GetAudited

Which compliance framework do you need?

Start with the sentence someone sent you. Almost every framework decision in a Canadian company can be settled by reading that sentence carefully rather than by comparing standards.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

If a customer asked for a SOC 2 report, get SOC 2. If a tender named ISO 27001, get ISO 27001. If a federal contract named CPCSC, nothing else will do. The framework question is only genuinely open when nobody has named one, and in that case the answer for most Canadian companies selling to North American businesses is SOC 2, because it is the cheapest and fastest route to a document a procurement team will accept.

That covers perhaps three quarters of the cases. The rest of this page is for the other quarter: the requests that name something that does not exist, the ones that name two things, the ones where a law applies whether or not anyone asked, and the ones where the framework is right but the timing makes it impossible. Work from what was actually said.

Start from what your buyer said

Find the row that matches the words you were sent, not the words you think they meant. Procurement teams are usually more literal than they are given credit for.

From the request you received to the work that answers it
What you were asked forWhat that meansWhere to go next
"Send us your SOC 2 report" A SOC 2 Type 2 report from a CPA firm, covering a past observation period SOC 2 requirements and auditors
"Are you SOC 2 certified?" The same thing, phrased wrongly. There is no SOC 2 certificate. Type 1 against Type 2
"ISO 27001 certification is a requirement of this tender" A certificate from an accredited certification body, not a readiness letter ISO 27001 certification
"We need assurance about your AI system" Increasingly ISO 42001, sometimes just a policy and a model inventory ISO 42001
"Provide evidence of annual penetration testing" A dated report from an independent tester, with retest evidence Penetration testing types
"Complete the attached security questionnaire" No framework yet. A negotiation, and an early warning of one coming. Answer it honestly, then read the section on questionnaires below
"You will be required to meet CPCSC Level 2" A federal or defence supply requirement arriving through a contract clause CPCSC readiness
"Confirm you are PIPEDA compliant" A legal obligation you already have. Nothing to certify, something to show. PIPEDA compliance
"You will act as our agent under PHIPA" An Ontario health custodian pushing statutory duties down to you by contract PHIPA compliance
"Our Quebec privacy officer needs to review your practices" Law 25, which is stricter than PIPEDA and has its own assessment duty Compliance in Quebec
"Who owns security at your company?" The buyer wants a named accountable person, not a framework What a vCISO does
"We need this before the contract signs next month" Usually impossible as asked. Read the section on timing. SOC 2 timeline

If nobody has named a framework

This is the situation where companies waste the most money, because with no external constraint the decision gets made on preference, and preference tends toward the framework whose name the founder has heard most often.

Three questions settle it. Where are your customers, how big are they, and what do they buy from you.

Selling to North American businesses. SOC 2. It is what their vendor security review is built around, their questionnaire tools are built around, and their legal team expects. A Type 2 report costs roughly $20,000 to $60,000 CAD in audit fees with readiness support on top, and takes six to twelve months from a standing start.

Selling to European, British or global enterprise buyers. ISO 27001. Certification is recognized internationally in a way a SOC 2 report is not, and tenders in those markets frequently name it as a threshold requirement rather than a preference. It costs more and takes longer, and it gives you a certificate rather than a report full of your auditor's observations.

Selling to Canadian federal departments or defence primes. CPCSC, arriving through your contract. Commercial frameworks do not substitute for it, though the control work overlaps heavily.

Selling to hospitals, clinics or health networks. The provincial health privacy statute first, because it binds you by law and by contract, and a commercial framework second to prove your controls to their procurement team.

Selling to consumers, or not selling yet. Neither. Get the privacy obligations right, put multi-factor authentication and backups in place, and revisit when a buyer forces the question. Buying a SOC 2 report before you have a customer who wants one is buying an expiring document.

The expensive misread

SOC 2 and ISO 27001 overlap by roughly two thirds in control content, which is why so many people treat them as interchangeable. They are not interchangeable in procurement. A buyer whose checklist says ISO 27001 will not accept a SOC 2 report because the two are similar, and the reverse is equally true. Get the one that was named, then decide separately whether the other is worth adding.

The frameworks side by side

Every figure below is Canadian dollars and every one is a range, because scope drives the number more than anything else.

What each framework produces, costs and takes, in Canada
Framework What you end up holding First-year cost (CAD) Time from nothing
SOC 2 Type 2 An attestation report from a CPA firm $40,000 to $120,000 6 to 12 months
SOC 2 Type 1 A point-in-time report on control design $30,000 to $70,000 3 to 5 months
ISO 27001 A certificate from an accredited body, valid three years $40,000 to $110,000 9 to 15 months
ISO 42001 A certificate covering an AI management system Varies widely, market is young 9 to 15 months
CPCSC A federal certification level tied to contracts Preparation only, fees not yet published Not yet fixed
PIPEDA or provincial privacy law Nothing. It is law, and there is no certificate. $8,000 to $25,000 for a first program 4 to 10 weeks

Privacy law is not one of the choices

Everything above is voluntary and arrives through commerce. Canadian privacy law arrives regardless, and it is where guidance written for a United States audience does the most damage, because it tells Canadian readers to worry about statutes that do not apply to them and skips the ones that do.

The federal Personal Information Protection and Electronic Documents Act covers private-sector organizations handling personal information in commercial activity. Quebec, British Columbia and Alberta have their own private-sector statutes that displace it provincially, and health information is governed separately again in most provinces. Quebec's Law 25 is the strictest of them and the one most often missed, and information crossing a provincial or national border pulls PIPEDA back into scope wherever you are based. The PIPEDA guide sets out which regime governs you, and the consultant pages by city name the statute that applies in each province.

When you need more than one

Doing two frameworks at once is usually a mistake and occasionally the right call. It is the right call when two named requirements are already on the table from two real customers, because the second framework then costs perhaps forty percent of the first rather than a hundred, given how much evidence is shared. It is a mistake when the second one is aspirational, because the work is real and the deadline is not.

The reliable ordering is the same every time. Do the data inventory first, since it feeds an audit scope, a retention schedule and a privacy assessment alike. Do the named framework second. Add the penetration test when your auditor asks for it, which they will, and budget $8,000 to $40,000 CAD for it depending on scope. Add the second framework at your first surveillance or second audit cycle, when the evidence machinery already runs.

When the timeline makes the answer wrong

A buyer who wants a SOC 2 Type 2 report in six weeks is asking for a document that cannot exist, because a Type 2 tests whether controls operated across an observation period of at least three months and that period cannot be compressed. This is not a negotiating position, it is arithmetic.

What works instead is telling them so, and offering the real alternatives: a Type 1 report on control design now with a Type 2 to follow on a stated date, a completed questionnaire with a dated remediation plan against the gaps, or a contractual commitment to deliver the report by a specific date. Buyers accept these routinely. What ends deals is discovering in month four that the report promised in month one was never possible.

If all you have is a questionnaire

A security questionnaire is not a framework request, and treating it as one leads companies to spend fifty thousand dollars answering a document that wanted a yes or a no. Answer it, including the parts where the answer is no, and attach dates to the gaps. Then read what it was built from: questionnaires are usually derived from whatever framework the buyer's own security team works to, and the question set tells you what they will ask for next.

If questionnaires are arriving faster than anyone internally can answer them, that is a staffing signal rather than a framework signal, and the usual answer is fractional security leadership rather than a certification project.

Still not sure which one applies

Send us what your buyer asked for, in their words, and we will tell you what they mean and which Canadian firms do that work.

Get matched

Common questions

Our buyer said SOC 2 or ISO 27001, either is fine. Which do we pick?

SOC 2, if your customers are mostly North American. It is faster to a usable document and cheaper in the first year, and the Type 1 report gives you something to send while the Type 2 observation period runs. Choose ISO 27001 instead if you expect European or British buyers within two years, because retrofitting a certificate later costs more than starting with one.

Can one project satisfy several frameworks at once?

Partly. The underlying controls in access management, change management, logging, vendor oversight and incident response are shared across SOC 2, ISO 27001 and CPCSC, so the second framework is substantially cheaper than the first. The evidence formats, the assessor and the report are not shared, so you still pay separately for each assessment.

Do we need a framework at all if we already follow privacy law?

Only if a customer asks for one. Privacy law tells you how you may handle personal information but produces no document you can send to a procurement team, which is usually what is being requested. If nobody has asked, staying compliant with the law and keeping your security basics in order is a defensible position.

Is a compliance platform a substitute for choosing a framework?

No. Platforms collect and monitor evidence against a framework you have already chosen, and they are configured per framework. Buying one before the decision is made tends to make the decision for you, in favour of whichever framework the platform sets up most easily.

Which framework does an insurer want?

Cyber insurers generally want controls rather than certificates: multi-factor authentication everywhere, tested backups, endpoint detection, and a documented incident response plan. Holding SOC 2 or ISO 27001 helps at renewal because it evidences those controls, but no insurer requires either as a condition of coverage in the way a customer requires them as a condition of purchase.