Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

SOC 2 Readiness Cost in Canada in 2026

Most Canadian founders start looking at SOC 2 because an enterprise buyer put it in a contract, and the first question is always the same: what is this going to cost. The honest answer has structure to it. There is a number you can publish, a number that depends on your environment, and a number that belongs to somebody else entirely. Mixing those three together is how budgets get blown and how scope arguments start in month three.

This article lays out what SOC 2 readiness costs in Canada in 2026, in Canadian dollars, what makes the figure move, and what a buyer should be able to ask for before any money changes hands.

The three costs a SOC 2 buyer actually pays

Almost every confused SOC 2 budget conversation traces back to treating one line item as if it were all three. There are three distinct costs, paid to different parties, on different schedules.

Readiness work. This is the consulting engagement that gets your control environment into a state an auditor can test. Policy set, access reviews, vendor management, change management, logging and monitoring, risk assessment, evidence collection, and the operational habits that produce evidence continuously rather than in a panic the week before fieldwork. This is what TrazTech does and what this article prices.

The audit fee. This is paid to an independent licensed CPA firm that performs the examination and issues the report. TrazTech is the readiness partner and never the auditor. The two roles are separate by design, and any firm that offers to do both should raise a question about independence. The audit fee is a genuinely separate contract, quoted by the CPA firm, and it varies with scope and with how much work your environment creates for them.

Tooling. Compliance automation platforms, if you use one. Also the security tooling the controls depend on: identity provider, endpoint agent, log aggregation, vulnerability scanning, background check vendor, security awareness training. Some of this you already own. Some of it you will buy because a control needs it.

A buyer who budgets only for the first line gets surprised twice. A buyer who is quoted a single all-in figure that silently bundles all three has no way to check whether any part of it is reasonable.

TrazTech's published starting prices, in CAD

TrazTech publishes starting prices rather than hiding them behind a call. These are the Phase 1 figures, all "from", all Canadian dollars:

  • SOC 2 in 75 Days, from $3,000 for the gap assessment
  • SOC 2 Type I in 10 Weeks, from $2,000 for the gap assessment
  • ISO 27001 Readiness, from $3,000 for the gap assessment
  • ISO 42001 Readiness, from $3,000 for the gap assessment
  • PIPEDA readiness, from $2,500
  • Security Questionnaire Completion, from $1,000
  • Auditor management, $2,000
  • Fractional CISO, from $3,000 per month

The word "from" is doing real work in those figures. It is the floor for a gap assessment on a defined scope, not a ceiling for a whole program. Phase 2, the remediation work, is scoped and priced after Phase 1, from the findings Phase 1 produced. The section below explains why that sequence is not a sales tactic.

What moves the readiness number up or down

Six variables account for most of the spread between a small engagement and a large one.

Trust Services Criteria in scope beyond Security. Security, the common criteria, is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional and are added because a customer contract or a market expectation demands them. Each one you add brings its own controls, its own evidence, and its own testing. Privacy in particular carries real weight for Canadian companies, because it pulls in PIPEDA obligations and, if you handle Quebec personal information, Law 25 requirements that came into force on 22 September 2024 and that the CAI can enforce with fines to $25M CAD or four percent of global revenue. Adding Privacy because it sounds thorough, rather than because a customer asked, is one of the most common ways Canadian companies double their own cost.

Headcount and number of systems. Access reviews, onboarding and offboarding evidence, background checks and training records scale with people. Twelve employees and one production system is a different engagement from ninety employees across four business units. The system count matters more than most founders expect, because every in-scope system needs access governance, change control, logging and a place in the asset inventory.

One cloud or several. A single AWS account with infrastructure as code is the cheap case. Two clouds, or one cloud plus a legacy colocated rack, or production split across a managed Kubernetes platform and a handful of long-lived virtual machines, multiplies the configuration review, the evidence collection and the monitoring coverage. Physical sites add another layer again, because physical access controls become testable.

How much is already documented. A company with a real policy set, a maintained risk register and an asset inventory is starting halfway up the hill. A company with a Notion page called "Security" and good intentions is starting at the bottom. This single variable produces the widest swing in remediation cost, and it is precisely the variable nobody can assess from the outside.

Whether a platform is already in use. If a compliance automation platform is already deployed and wired to your cloud and identity provider, evidence collection is largely mechanical and the readiness engagement spends its time on control design rather than plumbing. If there is no platform, you decide whether to buy one, and the setup itself is work. Platform choice also has a direct cost consequence, which TrazTech has written up in its platform cost savings case study.

Type I versus Type II and the observation window. A Type I reports on control design at a point in time. A Type II reports on operating effectiveness across a window, commonly three to twelve months. The readiness work for a Type II is not simply more of the same; it has to produce controls that keep generating evidence every week of the window without anybody remembering to do it. A three month window costs less to sustain than a twelve month window, and a first Type II with a short window followed by a longer one the next year is a legitimate way to manage cost. TrazTech has run both paths, including a SOC 2 Type II that closed with zero exceptions and an Ontario medtech Type I where the auditor issued an 84-item evidence request.

Why the gap assessment has to come before remediation is priced

TrazTech runs two phases. Phase 1 is a gap assessment that sets the scope and produces a findings register. Phase 2 is remediation, scoped and priced from those findings.

The reason is not procedural preference. Remediation cost is a function of the gaps, and nobody knows the gaps until somebody has looked. A company that believes it has a working access review process and discovers that three former contractors still hold production credentials has a different Phase 2 than a company whose access reviews already run quarterly with sign-off. The two companies can look identical on a discovery call. They can be in the same industry, the same size, the same cloud. The difference shows up only when someone opens the identity provider and reads the logs.

So the gap assessment is the priced, bounded piece of work whose output is the scope of everything after it. It produces a findings register: what exists, what does not, what is close enough to fix in a week, and what is a real project. From that register, Phase 2 can be quoted against work that actually needs doing.

What a flat number quoted sight unseen really does

Here is the part worth thinking about carefully, because it is a point about how honest pricing works rather than a point about anyone in particular.

If someone quotes a single flat figure for your entire SOC 2 program before anyone has looked at your environment, that figure has to absorb uncertainty. There are only two ways to absorb it, and both of them move risk onto the buyer.

The first way is to price for the bad case. The number includes a buffer large enough to cover the messiest environment the quoter can imagine. If your environment turns out to be clean, you have paid for remediation of gaps you did not have. You will never know, because nothing on the invoice tells you which part was the buffer.

The second way is to price for the good case and renegotiate later. The number looks attractive, the contract is signed, and then the findings come in and the scope conversation starts. Change orders, out of scope notices, or a quiet conversation about how the original estimate assumed a simpler environment. This is worse, because by then you have a customer deadline and no room to push back.

A two phase structure removes the guess. Phase 1 has a real, bounded price because the work is defined: assess, document, produce the findings register. Phase 2 has a real price because the findings exist. Neither phase requires anyone to estimate something they cannot see. That is what it means for pricing to be honest: the number is attached to work somebody has scoped, not to a scenario somebody has imagined.

The audit fee is not the readiness fee

The examination is performed by an independent licensed CPA firm, and their fee is theirs. It moves with the same scope variables described above, plus one more: how much work your evidence position creates for them. An audit team that receives organized, mapped, complete evidence spends less time chasing, and their quote reflects that.

Auditor selection is itself a cost decision, and the range between quotes for the same scope is wider than most buyers expect. TrazTech has published what those differences looked like in practice in an auditor price differences case study. TrazTech does not name audit partners and does not take referral arrangements that would compromise the vetting. References are available on request.

There is also a scheduling cost most budgets miss. Auditors book fieldwork months ahead. A readiness program that finishes in November for a firm whose next available slot is February has cost you a quarter, whatever the invoice says.

Tooling: the third line on the invoice

Compliance platforms are useful and they are not free. Annual costs vary by vendor, by headcount tier, and by which integrations you need. The important budgeting point is that a platform automates evidence collection; it does not create controls. A platform pointed at an environment with no access review process will faithfully report that there is no access review process.

Underneath the platform sits the security tooling the controls depend on. If your SOC 2 scope includes a control about vulnerability management, something has to scan. If it includes endpoint protection, something has to run on laptops. Most companies already own two thirds of this and buy the last third during readiness. Budget for that third.

A worked example: $11,000 off an audit quote

Concrete example, published: on one engagement, the readiness position was documented well enough before auditor selection that the audit quote came down by $11,000. The full write-up is in the auditor vetting and readiness case study.

The mechanism is not negotiation. It is that a CPA firm quoting an examination prices the effort they expect. When the control set is mapped, the evidence is organized, and the readiness position is documented in a form the audit team can read before they scope, the expected effort drops and the quote drops with it. The readiness spend partly pays for itself on the audit line, which is another reason the two costs need to be tracked separately rather than bundled into one number nobody can decompose.

What a realistic 2026 budget looks like

A Canadian SaaS company of roughly twenty to forty people, single cloud, going for a first Type I with Security only in scope, should be planning for a gap assessment starting at the published figure, a remediation phase scoped from the findings, a CPA firm's examination fee, and platform and tooling costs for the year. A company adding Availability and Confidentiality, running across two clouds, with three physical sites and ninety staff, is in a different budget class at every one of those lines. TrazTech has run that larger shape too, including a Waterloo data centre operator across three physical sites where SOC 2 Type II and ISO 27001:2022 ran together so the evidence was built once.

The most useful budgeting move a founder can make is to stop asking "what does SOC 2 cost" and start asking "what are my three costs, and who sets each one".

Questions to ask before you sign

Ask these of anyone you are considering, and expect specific answers:

  1. Is remediation priced before or after the gap assessment? If before, ask what happens when the findings do not match the assumption the price was built on.
  2. What exactly does the quoted figure include? Readiness only, or readiness plus audit plus tooling. If it is bundled, ask for the split.
  3. Who signs the audit report, and can they be referenced? The examination must come from an independent licensed CPA firm. Ask whether the readiness firm has any financial relationship with the auditor they recommend.
  4. Which Trust Services Criteria are in scope, and who decided? If Privacy is in scope, ask which customer contract requires it.
  5. Can you show completed Canadian engagements? Ask for published work, not logos.
  6. What are the practitioner's credentials beyond a baseline certification? TrazTech's principal, Jacob Masse, has five published CVEs, including CVE-2024-45163 at CVSS 9.1, a kill-switch against Mirai botnet infrastructure. They are listed on /research.
  7. Which entity signs the contract, and under which province's law?
  8. Where does engagement data live? Evidence collected during readiness includes your configuration, your access lists and sometimes your customer data structure. Ask where it is stored and what happens to it when the engagement ends.
  9. What happens after the report is issued? A Type II window does not end; it renews. Ask what ongoing support costs.

Next step

If you want a real number rather than an estimate, the gap assessment is the thing that produces one. TrazTech publishes its starting prices at traztech.ca/pricing, and the SOC 2 readiness paths are laid out at getsoc2.ca and soc2prep.ca. Bring your customer's actual contract language, your cloud account list, and your current headcount, and the scope conversation takes about thirty minutes.

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.