SOC2Prep

SOC 2 readiness consultants in Canada

Readiness consultants do the work between the day a customer asks for a SOC 2 report and the day an auditor can start. Here is when that is worth paying for, what a good engagement looks like, and what to ask before you sign one.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

A SOC 2 readiness consultant is hired to get your controls, policies and evidence into a state an auditor will accept. In Canada that engagement usually runs $20,000 to $60,000 CAD for a first Type 2, or $5,000 to $20,000 CAD if you only want an assessment and a gap list rather than somebody running the program. It is not a required purchase. A ten to fifty person engineering-led company can do the same work internally, and this page is mostly about telling those two situations apart.

Whichever way you go, the consultant cannot be the firm that audits you. Independence rules bar an auditor from examining controls it designed, so readiness and audit are two separate engagements with two separate suppliers. Auditor selection is a different question and GetSOC2 handles it.

When hiring help is the right call

Pay for readiness support when one of these is true, and be suspicious of the purchase when none of them are.

A signed contract sets your date. When a customer agreement names a month by which a report has to exist, you are buying calendar time and the knowledge of what an auditor accepts. That knowledge is what stops you producing three months of evidence in a form that gets rejected in week two of fieldwork.

Your environment is genuinely complicated. More than one product, an acquisition still on its own stack, on-premise infrastructure beside the cloud, or regulated data such as health information under PHIPA or personal information under Law 25. Scoping decisions in those cases are judgement calls with real consequences, and judgement is the thing you are actually buying.

The program has already stalled. A quarter has passed and the control list has not moved. This is almost always an ownership problem rather than a knowledge problem, and an outsider with a schedule and a weekly meeting fixes it more reliably than another internal push.

Nobody in the building has security ownership. If the answer to who owns this is nobody, a fixed-length readiness project will end with a policy set nobody maintains. That situation usually wants a fractional CISO rather than a readiness engagement, because the problem outlives the audit.

When to do it in house instead

Do it yourself when the date is yours to set, the environment is one cloud and one product, and somebody technical has a few hours a week protected. The work is unglamorous rather than difficult: write down what you do, close the gaps between that and the criteria, and keep records from day one of the window. The preparation guide is the full sequence and the checklist is the working document.

There is a second reason to do the first pass internally. The people who built the program understand it, and year two is cheaper and calmer when the knowledge is in the building rather than in an invoice. A consultant who hands over a finished policy set leaves you with documents you did not write and cannot defend in an audit interview.

The honest middle option is to do the work yourself and buy a readiness assessment near the end, so somebody independent tells you whether an auditor would accept what you have before you commit to a window.

Engagement models and what they cost

All figures are Canadian dollars and all are ranges. None of them include the audit fee, which is a separate engagement at roughly $20,000 to $60,000 CAD for a first Type 2.

Canadian SOC 2 readiness engagement models, CAD
ModelTypical rangeWhat you getWhat you still do
Readiness assessment only$5,000 to $20,000A gap list against the criteria and a written reportEvery fix, every policy, all evidence
Policy set and control design$8,000 to $25,000Documents written against how you operateRemediation and the whole window
Consultant-led program$20,000 to $60,000Someone running the plan to a date, with you in a weekly meetingEngineering changes and internal approvals
Day rate or advisory retainer$1,200 to $2,500 per dayAnswers when you are stuck, no schedule ownershipAll of it, faster
Audit support during fieldwork$4,000 to $15,000Someone who handles auditor requests with youProducing the underlying evidence

Compliance platform subscriptions sit beside these rather than inside them, at roughly $8,000 to $30,000 CAD a year. Some consultants resell one, which is worth knowing before you take their recommendation at face value. What the directory will record, when it has entries, is which consultants work with a platform and which are independent of one.

What a good engagement looks like

It starts with scope, not with a tool. A consultant who has not asked what your product is, which environments support it and who touches customer data has not started work yet, whatever the kickoff deck says.

It produces a dated plan working backwards from your window, with the long lead items at the front. Logging retention, access reviews, security awareness training, background checks and a penetration test all need calendar time, and a plan that puts policy writing first because it is easy is a plan that will slip. The timeline page shows how the dates fit.

It changes your systems, not only your documents. Most remediation is engineering work: retention settings, an offboarding runbook, change approval recorded in the pull request, a vendor register somebody owns. A consultant who never talks to your engineers is producing paperwork.

It hands over an evidence habit that survives their departure. Named owners, recurring calendar entries, a folder structure, and a naming convention with dates in it. The evidence collection page covers what auditors accept and what they push back on, and that is the standard the handover should meet.

Ask when they leave, not just when they arrive

The expensive failure is a consultant whose engagement ends the week the observation window opens. The window is the part where evidence has to be produced every month for three to twelve months, and a team that has never run a single access review alone will discover that in month four. Either extend the engagement through the first cycle of every periodic control, or make the handover a deliverable with a date on it.

What to ask before you sign

Shortlist three, and give all three the same written scope: headcount, the systems in scope, which Trust Services Criteria, whether you want a Type 1 first, and the date the report has to exist by. Quotes priced against different scopes are not comparable, and that explains most of the variation companies report between bids.

Then ask what is handed over at the end, and whether the policies are templates or written against how you actually operate. Ask who collects evidence during the window and what happens if you have not started when they leave. Ask which auditors they have worked alongside recently and what those firms pushed back on, because a consultant who cannot answer that has not been near recent fieldwork. Ask whether they resell a compliance platform. Ask what happens to the fee if the audit surfaces an exception in an area they designed.

Two things to walk away from. A fixed price quoted before anybody asked what is in scope, which means the scope will be argued about later at your cost. And any promise about the audit outcome, since nobody can promise the result of an examination they are not permitted to perform.

Readiness consultants by city

Each page below covers the privacy law that applies in that province, the local industries that usually trigger a first SOC 2, and what that means for how you scope the audit. That combination is genuinely different in Montreal, where Law 25 governs, than in Halifax or Calgary.

Location is rarely the deciding factor. Almost all readiness work is remote, and the useful test is whether a firm knows your industry and the statute that applies where your data lives.

Get readiness quotes

Tell us your scope, your date and where you are stuck, and we will put the request in front of Canadian firms that do this work.

Get matched

Common questions

How much does a SOC 2 readiness consultant cost in Canada?

Roughly $20,000 to $60,000 CAD for a consultant-led program through a first Type 2, or $5,000 to $20,000 CAD for an assessment and gap list on its own. Day rates for advisory work run about $1,200 to $2,500 CAD. The audit fee is separate and additional.

Can the same firm do our readiness work and our audit?

No. An auditor cannot give an opinion on controls it designed, so the firm that writes your policies and builds your evidence process is barred from auditing them. Budget for two suppliers engaged at different stages.

Do we need a consultant if we already have a compliance platform?

Often not. A platform gives you a control framework and automates part of evidence collection, which is the repetitive half. What it does not do is decide your scope, write a system description, or fix a control you do not have. If those judgement calls are the part you are stuck on, that is what a consultant is for.

How long is a readiness engagement?

Usually two to four months for a company starting from nothing, which is the same as doing it internally. Consultants compress the decision-making rather than the calendar, and the observation window that follows cannot be shortened by anybody.

Should the consultant be based in our province?

Not necessarily, but they should know the privacy statute that applies to you. A firm that treats PIPEDA as the answer everywhere will misadvise a Quebec company under Law 25 or a British Columbia company under PIPA. On-site presence matters mainly when physical security is in scope.

What should a readiness engagement hand over at the end?

A written scope and system description, an approved and dated policy set, a control list mapped to the criteria, a remediation record showing what was fixed and when, and a working evidence process with named owners and a schedule. If any of those is missing, the audit will surface it.