SOC2Prep

SOC 2 readiness consultants in Calgary

What is different about preparing for a SOC 2 audit from Calgary: who is asking you for the report, which privacy statute sits underneath it, and what that does to your scope.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

SOC 2 readiness work is the same standard everywhere, but the reason a Calgary company starts it, and the data it turns out to be holding, are local. A consultant-led program runs roughly $20,000 to $60,000 CAD nationally, with an assessment on its own at $5,000 to $20,000 CAD, and firms serving Calgary price inside that range. What changes locally is scope, and scope is what the money follows.

Alberta's Personal Information Protection Act applies instead of PIPEDA, and it is the only Canadian private-sector privacy law that has required breach notification to the provincial commissioner since 2010. Calgary's energy sector also brings operational technology into scope more often than a pure software audit would.

What triggers a first SOC 2 in Calgary

Around Calgary the demand comes from energy and industrial control systems. In practice a company here is pushed into SOC 2 by a customer in one of those sectors attaching a security schedule to a contract, rather than by a regulator, and that matters because the schedule usually names what it wants. Read it before you decide anything. It will tell you whether the buyer needs a Type 1 now or a Type 2 by a date, and whether it expects any criterion beyond security.

The sector also shapes what an auditor will look at. Buyers in energy tend to care about a narrow set of things repeatedly: who has production access, how changes are approved, what happens to data at the end of the contract, and whether an independent penetration test exists. Building the control set with that buyer in mind is not gaming the audit. It is scoping the audit around the commitments you actually made.

PIPA (Alberta) and what it does to your scope

Companies operating in Alberta answer to PIPA (Alberta) for private-sector personal information. SOC 2 does not replace that obligation and does not test it, since the security criterion asks about your controls rather than about statutory duties. The two intersect anyway: breach notification, retention limits and what you promise customers about their data all end up inside the same policy set.

The practical effect is on scope. If personal information subject to PIPA (Alberta) flows through a system, that system is difficult to exclude from the audit with a straight face, whatever the architecture diagram says. Decide that deliberately at the scoping stage rather than discovering it when an auditor asks where customer records live. The preparation guide covers how to write the scope down, and GetAudited explains which Canadian privacy law applies to you.

Hire locally, hire remotely, or do it yourself

Almost all readiness work is remote, so a Calgary address is rarely the deciding factor. On-site time earns its cost in two situations: physical security controls are in scope because you run your own space or hardware, or your team works better with somebody in the room for the scoping week. Otherwise judge a firm on whether it has taken a company like yours through this, and whether it treats PIPA (Alberta) correctly rather than defaulting to American guidance.

Doing it in house is a reasonable answer for a smaller Calgary team with one cloud, one product and somebody technical who has a few hours a week protected. The checklist is the working document for that route, and a paid readiness assessment near the end gives you an independent read before you commit to a window. The national guide covers when hiring help is worth it and what to ask.

Whoever does the preparation, they cannot also audit you. Independence rules keep those two engagements separate, so plan for two suppliers. Auditor selection is covered on GetSOC2.

Get readiness quotes for a Calgary company

Tell us your scope and your date, and we will put it in front of firms that work with companies in Alberta.

Get matched

Common questions

Does a SOC 2 readiness consultant have to be based in Calgary?

No. The work is documentation, control design and evidence process, nearly all of which is done remotely. The better test is whether the firm understands PIPA (Alberta) and has worked with companies in energy or similar sectors. On-site time matters mainly when physical security controls are in scope.

Does PIPA (Alberta) change what our SOC 2 covers?

It changes your scope rather than the criteria. SOC 2 tests the controls you say you operate, so systems holding personal information governed by PIPA (Alberta) are hard to leave out of the audited system, and the retention and notification commitments in your policies have to match what the statute requires of you in Alberta.

How long will preparation take for a Calgary company?

Two to four months of preparation from a standing start, then the observation window on top, which is three months at minimum for a Type 2. The window is calendar time and no consultant or platform shortens it. See the timeline for how the dates fit together.