SOC2Prep

SOC 2 readiness consultant directory

This directory lists the people and products that get you ready for a SOC 2 audit. It does not list audit firms, and the difference is the reason the page exists.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Filtering happens in your browser. Nothing is sent anywhere and the order never changes.

51 firms listed on SOC2Prep.

Our offerings

TrazTech Inc. VerifiedOperates this site

The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Canadian privacy, Trust center, Cloud compliance, AI-built app QA, AI security, Security questionnaires, Auditor management, Internal audit, Threat and risk assessment, Tabletop and continuity testing, Cyber insurance readiness, Technical due diligence, Outsourced privacy officer

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF, PIPEDA, PHIPA

Everyone else

Listed from public information and not yet claimed by the firm, so the details here are ours rather than theirs. If this is your firm, claim it and it becomes yours to edit.

13 Security Unclaimed

Information security consultancy that works through GRC platforms to get clients through SOC 2 Type 1 and Type 2 audits carried out by an independent auditor.

New York, New York, United States · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

3Tenets Consulting Unclaimed

Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.

Ontario · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, AI security

Frameworks: SOC 2, NIST CSF, PHIPA

7 River Systems Unclaimed

Runs internal audits and readiness assessments across SOC 2 and other frameworks and builds compliance programs for clients ahead of an external audit.

Maryland, United States · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

ABM Integrated Solutions Unclaimed

IT firm whose compliance practice prepares clients for SOC 2 and ISO 27001 certification using a compliance automation platform, and does not issue certificates.

Dartmouth, Nova Scotia · SOC 2 readiness, ISO 27001, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001

Accedere Unclaimed

Offers SOC attestation reporting and ISO/IEC certification work from offices in the United States, India and the UAE; the site states no CPA firm licence, so it is listed as readiness only here.

Denver, Colorado, United States · SOC 2 readiness, Compliance advisory, Cloud compliance

Frameworks: SOC 2

Adsero Security Unclaimed

Offers SOC 2 Audit Prep covering Type I and Type II certification preparation, leaving the attestation to an independent audit firm.

Tampa, Florida, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Agency Unclaimed

US based compliance engineers who run control implementation, evidence collection and audit coordination for client SOC 2 programs; the audit is performed by others.

United States · SOC 2 readiness, vCISO, Compliance advisory

Frameworks: SOC 2

Airius Unclaimed

Implements and manages regulatory compliance frameworks including SOC 2 and provides readiness assessments and audit preparation services rather than the audit itself.

Fairfield, Connecticut, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Amomitto Security Unclaimed

Runs SOC 2, ISO 27001 and HIPAA engagements covering readiness and post-audit maintenance, coordinating the audit rather than issuing the report.

SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA

Assurance Dimensions Unclaimed

A licensed independent CPA firm that provides attest services and performs SOC 1 and SOC 2 audits as well as readiness work through its IT advisory group.

SOC 2 audit, SOC 2 readiness

Frameworks: SOC 2

Atoro Unclaimed

Compliance consultancy that builds the controls and evidence behind the SOC 2 report North American buyers ask for, and runs internal audits rather than signing opinions.

Portarlington, Ireland · SOC 2 readiness, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Audit Peak Unclaimed

Performs SOC 1, SOC 2 and SOC 3 engagements and states its team members are CPAs, but the site carries no statement of firm level CPA licensure, so it is listed as readiness only here.

New York, New York, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

BALANCED+ Unclaimed

IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.

Mississauga, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy, Cloud compliance

Frameworks: SOC 2, ISO 27001, PIPEDA, PHIPA

BARR Advisory Unclaimed

Firm offering virtual CISO and security program management within its advisory and managed services line, oriented to compliance program delivery.

SOC 2 readiness, ISO 27001, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

Bright Defense Unclaimed

Cybersecurity firm that gets clients SOC 2 ready with scoping, a control baseline and evidence workflows, then supports them through the external audit.

Culver City, California, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Certi360 Unclaimed

Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.

Laval, Quebec · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

CLA (CliftonLarsonAllen) Unclaimed

A licensed CPA firm that performs SOC 1, SOC 2 and SOC 2+ examinations, including a readiness assessment before the examination.

Minnesota, United States · SOC 2 audit, SOC 2 readiness

Frameworks: SOC 2

Cognisys Unclaimed

UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.

United Kingdom · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Compass IT Compliance Unclaimed

Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.

SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, HIPAA, PCI DSS, NIST CSF

Compliance Foundry Unclaimed

Compliance engineering firm in Silicon Valley that prepares clients for the SOC 2 audit through a 28 day readiness program with automated remediation of cloud controls; it is not a CPA firm and does not sign opinions.

California, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Corporate Prime Solutions Inc. Unclaimed

Consultancy providing end to end ISO 27001 advisory, assessment and training to prepare clients for external certification audits, and does not issue certificates.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

Cyber Defense Advisors Unclaimed

Cyber compliance consultancy listing SOC 2 compliance among its services, preparing clients for the audit rather than signing the opinion.

Tampa, Florida, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

CyberCrest Compliance Unclaimed

Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.

Encinitas, California, United States · SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Cycore Unclaimed

Compliance services firm that guides clients through the whole SOC 2, ISO 27001 and HIPAA process from initial assessment to certification, with the audit done by others.

SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA

Digital Fort Unclaimed

Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.

Winnipeg, Manitoba · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Elastify Unclaimed

Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

ESKA Unclaimed

Provides end-to-end SOC 2 preparation covering gap analysis, policy development and control implementation, leaving the report itself to an independent auditor.

Ontario · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Framework Security Unclaimed

Firm selling virtual CISO under managed security, delivered hands-on through weekly working sessions and engineers paired with client staff.

SOC 2 readiness, vCISO, Compliance advisory, AI security

Frameworks: SOC 2, ISO 42001, PCI DSS, NIST CSF

Fusion Computing Limited Unclaimed

Toronto provider selling combined vCIO and vCISO services as strategic IT planning and security leadership, including SOC 2 readiness support.

Toronto, Ontario · SOC 2 readiness, vCISO, Compliance advisory

Frameworks: SOC 2, PIPEDA

Genius GRC Unclaimed

Develops SOC 2 controls and prepares clients to pass a cybersecurity audit conducted by an outside firm.

SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

GreenHat Security Unclaimed

Firm selling fractional and virtual CISO services positioned as security leadership that fits the company stage, with SOC 2 readiness work.

SOC 2 readiness, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, PIPEDA

Guardlii Unclaimed

Security services firm that assists clients in achieving SOC 2 compliance for supply chain and data protection requirements rather than performing the audit.

SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

GuardsArm Unclaimed

Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.

Edmonton, Alberta · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

IRM Consulting & Advisory Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Kobalt.io Unclaimed

Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

Lazarus Alliance Unclaimed

States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.

SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF, PIPEDA

Mirai Security Unclaimed

Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001

Oread Risk & Advisory Unclaimed

Attestation, information security and compliance consulting firm that conducts SOC reporting engagements and IT security reviews; the site names a CPA principal but does not state firm-level CPA licensure for signing SOC 2 opinions.

Kansas, United States · SOC 2 readiness, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Pilotcore Unclaimed

Ottawa cloud and DevSecOps consultancy whose audit readiness service maps SOC 2 and customer security requirements to controls and evidence. Not a CPA firm and does not sign SOC 2 opinions.

Ottawa, Ontario · SOC 2 readiness, Compliance advisory, Cloud compliance

Frameworks: SOC 2

Render Compliance Unclaimed

Licensed CPA firm in Washington State that performs SOC 2 attestations and signs the report, and also runs gap assessments to determine readiness before fieldwork.

Seattle, Washington, United States · SOC 2 audit, SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Rhymetec Unclaimed

Provider that sets up and runs a client internal information security and data privacy program, supplying executive-level security leadership.

SOC 2 readiness, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

risk3sixty Unclaimed

GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.

Roswell, Georgia, United States · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, NIST CSF

Sagentix Advisors Unclaimed

Ottawa advisory firm whose cyber and AI practice sells ISO 27001 and SOC 2 readiness alongside privacy and AI governance work. Not a CPA firm and does not sign SOC 2 opinions.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

SAV Associates Unclaimed

CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA

Tempo Audits Unclaimed

A UKAS accredited assurance provider offering SOC 2 work for SaaS teams; the site does not state which CPA firm signs the report, so it is listed as readiness only here.

United Kingdom · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

The Driz Group Unclaimed

Handles SOC 2 readiness assessment and gap remediation and supports clients through to attestation, which an independent auditor issues.

SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Trava Security Unclaimed

Offers compliance readiness and audit preparation plus a managed compliance program so clients can reach SOC 2 certification through an independent auditor.

Indianapolis, Indiana, United States · SOC 2 readiness, Compliance advisory

Frameworks: SOC 2

Truvo Cyber Unclaimed

Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

URM Consulting Services Unclaimed

Provides SOC 2 gap analysis, remediation and consultancy for organizations preparing for a Type 1 or Type 2 report rather than producing the report.

Reading, United Kingdom · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

Workstreet Unclaimed

Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.

100+ · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Trust center, Cloud compliance, Security questionnaires

Frameworks: SOC 2, ISO 27001

Browse a shorter list

The whole directory is above. These are the same firms cut down to one service or one province, which is usually the faster way in.

How do I know I can trust one of these firms?

Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.

Is a listing here a recommendation?

No. Firms are listed from public information or added by the firm itself, and a Verified badge is a tier rather than an endorsement. Nothing on this page says a firm is the right one for you. Compare at least three.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

If you want quotes now rather than a list to read, the quote form puts your scope in front of Canadian firms that do readiness work. If you want to understand what you are buying first, start with the guide to hiring readiness help in Canada, which also links to a page for each of twenty cities.

What this directory lists

Two categories, kept apart because they are bought differently and priced differently.

Readiness consultants. Firms and independent practitioners who do the preparation work: scoping, gap assessment, policy writing, control design, remediation project management, evidence collection and support during fieldwork. A listing will record the engagement models the firm offers, the size of company it usually works with, whether it works alongside a compliance platform or against a spreadsheet, and which provinces and industries it knows. That last item matters more than location, because a consultant who has taken a health technology company through PHIPA and SOC 2 together is a different hire from one who has only done cloud SaaS.

Compliance platforms. Software that connects to your cloud accounts, identity provider and code repository and collects part of the evidence automatically, on top of a control framework already mapped to the Trust Services Criteria. A listing will record what it integrates with, whether it includes policy templates, whether the pricing is public, and what the contract term usually is. Canadian pricing runs roughly $8,000 to $30,000 CAD a year, typically prepaid annually and often on a multi-year term, so the contract shape is worth listing beside the feature list. The three most commonly bought in Canada are covered in detail already: Vanta, Drata and Sprinto, including what each one leaves entirely to you.

Statute experience is the filter that does not exist on any American directory and it is the one that matters most here, because a firm that has never written a Law 25 clause is not the firm to hire for a Quebec scope. Sector experience will sit alongside it, since a consultant who has taken a health technology company through PHIPA and SOC 2 together is a different hire from one who has only done cloud SaaS.

Consultant, platform, auditor

These get conflated constantly, usually by a sales conversation that has an interest in conflating them. They are three different purchases and you may need all three, in that order.

What each kind of supplier does on a first SOC 2
QuestionReadiness consultantCompliance platformAudit firm
Decides your scopeAdvises, you decideNoNo
Writes your policiesYesSupplies templatesNo
Fixes a missing controlRuns the project, you make the changeTells you it is missingNo
Collects evidenceSets up the habitAutomates part of itRequests and tests it
Issues the reportNoNoYes, and only it can
Has to be a licensed CPA firmNoNoYes
When you engage itAt the startBefore the window opensOnce controls are running

The independence rule is the part worth understanding rather than memorising. An auditor is giving an opinion on whether your controls were designed properly and operated over a period. A firm that designed those controls, wrote the policy set behind them and built the evidence pipeline cannot then give an opinion on its own work, so it is barred from auditing what it built. That is why the readiness supplier and the audit firm are separate purchases, and why nobody in this directory can also sign your report.

Some large firms sell both through separated teams. That arrangement can be legitimate under professional standards, but a reader of your report does not know your supplier's internal governance and will ask about it when they see one name on both sides. For a company under fifty people the uncomplicated answer is two suppliers. When you get to picking the audit firm, GetSOC2 covers auditors, including fees, report types and independence. This site stops at the point where an auditor becomes useful to you.

What a listing shows

The two rows below are format examples, not real firms. The names are invented. Nothing here is a recommendation and no such company is listed.

Example Readiness Co Verified

Readiness consultantOntario and QuebecGap assessment, policy set, evidence setup10 to 100 staff

Illustration of a claimed and checked listing. Verified means somebody at the firm confirmed the detail and we checked the business is real and delivers the work itself.

Request a quote

Sample Compliance Platform Unclaimed

Compliance platformAnnual contractCloud, identity and code integrations

Illustration of an unclaimed listing. Nobody at the vendor has confirmed or corrected it, so the detail is only as good as the public record it came from.

Claim this listing

How listings work

A basic listing is free and stays free. Name, category, provinces served, what the firm or product does, and a link. Nothing about that tier expires or converts into a bill.

Verified is the paid tier. It costs $300 CAD a month or $3,000 CAD a year, and the firm-facing page sets out exactly what it includes and what it does not. Saying that here rather than after somebody has filled in a form is the whole point: a directory that calls itself free and then invoices you has told you what it is.

Claiming a listing means somebody at the firm confirms the detail is correct and takes responsibility for keeping it current. An unclaimed listing is one assembled from public information, and it carries the unclaimed badge so you know the difference. Claiming is free, it does not put the listing on a trial that later charges, and it is done from the listing page or by writing to [email protected] from a company address.

Verified is the only badge that means we did work, and it is the badge you pay for. For a consultant it means we confirmed the business exists, spoke to a person there, and checked the firm performs the work rather than subcontracting it under its own name. For a platform it means we confirmed the integrations and the contract terms with the vendor. Verified is not a quality rating and it is not an endorsement. It says the supplier is what it claims to be, nothing more, and paying for it does not change what its listing says.

How this site makes money

Three ways. TrazTech earns a fee when a quote request through this site turns into an engagement. Firms can pay $300 CAD a month or $3,000 CAD a year for the Verified tier, which sits above the free tier on the page. And some links to compliance platforms elsewhere on the site will become affiliate links once those programs are applied to. Worth knowing before you read anything here as neutral. Paying does not change what a listing says about a firm, and no amount of money moves a firm above another inside the same tier.

What to ask

You can run a good selection process without a directory, and the questions matter more than the list anyway. Give three candidates the same written scope: headcount, the systems in scope, which Trust Services Criteria, your intended observation window, and the date a report has to exist by. Quotes priced against different scopes cannot be compared, and that accounts for most of the wild variation companies report.

Ask a consultant what you are handed at the end, and whether the policies are templates or written against how you actually operate. Ask who does the evidence collection during the window, because a consultant who leaves at the point the window opens has left before the hard part. Ask how they work with your engineers, since remediation is engineering change rather than paperwork. Ask what happens if the auditor raises an exception later.

Before any of those conversations, the readiness scorecard tells you which control areas are weak, which is what a consultant will quote against anyway.

Ask a platform vendor for the contract term, the renewal price, and what happens to your evidence if you leave. Ask which of your systems it genuinely integrates with rather than which logos are on the page. Our readiness assessment page covers how to tell whether you are actually ready, and the preparation guide is the work itself if you decide to do it without anybody.

If you run one of these firms rather than shopping for one, the pages on where readiness work comes from and how to package the offer are written for you, and they are honest about how small a share of pipeline a directory listing is.

Add your firm to the directory

Canadian readiness consultants and compliance platforms get a free listing. The firm-facing page has the form, and it states the Verified price before it asks you for anything.

List your firm

Common questions

How did firms get into this directory?

Most were researched from public information: registration records, the firm's own site, and the credentials it publishes. Those listings are ours rather than the firm's until someone there claims it. A claimed listing is free and becomes the firm's to edit. Verified means we checked the firm is real and is what it says it is.

Why are audit firms not listed here?

Because this site is about the preparation, not the audit. Auditors are listed on GetSOC2, which covers firm selection, fees and report types. Keeping them apart also reflects how the engagements work: your readiness supplier and your audit firm have to be different organizations.

What does it cost to be listed?

A basic listing is free and claiming an existing listing is free. Verified is the paid tier at $300 CAD a month or $3,000 CAD a year, and it buys the badge, a fuller profile and placement above the free tier. The firm-facing page has the full comparison. TrazTech also earns a fee when a quote request through this site turns into an engagement.

Can our readiness consultant also do our audit?

No. The auditor has to be independent of the controls it examines, so a firm that designed your controls and wrote your policies cannot issue an opinion on them. Plan for two suppliers, engaged at different points.

Do we need a consultant and a platform, or just one?

Many companies buy neither for a first audit. A platform saves evidence collection time and is usually worth it above about thirty people or when all your infrastructure sits in one cloud. A consultant buys speed and the knowledge of what an auditor accepts. They solve different problems, so buying both is reasonable and buying neither is common.

Does a readiness consultant have to be in our city?

Rarely. Almost all of this work is done remotely, and the useful test is whether the firm knows your industry and the privacy law that applies in your province. On-site time matters mainly when physical security controls are in scope. The city pages cover what is different about each market.