SOC 2 audit services for Canadian SaaS companies
A customer asked for a SOC 2 report, and the clock is running. We take first-time teams from “where do we start” to a report that clears procurement, without the guesswork or the enterprise price tag.
- One SOC 2 engagement issued under AICPA and CSAE standards
- Readiness guidance and the independent audit, from one firm
- Fixed fee, confirmed once scope is set
Report
SOC 2 Type 1 + 2
Standards
AICPA + CSAE
Fee
TBD
Scope
TBD
- Licensed CPA firm, CPABC
- CISA
- CISSP
- CIA
- CFE
Get your first SOC 2 report without building for a company you are not yet.
A deal is waiting on the report, questionnaires are arriving faster than you can answer them, or US and enterprise accounts keep turning it into a requirement.
Criteria interpreted for how lean
The Trust Services Criteria are written for practitioners and assume enterprise structures.
Cloud-native evidence guidance
Most of what an audit asks for is already being produced by the tools you run. We help you identifyi.
A centralized library in the tools you
Guidance on structuring your policies, procedures and evidence in Confluence, Notion, GitHub
Type 1 and Type 2 audit for SaaS companies
We help you define the right SOC 2 path based on your timeline, budget, and customer commitments, whether that means starting with a Type 1 or going straight to Type 2.
SOC 2 Type 1 report
An independent auditor’s opinion on whether your controls were suitably designed and implemented as of a specific date.
- Interim assurance is needed to support an active deal while you progress toward Type 2
- You want confirmation that controls are sufficient before committing to a Type 2
- A customer is specifically asking for a Type 1
4 to 6 weeks from initial request to report issuance
SOC 2 Type 2 report
An independent auditor’s opinion on whether your controls were suitably designed and operated effectively throughout a defined reporting period.
- A prospect or customer requires a Type 2 report before signing or renewal
- You sell to US enterprises or regulated industries where a Type 2 is the baseline
- You expect the requirement to recur at renewal and with each new enterprise deal, rather than once
6 to 9 months from initial request to report issuance, including the observation period
A bounded process, with timing you can plan around
Six stages, each with a typical duration, so you can see the whole engagement before you commit to it.
Scoping and planning
We define the audit around your customer requirements, security objectives, systems, and operating environment. Together, we confirm the system boundary, applicable Trust Services Criteria, subservice organization approach, report type, and audit timeline.
Gap assessment and remediation roadmap
We assess your current policies, controls, processes, and evidence against the in-scope Trust Services Criteria, to identify what is already in place, what is missing, and what needs remediation.
Gap remediation
Your team uses the prioritized remediation roadmap as guidance to design, implement, and evidence applicable controls.
Readiness assessment
Before formal testing begins, we review the control environment and supporting evidence again, identify anything still outstanding, and confirm that the organization is ready to proceed.
Audit
We independently test controls using complete populations, appropriate sampling, evidence review, interviews, and walkthroughs to evaluate whether they operated effectively throughout the reporting period.
Report issuance
We evaluate the results of testing and any exceptions, prepare the report for management review, obtain the required representations, and issue the final independent SOC 2 report.
We advise and test. We never build.
Readiness guidance and the audit come from one firm without weakening the opinion, because you make every control decision and we never make it for you.
Templates, requirements, and review of what you propose, in plain language.
You design, decide, and implement each control in your own environment.
We independently test what you built and issue the report. That line is what makes it credible to your buyer.
Why choose Citadel Point for your SOC 2 audit
A licensed CPA firm, accountable in Canada
Hover to readA licensed CPA firm, accountable in Canada
Registered with CPABC and based in [Victoria / Vancouver], British Columbia. Your report is signed by a firm subject to professional standards and practice inspection, not by a platform with an audit attached.
One report for buyers in Toronto and New York
Hover to readOne report for buyers in Toronto and New York
A single engagement issued under both AICPA and Canadian assurance standards. The same report satisfies procurement in both markets. No second audit, no second fee, no duplicated evidence cycle.
We designed the requirements your buyers use
Hover to readWe designed the requirements your buyers use
Our team has worked with Fortune 500 organizations designing the vendor risk management requirements enterprise buyers now apply to companies like yours. We know how a SOC 2 report gets read, not just how one gets produced.
Sized for how a lean team actually runs
Hover to readSized for how a lean team actually runs
The Trust Services Criteria assume mature organizations with functions your team does not have. We tell you what satisfies each criterion at your size and stage, so you are not building structures you cannot sustain or being measured against ones you do not need.
One engagement, no handoff
Hover to readOne engagement, no handoff
You are not hiring a readiness consultant and then an auditor, re-explaining your environment to a second firm, or discovering at fieldwork that what the first one approved does not hold. The team that scopes your audit is the team that tests it and signs the opinion.
An auditor in the room for the hard sales conversations
The months before a report is issued are when trust with a security-sensitive buyer is won or lost. Having your auditor engaged and reachable through that period changes how those conversations go.
A signed auditor initiation letter
Written confirmation from the firm conducting your audit: scope, report type, and timeline. Something concrete for procurement while the work is underway.
Your auditor on the call
For high-stakes deals, we can join a prospect conversation to explain what the engagement covers, what is being tested, and where it stands.
Someone to ask before you answer
When a questionnaire asks something you are unsure how to answer, or a buyer’s security team pushes on a control, you can check rather than guess. That includes what you can credibly claim today and what you cannot claim yet.
Controls you can explain in your own words
Working through the criteria with an auditor means you understand what your controls do and why they matter, so you can answer a buyer’s questions directly instead of deferring every one.
The first-timer's guide to SOC 2
A plain-language walkthrough of what a first SOC 2 audit involves, written for the person who just got the questionnaire.
- 01 · What buyers actually mean when they ask for SOC 2
- 02 · Type 1 vs Type 2, and which one unblocks your deal
- 03 · Scoping without over-buying
- 04 · What evidence looks like in a cloud-native environment
- 05 · Answering a security questionnaire before the report exists
Start with a scoping conversation, not a contract
Tell us about your company and what your customer asked for
A short call to confirm scope and timeline
Receive a fixed-fee quote in writing
The questions we hear from first-timers
Anything not covered here, ask on the scoping call. You will get a plain answer, including “no” where the honest answer is no.
Yes. Both are issued by us on the same scope, so the Type 1 work carries directly into the Type 2 instead of being repeated. Many first-time teams start with a Type 1 to support an active deal and continue straight into the Type 2 observation period.
No. Small teams complete SOC 2 audits regularly. What matters is that your controls fit how you actually operate, so we interpret the criteria against your real structure rather than assuming functions you do not have.
It depends less on your stage than on demand. If a buyer is asking, you are not too early. If nobody has asked yet, scoping the work early is still useful, because the decisions made at the start are what keep the cost and timeline contained.
Yes. The engagement is issued under both AICPA and Canadian assurance standards, so the same report satisfies procurement in the United States and in Canada.
Because you make every control decision and we never make it for you. We provide readiness guidance: templates, requirements, and review of what you propose. You design, decide, and implement each control. Then we independently test what you built and issue the report. We advise and test; we never build. That line is what makes the report credible to your buyer.
No. A platform can organize the work, but it is not the process and it is not required. If you already run one, we work within it. If you do not, we help you build a practical evidence process on the tools you already use.
It depends on what your buyer is asking for and how fast the deal is moving. A Type 1 confirms your controls are designed correctly at a point in time and can move a deal quickly. A Type 2 shows they operated over a period and is what most enterprise buyers eventually expect. We will help you choose in the scoping conversation, and a Type 1 can lead into a Type 2 on the same scope.
Right-sizing is the point. We scope to what your buyer needs and what your team can operate, and we build evidence requests around the tools you already use, so you are not running a parallel compliance operation. The work is real, but it is bounded, and you will see the bound before you start.
Yes. The engagement is issued under both AICPA and Canadian standards, so the same SOC 2 report works whether your customer is in Canada, the United States, or both.
Type 1 starts from $15,000 CAD and Type 2 from $25,000 CAD for a Security-only engagement. The final number depends on your scope, which is exactly what the scoping conversation settles.
A Type 1 typically runs 4 to 6 weeks. A Type 2 depends on the observation period, usually 3 or 6 months for a first report, plus scoping, readiness, and fieldwork, so 6 to 9 months in total. We map realistic dates in scoping.
That is who this is built for. Your first SOC 2 is the one where early decisions matter most, and it is where independent audit judgment is most valuable, because getting scope and timing right at the start is what keeps the whole thing from ballooning.
Reading for your first SOC 2
Type 1 or Type 2: How to choose the right SOC 2 report
Placeholder article headline
Placeholder article headline
A licensed Canadian CPA firm.
© 2026 Citadel Point