Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

SOC 2 Consultant vs Auditor: Why You Need Both

The Short Answer

If a security questionnaire, an investor, or a board member just told you that your company needs "SOC 2," you are about to need two different firms, not one. A SOC 2 consultant (sometimes called a readiness or prep firm) is the team that gets your controls, policies, and evidence into audit-ready shape. A SOC 2 auditor is the independent, licensed CPA firm that examines your environment and issues the actual report your customers rely on. These roles are legally and practically separate. The AICPA's independence rules mean the firm that builds and operates your controls cannot also be the firm that opines on whether those controls work. You need both, and you need them to be different companies.

traztech is the first kind of firm. We are your SOC 2 prep partner: fixed-scope gap analysis, remediation roadmap, and evidence readiness, done before you ever sit down with an auditor. When you are ready, we hand you off to an independent CPA firm that signs the report. That separation is not a technicality; it is the thing that makes the report worth anything to the enterprise buyer reading it.

Why This Confusion Costs Companies Time and Money

Most founders and CTOs encounter SOC 2 for the first time under pressure: a mid-market or enterprise prospect has sent over a security questionnaire, or a Series A term sheet has a condition around information security maturity, or a renewal deadline is closing in and the current attestation is about to lapse. In that moment, "SOC 2" gets treated as a single purchase, like buying a certificate. Teams call an audit firm expecting them to also fix the gaps, or they hire a generalist consultant expecting that person can also sign the final report. Neither works, and discovering that mid-engagement burns weeks you do not have.

The practical cost of this mix-up shows up in three ways. First, wasted audit hours: CPA firms bill by the hour for fieldwork, and every control that is not yet operating, every missing policy, every access review that has not been run turns into audit time spent discovering problems rather than testing evidence. Second, failed or qualified opinions: if your controls are not actually operating when the audit period starts, no amount of auditor goodwill changes what they can attest to. Third, a stalled deal: the enterprise buyer who asked for SOC 2 does not care why it is late, they just see a missing artifact in procurement.

What a SOC 2 Consultant (Prep Firm) Actually Does

A prep consultant like traztech works on your side of the table, before the audit clock starts. The engagement typically includes:

  • Scoping and gap analysis, mapping your current environment against the Trust Services Criteria relevant to your business (security, availability, confidentiality, processing integrity, privacy) and flagging exactly where you fall short.
  • Policy and control design, drafting the information security policies, access control procedures, incident response plans, and vendor management processes an auditor will expect to see, written for how your company actually operates, not copy pasted boilerplate.
  • Remediation project management, driving the fixes (MFA rollout, logging, access reviews, offboarding workflows) with your engineering and ops teams so controls are demonstrably operating, not just documented.
  • Evidence collection setup, building the repeatable process for pulling the tickets, logs, screenshots, and approvals an auditor will sample.
  • Auditor handoff, packaging your readiness state and introducing you to an independent CPA firm suited to your size and scope.

None of this work involves the prep firm rendering an opinion. We are advocates helping you get ready, not the party attesting that you are ready. If you want the deeper breakdown of where our scope ends and the audit firm's begins, our SOC 2 audit prep vs. audit firm comparison walks through the handoff in detail.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

What an Independent CPA Auditor Does

The auditor is a licensed CPA firm, registered to perform attestation engagements under AICPA standards. Their job is narrow and specific: examine the evidence, test whether controls are designed appropriately (Type I) and operating effectively over a review period (Type II), and issue a signed report with their professional opinion attached. Enterprise security teams, procurement departments, and auditors on the buyer's own side trust that report specifically because the firm issuing it has no stake in whether your company passes.

This is why independence rules exist. If the same firm designed your access control policy and then tested whether that policy was followed, there is an obvious conflict: they would be grading their own work. The AICPA's Code of Professional Conduct restricts CPA firms from providing significant non-attest services (like building your controls from scratch) to a client they are also auditing, when doing so would impair independence. In practice, most serious CPA audit firms will not accept an engagement where they also did the prep work, and buyers who understand SOC 2 will ask who did your readiness work versus who signed the report.

Why the Two Firms Must Be Different (Not Just a Best Practice)

It is worth being direct about this: separating prep and audit is not a nice-to-have, it is the mechanism that gives a SOC 2 report credibility. An enterprise security reviewer, a Series B due diligence team, or a fintech partner running vendor risk assessments is trained to spot a report where the lines are blurred. If your prep firm and your audit firm are the same entity, or the audit firm quietly did most of the control design, that is a flag serious buyers will notice and ask about.

Keeping the two roles in separate firms also produces a better outcome for you. Your prep consultant's incentive is to get you genuinely ready, because their reputation rides on a clean audit, not on billing more audit hours. Your auditor's incentive is to test rigorously, because their license rides on the integrity of the opinion. When those incentives are aligned but the firms are separate, you get a faster, cleaner path through the audit and a report that actually moves deals forward.

How This Plays Out for Canadian Companies

Canadian B2B SaaS companies selling into the US market run into this most often: a US enterprise prospect's security team asks for SOC 2 as a condition of moving past procurement, and the Canadian company has never been through an attestation before. There is also a parallel domestic pressure, PIPEDA and Quebec's Law 25 push companies toward documented privacy and security practices even before a customer asks, and a SOC 2 readiness engagement tends to cover much of that same ground. Whether you are based in Toronto, Waterloo, Ottawa, Vancouver, Calgary, or Montreal, the sequence is the same: prep firm first, independent CPA auditor second, never the reverse and never combined.

How to Sequence Your SOC 2 Project

A realistic order of operations looks like this: engage a prep consultant for a fixed-scope gap analysis, get a remediation timeline and cost estimate before committing to anything open-ended, close the gaps with the consultant's support, then bring in an independent CPA firm to scope and schedule the actual audit. Trying to compress this by skipping the prep phase almost always extends the audit phase instead, at a higher hourly rate.

Where traztech Fits

traztech is a boutique Canadian consultancy that does exactly one side of this equation well: readiness. We run fixed-scope gap analyses, build the policies and controls your business actually needs, and get you to the point where an independent CPA firm can move quickly and confidently through the audit. We do not sign audit reports, and we will tell you plainly when a prospective partner is trying to blur that line. If your enterprise deal, your board, or your renewal deadline just made SOC 2 urgent, the fastest path forward starts with knowing exactly where your gaps are before the audit clock starts running. Book a free readiness call to get a clear, fixed-scope view of where you stand, or contact traztech to talk through your timeline and how the prep-to-audit handoff would work for your company.

Who Writes Which Part of the Report

A SOC 2 report has four sections, and the division of labor between you, your prep firm, and your auditor is not obvious from the outside. Section 1 is the auditor's opinion, written entirely by the CPA firm. Section 2 is management's assertion, which is your document: you are asserting that your description is fair and your controls were suitably designed and operating. Section 3 is the system description, which describes your infrastructure, people, data, processes, and the boundaries of the system being examined. Section 4 is the control matrix with the auditor's tests and results.

First-time buyers are routinely surprised that Section 3 is theirs to write. It is management's representation, not the auditor's prose, and it is the section enterprise reviewers actually read closely because it tells them what was in scope and what was quietly left out. A prep firm can draft it with you and pressure-test the wording. An auditor can tell you it is deficient but generally cannot author it for you without creating an independence problem. If a firm offers to write your system description and then audit against it, you have just found the blurred line this article is about.

Carve-Out or Inclusive: The Scoping Decision Nobody Explains

If you run on AWS, use a managed database provider, or push payroll through a third party, those are subservice organizations. You choose whether to treat them under the carve-out method, where their controls sit outside your report and you rely on their own SOC 2, or the inclusive method, where their controls are tested as part of yours. Almost every SaaS company uses carve-out, and almost none of them realize carve-out carries an obligation: you must define complementary subservice organization controls, meaning the specific things you are assuming your provider does, and you must have a process for reviewing their reports annually to confirm the assumption still holds.

The failure mode is predictable. A company carves out its cloud provider, never downloads the provider's report, and cannot answer an auditor asking who reviewed it and what exceptions were noted. That is an easy exception to avoid and an embarrassing one to explain to a buyer. The same logic applies to complementary user entity controls, the things your own customers must do for your controls to work, which belong in the report so your buyers know what falls to them.

What Actually Drives the Audit Fee

Audit pricing is not arbitrary, and understanding the drivers lets you shrink the bill before you ask for a quote. The variables that move a CPA firm's estimate are the number of trust services categories in scope, the number of distinct systems and environments they have to test, the number of control activities in your matrix, headcount because sampling sizes scale with population, the length of the observation window, and how much of your evidence arrives in a form they can test without back and forth.

The last one is where prep work pays for itself. If an auditor requests a population of terminated employees for the period and receives a spreadsheet somebody typed by hand, they will ask how it was generated, whether it is complete, and what system it came from. If they receive an export from the HR system of record with a timestamp and the query behind it, the request closes in one round. Multiply that across sixty evidence requests and you can see where the hours go. On one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which we broke down in our auditor vetting and readiness case study. Adding a trust services category you do not need is the fastest way to spend that saving back. Availability is worth adding when you have contractual uptime commitments. Privacy is a heavier lift than most teams expect and is frequently added because it sounded thorough, not because a buyer asked.

How to Vet the Auditor, Not Just the Consultant

Most of the buying advice in this space assumes the auditor is interchangeable. It is not. Ask a prospective CPA firm how many SOC 2 examinations they issued last year and for companies at what stage, because a firm whose practice is regional financial statement work and does a handful of SOC 2 reports on the side will move slowly and ask for the wrong things. Ask who performs the fieldwork and what their background is, since the partner who sells the engagement is often not the person reading your Terraform config. Ask whether they have been peer reviewed and when. Ask what their typical turnaround is from end of observation window to issued report, because six weeks and sixteen weeks are both answers you will hear and only one of them fits a renewal deadline.

Also ask what happens to the fee if fieldwork runs long. Some firms quote a fixed fee and absorb the overrun. Others quote an estimate and bill hourly against it, which turns your readiness gaps into their revenue. Neither is dishonest, but you should know which one you signed.

When an Exception Shows Up Mid-Audit

Exceptions happen. A single offboarding that took eleven days instead of the two your policy promises, an access review that was completed in April when the policy says quarterly and the previous one was in December, a change pushed straight to production during an incident without the ticket. The instinct is to argue. The better move is to establish the population, determine how many instances failed, document the root cause, and record what changed as a result.

Auditors have discretion in how they characterize a deviation, and that discretion responds to evidence, not to advocacy. One late offboarding out of forty, caught by your own monitoring, with a fix deployed, reads very differently from one late offboarding out of four discovered by the auditor. This is also why a prep firm earns its keep in the middle of an examination rather than only at the start. Someone who has sat on both sides of these conversations can tell you when a finding is genuinely fatal to the opinion and when it will land as a note in Section 4 that no buyer will ever ask about. Our retainer work exists largely for this window, when the questions are live and the auditor is waiting.

When You Should Not Hire a Prep Firm at All

There are real situations where paying us is the wrong call. If you are a ten-person company with one product, one cloud account, an engineering lead who has been through SOC 2 at a previous employer, and a six-month runway to the deadline, you can very likely do the readiness work yourself with a compliance platform and a good auditor who is willing to answer questions. The framework is not secret. The controls are not exotic. What you are buying from a consultant is speed and the avoidance of specific mistakes, and if you have time and someone who has made those mistakes before, buy neither.

You should also not hire a prep firm if nobody has actually asked you for a report. Prospects sometimes mention SOC 2 in a discovery call as a future concern, and a founder turns that into a budgeted project. Ask the prospect directly whether a report is a condition of signing or a nice-to-have for renewal, and get the answer before you spend. A security questionnaire and a well-written summary of your controls closes more early deals than people expect.

And if your buyer is a Canadian mid-market company that has never asked another vendor for an attestation, a lighter path may satisfy them entirely: a documented information security policy set, a recent penetration test, and a clear answer on where data lives. Our free traztech Workspace will hold that evidence and the policies without an engagement attached. If the answer later turns out to be a full examination, none of that work is wasted. If you want the fixed-scope version of the readiness path with the price published before you call, it is on the pricing page.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.