2 help you can hire in Canada, what each is good and bad at, and how to choose without overpaying.
Book a free readiness callSearching for a SOC 2 consultant in Canada turns up two kinds of company that do completely different jobs, and the pages that rank rarely tell you which is which. This guide separates them, sets out what to evaluate, names who is actually operating in this market, and says where each option including ours is the wrong call.
We are on this list. We have not put ourselves at the top, and every firm gets the same treatment: what they do well, who they suit, and what to watch for.
A SOC 2 report is issued by a licensed CPA firm. That firm has to remain independent of what it examines, which means it cannot build your controls, write your policies or assemble your evidence. If it did, it would be auditing its own work and the report would be worth nothing.
So there are two roles, and you will end up buying both:
The audit firm examines and issues the opinion. Examples operating in Canada include Prescient Assurance, MHM Professional Corporation, and the Big 4. You cannot avoid this cost and you should not want to.
The readiness or prep firm gets you to the point where that examination goes well. Scope, control design, remediation, evidence, and managing the auditor relationship. This is what we do.
Buyers who do not know this typically make one of two mistakes. They hire an audit firm and are surprised when it will not tell them how to fix anything. Or they hire a consultant and assume a report comes out at the end. Establish which one you are talking to in the first five minutes.
There is a third category worth naming: compliance platforms such as Vanta and Drata. They hold your control set and evidence and automate part of the collection. They are neither auditor nor consultant, and buying one does not remove the need for either.
1. Do they quote a scope or an hour? Hourly billing on a readiness engagement transfers all scope risk to you. A fixed scope with a fixed price means somebody has done this enough times to predict it.
2. Will they tell you the auditor fee is separate? It always is. A firm that lets you believe the quoted number covers the report is either careless or hoping you will not notice until it is too late to shop.
3. Do they set the observation window before starting? This is the single most common reason a SOC 2 programme slips. A Type II attests that controls operated across a period, so the period has to be chosen first and everything works backwards from it.
4. Can they run more than one framework? If ISO 27001 or HIPAA is anywhere in your future, mapping the overlap once is materially cheaper than doing the work twice a year apart.
5. Who actually does the work? At larger firms the person in the pitch is frequently not the person on the engagement. Ask directly.
6. Do they publish prices? Not every scope can be published. But a floor tells you the offering is productized rather than open-ended, and lets you compare without three discovery calls.
7. Will they say no? A firm that agrees your timeline is achievable without asking what evidence you already have is selling, not scoping.
Grouped by what they actually do. Facts from public pages, August 2026. Prices are shown where a firm publishes them.
| Firm | Role | Notes | Published price |
|---|---|---|---|
| Prescient Assurance | Audit firm | Licensed CPA firm, security-first background, SOC 2 and CSA STAR | Not disclosed |
| MHM Professional Corp. | Audit firm | Canadian CPA firm focused on cyber and privacy attestation | Not disclosed |
| Big 4 | Audit and advisory | Deep bench, regulator-grade documentation, separate teams for each role | Not disclosed |
| Truvo Cyber | Readiness | Ottawa, CISSP and GIAC leadership, publishes floor pricing | From CAD $25K build |
| ISA Cybersecurity | Readiness, managed | Long-established Canadian security firm, broad managed services alongside advisory | Not published |
| Elastify | Readiness | Canadian consultancy positioning on senior delivery | Not published |
| Kobalt.io | Readiness, managed | Vancouver, managed programme model with platform included | Publishes programme pricing |
| Canadian Cyber | Readiness | Canadian consultancy covering SOC 1 and SOC 2 readiness | Not disclosed |
| Vanta / Drata | Platform | Control set and evidence automation, not a consultant or auditor | Subscription, typically annual |
| traztech | Readiness | Toronto, fixed scope, CVE-researcher led, free workspace included | Published, from $2,500 |
What they do well. Both are licensed CPA firms specialising in cyber and privacy attestation rather than general accounting practices that added it. For SaaS scope they are frequently more efficient than a Big 4 engagement at comparable rigour.
Best fit. When you need the report and already have your controls in order.
Caveats. They are auditors. Independence rules mean they cannot design your controls or fix your gaps, so if you are not ready, engaging them first simply tells you that at your expense.
What they do well. Bench depth, brand recognition that satisfies internal governance, and the ability to handle group structures and regulated entities.
Best fit. Large or regulated organisations, or where procurement requires the name.
Caveats. Pricing sits well above what most startups expect, and the partner who scopes the work is rarely the person delivering it. Their audit and advisory arms are separate for good reason, so you are still buying two engagements.
What they do well. Ottawa-based with CISSP and GIAC-credentialed leadership, publishing a floor price, which almost nobody in this market does. They write openly about the difference between a dashboard and a programme, which is the right critique.
Best fit. Buyers wanting a build-and-operate relationship rather than a one-off project.
Caveats. Their published entry point is materially higher than a productized readiness sprint, which suits a full programme and less so a company that needs a gap analysis first.
What they do well. One of the longer-established Canadian security firms, with managed services running alongside the advisory work. If you want compliance preparation and ongoing monitoring bought from one organisation, that combination is genuinely useful.
Caveats. A broad services business has a different centre of gravity than a firm that only does readiness. Ask who specifically will run your engagement and how many SOC 2 programmes they have personally taken through to a report.
What they do well. Positions on senior-level delivery rather than leveraged teams, which is the right axis to compete on for work of this kind.
Caveats. Less public detail on pricing and on framework coverage than several firms above, so both are worth establishing on the first call.
What they do well. Vancouver-based, running managed compliance programmes with a monthly cadence and a platform included, across SOC 2 and ISO 27001.
Best fit. Companies that want somebody to hold the programme continuously rather than deliver and leave.
Caveats. The managed model is a recurring commitment. If you want a defined piece of work with an end, say so early.
What they do well. Hold the control set, automate part of evidence collection from cloud and identity providers, and give you a dashboard that management can read.
Best fit. Organisations maintaining several frameworks continuously, with someone whose job includes compliance.
Caveats. Automation covers a minority of controls, and generally the ones you already pass. What fails audits is organisational: reviews that never ran, controls nobody owns. Most buyers end up paying for the platform and for help using it. A client who priced one and ran the programme without it.
What we do well. Fixed scope, published prices from $2,500, and the whole thing runs in traztech Workspace, which is free and which you keep afterwards. Our founder took a venture-backed company from no compliance programme at all to a SOC 2 Type II across 76 controls with zero exceptions, and the work is led by a researcher with five published CVEs including a CVSS 9.1 in the Mirai botnet. We run SOC 2 alongside ISO 27001 where both are needed, and we handle programmes where physical sites are in scope, not only software.
Best fit. Companies that want a number before committing, one accountable person rather than a rotating bench, and somebody who will say Type I is enough for now when it is.
Caveats, and we mean them. We are deliberately small. A hundred-person engagement across multiple business units is a Big 4 job and we will tell you so. We do not issue reports, so you are still engaging an audit firm. And we are not the cheapest option in this market; if price is the only variable, a platform subscription and your own effort will cost less, and for some companies that is genuinely the right answer.
Ranges below are drawn from Canadian firms and cost studies that publish them, in Canadian dollars, for a first-year SOC 2 programme. They are the market, not our prices. Ours are separate and published on the pricing page.
| Tier | First-year consulting | What you get | Where it fits |
|---|---|---|---|
| Boutique / specialist | CAD $15,000 to $40,000 | A small senior team, usually one named operator, fixed scope | Startups and SMEs on a first report |
| Full-service consultancy | CAD $40,000 to $85,000 | Assessment, build and first audit cycle, larger delivery team | Mid-market, several frameworks at once |
| Big 4 | CAD $80,000 to $200,000+ | Brand on the engagement letter, board-level reporting | Enterprises with procurement mandates |
| The audit itself | CAD $10,000 to $40,000 | Paid to the CPA firm, never to your readiness partner | Every path above |
| Compliance platform | CAD $5,000 to $25,000 per year | Evidence automation and a control dashboard | Optional, and optional for longer than vendors suggest |
Published all-in estimates for a Canadian SME of roughly 20 to 75 people put a first-year Type II somewhere between CAD $40,000 and $120,000 once consulting, audit, tooling and internal time are counted, settling to something like CAD $25,000 to $60,000 a year afterwards. Those figures assume the full-service tier. A boutique engagement with a right-sized audit firm lands well below them, which is the whole reason the boutique tier exists.
Two things those ranges hide. The first is that the audit fee is not fixed by the market: across four firms quoting one identical scope on a recent engagement, the highest number was 2.1 times the lowest. The second is that readiness changes the audit price rather than merely adding to it. On another engagement the audit firm revised its own quote down by $11,000 once the readiness position was documented and a prep firm confirmed, because there was less uncertainty left to price. Neither of those is visible to a first-time buyer comparing proposals side by side.
Three numbers, and they are separate.
Readiness. Ours starts at $2,500 for a gap analysis with the full SOC 2 track published on our pricing page. Truvo publishes from CAD $25K for a build. Most firms do not publish at all.
The audit. Paid to the CPA firm, never to your readiness partner. This is where buyers get surprised. Across four firms quoting one identical scope on a recent engagement, the highest quote was 2.1 times the lowest. That spread is almost never about quality; it is about what each firm assumed. What drives that spread.
Tooling. Optional. A compliance platform is typically a five-figure annual subscription. Our workspace is free, and if you already run a commercial platform we will work inside it.
One thing worth knowing because nobody advertises it: being demonstrably ready reduces the audit fee. On a recent engagement the firm took $11,000 off a five-figure quote once the readiness position was evidenced and a prep firm was confirmed. That is not a negotiated discount, it is a smaller estimate because there was less uncertainty to price. How that worked.
No, and you should avoid any arrangement that looks like it. The CPA firm issuing the report has to stay independent of what it examines, so it cannot design your controls or build your evidence. Readiness and audit are two engagements with two firms, by design.
Three separate costs: readiness, the audit itself, and optional tooling. Readiness starts from $2,500 with us and published floors elsewhere run considerably higher. The audit is billed by the CPA firm and varies widely; across four firms quoting one identical scope, the highest was 2.1 times the lowest. Tooling is optional and typically a five-figure annual subscription.
Not for a first or second SOC 2. Automation covers a minority of controls, generally the ones you already pass, while what fails audits is organisational. If you maintain several frameworks continuously with dedicated staff, a commercial platform earns its money.
Type I for most first-time companies. It attests that controls are suitably designed at a point in time, so it is achievable now and unblocks the buyer conversation. The same control set then runs through an observation window and becomes the Type II, provided the controls were built to produce evidence.
Our track is 75 days of preparation, a window we have hit every time we have run it. The binding constraint on a Type II is usually the observation period rather than the control work, which is why the window should be chosen before anything starts.
The observation window being chosen after the work begins. A Type II covers a period and evidence has to exist across it, so a control implemented last week cannot produce three months of history no matter how well designed it is.
Frequently yes, and it is usually cheaper than doing them a year apart. A large share of ISO 27001 Annex A maps onto the SOC 2 common criteria, so the control and evidence work is done once. What ISO adds is the management system: risk methodology, Statement of Applicability, internal audit and management review.
Yes. There is no minimum stage and no minimum headcount. What matters is whether security or compliance is on your critical path, which for some pre-seed companies it already is because an enterprise pilot is waiting on it.
No. SOC 2 is an attestation report issued by a licensed CPA firm under AICPA standards, not a certificate issued by a certifying body. There is no SOC 2 certificate and no organisation that grants one, which is why a firm advertising SOC 2 certification is worth a second look. The report states what the auditor observed about your controls over a point in time or a period.
Only a licensed CPA firm operating under AICPA rules. A cybersecurity consultancy cannot issue the report regardless of how much of the preparation it did, and independence rules prevent the firm that designed your controls from attesting to them. That separation is a requirement rather than a market convention.
Scopes which Trust Services Criteria your buyers need, runs a gap analysis against the real environment, writes the policies, fixes what is failing, stands up evidence collection so it accumulates across the observation window, and manages the auditor relationship through fieldwork. What they do not do is issue the report.
It depends on who is asking. North American enterprise buyers usually ask for SOC 2. European and international buyers, and public tenders, more often ask for ISO 27001. If both appear in your pipeline, running them together is materially cheaper than sequencing them, because a large share of Annex A maps onto the common criteria and the evidence is gathered once.
At the boutique tier, plan for consulting in the CAD $15,000 to $40,000 band, an audit fee of CAD $10,000 to $40,000 depending on scope and firm, and tooling only if you genuinely need it. Get the audit quote before committing to a readiness budget, because the audit is the number that varies most and it is the one you control least.
Four steps, and the first two cost nothing.
Establish which report you need. Type I or Type II, which Trust Services Criteria beyond Security, and whether a specific buyer has already told you what they will accept.
Choose the observation window before anything else. Everything downstream is scheduled against it.
Send every audit firm the same package. Written scope, system description, target window, in-scope systems, headcount including contractors with production access, and an honest statement of where your evidence stands. Then ask each what they assumed about anything you left out. Most of the price spread disappears at that point.
Pick your readiness partner on fit, not on the headline. Ask who does the work, what the deliverable is, and what is excluded.
If you want to see where you stand before speaking to anybody, our auditor evidence request simulator runs the evidence request an auditor would send and gives you the gap list. How it works covers what an engagement involves phase by phase, and the cost hub has every cost breakdown we have written.
Most SOC 2 consultants expect you to arrive with a compliance platform already bought, or they resell you one. It is a separate annual number on top of the fee. Ours is not.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.