How to choose a SOC 2 readiness consultant
Buying SOC 2 readiness is awkward. You buy it once, with no basis for comparison, usually under a deadline set by somebody else. A customer's procurement team asked for the report. An investor's diligence list named it. Your sales cycle sta
Buying SOC 2 readiness is awkward. You buy it once, with no basis for comparison, usually under a deadline set by somebody else. A customer's procurement team asked for the report. An investor's diligence list named it. Your sales cycle stalled at the security questionnaire. So you go looking, and every firm describes itself in roughly the same words at prices that vary by a factor of five.
This is a checklist, not a ranking. The questions below apply to every firm doing SOC 2 readiness work in Canada, including the firm that owns this directory. Each has an answer a well-run practice can give in a sentence or two. Ask all ten, write down the answers, and compare them side by side once the enthusiasm has worn off.
Settle one thing first. SOC 2 readiness is not the audit. The report is issued by an independent licensed CPA firm that must stay independent of the work it examines. Anyone helping you prepare is doing readiness: scoping, control design, evidence, policy, remediation, audit management. If a conversation blurs those roles, clear it up early.
Can you show me Canadian engagements, not logos?
A logo wall tells you a company once had a commercial relationship of some kind. It does not tell you what was done, by whom, or how it went.
Ask instead for engagements you can see: published case studies with a described environment, a stated scope, a real constraint and a real outcome. Ask specifically about Canadian work, because those engagements carry details that travel poorly. Provincial privacy law alongside the Trust Services Criteria. Data residency commitments in customer contracts. PIPEDA obligations running in parallel with SOC 2 rather than inside it, and in Quebec, Law 25 requirements the criteria do not mention.
Why it matters. Readiness work is judgment work. The value is in knowing which of a hundred possible controls apply to a twenty-person SaaS company on one cloud account, and which an auditor will genuinely test. That judgment comes from repetition, and repetition leaves a trail.
What a good answer sounds like. "Here are three write-ups. One was a multi-site physical environment running SOC 2 Type II and ISO 27001 together. One was a medtech product with an AI component and an eighty-four-item evidence request. One was a first Type II that closed with no exceptions. Read them, then ask what is missing." A firm pointing you at published detail has nothing riding on you not looking closely. If the answer stays abstract through two rounds of questions, you have learned something anyway.
Will you show me a redacted sample deliverable before I sign?
You are buying documents and the thinking behind them: a gap assessment, a findings register, a risk assessment, a policy set, a remediation plan, an evidence index. Ask to see one.
Why it matters. Deliverable quality varies enormously and is invisible from outside. A findings register can be a working document with each finding tied to a criterion, an owner, an effort estimate and a fix. It can also be a spreadsheet export from a scanner with the severity column colour-coded. Both are called a findings register, both arrive as a PDF, and you will not know which you bought until the invoice is paid.
What a good answer sounds like. "Yes. Here is a gap assessment from a similar environment with client details stripped out. The findings are real and you can see how we write them up." Redaction is expected. Refusal to show anything at all is the part worth noting. When the sample arrives, check whether each finding names the criterion it maps to, whether there is a recommended fix rather than only a description of the problem, and whether an engineer could act on it without a follow-up call.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Which auditors do you work with, and can I speak to one?
Readiness firms work alongside audit firms constantly, and those relationships are worth asking about directly.
Why it matters. Auditors have preferences. They want evidence in particular formats, they weight some controls more heavily, they have views on what a satisfactory population sample looks like. A practitioner who has been through several audits with a given firm knows what is coming. One who has not prepares for a generic audit and reworks it during fieldwork, at the worst point in the calendar.
What a good answer sounds like. "We work regularly with several licensed CPA firms. Tell me which auditor you are considering and I will tell you whether we have worked with them, how often, and what they focus on. If you want a reference call with an auditor who has received our work, I will arrange it."
The reference call is the real test, and the question for an auditor is narrow: when this firm hands you a client, how much rework do you send back? Auditors answer honestly, because their independence depends on not being anyone's sales channel. Independence rules also prevent a firm from both preparing and examining the same controls, so anyone offering both should explain the separation clearly.
Is the gap assessment scoped and priced separately from remediation?
Readiness splits naturally into two phases. Phase one is a gap assessment: someone examines your environment against the criteria in scope and produces a findings register. Phase two is remediation: fixing what the register found, writing what is missing, building the evidence trail. Phase one establishes the facts, phase two acts on them.
Why it matters. Nobody can honestly price phase two before phase one is finished, because until the assessment is done nobody knows what the gaps are. That is arithmetic, not a hedge. A firm quoting one fixed price for the whole journey before looking at your environment has done one of three things. Guessed high, so you pay a premium for risk it absorbed. Guessed low, so there is a difficult conversation in week six. Or narrowed what counts as included, and you discover the boundary later.
What a good answer sounds like. "The gap assessment is a fixed price and a fixed scope, and it produces a findings register. We price remediation from that register, and you are free to take it elsewhere or do the remediation in-house. Plenty of clients do some of it themselves." A firm confident in its remediation work is not afraid to let you hold the findings before you decide.
What are the practitioner's credentials beyond a baseline certification?
Certifications establish a floor. CISSP, CISA, ISO 27001 Lead Implementer and the rest tell you someone studied a body of knowledge and passed an exam. That is worth something, and it is a starting point rather than a distinguishing feature, since the exam is open to anyone.
Why it matters. SOC 2 readiness sits on top of security engineering. Whoever reviews your access controls, change management, logging and vulnerability handling should understand those systems as an engineer does, not only as checklist items. The gap between a consultant who can say a control is missing and one who can say how to build it into your stack is the gap between a document and an outcome.
What a good answer sounds like. Specifics. Published security research. Disclosed vulnerabilities with CVE identifiers you can look up in the public record. Conference talks. Open source tooling. Named prior roles with named responsibilities. The test is whether you can verify the claim yourself in ten minutes. A CVE number is checkable, "extensive experience" is not. Ask who will do the technical review and what they have published.
Which legal entity signs the contract, and under which province's law?
Read the signature block and the governing law clause. This takes ninety seconds and is skipped constantly.
Why it matters. The entity on the contract is the entity you have recourse against, and the governing law clause determines where a dispute is resolved and under whose rules. If the contracting entity sits in one jurisdiction and the dispute clause points at another, that is not automatically a problem, but it is a fact to know before signing. Your own customers will eventually ask the same about your vendors, and you will want a clean answer.
What a good answer sounds like. A named legal entity, its registration, and a governing law clause naming a specific province with courts in that province. Ontario, British Columbia, Quebec, Alberta, wherever, so long as it is named and consistent with the rest of the agreement. Confirm the entity in the corporate registry, confirm the same name appears on the invoice, and check whether confidentiality survives termination.
Where does our engagement data live while you hold it?
During readiness work a firm accumulates a detailed map of your weaknesses: network diagrams, access reviews, unpatched systems, everything you have not fixed yet. Ask where that sits.
Why it matters. The obvious reason is that this collection is an attractive target and its security is now partly out of your hands. The less obvious reason is contractual. If you have made data residency commitments to your own customers, or you handle personal information subject to provincial requirements, the location of that material may touch obligations you already hold. Health information under Ontario's PHIPA and personal information under Alberta's PIPA and Quebec's Law 25 each carry expectations around disclosure and transfer, and Law 25 requires a privacy impact assessment before personal information is communicated outside Quebec.
What a good answer sounds like. Named systems and named regions. "Documents live in this platform, in this region. Access is limited to the two people on your engagement. Multi-factor authentication is enforced. Here is the retention period after the engagement closes, and what we delete versus keep." A firm that has thought about its own posture answers quickly, because it has answered before. Ask for a subprocessor list, and have the answers written into the agreement.
What happens when the assessment finds more work than expected?
It happens often. The assessment surfaces an unmanaged production system, a shared administrator account nobody wanted to discuss, or a subprocessor that never went through review. The question is not whether surprises appear, but what the contract does when they do.
Why it matters. This is where well-structured and poorly structured engagements diverge. In the first, the findings register lands, remediation is re-scoped, and you decide with a number in front of you. In the second, you are mid-engagement, past a deadline, negotiating from a weak position.
What a good answer sounds like. "The findings register is the re-scoping trigger. If it is materially larger than we assumed, we reprice remediation from it and you approve the new scope before we continue. Nothing beyond the assessment happens without your sign-off."
Ask for the change order process in writing, and for the rate that applies to work outside scope, so the number is published rather than negotiated under pressure.
Who does the work, and who am I talking to right now?
Ask directly, early, and by name.
Why it matters. The gap between the sales conversation and the delivery team is where most disappointment lives. You evaluate a firm based on the person in front of you, then someone else arrives on day one with a different depth of experience. Staffed teams are normal and junior people have to learn somewhere, so this is not wrong in itself, but know the arrangement before you buy.
What a good answer sounds like. "I am doing the technical work, and here is my background. My colleague handles evidence collection and audit coordination. You will have both of us from kickoff to handover." Equally acceptable: "A senior consultant leads, a junior consultant gathers evidence, and I review every deliverable before it reaches you." Subcontracting is common and fine when disclosed. The answer worth probing is a shift into the collective voice, where the firm has capability and resources but nobody has a name.
What does handover look like when the engagement ends?
Readiness is finite. The engagement closes and you run the program yourself. Ask what you are left holding.
Why it matters. Compliance is not a one-time event. SOC 2 Type II examines controls over a period, and the next period is already coming. Access reviews continue quarterly, the risk assessment is refreshed annually, policies need owners. A handover that leaves you with PDFs and no knowledge of how they were produced means buying the same engagement again next year.
What a good answer sounds like. "You get the source files, not only the PDFs, in formats you can edit. You get the evidence index mapped to each criterion so you know what to collect and when. You get a calendar of recurring control activities with owners assigned. If you use a compliance platform, everything lands in it under your account, not ours." The test: could you run the next audit cycle with that, assuming nobody from the firm answers the phone?
How to run the shortlist
Three firms is enough. More than that and the conversations blur together.
Send the same written questions to each before any call. Written answers are comparable in a way conversations are not, and the speed and specificity of a reply is itself information. Ask for the redacted deliverable in the same message, since that request quietly separates the firms with something to show.
Then take the calls and use them for what needs a human: how would you scope this environment, what would you expect to find, what are we underestimating. Listen for whether the firm asks questions back. A practitioner who has done this repeatedly will want to know how many production environments you have, whether you have a formal change process, and who owns access provisioning. A conversation with no questions in it is a pitch. Read the agreements before comparing prices, because price differences often turn out to be scope differences hiding in the terms.
What a good "no" sounds like
Some of the most useful signals come from what a firm declines to promise. One that will not price remediation before assessing your environment is refusing to guess with your money. One that will not commit to a certification date it does not control is being accurate, because the opinion belongs to the auditor. Confidence here often sounds like caution, and the answers worth trusting arrive with conditions attached.
Next step
Take these ten questions into your first three conversations. The firms worth working with will answer each in a paragraph and volunteer the parts you did not think to ask.
The SOC 2 buyer resources on getsoc2.ca cover scoping, Type I versus Type II, evidence expectations and what auditors actually test. If you are still working out whether SOC 2 is the right framework for what your customers are asking for, start there before shortlisting anyone. The most expensive readiness engagement is the one scoped against the wrong requirement.
Common questions
How many firms should I shortlist?
Three. One quote tells you a price, two tell you which is cheaper, and three tell you what the work actually costs and which firm understood your scope. Brief them all on the same scope or the numbers are not comparable.
Should remediation be priced in the first quote?
It cannot be, honestly. Until a gap assessment has run, nobody knows what the gaps are. A single figure covering assessment and remediation either carries a buffer large enough for the worst case, or it gets renegotiated later when you have a deadline.
What if a consultant will not name their auditor contacts?
That is a fair answer if they genuinely place clients with whichever firm fits, and a warning if they simply have none. Ask instead whether they have worked with the firm you are considering, and whether a reference call is possible.
Compare readiness consultants on one scope
The questions above work best when several firms answer them on the same brief. Send your scope once and compare what comes back.
Get matchedWhere to go from here
- What drives a SOC 2 quote. Why two quotes for the same company differ by a factor of three.
- Questions to ask a SOC 2 auditor. The questions that separate a firm that has done this from one that has read about it.
- SOC 2 compliance consulting in Canada. What readiness consulting actually covers, and where it stops.
- SOC 2 audit cost. What the audit itself costs once readiness is done.