A Canadian SaaS company gets far enough into an enterprise sales cycle that the buyer's security team sends two requirements at once: a SOC 2 report, and evidence of a recent penetration test. The founder searches for someone who can do both, finds a bundle with a single price on it, and books a call. That is reasonable. The two pieces belong in the same conversation.
What is less reasonable is the single number, not because it is high or low, but because of what it has to assume to exist at all. This article covers what a combined engagement should contain, how the testing portion ought to be scoped, why remediation is the part nobody can honestly price up front, and what belongs in writing before you sign.
Why the two pieces of work get sold together
SOC 2 does not contain a control that says "run a penetration test annually" in those words, but the Trust Services Criteria expect the organization to identify and evaluate vulnerabilities, and most companies satisfy that expectation with a periodic test. Auditors ask for the report, and so do enterprise customers and their questionnaires.
So the sequencing makes sense: build the control environment, test the environment you claim to control, remediate what the test finds, then walk into the audit with a documented control set and a dated testing artefact. In that order the test results feed the readiness evidence instead of arriving as a surprise partway through the audit window.
The problem is not the bundling. It is that bundling invites a fixed price, and a fixed price for unscoped work is a guess wearing a suit.
What a combined engagement actually contains
Strip the packaging and a combined engagement is four bodies of work, each with its own unit.
Readiness assessment. Someone maps your current state against the Trust Services Criteria you selected. Security is mandatory; availability, confidentiality, processing integrity and privacy are elective, and each one added expands the evidence burden and the audit fee. The output is a findings register: what exists, what does not, what exists but cannot be evidenced. Price and deliver it first, because everything after it depends on what it finds.
Remediation. Writing the missing policies, configuring the logging that is not on, standing up access reviews, building the vendor register, getting the risk assessment out of somebody's head and into a document. The volume is set entirely by the findings register. A company on a managed cloud platform with SSO, infrastructure as code and a real ticketing system has a short list. One with shared admin credentials and no change management has a long one.
Penetration testing. A scoped, time-boxed assessment against named targets, producing a findings report with severities, reproduction steps and remediation guidance, plus a retest if that was agreed.
Audit support. Managing the evidence request, answering follow-ups, sitting in the walkthroughs. Distinct work with a distinct cost. TrazTech publishes auditor management at $2,000 as its own line.
A bundle that does not break these four apart is one you cannot evaluate, and cannot adjust when scope moves.
The penetration test has to be scoped to your environment, not to a package
Penetration testing is sold by effort, and the unit is tester days. Everything else on a quote is downstream of how many days someone thinks the work takes, and that number can only come from facts about your environment. Here is what drives it.
Application count. One web application is not the same as a web application plus a customer portal plus an internal admin tool plus a mobile client. Each surface has its own authentication flow, session handling and logic.
User roles. The most commonly underestimated variable. Authorisation flaws live between roles, and testing them means holding credentials for each role and attempting every meaningful action from every position. An application with an admin, a manager, a standard user, a read-only auditor role and a support impersonation function is well above one times the work of a single-role application, and every role needs credentials provisioned before testing starts.
API surface. A documented REST API with forty endpoints is a different proposition from six. If the API is the product and the web interface is a thin client over it, that is where the test should spend its time. Ask whether the quote covers the API endpoints or only what the browser touches, and whether the tester gets the OpenAPI specification or has to discover endpoints by hand, because discovery comes out of the same budget.
Cloud accounts and infrastructure. A configuration review across three accounts with distinct IAM boundaries is not the same as one. External network ranges, live host counts, whether a corporate network is in scope at all, whether there are sites in more than one city: all of it moves the number.
Testing posture. Black box, grey box or white box changes how much time goes to reconnaissance rather than to real issues. For a test supporting SOC 2, grey box with credentials is usually better value.
Retest. Whether remediated findings get retested, and for how long afterward, is a scope decision with a cost, and the item most often left ambiguous.
None of this can be known from a form on a website. A tester quoting without it is quoting an assumption, and it surfaces later as a change order or as a thin report that technically satisfies the deliverable.
For market context, a Canadian tester day sits in the range of $1,500 to $2,800 CAD. That is the market, not any one firm's rate. TrazTech quotes penetration testing from $1,000, and "from" is doing real work in that sentence: it is the floor for a small, tightly defined scope, not a forecast for a multi-application environment with four roles and three cloud accounts.
Why remediation cannot be priced before the gap assessment
This is the heart of it. A bundle covering readiness, remediation and testing for one figure is pricing three things, one of which is unknowable at the moment of quoting. Readiness assessment can be estimated, because its scope is the criteria and your company size. Penetration testing can be estimated once the environment facts are on the table. Remediation cannot, because it is defined by the gaps, and the gaps are the output of an assessment that has not happened yet.
Consider what a seller has to do to put a number on it anyway. Price for the worst plausible case, and the well-prepared buyer overpays for work that never gets done. Price for the average case, and the number is wrong in both directions and gets renegotiated the moment reality asserts itself. Price low and define remediation narrowly enough that most of the real work falls outside it, and the buyer ends up holding a signed agreement plus a list of things that are their own responsibility. There is no fourth option, and the problem lands on the buyer.
The workable version is to split the engagement. Price and deliver the gap assessment, produce the findings register, then scope and price remediation from that register, with the buyer able to see which findings drive which line items and free to take some in house. TrazTech publishes readiness this way: SOC 2 in 75 Days from $3,000 and SOC 2 Type I in 10 Weeks from $2,000 are both gap assessment figures, with remediation scoped afterward from what the assessment finds.
When you are handed one figure, work backwards to what it must assume. If nobody asked how many applications you run, how many roles exist, or how many cloud accounts are in scope, a day count has been assumed, so ask what it is. If remediation is included and nobody has seen your environment, ask what happens when the assessment finds more than the bundle assumed. The answer is a change order, a narrower definition of remediation than you had in mind, or a delivery that thins out to fit the budget. Any of those is workable if you know in advance, and none is acceptable as a discovery in month three.
What to insist is written into the statement of work
Contracts are where ambiguity gets resolved or preserved. Items to require:
Tester days, stated as a number. A count, plus what happens if the test runs long. If it is not in the document, the effort is not committed.
The scope inventory, enumerated. Application names, in-scope domains and IP ranges, API base paths, cloud accounts by identifier, and the user roles with credentials to be provided for each. This list is the contract, and anything not on it is not being tested.
Retest, explicitly included or explicitly excluded. With a window. "One retest of findings rated medium and above, within sixty days of report delivery" is a clause. "Retesting available" is not.
Who writes the report and who signs it. Whether the person testing is the person writing, and whether you can hand the report to an auditor and to a prospect under NDA. Ask whether the practitioner has published security research or credentials beyond a baseline certification, and ask before the engagement, not after the report arrives.
What happens when the gap assessment finds more than expected. Name the mechanism in the document: findings register goes to the client, remediation is re-scoped and re-quoted against it, client approves before work proceeds. That one clause removes most disputes in these engagements.
Evidence and data handling. Where engagement data lives, which jurisdiction it sits in, how long it is retained, how it is destroyed. For buyers with PIPEDA obligations, or Quebec buyers under Law 25, this is not a formality: the Fair Information Principles make you accountable for personal information transferred to a third party for processing, and your consultant is a third party.
The contracting entity and governing law. Which legal entity signs, and under which province's law disputes are resolved.
Deliverables with dates. Findings register, remediation plan, test report, retest report and audit support hours, each with an owner and a date.
The audit fee sits outside all of this
Worth stating plainly, because it is where budgets break. TrazTech is a readiness partner, not the auditor, and cannot be. A SOC 2 report is issued by an independent licensed CPA firm, and independence is the basis on which the report carries weight. A firm that built your control environment cannot attest to it. The same separation applies to ISO 27001, where certification comes from an accredited certification body.
So the CPA firm's fee is a separate contract, a separate invoice and a separate negotiation, and it sits outside any readiness bundle. If a combined number appears to include the audit, clarify that first, because the only ways it can be true are that the figure is a pass-through estimate for a fee not yet quoted, or that the word "audit" is being used for something that is not an audit.
Readiness position does affect audit cost, which is the useful part. An auditor quoting a company with a documented control set, a complete evidence package and an organised point of contact is quoting fewer hours than one quoting a company that has not started. TrazTech has published a case where that took $11,000 off an audit quote, and a separate piece on how widely auditor pricing varies for the same scope.
The two-phase model as the alternative
The structure TrazTech uses is two phases, and it exists because of the pricing problem above.
Phase 1 is the gap assessment. It sets scope and produces a findings register. On the testing side it is where the environment facts get established: applications, roles, API surface, cloud accounts, and therefore the day count. It is priced and delivered as its own piece of work, and at the end you own a document that says what is actually wrong, whether or not you continue.
Phase 2 is remediation and testing, scoped and priced from those findings. Every line traces to a finding. You see what you are paying for, take items in house if you want, and sequence the test for the point where the environment is stable enough that the report still holds when the auditor reads it.
Published figures are all "from" figures for the same reason: SOC 2 readiness from $3,000, penetration testing from $1,000, fractional CISO from $3,000 a month. Those are floors for defined scopes, and the real number comes out of Phase 1.
Running both workstreams inside one structure also means the test scope comes from the same system inventory as the readiness scope, so the applications the auditor asks about are the applications the tester covered. Buy the two separately and you can find at audit time that the test covered a subset of what the report describes. The fix for that is another test.
TrazTech has published write-ups on this work: a Waterloo data centre operator running SOC 2 Type II and ISO 27001:2022 in parallel across three sites, an Ontario medtech company with an AI clinical assistant that went through SOC 2 Type I with an 84-item evidence request, and a SOC 2 Type II that closed with zero exceptions. Ask any firm you evaluate for comparable Canadian work you can read.
Questions to ask before you sign
Take these into the call:
- How many tester days are in this quote, and what environment facts produced that number?
- Which applications, roles, API endpoints and cloud accounts are in scope, by name?
- Is a retest included, and within what window?
- Is remediation priced before or after the gap assessment, and if before, on what basis?
- Who writes the test report, and what are their credentials?
- Can you show me Canadian engagements you have completed?
- Which licensed CPA firm would issue the report, and can they be referenced?
- Which entity signs the contract, under which province's law, and where does our engagement data live?
Each has a concrete answer if the work has been scoped. If the answers come back general, it has not been scoped, and the price on the page is not a price.
Where to go next
Get the gap assessment scoped on its own first. Once the findings register exists, the remediation plan and the test scope follow from a document rather than an assumption.
TrazTech's readiness and testing pricing is published at traztech.ca/pricing, all as "from" figures for defined scopes. For testing scope, including how tester days are estimated across applications, roles and cloud accounts, getpentest.ca covers the Canadian market in more detail. For readiness, getsoc2.ca and soc2prep.ca go through criteria selection and evidence work.
To scope an engagement, book time with Jacob Masse, Principal, and bring your application inventory, role list and cloud account structure. That is the conversation that produces a real number.