Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

SOC 2 Consultant in Alberta: How to Choose

Direct Answer: What to Look For in a SOC 2 Consultant in Alberta

If a security questionnaire, an enterprise procurement team, or an investor just told your Calgary or Edmonton SaaS company that a deal or a round is contingent on SOC 2, you are on the clock and probably do not have an in-house team that has run this process before. The right SOC 2 consultant in Alberta is not the firm that issues your report. It is a fixed-scope readiness partner who runs a gap analysis against your actual environment, scopes remediation as a separate, priced phase, and then hands you off to an independent CPA firm to perform the attestation. If a consultant offers to "do your SOC 2" end to end, including signing the report themselves, that is the first red flag, not a selling point. This guide covers what to check for, the questions to ask before you sign anything, and why boutique Canadian firms like traztech are built specifically for this handoff model rather than the all-in-one bundle.

Why Alberta Companies Are Feeling This Pressure Now

Calgary's energy-tech and fintech scale-ups and Edmonton's AI and health-data startups are increasingly selling into US enterprise accounts, and enterprise procurement in 2026 treats SOC 2 as table stakes, not a differentiator. The trigger is almost always the same: a security questionnaire lands mid-deal, a board or Series A term sheet names compliance as a condition, or an existing SOC 2 report is about to lapse and renewal has to happen on a hard deadline. In each case, the founder or CTO who now owns this has weeks, not months, to find a partner, and the wrong choice burns both time and the deal.

Alberta does not have the density of dedicated SOC 2 boutiques that Toronto or Vancouver do, which pushes many companies toward large US-based GRC platforms or generalist IT consultancies that treat compliance as a side offering. Neither is automatically wrong, but neither is automatically right either. What matters is whether the firm actually understands the audit mechanics and Canadian context, including how PIPEDA obligations and, where relevant, Quebec's Law 25 intersect with your SOC 2 controls if you handle personal data across provinces.

Red Flags to Watch For

A few patterns show up consistently among consultants that are not set up to do this well, and they are worth screening for during your first call:

  • They also want to be your auditor. A legitimate SOC 2 attestation requires an independent, licensed CPA firm to issue the report. If the same firm doing your remediation work is also proposing to sign your report, that is not independence, and it will not hold up under a sophisticated buyer's scrutiny.
  • Vague, open-ended scoping. "We'll figure out the scope as we go" means uncapped hours and an unpredictable invoice. A serious readiness partner scopes the gap analysis as a fixed engagement before remediation pricing is even discussed.
  • No named security background. Compliance consulting and security engineering are related but distinct disciplines. Ask who is actually reviewing your architecture and controls, and what their background is.
  • Selling you a platform subscription as the whole answer. GRC software helps manage evidence collection, but software alone does not close control gaps, write policies that match your actual environment, or prepare your team for auditor interviews.
  • No clear remediation scoping step. If a consultant jumps straight from "we found gaps" to a single lump-sum number without breaking down what remediation actually involves, you have no way to sanity check the price.
Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

Questions to Ask Before You Sign

These questions tend to separate the firms that have run dozens of readiness engagements from the ones learning on your dime:

  • Who is the CPA firm you coordinate with for attestation, and is that relationship independent of your remediation work?
  • Is the gap analysis fixed-scope and fixed-price, or time and materials?
  • What does the gap analysis actually produce, a report and control mapping, or a real remediation roadmap I can act on?
  • Will remediation be quoted separately once the gap analysis is complete, and can I choose to do remediation with my own team instead of yours?
  • What is your team's security background beyond compliance frameworks, have you done penetration testing, vulnerability research, or hands-on security engineering?
  • How do you handle evidence collection and audit prep logistics with the CPA firm during the actual attestation window?
  • Do you have experience with Canadian data residency and privacy overlap, specifically PIPEDA and, if relevant to your customer base, Quebec's Law 25?

If you want a broader view of how Canadian SOC 2 consultants compare on these criteria, our comparison of the best SOC 2 consultants in Canada breaks down how boutique prep firms differ from platforms and large generalist consultancies across the country, including in Alberta.

Why the Prep-and-Audit Split Matters for Your Report

The strongest reason to insist on separate firms for readiness and attestation is not just a compliance technicality, it is what happens when your customers' security teams actually read the report. Enterprise buyers and their procurement teams increasingly know to check whether the same organization prepared the controls and then graded them. A report attested by an independent CPA firm, built on remediation work done by a specialist readiness partner, carries more weight than an all-in-one package where the lines are blurred. That independence is also why traztech does not issue the attestation itself. We run the fixed-scope gap analysis, scope and, if you choose, deliver remediation, and then coordinate directly with an independent CPA firm through the attestation window so your evidence, timelines, and auditor questions are handled without friction on your side.

What a Fixed-Scope Gap Analysis Actually Involves

A proper readiness engagement starts by mapping your current environment, your infrastructure, access controls, vendor relationships, and existing policies, against the Trust Services Criteria relevant to your SOC 2 scope, typically security at minimum and often availability or confidentiality depending on your product. The output should be a concrete list of gaps, not a generic checklist, prioritized by what actually blocks attestation versus what is nice to have. From there, remediation gets scoped as its own phase with its own price, so you know exactly what you are paying for and can decide whether your team handles any of it internally. This is the model traztech runs for companies across Canada, including Calgary and Edmonton teams who need a partner that understands both the audit mechanics and the realities of a lean engineering team trying to ship product while also passing an audit.

What Jacob Masse and traztech Bring to the Engagement

traztech is led by Jacob Masse, a published security researcher credited with five CVEs, including CVE-2024-45163, a critical CVSS 9.1 vulnerability that functioned as a kill-switch against Mirai-based botnet infrastructure. That is the kind of hands-on security background that separates a firm that understands attacker behaviour and real technical risk from one that only knows how to fill in a controls matrix. For Alberta companies weighing a SOC 2 consultant, that distinction matters when the gap analysis needs to catch things a checklist alone would miss, and when your engineering team needs a partner who can speak credibly to both the compliance framework and the underlying security architecture.

Get Started With a Free Readiness Assessment

If a deal, a raise, or a renewal has put SOC 2 on your desk, the fastest way to get clarity on scope, timeline, and cost is to talk to a readiness partner before you talk to an auditor. You can book a free readiness call with traztech to get a straight answer on where your Alberta company actually stands against the Trust Services Criteria and what a fixed-scope gap analysis would look like for your environment. If you have questions first, or want to talk through your specific deal timeline, contact traztech and we will walk you through how the readiness and attestation process fits together.

Alberta's Own Privacy Act Sits Underneath Your SOC 2 Scope

Most SOC 2 guidance written for a national audience defaults to PIPEDA and stops there. Alberta has its own private-sector privacy statute, the Personal Information Protection Act, deemed substantially similar to PIPEDA, and it governs how an Alberta organization handles personal information in the course of commercial activity within the province, with PIPEDA continuing to apply to information moving across provincial and national borders and to federally regulated sectors. Alberta was also early to mandatory breach reporting: where a breach creates a real risk of significant harm, the organization must report to the Information and Privacy Commissioner, and the Commissioner can require notification to affected individuals.

That has a direct consequence for the incident response control in your SOC 2 scope. A generic incident response plan that says the security team will assess severity and notify customers as appropriate does not tell anybody what to do on the day. The version that survives both an auditor and an actual incident names who makes the real risk of significant harm determination, on what timeline, what the reporting route to the Commissioner is, what your contractual notification windows are with enterprise customers, and who talks to whom first. Write it that way once and it serves the SOC 2 evidence requirement, the PIPA obligation, and the questionnaire question about breach notification simultaneously. A consultant who does not raise this is running a US template.

What Alberta Energy and Industrial Buyers Ask That SaaS Buyers Do Not

Calgary companies selling software into midstream, pipeline, utility, or large industrial operators run into a vendor review that looks different from a typical enterprise SaaS review, and it catches teams off guard because they prepared for the wrong questions.

Those buyers ask what your product can reach. If your software pulls data from a historian, integrates with a SCADA or control environment, or is installed anywhere near an operational network, the review will move quickly past the Trust Services Criteria and into questions about network segmentation, remote access paths, whether your support staff can initiate a connection inward or only receive one outbound, and what your product does if it loses connectivity. Some will reference IEC 62443 or their own internal control standard rather than any framework you have heard of. A SOC 2 report is necessary and not sufficient here, and a readiness partner who only knows the compliance framework will not help you answer the architecture questions.

They also ask contractual and insurance questions early. Master services agreements with large Alberta operators frequently carry a security exhibit with specific requirements attached: notification windows measured in hours, right-to-audit clauses, subcontractor approval, data location commitments, and cyber liability limits that may exceed what your broker currently has you at. Read that exhibit before you scope your readiness work, because it tells you exactly which controls are contractual obligations rather than nice-to-haves. It is not unusual for the exhibit to demand something the SOC 2 scope you were planning would never have covered.

Picking the Observation Window Around Your Own Calendar

Type II is measured over a period, and companies pick that period carelessly. Two scheduling realities are worth planning around.

The first is auditor availability. CPA firms are busiest at calendar and fiscal year ends, and lead times to start fieldwork stretch accordingly. If your deal needs a report in hand by a particular month, work backwards from the auditor's fieldwork slot, not from when you finish remediation, because the fieldwork slot is the constraint you do not control. Book the firm before your window opens rather than after it closes.

The second is your own operational calendar. Every company has a period when controls quietly stop operating: a funding close, a major release, a rebuild of the data platform, a hiring surge. Whatever that period is for you, an observation window that contains it will surface exceptions, because that is the month the quarterly access review slips and the change approvals get done verbally in a war room. You cannot always avoid it, but you can decide in advance who is responsible for keeping the recurring controls alive through it, which turns a likely exception into a boring calendar entry.

How Evidence Decays During the Window

The most common way a well-prepared company still gets a finding is that the controls were designed properly, operated for two months, and then drifted. The pattern is consistent enough to plan against.

Access reviews get performed once, thoroughly, and then not again, because the person who ran the first one assumed it was a project rather than a recurring control. Change management holds until an urgent production fix goes out at midnight with no ticket, and then a second one, and by month four the deployment log and the approval record no longer agree. New vendors get signed by whoever needed them without touching the vendor register, so the auditor finds a subprocessor in your infrastructure that does not exist in your documentation. Security awareness training gets completed by the people who were there at kickoff and not by the six people who joined afterwards. Logging quietly stops on a service that was rebuilt.

None of that is a security failure and all of it is an audit failure. The countermeasure is unglamorous: put a named owner and a calendar date on every recurring control, review the list monthly for fifteen minutes, and capture evidence at the moment the control runs rather than reconstructing it during fieldwork. A free place to keep that evidence is the traztech Workspace, which you can use whether or not you engage us for anything.

Working With a Consultant Who Is Not in Alberta

Since Alberta has fewer dedicated readiness boutiques than Toronto or Vancouver, most companies here end up working with a firm somewhere else, and the reasonable worry is that remote means detached. In practice the work is remote almost everywhere now, because the artifacts are cloud consoles, identity provider configurations, repositories, ticket histories, and policy documents. Screen-shares over your actual environment tell a reviewer more than a site visit would.

What does need care is the meeting rhythm and the escalation path. Mountain time gives you a full overlapping working day with Toronto, which is more than you get with most US firms. What to insist on is a named individual rather than an account manager, a fixed weekly working session with your engineering lead in it, and a written record of decisions, since scope disputes late in an engagement almost always trace back to something agreed verbally on a call in week two. The one case where physical presence genuinely matters is an office, lab, or facility with physical controls in scope, which for a Calgary or Edmonton software company is usually a short conversation rather than a travel line item.

When You Should Not Hire Us, or Anyone

Four situations where the honest answer is no.

The buyer's requirement is their security exhibit, not a report. As above, large industrial and energy buyers often have their own control standard and their own questionnaire, and some of them will onboard you on that basis alone. Ask your champion directly whether a completed exhibit and a current penetration test would clear procurement. If it would, that is a matter of weeks and low four figures rather than a multi-month attestation program, and you can pursue SOC 2 later on your own timetable rather than theirs.

Your buyers are European or global and keep saying ISO. If the requests you receive name ISO 27001 rather than SOC 2, do not buy SOC 2 first on the theory that it is faster. You will end up doing both. Decide which framework your next four buyers actually want and start there. Our ISO 27001 implementation page sets out what that path involves so you can compare honestly.

You are about to re-platform. If you are mid-migration between clouds, replacing your identity provider, or splitting a monolith over the next two quarters, certifying the environment you are about to delete is money spent twice. Get the gap analysis done now so the new architecture is built with the controls in it, and open the observation window on the environment you will still have in a year.

You have someone internal who has done this before. An operations or engineering lead who has taken a company through SOC 2 and has bandwidth this quarter will do better work than any external firm, because they know your stack and your people. In that case buy a few hours of review on the scoping decisions and the evidence plan, not a full engagement. We would rather sell you the small thing and still be here for the audit that follows.

If none of those describe you and a deal is genuinely waiting, the useful next step is a straight conversation about scope and dates rather than a proposal. Tell us what your buyer asked for and what your deadline is, and if the answer is that you do not need a readiness partner, we will say that.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.