Pricing

Three ways to get certified.
Pick the one that fits your team.

Subscribe to the compliance platform, hand the whole program to a dedicated compliance manager, or bring in a virtual Chief Compliance Officer. Every plan runs on one control library covering twelve frameworks, with your data hosted in your own country.
Free gap analysis and project plan. No obligation.

Platform Subscription

For teams with in-house compliance capability who want the tooling, not the people.
Talk to us
Scope decides price. We quote after the gap analysis.
What you get
Most chosen

Compliance as a Service

For teams with no compliance expertise in-house who need a SOC 2 report or ISO 27001 certificate.
Talk to us
Scope decides price. We quote after the gap analysis.
What you get

Virtual Chief Compliance Officer

For teams that need a compliance executive on call, not just a certification project.
Talk to us
Scope decides price. We quote after the gap analysis.
What you get
Compare

What is in each plan

Every plan runs on the same platform. What changes is how much of the work we take off you.
Compare the plans
Platform
CaaS
vCCO
Platform
One control library across twelve frameworks
Automated evidence collection
Continuous control monitoring and drift alerts
Audit workspace for your auditor
People
Support channel
Slack
Slack + manager
Slack + vCCO
Dedicated compliance manager
Named virtual Chief Compliance Officer
Access to principal consultants
Certification work
Scoping and gap assessment
Policies drafted for your environment
Templates
Risk assessment and treatment plan
Internal audit before the external audit
Auditor coordination and audit attendance
Ongoing program
Customer security questionnaires
On request
Vendor and third-party risk reviews
On request
Board and executive reporting
Incident response advisory
How the service runs

Five phases, not one slice of them

Most vendors cover one part of the lifecycle and leave you the rest. Compliance as a Service and the vCCO plan cover all five.

Design

Objectives, owners and evidence requirements set up front and mapped across frameworks.

Implement

Rollout tasks assigned across teams, with the supporting policies drafted alongside.

Operate

Access reviews, approvals, scans and training scheduled, tracked and recorded as they happen.

Verify

Testing with documented sampling. Findings route to an owner and retesting runs to closure.

Audit

A scoped workspace for your auditor, evidence attached, every request tracked to a close.

12
Frameworks in one control library
3 mo
Typical time to audit-ready
5
Lifecycle phases covered
100%
Data hosted in your own country
Framework coverage

Write a control once. Satisfy every framework that asks for it.

Multi-framework programs stall on duplicated effort. One control library removes it, so your second certification costs a fraction of your first. Read the difference between ISO 27001 and ISO 27002, or start with what SOC 2 is.
ISO 27001
ISO 27701
ISO 42001
SOC 2
HIPAA
GDPR
PCI DSS
NIST CSF
NIST 800-53
CSA CCM
CMMC
FedRAMP
Built for Canada

SOC 2 and ISO 27001 in Toronto, Ontario and across Canada

We work from Toronto, in your time zone, and read the Canadian regulatory picture on its own terms rather than a US-centric version of it. PIPEDA at the federal level. PHIPA for Ontario health information. Quebec’s Law 25. Provincial privacy law in Alberta and British Columbia. OSFI’s B-13 and B-10 expectations for the institutions it regulates. See how we run SOC 2 compliance service in Canada and ISO 27001 certification in Toronto.
Canadian data residency compliance is a separate question from SOC 2. Nothing in the Trust Services Criteria asks where your data sits, so a clean report tells a Canadian buyer nothing about residency. We host your data in your own country, and we handle the residency answer in the system description and in your ISO 27001 supplier and transfer controls.
Who we serve
Compliance services Canada
Certification work, ongoing program management, and privacy and security advisory. See professional services.
Questions

Frequently asked questions

If you have nobody in-house who has run a certification before, start with Compliance as a Service. That is what it is built for. Platform Subscription suits teams that already have a compliance lead and want better tooling. The vCCO plan is for companies that need a compliance executive on an ongoing basis rather than a one-off certification.
Because scope decides the price, and scope varies more than most buyers expect. The number of frameworks, the size of your environment, how much already exists and how long your observation window runs all change the number. We quote after a free gap analysis, which costs you nothing and gives you a real figure rather than a range. If you want the shape of the number before you talk to us, we broke it down in what a SOC 2 Type 2 report costs.
We check your current controls against your target framework and hand you a written gap list and a project plan. You see where you stand and what the work to certification involves. There is no obligation.
Yes. Most clients start on Compliance as a Service to get the first certification, then move to Platform Subscription once they have built the internal capability, or up to a vCCO if compliance becomes a standing executive requirement.
No firm can promise an audit outcome, and you should be wary of one that does. What we do is run the internal audit before your external auditor arrives, so the findings surface while there is still time to fix them. Your compliance manager also attends the audit with you.
Most clients are audit-ready in about three months. For SOC 2 Type 2 the report comes later, because a Type 2 tests controls over an observation window of at least three months, and fieldwork and drafting follow that. ISO 27001 certification follows a Stage 1 and Stage 2 audit once you are ready. We set out each stage in how long a SOC 2 Type 2 takes.
Your data is hosted in the country your company resides in. For Canadian clients that means Canada.

Start with the gap analysis

It is free, it takes days rather than weeks, and it ends with a written plan you can budget against. Compliance as a service, from a Toronto team, with your data in your own country.
Scroll to Top