Back to resources
SOC 2Article

How a Canadian company prepares a SOC 2 report

US buyers and large Canadian accounts often ask for a SOC 2 Type II. The report describes your controls and whether they operated over a period.

8 min readSeptember 28, 2026GRC strategy lead, CapGRC

SOC 2 is an AICPA audit report, issued by an independent CPA firm. It is not an ISO certificate. It covers a system you define: the service your customers buy, and the people, software and suppliers that run it.

The criteria

Security is always in the report. You add availability, processing integrity, confidentiality and privacy when a customer asks for them. A security-only report answers many buyers. A report that includes privacy does not replace Law 25 or PIPEDA: those statutes still apply on their own.

Type I and Type II

  • Type I describes the controls and whether they are suitably designed at a point in time.
  • Type II covers design and tests whether the controls operated over a period. Buyers usually ask for Type II, often over 12 months.
  • In the first year, some teams use a Type I to fix the scope, then move to Type II. The market keeps Type II.

What to have before the examination

1. The system

Name the service, locations, tools and subcontractors in scope. What is out of scope is written down.

2. Controls and evidence

Access, change, incidents, backups, critical suppliers. Each control has dated evidence: a ticket, a review, an export, minutes.

3. The system description

The report relies on the description you sign. It matches what teams do.

4. The observation window

For a Type II, the controls are already running during the period the auditor will test. Starting the evidence on the day of the engagement letter leaves a gap.

The report is renewed. Last year's Type II does not cover the current year. Keep the same evidence register from one period to the next, and link it to ISO 27001 if you hold both: access, incidents and suppliers overlap.

The choice between ISO 27001 and SOC 2 depends on your buyers. The comparison is in the dedicated article.

SOC 2 and ISO 27001 controls in one program

CapCOM ties evidence to the criteria, so the report and the standard are not two projects.