SOC2Prep

SOC 2 readiness: what to do before the audit

You have been asked for a SOC 2 report and you do not have one yet. This site is about the months between that email and the day an auditor starts asking for evidence.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Compare the firms yourself, or describe the job once and we will send it to the ones that do this work in Canada. Both are free.

SOC 2 readiness is the work you do before an audit firm is any use to you: deciding scope, writing policies that match reality, closing the control gaps you find, and starting the evidence habit that a Type 2 report is built on. For a company starting from nothing, that work takes roughly two to four months of real effort, and you can do it yourself.

This site is operated by TrazTech Inc., a security and compliance practice in Toronto. It is written for the team doing the preparation, not for the person shopping for an auditor. When you are ready for that part, GetSOC2 covers auditors, fees and report types.

Readiness work ends in a written gap assessment, and it is worth knowing what one looks like before you either buy it or attempt it. TrazTech publishes a specimen gap assessment in full, no email required: a readiness score with unanswered controls counted against it, the scope decisions everything else is measured against, the gaps ranked worst first with the effort each one takes, and the controls claimed with no evidence behind them, which is where an auditor samples first.

2 to 4 months Real effort before a window can open

3 months Shortest observation window worth buying

$0 What you have to spend to start

The order this work actually goes in

Almost every stalled SOC 2 program is a sequencing problem. Companies buy a platform before they have decided what is in scope, or book an auditor before they have any evidence to show. The sequence below is boring on purpose. Each stage produces something the next one needs.

SOC 2 readiness stages and what each one produces
StageWhat it producesRough effort
Decide scope and criteria A written system description and a decision on which Trust Services Criteria apply 1 to 2 weeks
Gap analysis A list of controls you do not have, ranked by how long they take to fix 2 to 4 weeks
Remediation Policies, access reviews, logging, vendor register, onboarding and offboarding that work 4 to 12 weeks
Evidence collection A repeatable way to produce screenshots, exports, tickets and approvals on request Ongoing from here
Readiness assessment An independent read on whether an auditor would accept what you have 2 to 3 weeks
Observation window Three to twelve months of controls operating, which becomes the Type 2 report Calendar time, not effort

The preparation guide walks through each of those stages in order, with what to write, who should own it, and what an auditor will ask for at the end.

Where teams stall

Four failure modes account for most of the delay in first-time programs. None of them are about the auditor.

Nobody owns it. SOC 2 spread across three people who each have a day job moves at the speed of the least available one. It does not need a full-time hire, but it needs one named person with a few hours a week protected and the authority to make decisions about scope.

Scope was never written down. If you cannot describe your system in a page, you cannot decide whether the marketing site, the internal analytics warehouse or the acquired product line is in the audit. That ambiguity resurfaces at the worst moment, when an auditor asks for evidence from a system you assumed was out. The scope and system description page has the boundary tests that settle it in an afternoon.

Policies describe an imaginary company. Downloaded policy templates promise quarterly access reviews and annual penetration tests. If you do neither, you have manufactured a finding rather than a control. Write the policy to match what you will actually do, then raise the bar deliberately.

Evidence starts too late. A Type 2 report tests operation over a period. Evidence you cannot produce for the first two months of that period is not recoverable by working harder in month five. It is the most expensive mistake in SOC 2 preparation.

The constraint nobody warns you about

The observation window is calendar time and cannot be compressed. A Type 2 report covering three months requires three months to pass with your controls running. If a deal closes in eight weeks and you started yesterday, no amount of budget produces a Type 2 report in time. A Type 1, which tests design at a single date, is usually the interim answer. The timeline page lays out what fits into what.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Doing it yourself, and when not to

A first SOC 2 is well within reach of an engineering-led company of ten to fifty people without hiring a consultant. The work is unglamorous rather than difficult: write down what you do, fix the places where what you do is not defensible, and keep records. Doing the first pass internally also means somebody in the building understands the program, which matters more in year two than year one.

Pay for help when one of three things is true. Your date is set by a signed contract and you need someone who already knows what an auditor accepts. Your environment is complicated: multiple products, an acquisition, or regulated data such as health information under PHIPA. Or you have already tried and the program has stalled for a quarter, which is usually an ownership problem that an outsider with a schedule can fix.

Typical Canadian readiness spend, CAD, first year
ApproachExternal costWhat you still do yourself
Fully internal, no platform $0 Everything, plus manual evidence collection
Compliance platform only $8,000 to $30,000 per year Policies, remediation, judgement calls on scope
Paid readiness assessment $5,000 to $20,000 All remediation, all evidence
Consultant-led readiness $20,000 to $60,000 Engineering changes and internal approvals

None of those include the audit itself, which is a separate engagement with a separate firm. Budget $20,000 to $60,000 CAD for a first Type 2 audit, and add a penetration test at $8,000 to $40,000 CAD. Most auditors expect one and most customers ask for it.

If you land on the consultant-led row, the guide to hiring readiness help in Canada covers the engagement models, what a fair scope looks like and the questions that separate a firm that has done this from one that has read about it. It carries a page for each of twenty markets, so a company in Toronto, Montreal, Vancouver or Calgary can read what the local buyer and the provincial privacy statute do to its scope before asking for a price. The directory lists readiness consultants and compliance platforms, researched from public records rather than bought as a list. TrazTech runs this site and is listed first, labelled.

What TrazTech does, since we operate this site

TrazTech is a security and compliance practice in Toronto. It sells readiness: scope, gap analysis, remediation, the evidence habit, and the handover to an audit firm. That is the consultant-led row in the table above, and the band there is the real one. It does not issue the audit report, because the firm that builds your controls cannot also attest to them.

It also runs traztech Workspace, a free compliance workspace, which is the $0 row done with structure instead of a spreadsheet: 10 frameworks, guided self-assessments, an evidence register mapped to controls, 40 policy templates with approval history, a risk register and audit-readiness scoring. Scheduled checks run daily against AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira and file the result against the control they prove. No credit card, no trial period, no paid tier, no seat limit, no export fee. The data stays yours if you hire somebody else or nobody at all.

Buy a platform instead when you need hundreds of integrations, an endpoint agent or HR system evidence. The workspace has seven connectors, no endpoint agent and no HR integration, and we will tell you that and help you set Vanta or Drata up. Hire a different readiness firm when you want one with no stake in the site you read this on. The directory lists them.

Start here

If you were asked for a report this week, start with the first thirty days. The readiness quiz takes about a minute and tells you whether an auditor conversation is worth having. The other free tools cover scoring your controls, working out which policies you need and building the evidence list.

If you are at the very beginning, read the preparation guide end to end once, then work the checklist as your working document. If you already have controls and want to know what is missing, start with the gap analysis, or score yourself section by section with the readiness scorecard. If your problem is a date, start with the timeline and work backwards from the report you have been asked for.

Three questions come up often enough to have their own pages. If the deal that started this is with a US enterprise, read what a US buyer asks for besides the report. The report is the first item on a longer list. If you hold personal information about people in Quebec, SOC 2 and Law 25 covers the obligations no American policy pack mentions. And if you already know a second buyer wants ISO 27001, running both frameworks together is cheaper than running them in sequence.

Get readiness quotes from Canadian firms

Tell us your scope, your headcount and the date a report has to exist by, and we will put it in front of firms that do this work in Canada. It is free and there is no obligation to take any of them.

Get matched

Common questions

How long does SOC 2 readiness take?

Two to four months of preparation for a company starting from nothing, then the observation window on top. A Type 1 can follow readiness almost immediately. A Type 2 adds at least three months of controls operating before fieldwork begins, so six to nine months from a standing start to a Type 2 report is a realistic plan.

Do we need a compliance platform to get ready?

No. Platforms such as Vanta, Drata and Sprinto save real time on evidence collection and continuous monitoring, and they are usually worth it above about thirty people or when your infrastructure is entirely in one cloud. We have gone through what each of Vanta, Drata and Sprinto does and does not do. Below that, a spreadsheet, a shared drive and a recurring calendar entry get a first audit done. What a platform does not do is make scope decisions, write a system description, or fix a control you do not have.

Can we start readiness before we pick an auditor?

Yes, and you should. Nothing in the preparation stage depends on which firm you engage, and talking to auditors is far more productive once you can describe your scope and show a control list. The one thing worth confirming early is your intended observation window, because that sets the date the firm needs to be booked by.

Is readiness work wasted if we later do ISO 27001?

Mostly not. Access control, change management, vendor management, logging and incident response carry over almost entirely. What does not carry over is the structure: ISO 27001 wants a management system with risk treatment plans and internal audits, which SOC 2 does not require in the same form. Expect to reuse the controls and rewrite the documentation, and see running the two together for what the second framework actually adds.

Who should own SOC 2 preparation internally?

Whoever can change how engineering works without asking permission. In most companies under fifty people that is a senior engineer, a head of platform, or a technical co-founder. Assigning it to an office manager or a junior analyst fails predictably, because the majority of the remediation work is changes to systems and to how the engineering team operates.