Compliance

PIPEDA, PHIPA, SOC 2, cyber-insurance prep, and industry-specific frameworks, documented, tested, and ready when the auditors arrive. We translate compliance requirements into actual technical controls, write the policies your insurance needs, and keep the evidence you'll be asked to produce.

For regulated industries (healthcare, legal, financial services, public sector), we maintain ongoing compliance posture rather than scrambling once a year. For everyone else, we make sure your cyber-insurance application doesn't get rejected for missing controls, a common and expensive surprise.

Compliance you can actually maintain

Compliance work has a reputation for being a once-a-year scramble, auditors arrive, your team sprints to find evidence, you breathe a sigh of relief when the report comes back clean, and then you do nothing for eleven months until it's time again. That pattern is risky and expensive: risky because the controls you set up under deadline pressure tend to drift, expensive because the rebuild cost compounds every year.

We approach IT compliance services for SMBs as ongoing posture, not annual project. The core idea: design the controls once, automate the evidence collection, and run a low-effort monthly review so you're audit-ready every day, not just the week before the auditor shows up.

The frameworks we support most often:

  • PIPEDA (Canadian privacy): Every business handling personal information of Canadians needs to align with PIPEDA's ten fair information principles. We translate those principles into technical controls, encryption at rest and in transit, role-based access, breach notification procedures, data retention policies, and document the evidence.
  • PHIPA (Ontario health information): Healthcare practices, dental offices, and any organization that touches Ontario health data must comply with PHIPA. Our work covers the technical safeguards (audit logs, access reviews, encryption) and the policy framework (consent, breach reporting, training records).
  • SOC 2: For SaaS companies and service providers selling to enterprise customers, SOC 2 is increasingly the table-stakes ask. We prep clients for SOC 2 Type 1 audits in 4–6 months and Type 2 in roughly 12 months total.
  • Cyber-insurance readiness: Insurance carriers have tightened underwriting dramatically. Most policies now require specific controls (MFA, EDR, immutable backups, incident response runbooks). We document the controls in the format insurers expect, which is also the format that gets you better premiums.

What ongoing compliance support actually looks like: a documented control matrix that maps each framework requirement to the technical control that satisfies it; automated evidence collection where possible (system logs, access reviews, vulnerability scans); monthly compliance review meetings; a clear answer for "where's the evidence?" on every common audit question.

If you're going through a first-time audit, an insurance renewal, or due diligence for an acquisition, we can also do compliance as a project, gap assessment, remediation plan, controls implementation, evidence package, typically in 30 to 90 days.

What's included

The essentials, without the upsell

PIPEDA / PHIPA alignment

SOC 2 prep & evidence

Cyber-insurance readiness

Policy frameworks

FAQ

Common questions

What's the difference between PIPEDA and SOC 2?

PIPEDA is Canadian privacy law, it tells you how you must handle personal information. SOC 2 is a voluntary US-originated framework focused on five trust criteria (security, availability, processing integrity, confidentiality, privacy) and is often required by enterprise customers before they'll buy from you. They overlap on some controls but serve different audiences: PIPEDA is for regulators, SOC 2 is for customers.

How long does SOC 2 preparation typically take?

SOC 2 Type 1 (point-in-time attestation) usually takes 4–6 months from kickoff to audit. SOC 2 Type 2 (operational effectiveness over 6–12 months) adds the observation period on top. Most clients start with Type 1, then immediately enter the Type 2 observation window to compress the overall timeline.

My cyber-insurance renewal is asking for controls I don't have. How fast can you help?

We've turned around urgent insurance renewals in as little as 2–3 weeks for the basic controls (MFA enforcement, EDR deployment, immutable backup implementation). For more complex requirements (formal incident response plan, written security policies, vulnerability management program), 4–6 weeks is more realistic.

Do we need to comply with PIPEDA if we're a small business?

PIPEDA applies to any organization that collects, uses, or discloses personal information in commercial activity, there's no employee-count exemption. Most small businesses are technically in scope. The good news: PIPEDA is principle-based, not prescriptive, so a small business compliance program is much lighter than what a bank or insurer needs.

What happens if we have a data breach?

PIPEDA requires notification to the Office of the Privacy Commissioner of Canada and affected individuals if the breach creates "real risk of significant harm." We help build an incident response runbook before you ever need one, so the notification timeline, communications templates, and forensic process are documented and ready. The first hour after detection sets the tone for the rest of the response.

Want to talk about Compliance?

A no-pressure conversation with a senior engineer, not a sales script.