SOC2Prep

ISO 27001 firms in Canada

Firms in the SOC2Prep directory that do ISO 27001 work, ordered by tier and then alphabetically.

25 firms.

ISO 27001 firms in Canada

TrazTech Inc. VerifiedOperates this site

The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Canadian privacy, Trust center, Cloud compliance, AI-built app QA, AI security, Security questionnaires, Auditor management, Internal audit, Threat and risk assessment, Tabletop and continuity testing, Cyber insurance readiness, Technical due diligence, Outsourced privacy officer

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF, PIPEDA, PHIPA

13 Security Unclaimed

Information security consultancy that works through GRC platforms to get clients through SOC 2 Type 1 and Type 2 audits carried out by an independent auditor.

New York, New York, United States · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

7 River Systems Unclaimed

Runs internal audits and readiness assessments across SOC 2 and other frameworks and builds compliance programs for clients ahead of an external audit.

Maryland, United States · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

ABM Integrated Solutions Unclaimed

IT firm whose compliance practice prepares clients for SOC 2 and ISO 27001 certification using a compliance automation platform, and does not issue certificates.

Dartmouth, Nova Scotia · SOC 2 readiness, ISO 27001, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001

Amomitto Security Unclaimed

Runs SOC 2, ISO 27001 and HIPAA engagements covering readiness and post-audit maintenance, coordinating the audit rather than issuing the report.

SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA

Atoro Unclaimed

Compliance consultancy that builds the controls and evidence behind the SOC 2 report North American buyers ask for, and runs internal audits rather than signing opinions.

Portarlington, Ireland · SOC 2 readiness, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

BALANCED+ Unclaimed

IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.

Mississauga, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy, Cloud compliance

Frameworks: SOC 2, ISO 27001, PIPEDA, PHIPA

BARR Advisory Unclaimed

Firm offering virtual CISO and security program management within its advisory and managed services line, oriented to compliance program delivery.

SOC 2 readiness, ISO 27001, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

Certi360 Unclaimed

Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.

Laval, Quebec · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Cognisys Unclaimed

UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.

United Kingdom · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Corporate Prime Solutions Inc. Unclaimed

Consultancy providing end to end ISO 27001 advisory, assessment and training to prepare clients for external certification audits, and does not issue certificates.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

CyberCrest Compliance Unclaimed

Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.

Encinitas, California, United States · SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Cycore Unclaimed

Compliance services firm that guides clients through the whole SOC 2, ISO 27001 and HIPAA process from initial assessment to certification, with the audit done by others.

SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA

Digital Fort Unclaimed

Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.

Winnipeg, Manitoba · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Elastify Unclaimed

Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

GuardsArm Unclaimed

Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.

Edmonton, Alberta · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

IRM Consulting & Advisory Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Kobalt.io Unclaimed

Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

Lazarus Alliance Unclaimed

States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.

SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF, PIPEDA

Mirai Security Unclaimed

Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001

risk3sixty Unclaimed

GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.

Roswell, Georgia, United States · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, NIST CSF

Sagentix Advisors Unclaimed

Ottawa advisory firm whose cyber and AI practice sells ISO 27001 and SOC 2 readiness alongside privacy and AI governance work. Not a CPA firm and does not sign SOC 2 opinions.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

SAV Associates Unclaimed

CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA

Truvo Cyber Unclaimed

Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

URM Consulting Services Unclaimed

Provides SOC 2 gap analysis, remediation and consultancy for organizations preparing for a Type 1 or Type 2 report rather than producing the report.

Reading, United Kingdom · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

Get quotes instead of browsing

Describe what you need once and it reaches the firms on this page that match it.

Get quotes

Back to the full directory

Other ways to narrow the list

Same directory, cut a different way.

How do I know I can trust one of these firms?

Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.

How were these firms chosen?

They were listed from public information or added by the firm itself. Being listed is not a recommendation, and SOC2Prep does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

How many firms should I approach?

Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.