SOC 2 for contractors and remote teams
Contractors are in your populations. Every sampled joiner and leaver question applies to them, and the background check answer that works in the US does not exist in Canada.
If a contractor can reach production or customer data, they are inside your SOC 2 scope and inside every people-related population the auditor samples: onboarding, offboarding, confidentiality agreements, security training and policy acknowledgement. Employment status is irrelevant to the criteria. What changes for a Canadian company is the evidence available for background screening, because there is no equivalent of the US county-level records search that request lists and questionnaires assume. The answer to that question is a written policy rather than a missing document.
5 People populations contractors appear in
0 SOC 2 criteria that mention employment status
Consent What a Canadian criminal record check requires
Which contractors are in scope?
The test is access, not payroll. Work through these and treat anyone in the first four rows as workforce for SOC 2 purposes.
| Who | Treated as | What they appear in |
|---|---|---|
| Independent developer with repository and production access | Workforce | Every people population, same as an employee |
| Offshore development agency working in your systems | Workforce and vendor, both | People populations for the individuals, plus the vendor register for the agency |
| Fractional CTO or vCISO with admin access | Workforce | Access grants, agreements, acknowledgement, offboarding |
| Support contractor who can see customer data in a tool | Workforce | Access review, training, agreements |
| Designer working only in Figma with no product data | Neither, usually | Nothing, if the scope boundary excludes those systems and says so |
| Agency running your marketing site, separate from the product | Vendor | Vendor register only, if the site is out of the boundary |
| Accountant, lawyer, recruiter | Vendor | Vendor register, and processor agreements if they hold personal information |
Agency entries in the register are governed by the same rules as any other supplier, which the vendor management policy sets out, and the acceptable use terms contractors sign are the same document employees sign, covered on the acceptable use policy page.
The agency row is the one that surprises people, because it is both at once. The individuals doing the work need agreements, training records and access lifecycle evidence, and the agency itself needs a register entry, a risk rating and a contract with data protection terms. Doing only the second half is a common finding. Which side of the boundary each system sits on is a scope decision to make before the window opens.
Background checks under Canadian law
SOC 2 does not require background checks. CC1.4 asks that you demonstrate a commitment to competent personnel, and screening is one common way to evidence it, not the only one. Canadian screening does not look like the US screening a template assumes.
| Check | Available? | Notes |
|---|---|---|
| Criminal record check | Yes, with the individual's consent | Run through police services or an accredited provider. The individual usually obtains it and provides the result |
| Vulnerable sector check | Yes, restricted | Only where the role qualifies, and it is not appropriate for ordinary software work |
| County-level criminal search | No | Not a Canadian concept. Records are federal through CPIC rather than county by county |
| Credit check | Yes, with consent and a bona fide reason | Provincial rules limit when it is permitted, and for engineering roles it usually is not |
| Education and employment verification | Yes | The most defensible check for technical roles, and the least intrusive |
| Ongoing or continuous monitoring | Effectively no | US-style continuous criminal monitoring is not generally available or lawful here |
The right answer to a blank field
Never leave the screening field empty in a questionnaire or a request list. Write a short policy stating what you check, for which roles, why, and how you handle the checks you deliberately do not run. An auditor accepts a documented and reasoned position. A blank reads as no process, and a US reviewer reads it as no screening at all. This is also a privacy obligation: consent for a check and the record of the result are personal information under PIPEDA and Quebec Law 25.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Offshore and cross-border contractors
Contractors outside Canada are allowed and common, and they add three questions that a domestic team does not face. None is a blocker, and all three should be answered in writing before a US buyer asks.
- Where does the data go when they work? A developer in another country with production access is a cross-border transfer of whatever they can see. Under PIPEDA a transfer for processing does not require consent, but accountability stays with you, and Quebec Law 25 wants an assessment on file before personal information leaves the province.
- What can they reach, and can it be narrowed? Scoped access, a jump host, or a masked non-production dataset turns an awkward question into a short answer. The narrowing is usually easier than the explaining.
- Whose device is it? Contractor-owned machines are the hardest evidence problem on this page, and the answer is either managed devices you issue or browser-only access with no local data. Attesting to encryption on a machine you cannot inspect is not evidence.
Device evidence for a remote workforce
Remote-first Canadian companies consistently score worst on device inventory, and it is the item most likely to become an exception. The auditor wants a list of every device with access, showing disk encryption and endpoint protection status, dated inside the window.
0 of 0 done ·
The case for keeping contractors out of scope
Narrowing the boundary so contractors never touch in-scope systems is a real option, and under-used. Browser-only access to a masked dataset, no repository write access, no production credentials: done properly, that removes most of the evidence burden on this page and removes the offshore transfer question entirely.
The counter-case is that it usually costs more than the compliance work saved. Contractors who cannot reach production cannot debug production, and the engineering friction is paid every week while the evidence burden is a few hours a month. Choose it where contractor turnover is high or where a single agency supplies people you never meet. Otherwise put them in scope and treat them exactly like employees, which is simpler than maintaining two categories of person.
Do contractors need background checks for SOC 2?
Not as a requirement of the standard. SOC 2 asks that you commit to competent personnel and that you do what your own policy says. If your policy says you screen everyone with production access, the auditor will test that for contractors too, so write the policy you can actually follow in Canada.
Are contractors included in the auditor's samples?
Yes. Hires and departures during the period include contractors, and a population that omits them is incomplete, which is a more serious finding than a single missing document.
Can offshore developers work on a SOC 2 scoped system?
Yes. Nothing in SOC 2 restricts where your workforce is. What you need is the same evidence you keep for anyone else, plus a written position on the cross-border data transfer and on the devices being used.
Do we need to manage contractor laptops?
You need evidence of the controls you claim. If you claim disk encryption and endpoint protection across the workforce, that has to include contractor machines, which means enrolment or issued devices. The alternative is to claim something narrower and true: browser-only access with no local data storage.
How do we offboard a contractor properly?
The same way as an employee, with a timestamp. Access removed from every system on the list, device returned or wiped, and the record dated. Terminations are the single most commonly sampled population, and contractor departures are where the gaps usually are. The artifact itself is covered on onboarding and offboarding evidence.
Get quotes from firms that know Canadian screening
Tell us where your workforce actually sits. Firms here quote against Canadian obligations rather than a US template.
Get matched