Who asks for what
The question usually arrives from a customer's vendor risk team. North American buyers, especially in technology and finance, tend to ask for a SOC 2 report. Buyers in Europe, and larger multinationals everywhere, often ask whether you hold ISO 27001 certification. Public bodies have their own requirements, such as a security classification for the data and accessibility to WCAG AA.
Before starting either, ask your next few customers what they will actually accept. Some will take a completed questionnaire and your architecture documents for now; others will not sign without a report. That answer decides whether this is a this-quarter project or a next-year one.
SOC 2 in plain terms
A SOC 2 report is an examination of a service organization's controls, carried out by an independent CPA firm under the AICPA's standards [1]. It covers security, and optionally availability, processing integrity, confidentiality and privacy. It is an attestation, not a certificate: the auditor reports on your controls, and your customer reads the report.
- A Type I report looks at whether the controls are designed properly at a point in time. It is quicker and often the first step.
- A Type II report looks at whether the controls operated effectively over an observation period. It is what most enterprise customers eventually want.
- The report is shared with customers under a non-disclosure agreement; it is not a public badge.
ISO 27001 in plain terms
ISO/IEC 27001 is an international standard for an information security management system: how a company decides its risks, chooses controls and keeps improving them. Certification is issued by an accredited certification body after an audit, and is maintained with surveillance audits and periodic recertification.
The two overlap heavily in the controls themselves. A company that builds the controls once can usually map them to both, so a second framework costs mostly its difference: the management system and documentation ISO expects, or the reporting SOC 2 expects.
What is not a certification
| Name | What it is | What to say |
|---|---|---|
| SOC 2 | An attestation report by an independent CPA firm | We have a SOC 2 Type I or Type II report, available under NDA |
| ISO 27001 | A certification by an accredited certification body | We are certified to ISO 27001 by a named body, or we are working towards it |
| GDPR | A European law on personal data | Built for GDPR; there is no official GDPR certification to hold |
| PIPEDA and Quebec Law 25 | Canadian privacy laws | Built for them, with your privacy officer |
| HIPAA | A US law on health information | HIPAA-ready architecture; no official HIPAA certification exists |
| PCI DSS | The card industry's data security standard | A self-assessment or an assessor's report, scoped by your payment design |
What the work actually is
- 01
Gap assessment
Compare what you do today with what the framework expects, and list what is missing.
- 02
Controls in the product
Access by role and single sign-on, audit logs, encryption, backups with tested restores, monitoring, vulnerability scanning and change management, built into the system rather than described on paper.
- 03
Policies
A written policy set that matches what the team actually does, because the auditor tests the two against each other.
- 04
Evidence
Collected as the work happens, often in a compliance platform, so the observation period for a Type II report starts on a working system.
- 05
Fieldwork and findings
Support while the auditor tests, and fixes for anything they find.
Answering questionnaires in the meantime
Until there is a report, the security questionnaire is the report. Answer it well: keep one master set of answers, written by the people who run the system, and update it whenever the system changes. Attach what you can show rather than describe: an architecture diagram, the data flow, the backup and restore procedure, the access review, the result of the last penetration test. An honest answer that says a control is planned, with a date, reads better to a vendor risk team than a vague yes.
The same master answers become the starting point of the gap assessment when you do decide to pursue a report, so none of the effort is wasted.
Choosing an auditor
Choose the auditor early, before the readiness work is finished, and ask how they work: how they test, what evidence they expect, whether they accept evidence from your compliance platform, and how long fieldwork and the report take. Ask your customers whether they prefer particular firms. The auditor must be independent of whoever helped you prepare, which is one reason a studio that builds your controls can never be the one that reports on them.
What it costs, worked out now
The three worked examples below are priced by our estimator from the rate card in force when you open this page, for the same web product: readiness for a first SOC 2 Type I report, audit support through a Type II report, and both SOC 2 Type II and ISO 27001 kept up continuously. Our price covers the engineering and audit support; the auditor's fee and any compliance platform are shown by the estimator as indicative ranges on their own, because you pay them directly.
Worked example, priced now
Readiness for a first SOC 2 Type I report
Controls built into the product, a gap assessment and policies, with evidence in your compliance platform.
- Build
- ≈ US$82,700 to US$127,000, delivered within 26 weeksCAD 117,800 to 180,300
Prices in your currency are estimates from today's Bank of Canada rate. All invoicing is in CAD or USD.
How it is paid
- Deposit 20%
- CAD 23,560 to 36,060
- Discovery 6%
- CAD 7,068 to 10,818
- Design approved 6%
- CAD 7,068 to 10,818
- Core features 18.1%
- CAD 21,321.80 to 32,634.30
- Full build 12%
- CAD 14,136 to 21,636
- Testing and fixes 6%
- CAD 7,068 to 10,818
- Controls built and evidenced 7.7%
- CAD 9,070.60 to 13,883.10
- Readiness review 7.7%
- CAD 9,070.60 to 13,883.10
- Launch 6.5%
- CAD 7,657.00 to 11,719.50
- Holdback, 30 days after launch (10%)
- CAD 11,780 to 18,030
Running it
- Hosting
- ≈ US$492 a monthCAD 700 a month
- Support
- ≈ US$2,500 a monthCAD 3,565 a month
Worked example, priced now
Through a SOC 2 Type II report
The same product, with audit support through a six-month observation period.
- Build
- ≈ US$94,000 to US$144,000, delivered within 27 weeksCAD 133,800 to 204,700
Prices in your currency are estimates from today's Bank of Canada rate. All invoicing is in CAD or USD.
Estimated effort by role
- Development
- 272 to 415 h
- DevOps engineer
- 105 to 161 h
- Project manager
- 102 to 156 h
- Senior backend developer
- 76 to 116 h
- QA engineer
- 66 to 101 h
- Senior engineer
- 64 to 97 h
- Software architect
- 58 to 89 h
- Frontend developer
- 50 to 76 h
- Backend developer
- 45 to 68 h
- Technical writer
- 42 to 64 h
- Product designer
- 34 to 51 h
- Senior frontend developer
- 31 to 48 h
- Senior product designer
- 22 to 34 h
- Junior frontend developer
- 19 to 28 h
- Junior backend developer
- 18 to 28 h
How it is paid
- Deposit 20%
- CAD 26,760 to 40,940
- Discovery 5.4%
- CAD 7,225.20 to 11,053.80
- Design approved 5.4%
- CAD 7,225.20 to 11,053.80
- Core features 16.3%
- CAD 21,809.40 to 33,366.10
- Full build 10.8%
- CAD 14,450.40 to 22,107.60
- Testing and fixes 5.4%
- CAD 7,225.20 to 11,053.80
- Controls built and evidenced 7%
- CAD 9,366 to 14,329
- Readiness review 7%
- CAD 9,366 to 14,329
- Launch 5.4%
- CAD 7,225.20 to 11,053.80
- Audit support and remediation 7.3%
- CAD 9,767.40 to 14,943.10
- Holdback, 30 days after launch (10%)
- CAD 13,380 to 20,470
Running it
- Hosting
- ≈ US$492 a monthCAD 700 a month
- Support
- ≈ US$2,500 a monthCAD 3,565 a month
Worked example, priced now
SOC 2 Type II and ISO 27001, kept up
Both frameworks mapped to one set of controls, with continuous compliance and annual renewal support.
- Build
- ≈ US$112,000 to US$172,000, delivered within 42 weeksCAD 160,000 to 244,700
Prices in your currency are estimates from today's Bank of Canada rate. All invoicing is in CAD or USD.
How it is paid
- Deposit 20%
- CAD 32,000 to 48,940
- Discovery 5.4%
- CAD 8,640.00 to 13,213.80
- Design approved 5.4%
- CAD 8,640.00 to 13,213.80
- Core features 16.3%
- CAD 26,080.00 to 39,886.10
- Full build 10.8%
- CAD 17,280.00 to 26,427.60
- Testing and fixes 5.4%
- CAD 8,640.00 to 13,213.80
- Controls built and evidenced 7%
- CAD 11,200 to 17,129
- Readiness review 7%
- CAD 11,200 to 17,129
- Launch 5.4%
- CAD 8,640.00 to 13,213.80
- Audit support and remediation 7.3%
- CAD 11,680.00 to 17,863.10
- Holdback, 30 days after launch (10%)
- CAD 16,000 to 24,470
Running it
- Hosting
- ≈ US$492 a monthCAD 700 a month
- Support
- ≈ US$4,710 to US$5,870 a monthCAD 6,700 to 8,360 a month
When neither is the right answer yet
If no customer has asked, or the ones who asked will accept a questionnaire, a report can wait. What should not wait is the engineering: single sign-on, audit logs, encryption, backups that restore and change management cost far less to build in from the start than to retrofit before an audit. Build the controls now, and the report becomes a smaller project when a customer finally asks.