SOC2Prep

What SOC 2 readiness costs in Canada

Readiness is the part of a SOC 2 budget with the widest spread, because it is the only part priced against a company nobody has assessed yet. A gap assessment alone runs $6,000 to $15,000 CAD; a full consultant-led project runs $15,000 to $60,000.

Last reviewed 2026-09-18Written by Jacob Masse, TrazTech Inc.

Readiness in Canada divides into two purchases. A gap assessment, which is a defined piece of work costing $6,000 to $15,000 CAD, and remediation, which is whatever the assessment finds and runs from nothing to more than the audit fee. A consultant-led project covering both usually lands between $15,000 and $60,000 CAD. The audit itself is separate, and so is the platform if you use one.

The spread inside that range is not firms charging different amounts for the same work. It is the same work against companies in very different starting positions, which is also why a readiness price quoted before anybody looks at your environment contains an estimate of how much trouble you are going to be.

The four ways companies buy readiness

Readiness support in Canada, CAD
How you do itCostSuits
Internally, with a platform's built-in guidance $0 external Under 25 staff with an engineer who will own it and has the time
Gap assessment only, then fix it yourself $6,000 to $15,000 Companies that mostly know what they are doing and want the list
Consultant-led readiness project $15,000 to $60,000 A hard customer deadline, or nobody internal to own it
Fractional CISO, ongoing $3,000 to $12,000 per month Companies that will keep needing security leadership after the audit
What a first-timer with a customer deadline usually spends $15,000 to $60,000 A fixed-scope project, once

The gap-assessment-only option is underused and is the right answer more often than it gets chosen. It produces a findings register you own, which is the document that lets you decide whether to fix things yourself, hire somebody for the parts you cannot, or get comparable quotes for the remediation. Buying the whole project up front removes that decision, because the remediation was scoped before anyone knew what it was.

The cost nobody quotes

Readiness consumes your team whether or not you hire anybody, and the hours are usually the largest line in the whole budget once you cost them.

Internal hours by phase, first SOC 2 Type 2, company under 100 staff
PhaseElapsedOwner hours per weekTotal hours, whole company
Scope, gap analysis, auditor selectionWeeks 1 to 412 to 1630 to 60
Policies, remediation, long-lead itemsWeeks 5 to 1212 to 1690 to 250
Observation window, evidence collection3 months3 to 540 to 100
Fieldwork and auditor questions4 to 8 weeks15 to 2540 to 80
First report, total internal hoursAveraging 8 to 10 a week200 to 500

At a loaded rate of $80 to $150 CAD an hour, 200 to 500 hours is $16,000 to $75,000 of your own capacity. A proposal that promises very little of your time is describing either a narrow scope or a plan that has not thought about evidence, because evidence comes out of your systems and your people.

This is also the honest case for hiring help. A consultant does not remove those hours, and a good one moves them off your engineers and compresses the weeks 5 to 12 block, which is where the 90 to 250 hour range sits.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What actually moves the number

How much identity infrastructure already exists
Single sign-on, enforced multi-factor authentication and unique named accounts are the difference between an access control workstream of a week and one of two months. This is the single largest swing factor.
Whether logging is centralised
Evidence for monitoring controls comes out of logs. If they are centralised and retained, evidence collection is a query. If they live on individual systems with short retention, somebody is building that first.
Number of environments and products
Every additional production environment multiplies the evidence, not the policies. Two cloud accounts and one product is a modest increase; three products with separate stacks is a different engagement.
How many criteria you select
Security alone is the mandatory criterion. Availability, Confidentiality, Processing Integrity and Privacy each add controls, evidence and scope. Add them because a customer contract requires them, not defensively.
Whether a real deadline exists
A deadline does not change the work, and it changes the sequencing and usually the price, because long-lead items have to run in parallel and somebody has to coordinate that.
Contractors and remote staff
Onboarding, offboarding and access evidence for people who are not in your HR system is a recurring source of exceptions and of unplanned readiness work.

Two companies, same size, different bills

The ranges above are wide enough to be unhelpful without a worked example. Both of these are 40-person Canadian SaaS companies going for a first Type 2 on Security criteria only, with a customer deadline nine months out.

Where the difference actually comes from, CAD
LineCompany A, modern stackCompany B, grown organically
IdentitySSO and enforced MFA already in placeShared logins in two systems, MFA optional
LoggingCentralised, 12 month retentionPer-server, 7 day retention
EnvironmentsOne cloud account, one productTwo clouds, a legacy product still serving customers
PoliciesA handful, roughly accurateNone, or a template set nobody follows
Gap assessment$6,000 to $10,000$10,000 to $15,000
Remediation support$10,000 to $20,000$35,000 to $50,000
Internal hours150 to 250350 to 500
Readiness, all in$16,000 to $30,000$45,000 to $65,000

The audit fee for these two is nearly identical, because the auditor is examining the same number of controls over the same window. Everything that separates them happened before the auditor arrived, which is the argument for doing the gap assessment early rather than after you have signed with a CPA firm.

Company B's worst option is a single flat price covering both phases, because the firm quoting it does not yet know which company it is dealing with. It will price for the middle and recover the difference, or price for the worst case and charge Company A rates to a Company A that turns out to be Company B.

Read the pricing shape, not just the total

Two proposals at the same number can be structured completely differently, and the structure tells you what happens when the assessment finds something unexpected.

  1. Two phases, priced separately. A fixed price for the gap assessment, then a fixed price for remediation quoted from the findings. The second number is real because it is scoped against something real, and you get a decision point in between.
  2. One price covering both. Convenient, and it necessarily contains an estimate of your gaps. Ask what it assumes about your current state and what triggers a change order. Both answers should be in the statement of work rather than in an email.

The question that tells you most

"What does this price assume about our environment?" A defined scope has a specific answer: SSO in place, logging centralised, one production environment, policies existing in some form. Each of those is checkable and each is worth real money. A general answer about every engagement being different is true and is not an answer.

Where the platform fits

A compliance platform is a separate purchase from readiness, running $8,000 to $30,000 CAD a year for a single framework, and it is worth being clear about what it does. It collects evidence continuously and maps controls to criteria, which removes a real chunk of the manual work during the observation window. It does not decide your scope, write a system description that matches your architecture, or tell you which of its suggested controls do not apply to you.

Under about 25 staff with an engineer who will own the work, a platform plus internal effort is a reasonable path and plenty of companies pass that way. The combination that wastes money is buying the platform and the full consultant project and assuming each will cover what the other does not. Decide which half of the work each is doing before you sign either.

What year two looks like

Readiness is mostly a first-year cost. In year two the controls exist, the policies exist, and what remains is keeping evidence flowing and handling the drift: new systems, new staff, a changed architecture. Companies that spent $15,000 to $60,000 in year one commonly spend a fraction of that afterwards, or nothing external at all.

That shape is worth knowing during the first negotiation, because a multi-year readiness commitment is priced against a first year of work you will not repeat. See the SOC 2 timeline for how the calendar works across both years.

Is a gap assessment worth buying on its own?

Frequently, yes. It costs $6,000 to $15,000 CAD, produces a findings register you keep, and lets you get comparable quotes for the remediation instead of accepting the estimate of whoever ran the assessment.

Can the audit firm do our readiness work?

No. The examination is issued by a licensed CPA firm that has to be independent of the preparation, so readiness and audit are two parties by necessity. See whether one firm can do both.

How much cheaper is readiness the second time?

Substantially, and the saving is in remediation rather than in the assessment. The controls and policies already exist, so what is left is keeping evidence flowing and handling changes to your environment.

Does a platform replace a consultant?

It replaces part of the manual evidence work and none of the judgment about scope, criteria selection or what your system description should say. Under 25 staff with an engineer who owns it, a platform alone is often enough.

Get readiness quotes you can compare

Describe your environment once and it goes to Canadian firms that do readiness work, with the assessment and the remediation quoted separately.

Get matched