SOC 2 compliance: the Canadian guide
SOC 2 is an audit report about your security controls, written by a CPA firm, that you hand to a customer who wants proof rather than promises.
Compare the firms yourself, or describe the job once and we will send it to the ones that do this work in Canada. Both are free.
SOC 2 is a report, not a certificate. An independent CPA firm examines the controls you use to protect customer data, tests whether those controls did what you said they do, and issues a report with an opinion in it. You give that report to a prospect's security reviewer, and the review moves on. That is the entire purpose of the thing.
For a Canadian company starting from nothing, a first SOC 2 Type 2 report usually costs between $35,000 and $90,000 CAD all in and takes six to twelve months. Most of that time is not the auditor. It is the observation window and the work of getting your controls into a state worth observing.
This site is operated by TrazTech Inc., a security and compliance practice in Toronto. Prices here are Canadian dollars, and the guidance assumes a Canadian company selling into the United States, where most SOC 2 requests come from.
Four free tools cover the questions that decide a first SOC 2. If a customer has given you a date, start with the deadline back-calculator, which works backwards through the observation window and says what can honestly exist by then. If the argument is about report type, the Type 1 or Type 2 decider settles it. The cost calculator puts a Canadian dollar budget against your own scope.
When you get to choosing a firm, the directory of Canadian audit firms and readiness consultants keeps the two categories apart and says which listings are paid and which are free. TrazTech operates this site and is listed first, labelled.
What SOC 2 is
SOC stands for System and Organization Controls. The framework is defined by the American Institute of Certified Public Accountants, and a SOC 2 engagement is an attestation performed under the AICPA attestation standards. Canadian CPA firms perform these engagements routinely, and a report from a Canadian firm is accepted by American buyers without argument. If you are starting from scratch, what SOC 2 is and who needs one covers the whole subject in one page.
Why the report is worth more than a questionnaire
What makes SOC 2 different from a security questionnaire is independence. You are not asserting that you encrypt data at rest. An auditor is asserting that they looked, and that the control was in place. The report runs to forty or a hundred pages, and what is in each section is worth reading before you commission one.
The four parts of the report
| Section | Who writes it | What it contains |
|---|---|---|
| Independent auditor's opinion | The CPA firm | Whether controls were suitably designed, and for a Type 2 whether they operated effectively. This is the page procurement reads. |
| Management assertion | You | Your formal statement describing the system and asserting the controls are in place. |
| System description | You | What the service is, what infrastructure supports it, who your subservice organizations are, and what is in scope. |
| Controls and test results | Both | Each control, the test the auditor performed, and whether an exception was found. This is where a knowledgeable reader actually looks. |
Nobody is SOC 2 certified
There is no certificate, no certification body, and no registry of compliant companies. The output is an attestation report with an expiry built into the period it covers. The phrase "SOC 2 certified" is everywhere in marketing copy and it is wrong every time. We wrote about why the term persists and what to say instead.
Who is asking you for it, and why
Almost nobody pursues SOC 2 voluntarily. It shows up in one of a few predictable ways, and which one applies changes what you do next.
| How it arrives | What they will accept | Sensible response |
|---|---|---|
| Enterprise prospect's vendor security review | Type 2, or Type 1 plus a dated plan | Ask which report and which criteria. Then ask whether a Type 1 unblocks the contract. |
| Existing customer renewing a contract | Current Type 2, dated within twelve months | Confirm the period they need covered before you scope anything. |
| Cyber insurance renewal questionnaire | Usually controls evidence, not the report itself | SOC 2 is often more than the insurer needs. Answer the questionnaire first. |
| Your own board, after an incident | Something that proves accountability | A fractional CISO usually addresses this faster than an audit does. |
| A European or UK buyer | ISO 27001, not SOC 2 | Read the comparison before spending anything. |
Ask the buyer which report type they need and by when. Companies spend months on a Type 2 because a salesperson relayed the word "SOC 2" without checking, when the deal would have closed on a Type 1 and a remediation plan.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Type 1 and Type 2
- Type 1
- An opinion on whether your controls were designed correctly, as of a single date. No period, no evidence of operation.
- Type 2
- An opinion on whether the same controls also operated effectively across a stated period, typically three to twelve months.
- Observation window
- The period a Type 2 covers. The only part of a SOC 2 timeline you cannot buy your way out of.
- Bridge letter
- A statement you sign covering the gap between your report period ending and a customer reviewing you. Free, and it has limits.
Type 1 is a photograph, Type 2 is a video. Buyers want the video. The usual sequence for a first-time company is a Type 1 to unblock a deal, then a Type 2 covering a period that starts the day the Type 1 ends. The full comparison, including when skipping the Type 1 is the better call, is on the Type 1 versus Type 2 page, and the decider gives you an answer in five questions.
The five Trust Services Criteria
SOC 2 is built on five criteria categories. Security is mandatory. The other four are optional and you include them only if a customer needs them, because each one adds scope, evidence and cost.
| Criterion | Question it answers | Include it when |
|---|---|---|
| Security (common criteria) | Is the system protected against unauthorized access | Always. Every SOC 2 report includes it. |
| Availability | Is the system available as committed | You sell an uptime SLA. |
| Confidentiality | Is information designated confidential protected | Customers send you their own commercially sensitive data. |
| Processing integrity | Is processing complete, accurate and timely | You process transactions, payments or calculations on a customer's behalf. |
| Privacy | Is personal information handled as committed | Personal information is the product. Otherwise your privacy obligations sit under PIPEDA or Law 25, not here. |
Most first reports are Security only, and Security plus Availability is the next most common shape. If a buyer has not named a category, do not add one. The requirements page sets out what an auditor asks for against each of them, and the criteria reference goes through what each category adds to your scope and your fee.
If you would rather start from a list than from an explanation, the SOC 2 checklist is the whole project in four phases with the Canadian items US lists leave out, and the glossary defines the terms in a request list.
What SOC 2 costs in Canada
Every number below is Canadian dollars, and every one is a range. Price tracks the number of systems in scope, the number of criteria, and how much evidence already exists when the auditor arrives.
| Line item | Under 25 staff | 25 to 100 staff |
|---|---|---|
| Type 2 audit fee | $20,000 to $35,000 | $30,000 to $60,000 |
| Readiness support | $15,000 to $35,000 | $25,000 to $60,000 |
| Compliance platform, first year | $8,000 to $18,000 | $15,000 to $30,000 |
| Penetration test | $8,000 to $20,000 | $15,000 to $40,000 |
The line item nobody quotes you is your own team. A first SOC 2 consumes several hundred hours of engineering and management attention, concentrated in the weeks before fieldwork. Costed at a loaded engineering rate it is often the largest single number on the page. The cost breakdown works through each line and what moves it, and the cost calculator estimates all four lines against your own headcount and scope. If nobody has asked you for a report yet, read whether you need one before budgeting anything.
How long it takes
Six to twelve months from a standing start to a Type 2 report. The stages overlap less than people expect.
| Stage | Elapsed time | What decides the duration |
|---|---|---|
| Scoping and auditor selection | 2 to 6 weeks | How clear you are on criteria and systems in scope |
| Readiness and gap remediation | 2 to 5 months | Whether access reviews, logging and vendor management already exist |
| Type 1 report, if you need one | 3 to 6 weeks | Auditor availability |
| Observation window | 3 to 12 months | Fixed. You choose the length, then you wait it out. |
| Fieldwork and report issue | 4 to 10 weeks | How fast you return evidence requests |
When the date does not work
A company told in January that it needs SOC 2 to close a deal in March is being asked for something that cannot exist yet. The honest move is to say so, offer a Type 1 with a dated commitment to a Type 2, and start the window immediately. Buyers accept this more often than sales teams expect, and far better in week one than in the week before signature. Put your customer's date into the deadline back-calculator and it will give you both dates to take back to them.
What is different about doing this in Canada
The framework is American and the report is identical wherever it is issued. Three things do change for a Canadian company.
Your auditor does not have to be American
Canadian CPA firms perform these engagements. Their reports are accepted by US buyers. Using a Canadian firm removes a currency conversion, a time zone, and a conversation about who holds your evidence.
SOC 2 does not discharge your privacy obligations
Statute applies whether or not anyone asks. PIPEDA, and Quebec's Law 25 if you have Quebec customers, apply whether or not anyone asks for a report. The privacy criterion inside SOC 2 is not a substitute for either. If you handle Ontario health information, PHIPA sits on top again. Which privacy law applies to you is worth settling before you scope an audit. The data inventory feeds both.
Data residency arrives through contracts
SOC 2 will not make a region acceptable. Canadian public sector buyers and some regulated customers require data to stay in Canada. That is a contractual and architectural question. A SOC 2 report will describe where your data lives, but it will not make an American region acceptable to a buyer who has ruled one out.
Choosing an auditor
The auditor issues an opinion, so the firm's name has to be one your buyer's security team recognizes or can verify. Beyond that, the questions are practical.
- Is the audit performed by the firm you are contracting with, or subcontracted to another practice? Ask directly and get the answer in writing.
- What is the fee for year two and year three? First-year discounts are common and the renewal is where the real price shows up.
- How do they take evidence? A firm that works inside your compliance platform will consume far less of your team's time than one that emails spreadsheets.
- Who is on the engagement, and how many SOC 2 reports have they personally issued for companies your size and in your architecture?
- What is their turnaround from the end of fieldwork to a signed report? Four weeks is good. Twelve weeks has closed deals late.
- Will they discuss a possible qualified opinion with you before it lands in a draft?
Independence rules mean the firm that issues your report cannot also have built your control environment. If you want help getting ready, that is a separate engagement with a separate provider. Readiness work is covered on SOC2Prep, and the penetration test your auditor will expect is covered on GetPentest.
Do you need a compliance platform
Tools such as Vanta, Drata and Sprinto connect to your cloud accounts and identity provider, collect evidence continuously, and give the auditor a place to look. They cut manual effort. They are also a recurring cost that grows with headcount.
Under roughly twenty people with a single cloud account, a spreadsheet and a disciplined owner will get you through a first audit for less money. Above that, or with more than one production environment, the automation pays for itself in the evidence collection alone. Our Vanta and Drata comparison takes a position on which one suits which company, and on when neither is worth buying. The wider platform category covers the other options a Canadian buyer will be quoted, and SOC 2 for SaaS companies deals with the scoping decisions a multi-tenant product forces.
What TrazTech does, since we operate this site
TrazTech is a security and compliance practice in Toronto. It does SOC 2 readiness, the remediation that follows a gap analysis, penetration testing and fractional security leadership. It does not issue audit reports. Independence rules stop the firm that builds your control environment from also auditing it, so the CPA firm is somebody else.
It also runs traztech Workspace, a free compliance workspace: 10 frameworks, guided self-assessments, an evidence register mapped to controls, 40 policy templates with approval history, a risk register and audit-readiness scoring. Scheduled checks run daily against AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira and file the result against the control they prove. Anything else with an API is described as a check rather than picked off a list. Free means no credit card, no trial period, no paid tier, no seat limit and no export fee. Your data stays yours whether or not you ever hire us.
Buy Vanta or Drata instead when your estate needs hundreds of integrations, an endpoint agent or HR system evidence. The workspace has seven connectors, no endpoint agent and no HR integration, and we will help you set a platform up rather than argue about it. Hire a different readiness firm when you want one that does not also operate the directory you found it in. The directory lists the others.
Get quotes from Canadian SOC 2 auditors
Tell us your headcount, your cloud setup and the date your customer needs a report by. We will point you at firms that do this work in Canada.
Get matchedCommon questions
What is SOC 2 in plain language?
It is an independent audit report on the controls a company uses to protect customer data. A CPA firm tests those controls and publishes an opinion on whether they were designed properly and, in a Type 2 report, whether they worked over a period of time. Companies produce one because their customers ask for evidence rather than assurances.
How much does SOC 2 cost for a Canadian startup?
Budget $35,000 to $90,000 CAD for the first year including the audit fee, readiness help, a compliance platform and a penetration test. A very small company that does the readiness work internally and skips the platform can land closer to $25,000 CAD. Renewal years are cheaper, usually 60 to 80 percent of the first year.
How long is a SOC 2 report valid?
A report covers a stated period and does not technically expire, but buyers treat it as stale once the period end date is more than twelve months old. In practice that means an annual audit. Between reports you can offer a bridge letter, which is a short management statement that nothing material has changed since the period ended.
Can we get SOC 2 without a compliance platform?
Yes. Nothing in the framework requires one and auditors accept manually collected evidence without comment. The trade is your team's time against a subscription fee. Small companies with one cloud account often come out ahead doing it manually the first year, then buying a platform once the evidence volume becomes annoying.
Do we need SOC 2 or ISO 27001?
Follow the buyer. North American customers ask for SOC 2, and buyers in Europe, the UK and much of the rest of the world ask for ISO 27001. If you sell into both, do SOC 2 first because it is faster and cheaper, then reuse perhaps two thirds of the work for ISO 27001.
What happens if the auditor finds a problem?
Exceptions are recorded in the report along with your management response, and the opinion can still be unqualified if the exception did not prevent the criteria being met. A qualified opinion is unusual and is survivable, though it will generate questions in a vendor review. A good auditor tells you what they are seeing during fieldwork rather than surprising you in the draft report.