43 / 58SOC 2 Compliance Services

SOC 2 compliance work that ends in a report your buyer accepts

SOC 2 compliance for Canadian companies, scoped down to what your customers actually asked for, then evidenced.

  • CCIE Security-led team
  • Readiness only, never your auditor
  • Canadian data residency
THE WORK

SOC 2 compliance, three pillars, one operator.

One Canadian team runs the SOC 2 readiness work: scoping the criteria, closing the gaps, and packing the evidence.

  1. 1

    Scope it down

    Most companies scope five criteria when their customers only ever asked about one. Only one of the five trust services criteria, security, is mandatory. The rest is a decision with a price attached.

  2. 2

    Close the gaps

    A gap list with a named owner, a price, and a date against every line. You keep that list whether or not you carry on with us.

  3. 3

    Pack the evidence

    Policies, tickets, logs and screenshots, mapped to the criteria before your auditor asks twice. We attest to nothing ourselves, because a SOC 2 consultant who designed your controls cannot grade them.

THE PROOF

Built to last. Evidence over promises.

There's no SOC 2 certification and no certifying body. There's a licensed CPA firm's SOC 2 attestation, and the evidence sitting under it.

IN PRODUCTION

The Canadian report a US buyer accepted.

Our biggest prospect wanted SOC 2 and we'd been quoting five criteria to everyone because a blog told us to. SMEnode read the actual security questionnaire, cut us to security and confidentiality, and we passed the window six months earlier than planned. Nobody has asked for the other three since.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

SOC 2 compliance in Canada, made real.

I run this practice, so this is written by the engineer who'll sit on the scoping call, not a product page.

Cutting scope is the first decision, not the last.

Nobody in Canada is legally required to hold a SOC 2 report. Your customers require it, which is a harder deadline than a law. Good work starts by cutting scope, not adding it. Only one of the five trust services criteria is mandatory: security, the common criteria every examination covers. Availability, processing integrity, confidentiality and privacy are choices, and each one you add buys more controls, more evidence, and a longer window. So the first question isn't which criteria you want. It's which ones the customer who triggered this asked for, in writing, in their security questionnaire.

Most gaps are evidence problems, not tooling problems.

Then it's plumbing. Access reviews that happen on a date rather than when somebody remembers, offboarding that closes every account, change tickets that link to the change, logs kept as long as the policy claims. Most gaps we find in SOC 2 readiness work aren't missing tools. They're a control that works but produces nothing an auditor can read. That's the cheapest kind to fix and the easiest to leave broken.

Where the money goes, and who actually signs.

Where does the money go? Not the SOC 2 audit fee. Scope sets the price, remediation eats the budget, and a Type 2 window runs three to twelve months, so a bad scoping decision in month one is a bill you pay for a year. In Canada the report comes from a CPA firm working to the CPA Canada SOC 2 guide under CSAE 3000, with the AICPA's criteria underneath. Search for SOC 2 certification and you'll be shopping for a document nobody issues. What exists is a SOC 2 attestation carrying a licensed CPA firm's opinion. If your customers are federally regulated, OSFI's B-10 third-party risk guideline is usually what put SOC 2 in your contract. It won't cover PIPEDA.

Liste de contrôles
THE METHOD

How our SOC 2 readiness and gap assessment work runs.

Four steps, and step 01 is reading somebody else's paperwork. We want the security questionnaire, the contract clause, or the email that started this. Nine times in ten it names fewer criteria than the internal plan assumed, sometimes just security. That document sets the scope, the cost and the date. Guessing at it is how a nine-month project becomes an eighteen-month one.

  1. Étape 01

    Read the ask

    We start from your customer's actual words, not a framework poster. Which criteria, which report type, which deadline, and whether a Type 1 buys enough time to close the deal while the longer window runs underneath it.

  2. Étape 02

    Assess and price the gaps

    Every control tested against the criteria in scope, each gap written up with a named owner, an effort estimate and a cost. You get the list whether or not you carry on with us.

  3. Étape 03

    Close and evidence

    We build what's missing and, just as often, make an existing control produce proof. Screenshots, tickets, exports and policies, collected as you go rather than in a panic.

  4. Étape 04

    Hand off to the auditor

    We help you pick a CPA firm, prepare the description of the system, and answer the evidence requests. Then we step back, because the firm that built your controls cannot be the firm that grades them.

QUESTIONS

SOC 2 compliance questions, answered straight.

Answers first, including the one where we tell you the certificate you're asking for doesn't exist. An architect takes the call, not a salesperson.

No, and the distinction matters when an enterprise buyer reads your reply. SOC 2 is an attestation. A licensed CPA firm examines your controls against the AICPA's Trust Services Criteria and issues a report carrying its opinion. No body certifies you, and there's no certificate to frame. Say "we hold a SOC 2 Type 2 report" rather than "we're SOC 2 certified" and your answer will survive the security review.

The criteria are American, the report is usually Canadian. A CPA firm here works to the CPA Canada SOC 2 guide, revised in 2024, under CSAE 3000, using the AICPA's 2017 Trust Services Criteria with their 2022 revised points of focus. Canadian law doesn't require any of it. Your customers do, and if they're federally regulated their OSFI third-party risk obligations are usually why.

No, and nobody honest can. AICPA independence rules stop a firm from attesting to controls it designed, documented or operated. So we do readiness, remediation and evidence, then hand you to a CPA firm and help you answer their requests. Any provider offering both under one roof is either misreading the rules or hoping you don't check.

Yes, once you've been through it. The AICPA licenses a "SOC for Service Organizations" logo to any organisation holding a SOC 1, 2 or 3 report from a licensed CPA or a non-US equivalent, and you register with them to download it. Two catches: your opinion has to be unqualified, and it isn't a certification mark. It says an examination happened.

A Type 1 reports on whether your controls were designed properly on one date. A Type 2 reports on whether they operated over a window, usually three to twelve months. Buyers who know the difference want Type 2. If a deal closes before a window can run, a Type 1 buys time while the longer examination starts underneath it.

When no customer has asked yet, because scope drifts without a real questionnaire to anchor it. When your access reviews and offboarding are still manual, since those are the first controls tested and the cheapest to fix beforehand. And when the deal closes in six weeks, because a Type 2 window can't be compressed. Ask for a Type 1, then start the window.

PARLONS-EN

Un spécialiste chevronné répond en moins d'une heure, 24/7.