SOC2Prep

SOC 2 for contractors and remote teams

Contractors are in your populations. Every sampled joiner and leaver question applies to them, and the background check answer that works in the US does not exist in Canada.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

If a contractor can reach production or customer data, they are inside your SOC 2 scope and inside every people-related population the auditor samples: onboarding, offboarding, confidentiality agreements, security training and policy acknowledgement. Employment status is irrelevant to the criteria. What changes for a Canadian company is the evidence available for background screening, because there is no equivalent of the US county-level records search that request lists and questionnaires assume. The answer to that question is a written policy rather than a missing document.

5 People populations contractors appear in

0 SOC 2 criteria that mention employment status

Consent What a Canadian criminal record check requires

Which contractors are in scope?

The test is access, not payroll. Work through these and treat anyone in the first four rows as workforce for SOC 2 purposes.

Contractor types and how each is treated
WhoTreated asWhat they appear in
Independent developer with repository and production accessWorkforceEvery people population, same as an employee
Offshore development agency working in your systemsWorkforce and vendor, bothPeople populations for the individuals, plus the vendor register for the agency
Fractional CTO or vCISO with admin accessWorkforceAccess grants, agreements, acknowledgement, offboarding
Support contractor who can see customer data in a toolWorkforceAccess review, training, agreements
Designer working only in Figma with no product dataNeither, usuallyNothing, if the scope boundary excludes those systems and says so
Agency running your marketing site, separate from the productVendorVendor register only, if the site is out of the boundary
Accountant, lawyer, recruiterVendorVendor register, and processor agreements if they hold personal information

Agency entries in the register are governed by the same rules as any other supplier, which the vendor management policy sets out, and the acceptable use terms contractors sign are the same document employees sign, covered on the acceptable use policy page.

The agency row is the one that surprises people, because it is both at once. The individuals doing the work need agreements, training records and access lifecycle evidence, and the agency itself needs a register entry, a risk rating and a contract with data protection terms. Doing only the second half is a common finding. Which side of the boundary each system sits on is a scope decision to make before the window opens.

Background checks under Canadian law

SOC 2 does not require background checks. CC1.4 asks that you demonstrate a commitment to competent personnel, and screening is one common way to evidence it, not the only one. Canadian screening does not look like the US screening a template assumes.

What is actually available for screening in Canada
CheckAvailable?Notes
Criminal record checkYes, with the individual's consentRun through police services or an accredited provider. The individual usually obtains it and provides the result
Vulnerable sector checkYes, restrictedOnly where the role qualifies, and it is not appropriate for ordinary software work
County-level criminal searchNoNot a Canadian concept. Records are federal through CPIC rather than county by county
Credit checkYes, with consent and a bona fide reasonProvincial rules limit when it is permitted, and for engineering roles it usually is not
Education and employment verificationYesThe most defensible check for technical roles, and the least intrusive
Ongoing or continuous monitoringEffectively noUS-style continuous criminal monitoring is not generally available or lawful here

The right answer to a blank field

Never leave the screening field empty in a questionnaire or a request list. Write a short policy stating what you check, for which roles, why, and how you handle the checks you deliberately do not run. An auditor accepts a documented and reasoned position. A blank reads as no process, and a US reviewer reads it as no screening at all. This is also a privacy obligation: consent for a check and the record of the result are personal information under PIPEDA and Quebec Law 25.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Offshore and cross-border contractors

Contractors outside Canada are allowed and common, and they add three questions that a domestic team does not face. None is a blocker, and all three should be answered in writing before a US buyer asks.

  1. Where does the data go when they work? A developer in another country with production access is a cross-border transfer of whatever they can see. Under PIPEDA a transfer for processing does not require consent, but accountability stays with you, and Quebec Law 25 wants an assessment on file before personal information leaves the province.
  2. What can they reach, and can it be narrowed? Scoped access, a jump host, or a masked non-production dataset turns an awkward question into a short answer. The narrowing is usually easier than the explaining.
  3. Whose device is it? Contractor-owned machines are the hardest evidence problem on this page, and the answer is either managed devices you issue or browser-only access with no local data. Attesting to encryption on a machine you cannot inspect is not evidence.

Device evidence for a remote workforce

Remote-first Canadian companies consistently score worst on device inventory, and it is the item most likely to become an exception. The auditor wants a list of every device with access, showing disk encryption and endpoint protection status, dated inside the window.

0 of 0 done ·

The case for keeping contractors out of scope

Narrowing the boundary so contractors never touch in-scope systems is a real option, and under-used. Browser-only access to a masked dataset, no repository write access, no production credentials: done properly, that removes most of the evidence burden on this page and removes the offshore transfer question entirely.

The counter-case is that it usually costs more than the compliance work saved. Contractors who cannot reach production cannot debug production, and the engineering friction is paid every week while the evidence burden is a few hours a month. Choose it where contractor turnover is high or where a single agency supplies people you never meet. Otherwise put them in scope and treat them exactly like employees, which is simpler than maintaining two categories of person.

Do contractors need background checks for SOC 2?

Not as a requirement of the standard. SOC 2 asks that you commit to competent personnel and that you do what your own policy says. If your policy says you screen everyone with production access, the auditor will test that for contractors too, so write the policy you can actually follow in Canada.

Are contractors included in the auditor's samples?

Yes. Hires and departures during the period include contractors, and a population that omits them is incomplete, which is a more serious finding than a single missing document.

Can offshore developers work on a SOC 2 scoped system?

Yes. Nothing in SOC 2 restricts where your workforce is. What you need is the same evidence you keep for anyone else, plus a written position on the cross-border data transfer and on the devices being used.

Do we need to manage contractor laptops?

You need evidence of the controls you claim. If you claim disk encryption and endpoint protection across the workforce, that has to include contractor machines, which means enrolment or issued devices. The alternative is to claim something narrower and true: browser-only access with no local data storage.

How do we offboard a contractor properly?

The same way as an employee, with a timestamp. Access removed from every system on the list, device returned or wiped, and the record dated. Terminations are the single most commonly sampled population, and contractor departures are where the gaps usually are. The artifact itself is covered on onboarding and offboarding evidence.

Get quotes from firms that know Canadian screening

Tell us where your workforce actually sits. Firms here quote against Canadian obligations rather than a US template.

Get matched