Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A lot of firms in this city advertise ISO 27001 certification, which is not something a consultant is able to sell you: the certificate is issued by an accredited certification body, and everything that happens before that is preparation. This guide sets out who does which part, what to check before you sign anything, and what each piece genuinely costs.
Search for ISO 27001 in Toronto and most of what comes back is branded as certification: "ISO 27001 Certification in Toronto", "certification consulting", "get certified". It is worth knowing before you spend anything that a consultant cannot issue you an ISO 27001 certificate. Only an accredited certification body can, and the firm that prepares you is not allowed to be the firm that certifies you.
This guide sets out who does what, what to verify before signing, what the work actually involves, and where each option including ours is the wrong choice.
The certification body performs the stage 1 and stage 2 audits and issues the certificate. It must be accredited by a recognised accreditation body. In Canada that is normally the Standards Council of Canada, and internationally you will see UKAS, ANAB and others. A certificate from an unaccredited body is not worth what you paid for it, and sophisticated buyers check.
The consultant or readiness firm builds the ISMS with you: scope, risk assessment, Statement of Applicability, controls, internal audit, management review, and the evidence behind all of it. This is where the work is. It is also what we do.
The certification mill is the category to be careful with. Sites that market "certification" while actually selling consulting, or that promise a certificate in an implausible timeframe, are describing an outcome they cannot deliver on their own.
Two questions settle it in any first call. Are you an accredited certification body, and if so which accreditation? And if you prepare us, who audits us? A straight answer to both is a good sign regardless of which role they occupy.
Teams arriving from SOC 2 are frequently surprised here, because the control overlap is large but ISO adds something SOC 2 has no equivalent for: a management system.
A defined scope. Which parts of the organisation, which locations, which systems. Written down and defensible.
A risk assessment methodology. Not just a risk register. The method itself has to be documented and repeatable, and you have to be able to show your working.
A Statement of Applicability. Every Annex A control, included or excluded, with justification for each decision. This is the document auditors spend the most time in.
Internal audit. Performed by somebody sufficiently independent of what they are auditing, before the certification body arrives.
Management review. Evidence that leadership reviewed the ISMS and that decisions came out of it. A calendar invite is not evidence.
The 2022 revision also brought the Climate Action Amendment, which requires climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect to see it reflected, and a good deal of template ISMS documentation still predates it.
1. Do they name the certification body relationship? A consultant who has worked alongside accredited bodies before knows what each expects and can introduce you. One who is vague about this stage has probably not been through it often.
2. Do they build the management system or only the controls? Controls are the part that overlaps with SOC 2 and the part most firms are comfortable with. The SoA, internal audit and management review are where inexperienced engagements fall down.
3. Do they handle the 2022 revision properly, including the Climate Action Amendment? Ask directly. It is a fast way to tell whether their templates are current.
4. Can they run ISO alongside SOC 2? If North American buyers are asking for SOC 2 and others want the certificate, doing both together is materially cheaper than a year apart, because a large share of Annex A maps onto the SOC 2 common criteria.
5. Local presence, honestly assessed. Toronto matters for on-site work, for physical scope, and for time zone. It matters less than people assume for a software-only ISMS. Do not pay a premium for a postcode you do not need.
6. Is the price fixed and is the audit fee excluded? The certification body bills you separately, for stage 1, stage 2 and then surveillance audits across a three-year cycle. Any quote that does not make that clear is incomplete.
Grouped by role. Facts from public pages, August 2026.
| Provider | Role | Notes | Published price |
|---|---|---|---|
| Accredited certification bodies | Certify | Issue the certificate after stage 1 and stage 2. Verify accreditation before engaging | Varies by scope |
| Big 4 | Advisory | Bench depth for group structures and regulated entities | Not disclosed |
| Plurilock | Security vendor | Toronto location page; full-spectrum vendor that can implement as well as advise | Not disclosed |
| Kobalt.io | Readiness, managed | Vancouver, managed programme model across ISO and SOC 2 | Publishes programme pricing |
| Certification-branded consultancies | Consulting | TopCertifier, CertPro, Qualitcert and similar. Confirm the role and who audits | Generally not disclosed |
| traztech | Readiness | Toronto, fixed scope, runs ISO with SOC 2, physical sites in scope | Published, from $3,000 |
What they do. The audits and the certificate. Nothing else, and that is the point.
Caveats. They cannot help you prepare. Ask which accreditation they hold and confirm it independently; the accreditation is what makes the certificate mean anything to a buyer.
What they do well. Scale, group structures, regulated entities, and a name that satisfies internal governance.
Caveats. Cost sits well above most mid-market expectations, and the people who scope the work are rarely the people delivering it.
What they do well. A full-spectrum security vendor rather than a pure compliance shop, so where readiness surfaces a technology gap they can implement it. They publish a Toronto service location and hold notable government and NATO framework positions.
Caveats. Their Toronto ISO page is a location listing rather than a detailed service description, and no pricing or timeline is published. A vendor that also sells remediation technology has an interest in what an assessment recommends, which is worth naming even where handled well.
What they do well. Managed compliance programmes with a monthly cadence and a platform included, spanning ISO 27001 and SOC 2. Among the most price-transparent firms in the Canadian market.
Caveats. Vancouver-based, and the managed model is a recurring commitment rather than a defined project.
What they do well. Several are established, work at volume, and move quickly on documentation-heavy engagements.
Caveats. This is the category where the role question matters most. Marketing that reads as "we certify you" alongside a service that is actually consulting is common. Ask the two questions above and get the answers in writing.
What we do well. Toronto-based, fixed scope, published prices from $3,000 for a gap analysis, and the programme runs in traztech Workspace which is free and which you keep. We run ISO 27001:2022 including the Climate Action Amendment, we run it alongside SOC 2 where both are needed rather than sequentially, and we handle scopes where physical sites are in the boundary. Our current dual-framework engagement covers a data centre operator's production campus with physical and environmental controls in scope. The work is led by a researcher with five published CVEs. How we run both frameworks together.
Best fit. Companies that want a defined scope and price, that need ISO and SOC 2 together, or whose scope includes facilities rather than only software.
Caveats, and we mean them. We are deliberately small; a multi-entity global ISMS rollout is a Big 4 job and we will say so. We do not issue certificates and are not an accredited certification body, so you engage one separately. And we are a readiness firm rather than a managed service; if you want somebody holding the ISMS continuously for years, a managed provider may suit you better than we do.
Two separate costs, and conflating them is the most common budgeting error.
Readiness. Building the ISMS. Ours starts from $3,000 for a gap analysis with the full track on our pricing page. Most firms in this market do not publish.
Certification. Paid to the accredited body, across stage 1, stage 2, and surveillance audits through a three-year cycle. This is not a one-time fee and it is never included in a consultant's quote.
Two things move the certification number more than anything else: the size of your scope, and how prepared you are when the body arrives. On a recent engagement an audit firm reduced its quote by $11,000 once the readiness position was evidenced, because there was less uncertainty left to price. How that worked.
No. Only an accredited certification body can issue an ISO 27001 certificate, and it must be independent of whoever prepared you. Any provider marketing certification should be asked directly whether they are an accredited body and, if not, who performs your audit.
For most mid-market organisations, several months from a standing start, driven less by the control work than by the management system: the risk assessment, Statement of Applicability, internal audit and management review all have to exist and have been performed before a certification body will assess you.
Readiness and certification are separate. Our readiness starts from $3,000 for a gap analysis. The certification body bills separately across stage 1, stage 2 and surveillance audits over a three-year cycle. Being demonstrably ready reduces the audit estimate, because there is less uncertainty for the firm to price.
Neither is better; they answer different buyer questions. SOC 2 is usually the shorter road for North American customers. The ISO certificate carries more weight with European and Middle Eastern buyers and with procurement teams working from an approved standards list. Running both together is frequently cheaper than sequencing them.
A 2024 amendment to ISO 27001:2022 requiring climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect it reflected in the ISMS, and older template documentation predates it.
Only if your scope needs on-site work. For a software-only ISMS, local presence matters less than experience with the standard and with certification bodies. If your scope includes facilities, physical and environmental controls are in play and proximity starts to matter.
A document listing every Annex A control with a decision on whether it applies to you and a justification for that decision. It is the document certification bodies spend the most time in, and building it from your risk assessment rather than from a template is what separates a real ISMS from a paperwork exercise.
Three years, with surveillance audits in between. It is an ongoing cycle rather than a one-off project, which is worth budgeting for at the outset.
Ask every provider the same four questions and the market sorts itself quickly.
Are you an accredited certification body? If yes, they cannot prepare you. If no, ask who audits you.
Does your scope include the management system, or only the controls? The SoA, internal audit and management review are where engagements fail.
What is excluded from your price? The certification body fee always is.
How do you handle the 2022 revision, including the Climate Action Amendment? A quick test of whether their material is current.
If you want to see where you stand first, our free ISO 27001 gap assessment runs your position against the standard and returns the gaps, free. How it works covers what an engagement involves phase by phase, and the cost hub has every cost breakdown we have written.
The Annex A controls, the Statement of Applicability, the risk register and the evidence all have to live somewhere. That is normally quoted as an annual subscription.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
A few short notes on what ISO 27001 actually asks for, where the management system trips people up, and what it costs. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.