Once you decide you need SOC 2, the next problem shows up fast: who should you hire to help. Search for a SOC 2 consultant in Canada and you will find software platforms, global audit firms, solo practitioners, and full-service prep partners, all using similar language and all promising to get you compliant. They are not the same, and picking the wrong one costs you time, money, and sometimes a failed audit.
Here is how to tell them apart and choose well.
First, know what you are actually hiring
The single most important thing to understand is that the firm which prepares you for SOC 2 cannot be the same firm that signs your report. That independence is built into the standard. So the market splits in two. Auditors are licensed CPA firms that issue the report. Prep partners get you ready for that report. A good prep partner also helps you choose and coordinate the auditor, but they do not sign it. If someone claims to do both, walk away.
The criteria that actually matter
Do they do the work, or just sell you software. Compliance platforms are great at tracking controls and collecting evidence, but they do not write your policies, decide your scope, or close a failing control. Plenty of teams buy the tool, reach sixty percent, and stall. Make sure the person you hire actually does the hands-on work, with or without a tool.
Fixed scope, not an open meter. SOC 2 readiness is a well-understood project. A good partner can scope it and quote it, so you know the deliverable, the timeline, and the price before you start. Be cautious of open-ended hourly arrangements where the incentive is to take longer.
Real technical depth. SOC 2 is a security standard, and the controls have to survive a buyer whose engineers will poke at them. A partner with genuine security expertise designs controls that reflect how attackers actually behave, not just paperwork that looks right. Ask who on the team has hands-on security experience.
They understand the Canadian context. Auditor fees and tooling are usually priced in US dollars, and a lot of the SOC 2 work overlaps with Canadian privacy law under PIPEDA and Quebec Law 25. A partner who works with Canadian companies will help you scope the audit sensibly and avoid building the same evidence twice.
They work with your stack and your tools. If you already have Vanta or Drata, your partner should build on top of it, not force a restart. If you have nothing, they should be able to stand it up.
Red flags
- They promise a specific price or timeline before understanding your systems
- They claim they can also be your auditor
- They quote a suspiciously round, very low number that will balloon later
- They cannot explain the difference between Type I and Type II in plain language
- They lean entirely on a software platform and cannot tell you what they will actually do by hand
Questions to ask on the first call
- Are you preparing us, coordinating the auditor, or both, and who signs the report
- Is your fee fixed for a defined scope, and what is in that scope
- Who on your team has hands-on security experience
- How do you handle the overlap with PIPEDA and Law 25
- What exactly do you need from our team, and how much of their time
How we approach it
We are a Toronto team, and we are the prep partner, not the auditor. Our founder is a published security researcher with five published CVEs, including CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet, so the controls we build are designed by someone who understands real attacks. We quote fixed scope, we work with or without a compliance platform, and we coordinate the independent auditor for you. When a penetration test is needed as evidence, we run it with our partner Lorikeet Security.
If you want to see how the full program works, visit our compliance page, or read the playbook for SOC 2 for Canadian SaaS. When you are ready to talk, book a free readiness call and we will give you a straight answer on scope, timeline, and cost.
The four things you might be buying
The market looks confusing because four different products are sold under the same search term. Once you can name which one a vendor is selling, the pricing stops looking arbitrary.
A compliance platform. Vanta, Drata, Sprinto and their competitors sell software that connects to your cloud and identity providers, tests configuration continuously, stores evidence and tracks control status. Priced as an annual subscription, usually low five figures for a small company, and quoted in US dollars. What it does well is collect evidence and stop you from losing track. What it cannot do is decide your scope, write policies that reflect how your company actually works, or fix a failing control. Teams who buy only the platform typically get most of the way through the checklist and then stall on the items that require judgment.
A solo practitioner. An experienced individual, often a former auditor or security lead, working hourly or on a monthly retainer. Frequently excellent value and frequently the right answer for a straightforward environment. The risks are capacity and continuity: one person with four clients in the same audit month, and no cover if they are ill during your fieldwork. Ask how many engagements they are running concurrently and what happens if they are unavailable for two weeks.
A prep partner. A firm that does the readiness work, produces the artifacts, coordinates the auditor and sits in the buyer conversations. Priced by scope rather than by hour if they know what they are doing. This is what we sell, so weigh the description accordingly, and the honest test of whether you need it is whether the work is going to get done otherwise.
A large advisory or audit firm's readiness arm. Real bench depth, strong brand recognition with enterprise buyers, and a price that reflects both. Independence rules mean they cannot both prepare you and issue your report, so a firm offering readiness will hand you to a different firm for the audit. This route makes sense when your buyer specifically wants a recognizable name in the room or when your environment is genuinely complex, and it is usually poor value for a 30-person SaaS company.
Ask about scope before you ask about price
Quotes are not comparable until scope is defined, and scope is where the money is. Five decisions drive the number, and a partner who does not raise them on the first call is quoting on assumptions you have not seen.
Which trust services criteria. Security is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional, and each one you add brings more controls, more evidence and more audit hours. The right approach is to read what your customers are actually asking for. Most enterprise buyers ask for Security and Availability. Adding Privacy because it sounds thorough is a common and expensive mistake, particularly when the privacy obligations you actually face come from PIPEDA and Quebec Law 25 and are better addressed directly.
The system boundary. Which product, which environments, which supporting systems. A boundary drawn around one production platform is a different engagement from one that covers three products and a legacy environment nobody wants to touch. Draw it deliberately and be able to justify it, because the boundary is the first thing an auditor tests and the first thing a sophisticated buyer questions.
Subservice organizations. Your cloud provider, your payroll platform, your managed database vendor. You choose whether to carve them out of your report, which is normal and which puts the burden on you to describe the complementary controls you rely on, or to include them, which almost nobody does. Your consultant should have an opinion and be able to explain it in a sentence.
Type I or Type II. A Type I attests to design at a point in time and can be produced quickly. A Type II attests to operating effectiveness across a window, typically three months for a first report. Buyers increasingly say Type II or nothing. If a partner steers you to Type I without explaining that you will be back for a Type II within the year, they are optimizing for a fast delivery rather than for your buyer.
Whether a penetration test is in scope. SOC 2 does not mandate one, but plenty of buyers do, and many organizations describe testing within their control set and are then held to it. Decide early, because the report and the remediation have to land inside the observation window. We run testing from $1,000 depending on scope.
What the whole thing costs, not just the consultant
The consultant's fee is one line of five, and comparing consultants without the other four leads people to the wrong choice.
Readiness work is the first line. Ours starts at $3,000 for a gap analysis, which produces a documented position on where you stand and what closing the gaps requires. That document has value beyond the project: one client used their readiness position to take $11,000 off an audit quote, because the auditor could see exactly what they would be walking into. Our fixed-scope pricing exists so you can compare like with like.
The platform subscription is the second, if you use one, and it is usually quoted in US dollars, so budget the exchange rate rather than the sticker.
The auditor fee is the third, also generally in US dollars for the firms most Canadian companies use, and driven by scope, criteria count and how clean your evidence is. This is the line most affected by good preparation, because auditors price uncertainty.
Remediation engineering is the fourth and the one nobody budgets. If your gaps include centralizing logging, introducing single sign-on across every tool, building an access review process or separating environments, that is engineering weeks from your own team. It is the largest hidden cost in most SOC 2 programs and it is why the "how much of our team's time" question matters more than the quote.
Ongoing maintenance is the fifth. A Type II report covers a window and then expires, so this becomes an annual obligation with continuous evidence collection in between. Ask what year two looks like and what it costs before you sign year one.
Reference checks that actually tell you something
Every firm has three happy clients on speed dial. Ask for something else.
Ask to speak to a client whose audit produced exceptions, and ask that client how the firm behaved when it happened. Exceptions are normal and how a partner handles one is the most useful signal available.
Ask which auditors they have worked with in the last year and whether they will introduce you to one of them directly. A prep partner who is genuinely coordinating audits has those relationships and will not mind you talking to the other side. If they resist, ask why.
Ask a former client, not a current one, whether they could maintain the program after the engagement ended. The failure mode you are screening for is a partner who builds a program only they can operate, so year two requires them again at full price.
And ask any prospective partner to describe a control they told a client not to implement. Anyone can add controls. Knowing which ones are not worth the operating cost at your size is the harder skill, and the answer tells you whether you are hiring judgment or a checklist.
How these engagements go wrong
Four failure patterns account for most of the unhappy outcomes we hear about.
Policies that describe a different company. A consultant delivers twenty polished documents in week two, drawn from a template library. They read well and they say your change management process requires two approvals when in practice one engineer merges their own work. During fieldwork the auditor compares the policy to the evidence, finds the mismatch and records an exception. The policy set has to describe what you actually do, and where the practice needs to improve, the improvement has to happen before the window opens rather than being written into a document as an aspiration.
The population problem. Type II testing works on populations and samples. The auditor asks for a complete list of every employee onboarded in the window, every change deployed, every access request granted. If you cannot produce a complete and verifiable population, the auditor cannot sample it, and the control cannot be tested. Companies discover this in week two of fieldwork when the deployment log turns out to cover only one of three repositories. Ask your partner, early, which populations you will need to produce and where each one will come from.
Evidence collected at the wrong time. A control that operates quarterly needs evidence from within the window, dated, with the reviewer identifiable. Screenshots taken retroactively in the last week of the window are visible for what they are. This is the single most common cause of a delayed report.
Nobody internally owns it. The consultant needs decisions, access and answers. If the internal counterpart is a founder with no spare hours, the project stalls and both parties blame each other. Name the internal owner and protect their time before the engagement starts. Realistically, budget several hours a week from that person across the readiness period, with heavier weeks around fieldwork.
What happens if the report comes back with exceptions
Founders imagine a pass or fail. SOC 2 does not work that way. The auditor issues an opinion, and exceptions are described in the report along with management's response. A qualified opinion is unwelcome but it is not the end, and a report with a small number of well-explained exceptions and a credible remediation plan is routinely accepted by buyers.
What matters is how the exception reads. An exception with a documented cause, a fix already implemented and a date is a company that noticed and acted. The same exception with a defensive management response is a company that argues with its auditor. Your prep partner should be drafting that response with you, and their willingness to do so is worth asking about before you sign, because it is the moment their work is actually visible.
Agree in advance what happens if the report is delayed or qualified because of something within the partner's control. Not a penalty clause, which nobody enforces, but a stated position on whether remediation support is included or billed again.
Look one framework ahead before you commit
If ISO 27001 is anywhere in your future, raise it on the first call. The frameworks overlap heavily in the underlying work, and the expensive parts of any compliance program are evidence collection and remediation. Running them a year apart means doing both of those twice, and it leaves you with two sets of evidence produced at different times by different people, which tend not to agree in ways an auditor notices. ISO 27001 brings 93 Annex A controls plus clauses 4 to 10, and a partner who knows both can build the control set once. Our ISO 27001 implementation work is designed to run alongside SOC 2 for exactly this reason.
The same logic applies to PIPEDA and Quebec Law 25. Ask any prospective partner how they would map the evidence across whatever combination applies to you. If the answer is that each framework is a separate project, you are looking at paying for the same access reviews three times.
When you should not hire anyone
Plenty of companies do not need a consultant, and we have told several so.
If you have a technical founder or a senior engineer with genuine interest, a simple single-product environment on one cloud, fewer than about twenty-five people, and six months before the report is needed, buy a platform, engage an auditor directly, and do the work yourselves. The framework is documented, the platform will tell you what is missing, and the money you save covers the audit fee. What you are trading is calendar time and founder attention, so be honest about whether those are available.
If a single prospect is the whole reason, ask them what they will actually accept. Buyers often accept a documented readiness position with dates, a recent penetration test and a completed questionnaire while the observation window runs. That conversation costs nothing and occasionally removes the deadline entirely, which changes what you should buy.
If nobody internally has hours for the next quarter, wait a quarter. A readiness engagement running against an absent counterpart burns budget and goodwill and ends where it started.
And if you have already reached seventy percent on a platform, do not restart. Buy a short, scoped engagement aimed only at the remaining thirty percent, which is usually policy alignment, the populations problem and two or three engineering gaps. Paying for a full program at that point is paying twice for work you have already done. If you want a free place to keep the evidence and documents while you figure out which of these you are, our Workspace is available without an engagement.
Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.
See SOC 2 in 75 DaysOr talk about a retainer