SOC2Prep

SOC 2 readiness consultants in Edmonton

What is different about preparing for a SOC 2 audit from Edmonton: who is asking you for the report, which privacy statute sits underneath it, and what that does to your scope.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

A consultant-led SOC 2 readiness program for an Edmonton company runs roughly $20,000 to $60,000 CAD. An assessment and a gap list, with nobody running the program for you, runs $5,000 to $20,000 CAD. Alberta firms price inside that national range. Price is not what changes in Edmonton. Scope is, because scope here is set by health technology buyers, by public sector contracts and by PIPA (Alberta), and the money follows scope.

Alberta's PIPA governs private-sector personal information, and health information is separately governed by the Health Information Act, which matters for any company touching custodian data in the province.

PIPA (Alberta) Private-sector privacy statute in Alberta

HIA Health information statute, separate obligation

about 1.4 million people In the Edmonton metropolitan area

What a readiness engagement has to account for in Edmonton
Local factorWhat it is hereWhat it does to a SOC 2 scope
Private-sector privacy statute PIPA (Alberta) Systems holding personal information under PIPA (Alberta) are hard to exclude from the audited system
Health information statute HIA Where HIA applies, the custodian agreement usually adds obligations the criteria do not mention
Who is asking health technology and public sector Their security schedule names the report type and often the criteria beyond security
Second wave of demand artificial intelligence research Usually arrives later and with a shorter deadline, so plan the window once rather than twice
Market size about 1.4 million people in the Edmonton area Decides how many AB firms will quote, not what the work is
On-site time Rarely needed, since Alberta readiness work is almost all remote Only physical security controls make an Edmonton address worth paying for

What triggers a first SOC 2 in Edmonton

Demand around Edmonton comes from health technology, public sector, artificial intelligence research, energy services. The pattern across those sectors is worth naming: an Alberta company gets pushed into SOC 2 by a customer attaching a security schedule, not by a regulator enforcing PIPA (Alberta). That schedule usually says what it wants. Read it first. It tells you whether the health technology buyer needs a Type 1 now or a Type 2 by a date, and whether public sector expects any criterion beyond security, which decides half of an Edmonton budget.

Sector shapes what an auditor looks at. health technology buyers ask one short list repeatedly: who holds production access, how changes get approved, what happens to data when an Edmonton contract ends, whether an independent penetration test exists. public sector buyers add a questionnaire on top. artificial intelligence research buyers arrive with neither and take whatever the PIPA (Alberta) policy set says. Building controls around those commitments is not gaming the audit. It is scoping around promises already made to Edmonton customers in Alberta.

What moves with geography is the deadline. An health technology buyer negotiating from Edmonton usually hands over a renewal date to work back from. An artificial intelligence research buyer usually does not. Get that date written down early, read the timeline, count backwards. The observation window is calendar time. No Alberta firm shortens it for an Edmonton client at any price, whatever AB sales copy suggests.

PIPA (Alberta) and what it does to your scope

A company operating in Alberta answers to PIPA (Alberta) for private-sector personal information, and to HIA where health data is in play. SOC 2 replaces neither. It tests neither, since the security criterion asks about controls, not about Alberta statutory duties. They intersect anyway: breach notification under PIPA (Alberta), retention limits under HIA, and whatever an Edmonton customer was promised, all landing inside one policy set.

The practical effect lands on scope. Where personal information subject to PIPA (Alberta) flows through a system, excluding that system from an Alberta audit is hard to do with a straight face, whatever the architecture diagram in Edmonton says. Decide it deliberately while writing the system description, not when an auditor asks where Edmonton customer records actually live. That single decision moves an AB quote more than any other.

The statute that applies to you in Alberta

PIPA (Alberta) governs personal information held by a private-sector organisation in Alberta. HIA governs health information separately. A clean SOC 2 report discharges neither. Neither waits for an Edmonton customer to ask. An American pack will not mention PIPA (Alberta) anywhere, the defect we find most often in a first Alberta policy set. GetAudited explains which Canadian privacy law applies to you, and the policy checklist tool separates the documents SOC 2 drives from the ones PIPA (Alberta) drives.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Hire in Edmonton, hire remotely, or do it yourself

Readiness work is nearly all remote, so an Edmonton address rarely decides anything. On-site time earns its cost twice in Alberta: when physical security controls are in scope because you run your own space or hardware, and when a team works better with somebody in the room for the scoping week. Otherwise judge a firm on whether it has taken an AB company like yours through this, and whether it treats PIPA (Alberta) properly rather than defaulting to American guidance written for neither Alberta nor Edmonton.

In house suits a smaller Edmonton team: one cloud, one product, no HIA exposure, somebody technical holding a few protected hours weekly. Work the checklist, which ticks and remembers where you got to. Score the six control areas on the readiness scorecard before committing an Alberta window date. Buy a readiness assessment near the end for an independent read, the cheapest insurance an AB company puts on a first audit. The national guide covers when hiring help is worth it and what to ask, and Alberta firms appear in the directory as they are checked.

Whoever prepares you cannot audit you. Independence rules keep the two engagements apart, so an Edmonton company plans on two suppliers, two invoices, two sets of Alberta paperwork. Auditor selection is a separate decision, covered on GetSOC2 rather than here.

If HIA is in play

HIA sits outside SOC 2, and outside PIPA (Alberta) too. An Edmonton company holding health records for a clinic, a hospital or an insurer usually inherits its duties through the custodian agreement rather than from HIA directly. Read that agreement in Alberta before writing a single policy: it commonly names retention periods, notification timing and audit rights stricter than the Trust Services Criteria ask for. Where health technology or public sector work touches patient records, add two to four weeks of Edmonton scoping and expect the audited system to be larger than you first drew it in AB.

What to ask a firm quoting Alberta work

  1. Give three candidates one written scope: headcount, systems in scope, criteria, the intended window, the date a report must exist by, and whether PIPA (Alberta) data sits inside it. Quotes priced on different scopes cannot be compared, which is most of the variation Edmonton firms report in AB.
  2. Ask which Alberta companies they have taken through this, and whether any were in health technology or public sector. Sector experience is worth more than a local address.
  3. Ask how PIPA (Alberta) is handled in the policy set, by name, and how HIA is handled if health data moves through Alberta. A firm answering on American breach wording has told you which pack it ships.
  4. Ask who collects evidence during the window. A firm that leaves when the window opens has left before the hard part.
  5. Ask what you are handed at the end, and whether the policies are templates or written against how you actually operate in Edmonton.

The rest of the country

Work the shortlist outward before you commit an afternoon to the wrong two firms. Practices that run readiness in Edmonton take the same engagements in Calgary, Saskatoon and Vancouver, and a round of calls across those three usually turns up the second quote that makes the first one negotiable. Read those pages beside Edmonton when buyers sit outside Alberta. The statute deciding an argument is usually the one on the buyer's side, not PIPA (Alberta) on yours, and public sector contracts test that.

Get readiness quotes for an Edmonton company

Tell us your scope and your date, and we will put it in front of firms that work with companies in Alberta.

Get matched

Common questions

Does a SOC 2 readiness consultant have to be based in Edmonton?

No. Documentation, control design and evidence process are nearly all remote work. The better test for an Edmonton buyer is whether the firm understands PIPA (Alberta), knows what HIA adds, and has taken a company in health technology or public sector through it. On-site time matters when physical security controls are in scope, which in Alberta usually means you run your own space.

Does PIPA (Alberta) change what our SOC 2 covers?

It changes scope, not criteria. SOC 2 tests controls you say you operate, so an Edmonton system holding personal information governed by PIPA (Alberta) is hard to leave outside the audited system. Retention and notification commitments in the policy set then have to match what PIPA (Alberta) demands of an Alberta organisation, plus whatever HIA demands where health data is involved.

How long will preparation take for an Edmonton company?

Two to four months from a standing start in Edmonton, then the window on top, three months minimum for a Type 2. That window is calendar time. No Alberta consultant shortens it, no platform shortens it, whatever an health technology buyer would prefer. The timeline shows how AB dates fit together.

What does SOC 2 readiness cost in Edmonton?

$20,000 to $60,000 CAD for a consultant-led program. $5,000 to $20,000 CAD for an assessment alone. Both are national ranges, not Edmonton ones. The Alberta audit is a separate invoice, $20,000 to $60,000 CAD for a first Type 2. Sitting in AB moves those figures very little. Scope, and how much of it PIPA (Alberta) drags in, moves them a lot.

Are there SOC 2 consultants listed for Edmonton?

The directory lists firms researched from public records rather than bought as a list, and you can filter it by province. Most do this work remotely, so the Alberta filter matters less than whether a firm has done a company shaped like yours. The quote form puts your scope in front of the ones that match.