Is SOC 2 worth it at our size?
The test is not whether you can afford it. It is whether the revenue that is genuinely blocked, this year and next, exceeds roughly $100,000 CAD of committed contract value. Below that line, most companies are buying a report nobody asked twice for.
For a Canadian company between 15 and 80 people, SOC 2 pays for itself when around $100,000 CAD or more of committed, multi-year contract value is blocked on it. Below that, with only one buyer asking, the answer is usually not yet. The cost is $35,000 to $90,000 CAD in year one and $30,000 to $60,000 CAD every year after, plus 200 to 500 hours of your own team's time, and the recurring half is what most break-even calculations forget.
$100,000 Blocked committed revenue that justifies year one, CAD
200 to 500 Internal hours, on top of the fees
Year 2 When the cost stops feeling like a project
The break-even, drawn
| Enterprise buyers who have asked | Typical blocked committed value | Verdict |
|---|---|---|
| None, you are anticipating | $0 | No. Do the control work, not the audit |
| One | $25,000 to $80,000 | Usually no on its own. Offer a substitute |
| Two | $80,000 to $200,000 | Yes in most cases, and the second one is the signal |
| Three | $200,000 to $400,000 | Yes, and you are already late |
| Four or more | $400,000 and up | Yes, and the delay costs more than the fee |
| Where the line sits for a 15 to 80 person Canadian company | Around two enterprise buyers, or $100,000 CAD committed | |
Three situations where the answer is no
These are the cases where a Canadian company of this size should hold off.
- Nobody has asked
- Buying a report against an anticipated requirement spends the money a year early, and the period will have lapsed by the time a buyer wants it. The control work carries forward. SOC 2 for startups makes the case.
- One buyer, a modest contract, and an exception path
- A single deal under roughly $60,000 CAD a year does not pay for a recurring $30,000 to $60,000 CAD obligation. Offer an interim package and revisit when the second buyer asks. What to send is on what to offer instead.
- Your product is not stable enough to describe
- A SOC 2 report describes a system. A company rewriting its architecture, migrating clouds or about to change what it sells will write a system description that is wrong by the time it is signed, and the second audit will cost close to the first. Wait until the shape holds still for a quarter.
What tips the decision toward yes
Beyond a second buyer asking, four things move a marginal case over the line. Sales cycle length is the biggest and the least measured. An enterprise deal that sits three extra months in a security review carries a cost that rarely appears beside the audit fee. Multi-year terms matter: the report is a recurring cost and a one-year contract is not. Segment matters: a company selling into US enterprise will be asked repeatedly, one selling to small businesses may never be asked again. An existing ISO 27001 certificate changes the number substantially, since much of the control work is already done and running the two together is cheaper than running either twice.
Count the recurring cost, not the project cost
The most common budgeting error at this size is treating SOC 2 as a one-time $50,000 CAD project. It is an annual obligation: a new observation window, new fieldwork, a renewed report, and a program that has to keep running in between. Companies that let the program lapse between windows pay close to the first-year number again, which year two sets out.
If the answer is yes but the number is not affordable
The gap between $35,000 and $90,000 CAD is mostly decisions rather than inflation. Security criteria only, one environment in scope, readiness done internally, no platform in year one and a tightly scoped penetration test lands a small Canadian company nearer $28,000 to $45,000 CAD. What each of those decisions costs you is on the cheapest honest way to get SOC 2, and the internal-effort version of the same question is on preparing with no compliance budget. If the deal cannot wait for any of it, saying no is a legitimate answer.
We are 20 people. Can we afford SOC 2?
Yes, at $25,000 to $40,000 CAD in year one on a lean path, but affording it and needing it are different questions. At 20 people the constraint is usually the 200 to 500 hours rather than the fee, because those hours come out of the same two engineers who ship the product.
Will SOC 2 bring us new customers on its own?
No. It removes an objection rather than creating demand. Companies that expect a report to generate pipeline are consistently disappointed, and that expectation is why some of them conclude it was not worth it.
Should we do a Type 1 first to spread the cost?
A Type 1 costs more in total, not less, because you pay for two engagements in one year. Do it when the Type 1 unblocks revenue now. Do not do it as a budgeting device.
Is ISO 27001 cheaper for a company our size?
Not usually in year one, and it is the wrong comparison for most Canadian SaaS companies because North American buyers ask for SOC 2. It becomes the better buy when your buyers are in the EU or the UK.
How do we know if the revenue is really blocked?
Ask the buyer whether their vendor risk policy permits an exception, and for how long. If it does, the revenue is delayed rather than blocked, and delayed revenue rarely justifies the spend on its own.
Put a real number against the decision
The cost calculator gives a four-line CAD budget for your scope, and firms here quote against it.
Estimate the cost