Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Buyer’s guide · 2026

ISO 27001 consultants
in Toronto.

A lot of firms in this city advertise ISO 27001 certification, which is not something a consultant is able to sell you: the certificate is issued by an accredited certification body, and everything that happens before that is preparation. This guide sets out who does which part, what to check before you sign anything, and what each piece genuinely costs.

Search for ISO 27001 in Toronto and most of what comes back is branded as certification: "ISO 27001 Certification in Toronto", "certification consulting", "get certified". It is worth knowing before you spend anything that a consultant cannot issue you an ISO 27001 certificate. Only an accredited certification body can, and the firm that prepares you is not allowed to be the firm that certifies you.

This guide sets out who does what, what to verify before signing, what the work actually involves, and where each option including ours is the wrong choice.

The three roles, and why conflating them costs money

The certification body performs the stage 1 and stage 2 audits and issues the certificate. It must be accredited by a recognised accreditation body. In Canada that is normally the Standards Council of Canada, and internationally you will see UKAS, ANAB and others. A certificate from an unaccredited body is not worth what you paid for it, and sophisticated buyers check.

The consultant or readiness firm builds the ISMS with you: scope, risk assessment, Statement of Applicability, controls, internal audit, management review, and the evidence behind all of it. This is where the work is. It is also what we do.

The certification mill is the category to be careful with. Sites that market "certification" while actually selling consulting, or that promise a certificate in an implausible timeframe, are describing an outcome they cannot deliver on their own.

Two questions settle it in any first call. Are you an accredited certification body, and if so which accreditation? And if you prepare us, who audits us? A straight answer to both is a good sign regardless of which role they occupy.

What ISO 27001 actually asks for

Teams arriving from SOC 2 are frequently surprised here, because the control overlap is large but ISO adds something SOC 2 has no equivalent for: a management system.

A defined scope. Which parts of the organisation, which locations, which systems. Written down and defensible.

A risk assessment methodology. Not just a risk register. The method itself has to be documented and repeatable, and you have to be able to show your working.

A Statement of Applicability. Every Annex A control, included or excluded, with justification for each decision. This is the document auditors spend the most time in.

Internal audit. Performed by somebody sufficiently independent of what they are auditing, before the certification body arrives.

Management review. Evidence that leadership reviewed the ISMS and that decisions came out of it. A calendar invite is not evidence.

The 2022 revision also brought the Climate Action Amendment, which requires climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect to see it reflected, and a good deal of template ISMS documentation still predates it.

What to evaluate in a Toronto consultant

1. Do they name the certification body relationship? A consultant who has worked alongside accredited bodies before knows what each expects and can introduce you. One who is vague about this stage has probably not been through it often.

2. Do they build the management system or only the controls? Controls are the part that overlaps with SOC 2 and the part most firms are comfortable with. The SoA, internal audit and management review are where inexperienced engagements fall down.

3. Do they handle the 2022 revision properly, including the Climate Action Amendment? Ask directly. It is a fast way to tell whether their templates are current.

4. Can they run ISO alongside SOC 2? If North American buyers are asking for SOC 2 and others want the certificate, doing both together is materially cheaper than a year apart, because a large share of Annex A maps onto the SOC 2 common criteria.

5. Local presence, honestly assessed. Toronto matters for on-site work, for physical scope, and for time zone. It matters less than people assume for a software-only ISMS. Do not pay a premium for a postcode you do not need.

6. Is the price fixed and is the audit fee excluded? The certification body bills you separately, for stage 1, stage 2 and then surveillance audits across a three-year cycle. Any quote that does not make that clear is incomplete.

Who operates in the Toronto market

Grouped by role. Facts from public pages, August 2026.

ProviderRoleNotesPublished price
Accredited certification bodiesCertifyIssue the certificate after stage 1 and stage 2. Verify accreditation before engagingVaries by scope
Big 4AdvisoryBench depth for group structures and regulated entitiesNot disclosed
PlurilockSecurity vendorToronto location page; full-spectrum vendor that can implement as well as adviseNot disclosed
Kobalt.ioReadiness, managedVancouver, managed programme model across ISO, SOC 2 and CPCSCPublishes programme pricing
Certification-branded consultanciesConsultingTopCertifier, CertPro, Qualitcert and similar. Confirm the role and who auditsGenerally not disclosed
traztechReadinessToronto, fixed scope, runs ISO with SOC 2, physical sites in scopePublished, from $3,000

Accredited certification bodies

What they do. The audits and the certificate. Nothing else, and that is the point.

Caveats. They cannot help you prepare. Ask which accreditation they hold and confirm it independently; the accreditation is what makes the certificate mean anything to a buyer.

Big 4

What they do well. Scale, group structures, regulated entities, and a name that satisfies internal governance.

Caveats. Cost sits well above most mid-market expectations, and the people who scope the work are rarely the people delivering it.

Plurilock

What they do well. A full-spectrum security vendor rather than a pure compliance shop, so where readiness surfaces a technology gap they can implement it. They publish a Toronto service location and hold notable government and NATO framework positions.

Caveats. Their Toronto ISO page is a location listing rather than a detailed service description, and no pricing or timeline is published. A vendor that also sells remediation technology has an interest in what an assessment recommends, which is worth naming even where handled well.

Kobalt.io

What they do well. Managed compliance programmes with a monthly cadence and a platform included, spanning ISO 27001, SOC 2 and CPCSC. Among the most price-transparent firms in the Canadian market.

Caveats. Vancouver-based, and the managed model is a recurring commitment rather than a defined project.

Certification-branded consultancies

What they do well. Several are established, work at volume, and move quickly on documentation-heavy engagements.

Caveats. This is the category where the role question matters most. Marketing that reads as "we certify you" alongside a service that is actually consulting is common. Ask the two questions above and get the answers in writing.

traztech

What we do well. Toronto-based, fixed scope, published prices from $3,000 for a gap analysis, and the programme runs in traztech Workspace which is free and which you keep. We run ISO 27001:2022 including the Climate Action Amendment, we run it alongside SOC 2 where both are needed rather than sequentially, and we handle scopes where physical sites are in the boundary. Our current dual-framework engagement covers a data centre operator's production campus with physical and environmental controls in scope. The work is led by a researcher with six published CVEs. How we run both frameworks together.

Best fit. Companies that want a defined scope and price, that need ISO and SOC 2 together, or whose scope includes facilities rather than only software.

Caveats, and we mean them. We are deliberately small; a multi-entity global ISMS rollout is a Big 4 job and we will say so. We do not issue certificates and are not an accredited certification body, so you engage one separately. And we are a readiness firm rather than a managed service; if you want somebody holding the ISMS continuously for years, a managed provider may suit you better than we do.

What ISO 27001 costs in Toronto

Two separate costs, and conflating them is the most common budgeting error.

Readiness. Building the ISMS. Ours starts from $3,000 for a gap analysis with the full track on our pricing page. Most firms in this market do not publish.

Certification. Paid to the accredited body, across stage 1, stage 2, and surveillance audits through a three-year cycle. This is not a one-time fee and it is never included in a consultant's quote.

Two things move the certification number more than anything else: the size of your scope, and how prepared you are when the body arrives. On a recent engagement an audit firm reduced its quote by $11,000 once the readiness position was evidenced, because there was less uncertainty left to price. How that worked.

Frequently asked questions

Can a consultant certify us to ISO 27001?

No. Only an accredited certification body can issue an ISO 27001 certificate, and it must be independent of whoever prepared you. Any provider marketing certification should be asked directly whether they are an accredited body and, if not, who performs your audit.

How long does ISO 27001 certification take in Toronto?

For most mid-market organisations, several months from a standing start, driven less by the control work than by the management system: the risk assessment, Statement of Applicability, internal audit and management review all have to exist and have been performed before a certification body will assess you.

How much does ISO 27001 cost?

Readiness and certification are separate. Our readiness starts from $3,000 for a gap analysis. The certification body bills separately across stage 1, stage 2 and surveillance audits over a three-year cycle. Being demonstrably ready reduces the audit estimate, because there is less uncertainty for the firm to price.

Is ISO 27001 better than SOC 2?

Neither is better; they answer different buyer questions. SOC 2 is usually the shorter road for North American customers. The ISO certificate carries more weight with European and Middle Eastern buyers and with procurement teams working from an approved standards list. Running both together is frequently cheaper than sequencing them.

What is the Climate Action Amendment?

A 2024 amendment to ISO 27001:2022 requiring climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect it reflected in the ISMS, and older template documentation predates it.

Do we need a Toronto-based ISO 27001 consultant?

Only if your scope needs on-site work. For a software-only ISMS, local presence matters less than experience with the standard and with certification bodies. If your scope includes facilities, physical and environmental controls are in play and proximity starts to matter.

What is a Statement of Applicability?

A document listing every Annex A control with a decision on whether it applies to you and a justification for that decision. It is the document certification bodies spend the most time in, and building it from your risk assessment rather than from a template is what separates a real ISMS from a paperwork exercise.

How long is an ISO 27001 certificate valid?

Three years, with surveillance audits in between. It is an ongoing cycle rather than a one-off project, which is worth budgeting for at the outset.

How to run the selection

Ask every provider the same four questions and the market sorts itself quickly.

Are you an accredited certification body? If yes, they cannot prepare you. If no, ask who audits you.

Does your scope include the management system, or only the controls? The SoA, internal audit and management review are where engagements fail.

What is excluded from your price? The certification body fee always is.

How do you handle the 2022 revision, including the Climate Action Amendment? A quick test of whether their material is current.

If you want to see where you stand first, our free ISO 27001 gap assessment runs your position against the standard and returns the gaps, free. How it works covers what an engagement involves phase by phase, and the cost hub has every cost breakdown we have written.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
15+
Penetration testing engagements delivered
$11k
Taken off one client's audit quote by arriving ready

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.

The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.

Recent engagements

For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Working through ISO 27001?

A few short notes on what ISO 27001 actually asks for, where the management system trips people up, and what it costs. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.