Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →People say "we need to hire someone for our SOC 2" as if it is one purchase. It is two, and by design they cannot be the same firm. Understanding the split is how you avoid overpaying and choose the right help for each half.
Book a free readiness callA SOC 2 report is only worth something because an independent party vouches for it. That independence is the whole point. So the standard splits the work in two. One party helps you get ready, which means finding your gaps, writing policies, fixing controls, and organising evidence. A separate party, a licensed CPA firm, examines the result and issues the report. The firm that prepares you is not allowed to be the firm that judges you.
The practical takeaway: you are going to hire two things. A prep partner to do the readiness work, and an audit firm to sign the report. Confusing the two, or trying to buy them from one place, is where budgets and timelines go wrong.
| Audit prep partner | Full audit firm (the auditor) | |
|---|---|---|
| Job | Gets you audit-ready: gap assessment, policies, remediation, evidence | Independently examines your controls and issues the SOC 2 report |
| Signs the report | No, and is not allowed to | Yes, this is the whole point of them |
| Where the effort is | Most of it, this is the heavy lifting | A defined examination once you are ready |
| Hands-on with your systems | Yes, closes real gaps with your team | No, observes and tests from the outside |
| Typical cost | Fixed fee, sized to scope | Often USD 10,000 to 30,000 or more, priced in USD |
| Best value for a startup | A boutique specialist, fast and focused | A reputable licensed CPA firm your buyers accept |
Large national and Big 4 firms can do SOC 2 readiness advisory, and for a very large or complex multi-framework program at enterprise scale they are a reasonable choice. The trap is using them for a first SOC 2 at a startup. You tend to pay premium rates for junior staff, move slowly, and get a process built for a 5,000-person company applied to your 30-person one.
For the readiness half, a specialist prep partner is usually faster and far less expensive for the same outcome. For the audit half, you do not need the biggest name, you need a reputable licensed CPA firm whose report your buyers will accept. Spending Big 4 money on a first SOC 2 is the most common way startups overpay.
People assume the risk of going straight to an audit firm is a bad report. Bad reports do exist: an adverse opinion and a disclaimer are both real outcomes, and ISO 27001 will withhold a certificate outright for a major nonconformity at Stage 2, then charge you for the additional audit days it takes to verify the fix. But the outcome that actually catches unprepared companies is a stall. The auditor gets into fieldwork, works the document request list, finds that a meaningful share of the evidence does not exist in a form they can test, and recommends stopping.
That is worse than a qualified opinion in every direction, because a qualified report is at least a document you can hand a buyer. A stall gives you nothing.
The fee is spent against quotes that commonly run USD 10,000 to 30,000 and up, and re-entering fieldwork means paying again. A Type II gap can add a fresh three to twelve month window. Your engineers spend the same weeks twice. And the readiness work is still ahead of you, on a shorter runway with a smaller budget.
Which is why the split is not just a rule. The independence requirement means your auditor is barred from fixing the thing they found. They can tell you a control will not pass; they cannot rebuild it for you. Somebody has to do that work, and doing it before fieldwork is the cheap version. What auditors see most, and what it costs.
traztech is a prep partner, not an auditor. We do the readiness and remediation, we handle auditor management and advocacy so the examination goes smoothly, and we bring real security depth to the controls. Our founder is a published security researcher with five CVEs, so what we build survives a buyer's technical reviewer, not just the audit. We quote fixed scope, so you know the readiness number before you commit, see our pricing for the specific engagements, and we are honest that the audit itself is a separate cost you pay the CPA firm.
Tell us your scope and deadline and we will quote the readiness work fixed, then help you pick an auditor that fits. No Big 4 markup, no invented numbers.
Book a free readiness callAudit prep is the work of getting ready: closing control gaps, writing policies, and collecting evidence. The audit is the independent examination that produces the SOC 2 report. They are two separate jobs, and by the rules of the standard they must be done by two independent parties. A prep partner gets you ready, and a licensed CPA firm issues the report.
Because the standard requires the auditor to be independent of the work they are examining. If the same firm built your controls and then judged them, the report would not be trustworthy. This is why you hire a prep partner and a separate CPA audit firm. A good prep partner coordinates with your auditor but never signs the report.
For a startup or mid-market company, usually not for the prep. The Big 4 are built for large, complex engagements and price accordingly, often with junior staff doing the work. For the readiness itself, a specialist prep partner is typically faster and far less expensive for the same outcome. For the audit signature, choose a reputable licensed CPA firm that fits your buyers' expectations.
Bad reports are possible, since adverse opinions and disclaimers both exist, and for ISO 27001 a major nonconformity at Stage 2 withholds the certificate until you remediate and pay for the verification days. But the usual outcome is a stall, which is worse. The firm reaches fieldwork, finds the evidence is not testable, and recommends pausing. You have paid for an audit that produced no report, so nothing goes to the buyer who asked, re-entering fieldwork means paying a firm again against quotes that commonly run USD 10,000 to 30,000 and up, a Type II gap can cost a fresh three to twelve month observation window, and the readiness work is still ahead of you. More on what actually goes wrong.
Most of the time and effort is in readiness, not the audit, so that is where good help pays off. Budget a fixed fee for a prep partner to close the gaps, a separate fee for the independent auditor, and optionally a compliance platform subscription. Avoid paying enterprise-firm rates for a first SOC 2 that a boutique can deliver faster.
Preparation and the audit are two separate bills, and there is usually a third: the platform you are told to run the programme in. That one is avoidable.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.