Compliance Support

SOC 2 Readiness Support for Northern Ontario Businesses

Control implementation, documentation, and evidence collection that gets your business ready for a SOC 2 examination — with your licensed CPA auditor issuing the report.

Serving Greater Sudbury, Northern Ontario, and surrounding communities. Remote support available throughout Ontario.

SOC 2 readiness is what happens before an audit. It is the work of implementing the access, monitoring, backup, change, and incident controls the Trust Services Criteria expect, documenting them honestly, and building a way to produce evidence on demand rather than reconstructing it under pressure.

To be completely clear about roles: Nickel City Tech Solutions does not issue SOC 2 reports and cannot certify your business. Only a licensed CPA firm can perform the examination and issue the report. We are the technical partner that prepares your environment, produces the evidence for the systems we manage, and stays available to your auditor during fieldwork.

This service is most often triggered by a customer requirement — an enterprise client, a government contract, or an insurer that will not proceed without evidence of your controls. Readiness turns that requirement into a scoped project instead of a lost deal.

Where readiness starts: a gap assessment

We begin by comparing your current environment against the Trust Services Criteria in scope for you — Security is mandatory, with Availability, Confidentiality, Processing Integrity, and Privacy added depending on what your customers are asking for.

The output is a plain list: what already meets the criteria, what needs technical work, what needs a written policy, and what needs an operational habit your team has to adopt. Nothing is marked complete because a tool is installed; it is complete when it is configured, documented, and producing evidence.

  • Scope definition — which systems, which criteria, Type I or Type II
  • Control-by-control gap list with owners and effort
  • Remediation plan sequenced by risk and by auditor visibility
  • Realistic timeline based on your environment, not a template

Technical controls we implement and manage

Most SOC 2 gaps for a small or mid-sized business fall into a handful of areas, and they are the same areas good managed IT already covers — the difference is that readiness requires them to be provable, not just present.

  • Identity and access: MFA, conditional access, least privilege, and periodic access reviews
  • Endpoint management: monitored, patched, encrypted devices with protection agents verified
  • Logging and retention: sign-in, admin, and security logs retained for the audit window
  • Backup and recovery: monitored jobs, tested restores, documented retention
  • Change management: documented, approved, and recorded changes to managed systems
  • Vendor management: a maintained inventory of subprocessors and their access

Documentation and policy support

Auditors read policies and then look for evidence that reality matches them. We help you write policies that describe what your business genuinely does — access control, acceptable use, onboarding and offboarding, incident response, backup and recovery, change management, and vendor management.

Policies you cannot follow are worse than no policy at all, because the audit will find the gap. We deliberately write to your actual operating model.

Evidence collection that runs continuously

Type II examinations look at a period, not a moment. That means evidence has to accumulate: access review records, patch compliance reports, backup job results, offboarding checklists, ticket history, and incident write-ups.

We set up the collection so it is a by-product of normal operations. Monthly reporting from our monitoring platform, structured ticketing, and documented offboarding become the evidence trail rather than an extra chore.

Working with your CPA auditor

You choose the auditor — their independence is the whole value of the report, and we would never recommend an arrangement that compromises it. Once selected, we act as your technical counterpart: attending scoping calls, responding to evidence requests for systems we manage, explaining architecture, and closing technical findings before they become exceptions in the report.

If a full SOC 2 is more than you need

Plenty of businesses are asked for assurance but not specifically for SOC 2. If your driver is an enterprise security questionnaire, a cyber-insurance application, or a client's vendor-risk review, we can scope a lighter engagement that implements and documents the same underlying controls without the audit cost.

What's included

Gap Assessment

Your environment measured against the Trust Services Criteria in scope, with a prioritized remediation plan.

Access Control Implementation

MFA, conditional access, least privilege, and recurring access reviews with records auditors accept.

Endpoint & Security Controls

Managed, patched, encrypted, and monitored devices with verified protection agents.

Backup & Recovery Evidence

Monitored backup jobs, documented retention, and tested restores with written results.

Policy Documentation

Written policies that match how your business actually operates, not generic templates.

Evidence Collection Process

Continuous evidence generated by monitoring, ticketing, and offboarding — not reconstructed at audit time.

Auditor Coordination

Direct support to your chosen CPA firm during scoping and fieldwork for systems we manage.

Questionnaire Support

Help answering enterprise client, insurer, and vendor-risk security questionnaires accurately.

Who it's for

  • Businesses that lost or stalled a deal because a client asked for a SOC 2 report
  • SaaS, professional services, and data-handling firms selling into enterprise accounts
  • Organizations facing an insurer or vendor-risk security questionnaire they cannot confidently answer
  • Teams pursuing a Type I now with a Type II planned for the following period
  • Businesses with internal IT that need a partner for the technical control and evidence layer

Common problems we solve

  • No documented policies, or policies that do not match how the business really operates
  • Access granted informally, with no review record and inconsistent offboarding
  • Backups running but never tested, with no evidence of recovery capability
  • Logs not retained long enough to cover the examination period
  • Evidence assembled frantically during fieldwork instead of collected continuously
  • Uncertainty about what an IT provider can and cannot do in a compliance project

Why Nickel City Tech Solutions

  • Honest scope: we prepare you, a licensed CPA firm issues the report
  • The same team runs your day-to-day IT, so controls stay in place after the audit
  • Evidence is produced by your normal operations, not a one-time push
  • Local, founder-led delivery across Greater Sudbury and Northern Ontario
  • No implied certifications — read our Trust & Security page for exactly what we claim
  • Comfortable working directly with your auditor and your enterprise clients' risk teams

Frequently asked questions

Can Nickel City Tech Solutions certify us for SOC 2?

No, and neither can any IT provider. A SOC 2 report is issued only by a licensed CPA firm after an independent examination. What we do is readiness work: implement and document the technical controls, gather evidence, and get your environment into a state where the audit is a review rather than a scramble. The audit itself stays with your chosen CPA firm.

Are you SOC 2 certified yourselves?

No. We do not hold SOC 2, ISO 27001, or equivalent certification and we will not imply otherwise. We apply the security practices described on our Trust & Security page, and we support clients pursuing their own attestations.

Why would a small business need SOC 2 readiness?

Usually because a customer asked. Enterprise clients, government contracts, and larger partners increasingly require a SOC 2 report or a detailed security questionnaire before signing. Readiness work is what turns that request from a deal-blocker into a project with a timeline.

What is the difference between Type I and Type II?

A Type I report examines whether your controls are suitably designed at a point in time. A Type II examines whether they operated effectively over a period, commonly three to twelve months. Type II requires evidence collected consistently across that window, which is why the tooling and habits matter more than the paperwork.

How long does readiness take?

It depends on where you are starting. An environment already running MFA, managed endpoints, centralized identity, monitored backups, and documented offboarding is much closer than one where access is informal. We begin with a gap assessment so the timeline is based on your actual environment rather than a generic estimate.

What do you actually deliver?

A gap assessment against the Trust Services Criteria relevant to your scope, a remediation plan, implementation of the technical controls we manage, written policies and procedures covering those controls, an evidence collection process, and direct coordination with your auditor during fieldwork.

Do you work with our chosen CPA firm?

Yes. You select the auditor — that independence is the point of the report. We work alongside them, respond to evidence requests for the systems we manage, and help you answer the parts that are technical rather than operational.

What if we only need to answer a security questionnaire?

Many businesses do not need a full SOC 2 report — they need to credibly answer an enterprise client's or insurer's questionnaire. We can scope a smaller engagement focused on implementing the controls those questionnaires ask about and documenting them properly.

Case studies

Related real-world projects

Let's talk about your environment

Free 30-minute consultation. Serving Greater Sudbury, Northern Ontario, and surrounding communities. Remote support available throughout Ontario.

Internal links

Related services, locations, and resources

Related services

Helpful resources

Resources

Latest IT Insights

Cybersecurity guides, Microsoft 365 tips, and managed IT advice from our Ontario team.

Browse all resources