Pricing
Three ways to get certified.
Pick the one that fits your team.
Subscribe to the compliance platform, hand the whole program to a dedicated compliance manager, or bring in a virtual Chief Compliance Officer. Every plan runs on one control library covering twelve frameworks, with your data hosted in your own country.
Free gap analysis and project plan. No obligation.
Platform Subscription
For teams with in-house compliance capability who want the tooling, not the people.
Talk to us
Scope decides price. We quote after the gap analysis.
What you get
- One control library, twelve frameworks
- Automated evidence collection
- Policy management and templates
- Continuous control monitoring
- Asset register and audit workspace
- Integrations and reporting
- Support through a shared Slack channel
Most chosen
Compliance as a Service
For teams with no compliance expertise in-house who need a SOC 2 report or ISO 27001 certificate.
Talk to us
Scope decides price. We quote after the gap analysis.
What you get
- Everything in Platform Subscription
- A dedicated compliance manager
- Scoping and gap assessment
- Policies drafted for your environment
- Risk assessment and treatment plan
- Internal audit before the external one
- Auditor coordination and audit support
- Audit-ready in about three months
Virtual Chief Compliance Officer
For teams that need a compliance executive on call, not just a certification project.
Talk to us
Scope decides price. We quote after the gap analysis.
What you get
- Everything in Compliance as a Service
- A named vCCO owning your program
- Board and executive reporting
- Customer security questionnaires handled
- Vendor and third-party risk reviews
- Incident and breach response advisory
- Ongoing regulatory guidance
Compare
What is in each plan
Every plan runs on the same platform. What changes is how much of the work we take off you.
Compare the plans
Platform
CaaS
vCCO
Platform
One control library across twelve frameworks
✓
✓
✓
Automated evidence collection
✓
✓
✓
Continuous control monitoring and drift alerts
✓
✓
✓
Audit workspace for your auditor
✓
✓
✓
People
Support channel
Slack
Slack + manager
Slack + vCCO
Dedicated compliance manager
—
✓
✓
Named virtual Chief Compliance Officer
—
—
✓
Access to principal consultants
—
✓
✓
Certification work
Scoping and gap assessment
—
✓
✓
Policies drafted for your environment
Templates
✓
✓
Risk assessment and treatment plan
—
✓
✓
Internal audit before the external audit
—
✓
✓
Auditor coordination and audit attendance
—
✓
✓
Ongoing program
Customer security questionnaires
—
On request
✓
Vendor and third-party risk reviews
—
On request
✓
Board and executive reporting
—
—
✓
Incident response advisory
—
—
✓
How the service runs
Five phases, not one slice of them
Most vendors cover one part of the lifecycle and leave you the rest. Compliance as a Service and the vCCO plan cover all five.
Design
Objectives, owners and evidence requirements set up front and mapped across frameworks.
Implement
Rollout tasks assigned across teams, with the supporting policies drafted alongside.
Operate
Access reviews, approvals, scans and training scheduled, tracked and recorded as they happen.
Verify
Testing with documented sampling. Findings route to an owner and retesting runs to closure.
Audit
A scoped workspace for your auditor, evidence attached, every request tracked to a close.
12
Frameworks in one control library
3 mo
Typical time to audit-ready
5
Lifecycle phases covered
100%
Data hosted in your own country
Framework coverage
Write a control once. Satisfy every framework that asks for it.
Multi-framework programs stall on duplicated effort. One control library removes it, so your second certification costs a fraction of your first. Read the difference between ISO 27001 and ISO 27002, or start with what SOC 2 is.
ISO 27001
ISO 27701
ISO 42001
SOC 2
HIPAA
GDPR
PCI DSS
NIST CSF
NIST 800-53
CSA CCM
CMMC
FedRAMP
Built for Canada
SOC 2 and ISO 27001 in Toronto, Ontario and across Canada
We work from Toronto, in your time zone, and read the Canadian regulatory picture on its own terms rather than a US-centric version of it. PIPEDA at the federal level. PHIPA for Ontario health information. Quebec’s Law 25. Provincial privacy law in Alberta and British Columbia. OSFI’s B-13 and B-10 expectations for the institutions it regulates. See how we run SOC 2 compliance service in Canada and ISO 27001 certification in Toronto.
Canadian data residency compliance is a separate question from SOC 2. Nothing in the Trust Services Criteria asks where your data sits, so a clean report tells a Canadian buyer nothing about residency. We host your data in your own country, and we handle the residency answer in the system description and in your ISO 27001 supplier and transfer controls.
Who we serve
- SaaS and technology
- Healthcare and healthtech
- Financial services
- Logistics and supply chain
- Retail
- Public sector
Compliance services Canada
Certification work, ongoing program management, and privacy and security advisory. See professional services.
Questions
Frequently asked questions
If you have nobody in-house who has run a certification before, start with Compliance as a Service. That is what it is built for. Platform Subscription suits teams that already have a compliance lead and want better tooling. The vCCO plan is for companies that need a compliance executive on an ongoing basis rather than a one-off certification.
Because scope decides the price, and scope varies more than most buyers expect. The number of frameworks, the size of your environment, how much already exists and how long your observation window runs all change the number. We quote after a free gap analysis, which costs you nothing and gives you a real figure rather than a range. If you want the shape of the number before you talk to us, we broke it down in what a SOC 2 Type 2 report costs.
We check your current controls against your target framework and hand you a written gap list and a project plan. You see where you stand and what the work to certification involves. There is no obligation.
Yes. Most clients start on Compliance as a Service to get the first certification, then move to Platform Subscription once they have built the internal capability, or up to a vCCO if compliance becomes a standing executive requirement.
No firm can promise an audit outcome, and you should be wary of one that does. What we do is run the internal audit before your external auditor arrives, so the findings surface while there is still time to fix them. Your compliance manager also attends the audit with you.
Most clients are audit-ready in about three months. For SOC 2 Type 2 the report comes later, because a Type 2 tests controls over an observation window of at least three months, and fieldwork and drafting follow that. ISO 27001 certification follows a Stage 1 and Stage 2 audit once you are ready. We set out each stage in how long a SOC 2 Type 2 takes.
Your data is hosted in the country your company resides in. For Canadian clients that means Canada.
Start with the gap analysis
It is free, it takes days rather than weeks, and it ends with a written plan you can budget against. Compliance as a service, from a Toronto team, with your data in your own country.