Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

SOC 2 Consultant in British Columbia: How to Choose

If you are searching for a SOC 2 consultant in British Columbia, you are likely staring down a security questionnaire from an enterprise prospect, a board that wants proof of controls before the next funding round, or a renewal deadline that snuck up on you. The short answer: look for a firm that runs fixed-scope gap analyses, is independent from the CPA who ultimately signs your report, has genuine hands-on experience with the Trust Services Criteria, and can show you a clear, dated path from where you are today to an audit-ready state. Avoid consultants who blur the line between prep and attestation, quote vague "it depends" pricing, or push you toward tooling before they have even looked at your environment.

Why British Columbia companies are searching for SOC 2 help right now

Vancouver's SaaS and fintech scene has matured to the point where enterprise buyers in the US and Canada simply will not sign without a SOC 2 report attached to the vendor security review. If you are a B2B SaaS company based in Vancouver, Victoria, Kelowna, or Surrey and trying to move upmarket into US enterprise accounts, the trigger is almost always the same: a security questionnaire lands in your inbox, or a procurement team flags "SOC 2 certification" as a blocker in the deal cycle. Sometimes it is investor-driven, a term sheet contingent on demonstrating security maturity before close. Either way, the clock is already running, and the company usually has no internal bandwidth to figure out the Trust Services Criteria from scratch while also closing the deal.

That urgency is exactly where a good SOC 2 consultant earns their fee, and where a bad one wastes your quarter.

What a SOC 2 consultant actually does (and does not do)

A SOC 2 consultant is a readiness partner, not the auditor. Their job is to assess your current controls against the Trust Services Criteria, identify gaps, help you remediate them, and prepare your evidence package so the audit itself goes smoothly. The actual SOC 2 report is issued by an independent, licensed CPA firm. That separation matters: a consultant who also signs your attestation report has a conflict of interest, and any credible CPA firm will flag it. Reputable prep firms coordinate with an independent CPA on your behalf rather than trying to be both the coach and the referee.

This is worth stating plainly because it is the single most common point of confusion in the BC market. If a firm tells you they can "do your SOC 2 audit" end to end under one roof, ask directly who signs the report and whether that person is independent of the prep team.

Red flags to watch for when evaluating BC-based (or BC-serving) consultants

  • Vague, unbounded pricing. If a firm cannot give you a fixed scope and fixed price for a gap analysis before you sign anything, that is a sign the engagement will balloon once it starts.
  • No separation between prep and attestation. As noted above, the firm assessing your gaps should not also be the one issuing your report.
  • Tooling-first sales pitches. Some vendors lead with a GRC platform subscription before they have assessed your actual control environment. Software can help track evidence, but it does not replace a real gap analysis done by someone who understands your business.
  • No named security expertise. Ask who on the team will actually perform the assessment, and what their background is. A firm staffed entirely by generalist consultants is a different proposition than one led by someone with real applied security research experience.
  • One-size-fits-all templates. Your controls should reflect how your engineering team actually operates, not a generic policy pack copied across every client.
  • Silence on remediation scope. A gap analysis that ends with a PDF and no plan for who fixes what, and by when, leaves you exactly where you started.
Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

Questions to ask before you hire

Bring these to any discovery call with a prospective SOC 2 consultant serving British Columbia:

  • Is the gap analysis fixed-scope and fixed-price, or time and materials with no ceiling?
  • Who performs the assessment, and what is their direct security background?
  • Do you coordinate with an independent CPA firm for the actual attestation, or do you issue reports yourselves?
  • What does the remediation phase look like once gaps are identified, and is it scoped separately from the initial assessment?
  • Can you work with a team that is mostly remote or distributed across Canada and the US, since much of Vancouver's tech workforce is?
  • How do you handle Type I versus Type II readiness, and what is realistic for our timeline given the deal or renewal we are facing?
  • Do you have experience with PIPEDA and, if relevant, Quebec's Law 25, alongside SOC 2, since many BC companies serve customers across Canada as well as the US?

A consultant who answers these clearly and specifically, without hedging, is one worth taking further. For a broader comparison of how prep firms across the country stack up on scope, pricing model, and independence, see our guide to the best SOC 2 consultants in Canada.

Why boutique often beats platform for BC scale-ups

Large compliance platforms are built to serve thousands of companies with standardized workflows, which works fine if your environment is simple and your team has bandwidth to run the software yourself. Many BC scale-ups do not have that bandwidth, and their environment is not simple, especially once you factor in multi-cloud infrastructure, contractor-heavy engineering teams, or products with real security surface area like fintech APIs or health data integrations.

A boutique Canadian prep firm can spend real time understanding your architecture before recommending controls, rather than mapping you into a generic template. That matters most when your internal champion, often a CTO or head of engineering, has finally secured budget and needs the engagement to actually move the needle before the next board meeting or renewal date, not just produce a binder of policies nobody follows.

How traztech approaches SOC 2 readiness

traztech is a Canadian security and compliance consultancy led by Jacob Masse, a published security researcher credited with five CVEs, including CVE-2024-45163, a CVSS 9.1 vulnerability that functioned as a kill-switch against Mirai-based botnets. We work with companies across Canada, including Vancouver and the broader British Columbia tech corridor, as the readiness and preparation partner, not the auditor.

Our engagement model starts with a fixed-scope gap analysis: we assess your environment against the Trust Services Criteria, document exactly where you stand, and give you a clear picture of what needs to change. Remediation work is scoped separately once you know what you are actually dealing with, so you are never signing up for an open-ended retainer before you understand the size of the problem. When you are ready for attestation, we coordinate with an independent CPA firm to issue your SOC 2 report, keeping prep and audit properly separated the way a credible engagement should be.

This structure exists because rushing a SOC 2 program to satisfy a single enterprise deal or investor deadline, without understanding your actual gaps first, tends to cost more time and money than doing the assessment properly up front.

Get a clear picture before you commit to anything

If a security questionnaire, an investor, or a compliance deadline has put SOC 2 on your desk, the fastest way to de-risk the decision is to start with an assessment, not a sales pitch. Book a free readiness call with traztech and get a straight answer on where your British Columbia company actually stands against the Trust Services Criteria, what a realistic timeline looks like, and what a fixed-scope engagement would cost before you commit to anything. Or if you would rather talk through your specific deal timeline or renewal date first, contact us and we will walk you through how the process works.

BC has its own privacy law, and consultants who miss that will miss controls

A detail that gets skipped in generic SOC 2 guidance written for the whole country: British Columbia is one of three provinces with private-sector privacy legislation deemed substantially similar to PIPEDA, so a BC company handling the personal information of BC residents in the course of commercial activity is generally governed by BC's Personal Information Protection Act rather than PIPEDA, with PIPEDA still applying to information crossing provincial or national borders and to federally regulated work. If a consultant tells you your only Canadian obligation is PIPEDA and never mentions PIPA, they are working from a national template rather than your situation.

This matters to SOC 2 in a practical way. The Trust Services Criteria include a Privacy category that most companies leave out of scope, and leaving it out is usually the right call. What you cannot leave out is the obligation itself, because your buyer's data processing agreement will reference it and your questionnaire will ask about breach notification, retention, and access requests. Building your access control, retention, and incident response controls once, in a way that satisfies both the Security criteria and your PIPA duties, is meaningfully cheaper than doing two passes.

There is a second BC-specific wrinkle if you sell to public bodies. Health authorities, post-secondary institutions, ministries, and Crown corporations operate under the Freedom of Information and Protection of Privacy Act, and their procurement processes ask questions a US-focused SOC 2 report does not answer on its own: where personal information is stored and accessed from, which subprocessors can reach it, what the privacy impact assessment says, and what happens on contract termination. If a meaningful share of your pipeline is BC public sector, tell any prospective consultant that on the first call and watch whether they know what a PIA is. Companies that sell to both US enterprises and BC public bodies are running two different buyer motions and the readiness work should be scoped for both. Our compliance practice treats those as one program rather than two, because the underlying evidence is largely the same.

What a gap analysis deliverable should actually contain

The word "gap analysis" covers everything from a two-hour call and a spreadsheet to six weeks of architecture review. Ask to see a redacted example before you sign anything, and check it for these things.

A control-by-control mapping against every criterion in scope, with a current-state finding for each, not just the ones that failed. You want to know what is already fine, because that is what stops you rebuilding working controls. A severity ranking that distinguishes what blocks attestation from what is good hygiene, since treating those as equal is how a four-week remediation becomes four months. Named artifacts for each gap, meaning the specific policy, log export, or configuration change that closes it, rather than a restatement of the criterion in the imperative. An owner column, because a finding without a name attached does not get fixed. A scope recommendation that says plainly which criteria beyond Security you should include and why, with the cost consequence spelled out. And a realistic date for auditor engagement, including the observation window if you are heading to Type II.

If the sample deliverable is mostly the text of the Trust Services Criteria with a red, amber, or green tag beside each line, you are looking at a template, and you can generate that yourself from a platform trial for far less money.

The total cost of the first fourteen months

The consultant's fee is one of four numbers, and quoting only the first is how BC scale-ups end up over budget in month nine. Budget for the readiness engagement, which for a fixed-scope gap analysis starts at $3,000 on our published pricing. Budget separately for remediation, which is either your engineers' time taken off the roadmap or a scoped delivery engagement, and which is genuinely unknowable until the gap analysis is done, which is precisely why anyone quoting remediation before assessing you is guessing. Budget for the CPA firm's examination fee, which is theirs and not your consultant's, and which varies with your scope, your headcount, and whether it is Type I or Type II. And budget for tooling if you decide you want it, keeping in mind that an evidence platform subscription is an ongoing cost that does not replace any of the other three.

The number people forget entirely is internal time. Someone on your team will spend real hours in walkthrough calls, pulling exports, and chasing colleagues for training completions. On a lean BC engineering team that is usually the person you least want distracted. Deciding up front how much of that you are willing to hand to a partner is a scoping decision worth making deliberately rather than discovering in week five.

Will US buyers accept a report signed by a Canadian CPA firm

This comes up on almost every first call in Vancouver, because the pipeline is usually American. The examination is performed under the attestation standards a licensed CPA firm is authorized to work under, and reports issued by qualified Canadian firms are routinely accepted by US buyers. Occasionally a US procurement team unfamiliar with cross-border reports asks a question about it, and the answer is a short note explaining the standard and the firm's licensing.

The questions worth asking your prospective auditor are more mundane than nationality. How many reports of your type and size do they issue a year. What is their lead time to start fieldwork, which in practice determines your date more than your readiness does. What does their evidence request list look like, since some firms send a portal and some send a spreadsheet and the difference is weeks of your life. And what happens if fieldwork surfaces a control that was not operating, because you want to know their exception handling posture before you are living it. A readiness partner who has worked with several firms should be able to tell you which of them fit your stack, and should be willing to introduce you to more than one.

The contractor-heavy engineering team problem

Vancouver's engineering market runs on a higher proportion of contractors, agency partners, and distributed staff than most Canadian cities, and that shows up in readiness work more than anything technical. The controls that break are onboarding and offboarding evidence, background screening where you have committed to it in a customer contract, security awareness training completion for people who are not in your HR system, and confidentiality agreements for individuals engaged through a corporation rather than directly.

The fix is not complicated but it has to be decided before the observation window opens. Pick one system of record for every human with access, contractors included, and make access provisioning flow from it. If your HR platform cannot hold contractors, use the identity provider as the source of truth and reconcile against it quarterly with a saved export. An auditor sampling ten access grants and finding one belonging to a person nobody can identify is a routine outcome of not making this decision, and it is a routine cause of a first-year exception.

When you should not hire a SOC 2 consultant at all

Three cases, and we would rather say them here than on a discovery call after you have spent two weeks evaluating firms.

Nobody has actually asked for SOC 2. If this is on your desk because a board member said you should have it, or because a competitor has one, you are buying a sales asset rather than solving a blocker. That can be a legitimate decision, but price it as marketing spend and time it around your fundraising or pipeline, not around a deadline that does not exist.

Your environment is genuinely simple and someone competent has time. A team on a single cloud account, one identity provider, managed laptops, and no on-premises anything can often get to Type I readiness with a platform subscription, a good template set, and a determined operations lead who has done it before. Consultants earn their fee on judgment calls about scope, on architecture that does not fit the template, and on speed. If none of those apply to you, keep the money.

The real requirement is one questionnaire and a penetration test. Ask your champion, in writing, what would satisfy their security team for this specific contract. A surprising share of "we need SOC 2" turns out to be a completed vendor questionnaire, a current penetration test, and one technical call. That path starts around $1,000 for testing and takes weeks, and if it closes the deal, chasing an attestation you were not asked for is a spectacular way to spend a quarter.

If you are unsure which of those describes you, that is a five-minute conversation rather than an engagement. Tell us what the buyer asked for and we will tell you which one it is, including when the answer is that you do not need us yet. If the answer is that this will keep happening, the honest recommendation is usually continuous coverage rather than a one-off, and our retainer options explain what that involves.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.