SOC 2 readiness without a paid platform
Readiness is four artifacts and an owner. None of the four requires a subscription, and knowing which ones a platform would not have built for you anyway is how you decide whether to buy one.
A SOC 2 readiness program is four artifacts: a control set mapped to the criteria you are in scope for, an evidence register that says which artifact proves each control and who produces it, a policy set that matches what your company actually does, and a risk register that shows the assessment happened and was reviewed. Add one named owner and you have everything the auditor will ask to see at the start of fieldwork. Nothing on that list requires paid software, and the paid platforms do not produce three of the four for you.
4 Artifacts a readiness program is made of
$8,000 to $30,000 Paid platform, CAD per year, single framework
The four artifacts, and what each has to contain
Each artifact has a shape an auditor recognises, and each fails in a specific way when it is built badly.
- Control set
- One row per control, mapped to the criterion it satisfies, with a plain description of how the control operates at your company. Fails when it is a copied list nobody has rewritten, because the auditor asks how a control works and gets the vendor's sentence back.
- Evidence register
- One row per control naming the artifact, the cadence, the owner and where it is filed. Fails when it records intentions rather than filed artifacts, which is only discovered in month nine.
- Policy set
- Approved documents with dates, versions and an owner each. Fails when the policy describes a company larger and more formal than yours, and the walkthrough contradicts it.
- Risk register
- Identified risks with an assessment, a treatment decision and a review date. Fails by being written once and never reviewed, which is visible from the dates.
| Artifact | Spreadsheet and drive | Free compliance workspace | Paid platform |
|---|---|---|---|
| Control set mapped to criteria | You write the mapping | Mapped set provided | Mapped set provided |
| Evidence register | A sheet you maintain | Register mapped to controls | Register mapped to controls |
| Policy set | Templates you edit | Templates with approval history | Templates with approval history |
| Risk register | A sheet you maintain | Provided | Provided |
| Automated evidence from your cloud | No | Seven systems built in, anything else described as a check | Hundreds of pre-built integrations |
| How often the checks run | When somebody remembers | Daily, on a schedule | Continuously, with an alert when a control drifts |
| Endpoint agent and HR system evidence | No | No | Yes |
| Trust page and questionnaire automation | No | No | Yes |
| Year one tooling cost, CAD | $0 | $0 | $8,000 to $30,000 |
What only a paid platform does
The bottom four rows of that table are the case for spending the money. The difference is breadth. Vanta and Drata maintain hundreds of pre-built integrations, an endpoint agent and connectors into HR systems, with teams behind them who do only that. A large estate gets covered; a free workspace covers the systems it has connectors for and expects the rest to be described. They also alert on the morning a control drifts rather than at the quarterly review, and they carry deep auditor networks. If your systems are spread wider than a handful of connectors reach, that is what you should buy.
The rest of the value is commercial rather than audit-related. A trust page and questionnaire automation are doing sales work, and for a company losing deals in security review that line alone can justify the subscription before the audit does. Across the category the subscriptions run roughly $7,500 to $50,000 CAD a year, with $8,000 to $30,000 CAD being the band most Canadian SMEs are quoted for a single framework. Our reads on each are at Vanta, Drata and Sprinto.
Buy one when any of these is true
You are above about thirty people; your systems reach past the handful a free workspace connects to; you need endpoint or HR evidence; a customer contract commits you to drift alerting rather than periodic evidence; you carry a second framework; or security questionnaires are consuming selling time. Two of those make it worth pricing. None of them and you are buying integration breadth you will not use.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The free options, including ours
Below that threshold there are two ways to run the program at no tooling cost, and they fail differently.
The first is a spreadsheet, a shared drive and a calendar. It is enough under about thirty people, it teaches you your own controls better than any tool will, and it collapses when the person who built it leaves, because nothing in it is enforced by anything except their habits. The layout that works, folder by folder, is on collecting evidence without a platform.
The second is a free workspace, which is a structured version of the same thing, and the one we run is described below. Either free option leaves you doing the same four artifacts. The difference is whether the structure is given to you or built by you, and at fifteen people with one product that is a preference rather than a decision. Tooling is only one line of the budget, and which of the others can also go to zero is on SOC 2 prep with no compliance budget.
The workspace we run
TrazTech operates this site. It runs a free compliance workspace called traztech Workspace: 10 frameworks, guided self-assessments, an evidence register mapped to controls, 40 policy templates with approval history, a risk register, vendor risk questionnaires and audit-readiness scoring. It is free with no credit card, no trial period, no paid tier, no seat limit and no export fee. Sign-in is an email link. The data stays in the workspace and stays yours if you later hire someone else or nobody at all.
It connects to AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira. Anything else with an API is described as a check rather than picked off a list. Those checks run daily and file evidence against the control they prove. There is no endpoint agent and no HR integration.
Buy Vanta or Drata instead when your estate needs hundreds of integrations, endpoint coverage or HR evidence. That is not close, and TrazTech will say so and help you set the platform up. This is an interested party describing its own product. The directory lists other firms doing the same work.
The order to build them in
Sequence matters more than tooling here, because three of the four artifacts depend on a decision made in the first one.
- Write the scope: products, environments, headcount, criteria and proposed period dates. Everything downstream inherits from this, and it is on the scope page.
- Pick the control set and map it to the criteria you actually chose, not to all five.
- Run a gap analysis against that set and record met, partial or absent per control, failures included.
- Write or edit the policies so they describe your company, then approve them with dates and owners.
- Build the evidence register from the control set, name an owner per row, and put every periodic row in a calendar.
- Do the risk assessment, record treatments, and set the next review date before you forget.
- File one month of real evidence as a dry run before the observation window opens.
0 of 7 done ·
What this does to your audit fee
Holding the four artifacts before you ask for audit quotes is worth money separately from the tooling saving. An auditor pricing a company it cannot see holds hours back in contingency for the possibility that your controls are aspirational and your evidence will arrive in three rounds. Documenting the readiness position removes that guess, and the estimate comes down because the work looks smaller. Why audit quotes differ works through the mechanism and the one engagement where a firm took $11,000 CAD off a five-figure quote after the readiness position was set out. That was one engagement, not a rate.
Get readiness quoted, whatever you run it on
Tell us your scope and we will put it in front of Canadian firms that do this work. There is no charge to you.
Get matchedCommon questions
Can we pass a SOC 2 audit without a compliance platform?
Yes, and a large share of first Canadian SOC 2 reports are produced that way. Auditors work from a request list and care whether evidence is complete, dated and attributable, not what software it came out of. The threshold where manual collection stops being sensible is around thirty people, or sooner if you carry a second framework.
Is a free compliance workspace as good as Vanta or Drata?
No, and it is not the same product. The difference is breadth. Vanta and Drata maintain hundreds of pre-built integrations, an endpoint agent and HR connectors. A free workspace connects to a handful of common systems and expects anything else to be described as a check. What it does cover is the control set, the evidence register, the policies and the risk register, which is most of what a company at the start of a first SOC 2 needs. Buy the paid platform when your estate is wider than the connectors reach.
What happens to our data if we stop working with a consultant?
Ask before you start, because the answer varies by firm and by tool. Some consultants keep your control set and evidence inside their own tenancy, and getting it back at the end is a conversation you do not want to be having then. With a paid platform the subscription is yours, so the data is too, but it goes when you stop paying and the switching cost rises the longer your evidence history accumulates inside it.
Do we need all four artifacts for a Type 1?
Yes, but with less depth. A Type 1 tests design at a point in time, so the evidence register holds one dated artifact per control rather than a year of them. The control set, policies and risk register are the same work, which is why a Type 1 is a smaller step toward a Type 2 than it looks.