Skip to main content
Home/Readiness/SOC 2 Readiness
SOC 2 Compliance

SOC 2 Readiness

Know exactly where you stand before your auditor walks in - control by control, with the evidence your CPA firm will ask for already filed.

Standard SOC 2
Typical Timeline 2-4 weeks
Starting Price $3,500
Scope Delivery Calgary, Toronto & Remote
Assessment Scope

What This Engagement Covers

SOC 2 is the report North American enterprise buyers ask for, and the one most often failed for reasons that have nothing to do with security. We run the readiness engagement so that when your auditor arrives, every Trust Services Criterion has an owner, a control, and evidence that survives being asked about. The gap list lands early so your team can start on the long poles while the rest of the assessment continues.

Canadian Operations & Law

What This Means for Canadian Businesses

Many Canadian technology companies serving US enterprise customers are required to demonstrate SOC 2 compliance as a condition of procurement. The report is issued by a US CPA firm and assessed against the AICPA Trust Services Criteria - there is no Canadian equivalent, which is why Canadian SaaS companies pursuing US enterprise deals routinely need it. Our team has prepared Canadian organisations for SOC 2 audits across the full Trust Services Criteria set, and we map your readiness gaps to the controls your CPA firm will actually test.

Calgary HubAlberta Operations
Toronto HubOntario Operations
Control Framework

Domains & Controls We Assess

We evaluate every technical, operational, and administrative requirement against authoritative criteria.

Security (CC - Common Criteria)

  • CC6.1 - Logical and physical access controls restrict access to system components
  • CC6.2 - Authentication controls prevent unauthorised access to system components
  • CC6.3 - Role-based access is reviewed, modified, and removed on a defined cycle
  • CC7.1 - Vulnerability detection and monitoring processes are in place
  • CC7.2 - Security events are identified, evaluated, and responded to

Availability (A)

  • A1.1 - Current processing capacity is monitored and managed
  • A1.2 - Environmental and technological risks to availability are identified and mitigated
  • A1.3 - Recovery procedures are tested to restore operations within defined objectives

Confidentiality (C)

  • C1.1 - Confidential information is identified and classified at collection
  • C1.2 - Confidential information is protected from unauthorised disclosure during processing and disposal

Change Management (CC8)

  • CC8.1 - Changes to infrastructure, data, software, and procedures follow a documented change management process
  • CC8.1 - Unauthorised changes are detected and addressed

Risk Assessment (CC3)

  • CC3.1 - Risk assessment process identifies risks to the achievement of entity objectives
  • CC3.2 - Fraud risk is assessed and mitigated as part of risk management
  • CC3.3 - Changes to the business that may affect risk are identified and assessed

Monitoring Activities (CC4 & CC9)

  • CC4.1 - Ongoing and separate evaluations assess the effectiveness of controls
  • CC9.1 - Risk from business relationships is identified and managed
  • CC9.2 - Vendor and supplier risk is assessed before onboarding and on a periodic basis
What You Receive

Engagement Deliverables

Everything you need to prove control operating effectiveness to your auditors and enterprise clients.

Gap Assessment Report mapped to Trust Services Criteria

Control Mapping Spreadsheet with Owner and Status

Evidence Collection Guide by Criterion

Prioritised Remediation Roadmap

Audit-Ready Policy and Procedure Templates

Direct CPA Auditor Introduction & Fieldwork Support

Retest of Critical and High Gaps

Client Stories

Trusted by Growing Businesses

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
FAQ

Common Questions

Can one firm do both our readiness prep and our official SOC 2 audit? +

No. Under AICPA professional standards and CPA independence rules, the CPA firm issuing the final attestation report cannot design, build, or implement your internal controls. Doing so would violate auditor independence. Lorikeet Security Canada acts as your specialized readiness consultant - designing controls, authoring policies, preparing evidence, and sitting in on auditor calls. We introduce you to accredited CPA firms (e.g. Prescient Assurance, MHM) and coordinate the entire audit hand-off.

What is the difference between your $3,500 Gap Assessment and the $9,500 Full Sprint? +

The $3,500 Gap Assessment is a rapid 1 to 2 week evaluation of your real environment against the Trust Services Criteria, delivering a detailed gap matrix and remediation roadmap. The $9,500 Full Sprint includes end-to-end control design, custom policy writing, vendor risk reviews, evidence collection setup, and direct auditor coordination through fieldwork. Best of all, 100% of your Gap Assessment fee is credited toward the Full Sprint if you upgrade.

Do Canadian companies actually need SOC 2? +

Not as a regulatory obligation - SOC 2 is not law in Canada. But US enterprise buyers routinely require it as a procurement condition, and Canadian SaaS companies selling into that market increasingly cannot close deals without a report in hand. If your pipeline includes US enterprise prospects or if a US customer has asked for it, you need it.

How long does SOC 2 readiness take? +

The readiness assessment itself is typically two to four weeks. Closing the gaps the assessment finds is what sets the real timeline - how much of the control set already exists and how quickly your team can build and evidence what is missing. We give you the gap list early so you can start on the long items while the rest of the assessment continues.

What is the difference between SOC 2 Type I and Type II? +

Type I says your controls were designed correctly on a single date. Type II says they operated correctly across a window - typically six to twelve months. US enterprise buyers increasingly ask for Type II. If you need something in hand quickly, a Type I gets you a report while the Type II observation window runs in parallel.

Get Started

Ready for Your SOC 2 Readiness Assessment?

Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.