Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A lot of firms in this city advertise ISO 27001 certification, which is not something a consultant is able to sell you: the certificate is issued by an accredited certification body, and everything that happens before that is preparation. This guide sets out who does which part, what to check before you sign anything, and what each piece genuinely costs.
Search for ISO 27001 in Toronto and most of what comes back is branded as certification: "ISO 27001 Certification in Toronto", "certification consulting", "get certified". It is worth knowing before you spend anything that a consultant cannot issue you an ISO 27001 certificate. Only an accredited certification body can, and the firm that prepares you is not allowed to be the firm that certifies you.
This guide sets out who does what, what to verify before signing, what the work actually involves, and where each option including ours is the wrong choice.
The certification body performs the stage 1 and stage 2 audits and issues the certificate. It must be accredited by a recognised accreditation body. In Canada that is normally the Standards Council of Canada, and internationally you will see UKAS, ANAB and others. A certificate from an unaccredited body is not worth what you paid for it, and sophisticated buyers check.
The consultant or readiness firm builds the ISMS with you: scope, risk assessment, Statement of Applicability, controls, internal audit, management review, and the evidence behind all of it. This is where the work is. It is also what we do.
The certification mill is the category to be careful with. Sites that market "certification" while actually selling consulting, or that promise a certificate in an implausible timeframe, are describing an outcome they cannot deliver on their own.
Two questions settle it in any first call. Are you an accredited certification body, and if so which accreditation? And if you prepare us, who audits us? A straight answer to both is a good sign regardless of which role they occupy.
Teams arriving from SOC 2 are frequently surprised here, because the control overlap is large but ISO adds something SOC 2 has no equivalent for: a management system.
A defined scope. Which parts of the organisation, which locations, which systems. Written down and defensible.
A risk assessment methodology. Not just a risk register. The method itself has to be documented and repeatable, and you have to be able to show your working.
A Statement of Applicability. Every Annex A control, included or excluded, with justification for each decision. This is the document auditors spend the most time in.
Internal audit. Performed by somebody sufficiently independent of what they are auditing, before the certification body arrives.
Management review. Evidence that leadership reviewed the ISMS and that decisions came out of it. A calendar invite is not evidence.
The 2022 revision also brought the Climate Action Amendment, which requires climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect to see it reflected, and a good deal of template ISMS documentation still predates it.
1. Do they name the certification body relationship? A consultant who has worked alongside accredited bodies before knows what each expects and can introduce you. One who is vague about this stage has probably not been through it often.
2. Do they build the management system or only the controls? Controls are the part that overlaps with SOC 2 and the part most firms are comfortable with. The SoA, internal audit and management review are where inexperienced engagements fall down.
3. Do they handle the 2022 revision properly, including the Climate Action Amendment? Ask directly. It is a fast way to tell whether their templates are current.
4. Can they run ISO alongside SOC 2? If North American buyers are asking for SOC 2 and others want the certificate, doing both together is materially cheaper than a year apart, because a large share of Annex A maps onto the SOC 2 common criteria.
5. Local presence, honestly assessed. Toronto matters for on-site work, for physical scope, and for time zone. It matters less than people assume for a software-only ISMS. Do not pay a premium for a postcode you do not need.
6. Is the price fixed and is the audit fee excluded? The certification body bills you separately, for stage 1, stage 2 and then surveillance audits across a three-year cycle. Any quote that does not make that clear is incomplete.
Grouped by role. Facts from public pages, August 2026.
| Provider | Role | Notes | Published price |
|---|---|---|---|
| Accredited certification bodies | Certify | Issue the certificate after stage 1 and stage 2. Verify accreditation before engaging | Varies by scope |
| Big 4 | Advisory | Bench depth for group structures and regulated entities | Not disclosed |
| Plurilock | Security vendor | Toronto location page; full-spectrum vendor that can implement as well as advise | Not disclosed |
| Kobalt.io | Readiness, managed | Vancouver, managed programme model across ISO, SOC 2 and CPCSC | Publishes programme pricing |
| Certification-branded consultancies | Consulting | TopCertifier, CertPro, Qualitcert and similar. Confirm the role and who audits | Generally not disclosed |
| traztech | Readiness | Toronto, fixed scope, runs ISO with SOC 2, physical sites in scope | Published, from $3,000 |
What they do. The audits and the certificate. Nothing else, and that is the point.
Caveats. They cannot help you prepare. Ask which accreditation they hold and confirm it independently; the accreditation is what makes the certificate mean anything to a buyer.
What they do well. Scale, group structures, regulated entities, and a name that satisfies internal governance.
Caveats. Cost sits well above most mid-market expectations, and the people who scope the work are rarely the people delivering it.
What they do well. A full-spectrum security vendor rather than a pure compliance shop, so where readiness surfaces a technology gap they can implement it. They publish a Toronto service location and hold notable government and NATO framework positions.
Caveats. Their Toronto ISO page is a location listing rather than a detailed service description, and no pricing or timeline is published. A vendor that also sells remediation technology has an interest in what an assessment recommends, which is worth naming even where handled well.
What they do well. Managed compliance programmes with a monthly cadence and a platform included, spanning ISO 27001, SOC 2 and CPCSC. Among the most price-transparent firms in the Canadian market.
Caveats. Vancouver-based, and the managed model is a recurring commitment rather than a defined project.
What they do well. Several are established, work at volume, and move quickly on documentation-heavy engagements.
Caveats. This is the category where the role question matters most. Marketing that reads as "we certify you" alongside a service that is actually consulting is common. Ask the two questions above and get the answers in writing.
What we do well. Toronto-based, fixed scope, published prices from $3,000 for a gap analysis, and the programme runs in traztech Workspace which is free and which you keep. We run ISO 27001:2022 including the Climate Action Amendment, we run it alongside SOC 2 where both are needed rather than sequentially, and we handle scopes where physical sites are in the boundary. Our current dual-framework engagement covers a data centre operator's production campus with physical and environmental controls in scope. The work is led by a researcher with six published CVEs. How we run both frameworks together.
Best fit. Companies that want a defined scope and price, that need ISO and SOC 2 together, or whose scope includes facilities rather than only software.
Caveats, and we mean them. We are deliberately small; a multi-entity global ISMS rollout is a Big 4 job and we will say so. We do not issue certificates and are not an accredited certification body, so you engage one separately. And we are a readiness firm rather than a managed service; if you want somebody holding the ISMS continuously for years, a managed provider may suit you better than we do.
Two separate costs, and conflating them is the most common budgeting error.
Readiness. Building the ISMS. Ours starts from $3,000 for a gap analysis with the full track on our pricing page. Most firms in this market do not publish.
Certification. Paid to the accredited body, across stage 1, stage 2, and surveillance audits through a three-year cycle. This is not a one-time fee and it is never included in a consultant's quote.
Two things move the certification number more than anything else: the size of your scope, and how prepared you are when the body arrives. On a recent engagement an audit firm reduced its quote by $11,000 once the readiness position was evidenced, because there was less uncertainty left to price. How that worked.
No. Only an accredited certification body can issue an ISO 27001 certificate, and it must be independent of whoever prepared you. Any provider marketing certification should be asked directly whether they are an accredited body and, if not, who performs your audit.
For most mid-market organisations, several months from a standing start, driven less by the control work than by the management system: the risk assessment, Statement of Applicability, internal audit and management review all have to exist and have been performed before a certification body will assess you.
Readiness and certification are separate. Our readiness starts from $3,000 for a gap analysis. The certification body bills separately across stage 1, stage 2 and surveillance audits over a three-year cycle. Being demonstrably ready reduces the audit estimate, because there is less uncertainty for the firm to price.
Neither is better; they answer different buyer questions. SOC 2 is usually the shorter road for North American customers. The ISO certificate carries more weight with European and Middle Eastern buyers and with procurement teams working from an approved standards list. Running both together is frequently cheaper than sequencing them.
A 2024 amendment to ISO 27001:2022 requiring climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect it reflected in the ISMS, and older template documentation predates it.
Only if your scope needs on-site work. For a software-only ISMS, local presence matters less than experience with the standard and with certification bodies. If your scope includes facilities, physical and environmental controls are in play and proximity starts to matter.
A document listing every Annex A control with a decision on whether it applies to you and a justification for that decision. It is the document certification bodies spend the most time in, and building it from your risk assessment rather than from a template is what separates a real ISMS from a paperwork exercise.
Three years, with surveillance audits in between. It is an ongoing cycle rather than a one-off project, which is worth budgeting for at the outset.
Ask every provider the same four questions and the market sorts itself quickly.
Are you an accredited certification body? If yes, they cannot prepare you. If no, ask who audits you.
Does your scope include the management system, or only the controls? The SoA, internal audit and management review are where engagements fail.
What is excluded from your price? The certification body fee always is.
How do you handle the 2022 revision, including the Climate Action Amendment? A quick test of whether their material is current.
If you want to see where you stand first, our free ISO 27001 gap assessment runs your position against the standard and returns the gaps, free. How it works covers what an engagement involves phase by phase, and the cost hub has every cost breakdown we have written.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.
That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.
Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.
The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.
For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
A few short notes on what ISO 27001 actually asks for, where the management system trips people up, and what it costs. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.