
You're a Canadian company selling into US enterprise buyers, and the security questionnaire came back with 'SOC 2 Type 2 report required for deal closure.' That's the moment most of our SOC 2 conversations start. NFD is SOC 2 Type 2 attested ourselves — our controls stack maps directly to what your auditor will ask for. We handle readiness, control implementation, evidence collection, and auditor liaison so your founders and CTO can keep shipping product.
Enterprise buyer said SOC 2 Type 2 is a requirement, and you're wondering where to start? Tell us the deadline and we'll come back with a scoped readiness plan.
We respect your privacy. We won’t send you marketing you didn’t ask for.
Trusted by businesses across Canada and North America
Your local NFD office
22 Frederick St, Suite 700, Kitchener, ON N2H 6M6
“NetFusion Designs has been our IT guru for several years now and they have proved themselves to be one of the best companies we’ve seen in a long time.”
“They rebuilt our environment which was aging and under-performing; the new environment was super fast and enabled us to scale our business.”
“They take the time to explain the how’s and why’s and do not assume everyone has the same IT brain — which I personally appreciate.”
SOC 2 attestation isn't for everyone — it's for companies with a specific commercial trigger. Three profiles cover most of our engagements.
You closed your first Fortune 500 customer with a Type 1. Now the next five prospects are asking for Type 2, and your GC is quietly worried about the audit runway. We plug in as your outsourced compliance function until you can hire your first security or GRC lead.
We deliver a readiness assessment against Type 1 or Type 2 scope, remediation on the gap items, and an audit-firm handover — with an MSP partner who has been through their own SOC 2. See managed IT services for the fixed-fee model.
PIPEDA plus PHIPA, or PIPEDA plus OSFI-adjacent expectations. SOC 2 becomes the umbrella framework that satisfies most of your enterprise buyers without needing five separate certifications. We handle the mapping across.
We deliver a bench of engineers, a virtual CIO who runs quarterly compliance reviews, and SOC 2 evidence collection built into the day-to-day so audit season is a report, not a sprint.
If your customers are SOC 2 attested, you're going to be asked for your own report inside a year. We know the vendor-management dance because we live it. Our own SOC 2 report is a common example we hand to clients as a template.
We deliver an operator who runs a SOC 2 shop themselves and can share what actually works — tool selection, policy templates, evidence cadence, and auditor coordination.
SOC 2 comes in two flavours. Type 1 is a point-in-time snapshot: "as of a date, these controls existed." Type 2 is a period-of-time report: "across at least six months, these controls operated effectively." Type 2 is what enterprise buyers actually mean when they say "SOC 2." Here is how the two compare and which fits your buyer's ask.
For most Canadian SaaS companies going after their first SOC 2, a full Type 2 engagement is the goal. Readiness-only makes sense when you already have an internal GRC lead and need controls implementation without the audit-manager layer.
A useful SOC 2 engagement is more than "we'll help you buy a compliance platform." It is a mapped control set against the trust services criteria, gap remediation on your systems and processes, evidence collection built into the day-to-day, and coordination with the audit firm that issues the report. This is what our SOC 2 clients actually get.
People pick up. Tickets are logged, ranked, and routed by severity. First-touch resolution wherever possible, escalation with named owners when not. 24/7 for managed clients.
Engineers dispatch from Kitchener, Toronto, Markham, and Montreal offices for on-site scoping and remediation. Remote-first for evidence collection and continuous review. National coverage across Canada.
Endpoints, servers, network gear, and Microsoft 365 tenants monitored around the clock. Windows and third-party patch cycles managed on a documented schedule, tested before broad rollout.
MFA on every account, EDR on every endpoint, DNS filtering, phishing training, quarterly review. See cyber security & antivirus for the full stack.
Tenant licensing, mailbox hygiene, SharePoint governance, and Teams rollout done properly. Details on the Microsoft 365 optimization page.
Immutable backups, off-site copies stored in Canada, and quarterly restore drills. Real recovery targets, not just "we have backups." See cloud backup & DR.
Quarterly business reviews, three-year technology roadmap, budget forecasting, and vendor negotiation. Virtual CIO services included with mid-market managed IT.
Every network diagram, admin account, license, and vendor contact captured in a maintained knowledge base. If we walk away tomorrow, the next provider can pick up where we left off. Most competitors won't tell you this — most don't have it.
Auditor requests during an active engagement are their own SLA category. Sample requests, control-evidence pulls, and clarification questions land in our shared portal and get turned around inside two business days as standard.
Most audit stall-outs happen because evidence takes weeks to gather. Our control-mapping and evidence portal collapse that to hours.
Cyber-insurance renewals, client questionnaires, and board risk reviews now ask for evidence, not adjectives. This is the security floor every managed IT client gets, and the audit trail behind it.
NetFusion Designs is independently audited to the SOC 2 Type 2 standard — trust services criteria across security, availability, and confidentiality. Not a checklist we filled out; a report a third party signs.
Multi-factor authentication is mandatory across Microsoft 365, VPN, admin consoles, and privileged internal systems. No exceptions, no long-term bypass tokens, no shared logins.
Endpoint detection and response with a 24/7 SOC watching the alert stream. Not signature-based antivirus — behavioural detection that catches things AV misses, with automated containment.
Immutable backups with Canadian data residency, tested by monthly automated restore and quarterly manual restore drills. If your backup has never been restored, you don't have a backup — you have a hope.
Annual tabletop and one live failover per managed client. Recovery time and recovery point objectives are documented per system, not guessed at during the incident.
Every configuration change to a production system goes through review and is recorded in the ticket. When something breaks at 11 p.m., we know what changed at 3 p.m.
National coverage from four Canadian offices — Kitchener (HQ), Toronto, Markham, and Montreal. SOC 2 work is remote-first once scoping is complete, so location is not a barrier. Our own SOC 2 Type 2 attestation is the credential the audit firm and your enterprise buyer will both want to see.
The largest concentration of our SOC 2 engagements. Series A and B SaaS teams in King West, health-tech shops in North York, and fintech companies along Bay.
Kitchener-Waterloo scale-ups selling into US buyers. We run readiness engagements out of our 22 Frederick Street office in downtown Kitchener with on-site working sessions.
Remote-first Canadian SaaS teams headquartered outside Ontario. Engagement runs on Zoom with quarterly on-site working sessions when the calendar supports it.
Cross-border scope is common. Our own attestation includes a US subsidiary, so we've walked the cross-border boundary in a real report. It's a reason clients pick us over US-only firms.
Switching MSPs sounds painful. Done properly, it isn't. Here is the exact sequence from first call to steady-state operations — usually inside 30 days.
A working conversation, not a sales pitch. What's broken today, what's threatening to break, what's on the roadmap. We come back with a written summary and a rough scope inside three business days.
A compliance engineer walks the environment — on-site or remote — and runs a gap assessment against the trust services criteria you need in scope. Deliverable: a documented current-state, a prioritised remediation list, a Type 1 or Type 2 target date, and an evidence-collection plan the audit firm can attest against.
Admin credentials rotated to our vaults, monitoring agents deployed, backups verified, MFA rolled out. Handover from your previous provider is coordinated so nothing lapses between the two of us — no dark days.
Controls implemented, policies signed, evidence collection cadence live, quarterly compliance review scheduled with the vCIO, and the audit firm engaged. From day 31 onward, SOC 2 is a running programme, not a fire drill — which is what makes Type 2 possible.
Three quotes from managed IT clients who let us paraphrase what happened. Names redacted at their request — the specifics are real.
“We went from zero controls to a clean Type 2 report in seven months. The auditor asked six clarifying questions across the entire engagement. That's a testament to how well NFD had our evidence organised.”
“Our first attempt at SOC 2 with another vendor took eighteen months and stalled at the observation window. Switching to NFD, we finished the observation and audit in ten months combined.”
“The evidence portal alone is worth the engagement. Every quarter we run it, pull the latest control evidence, and drop it into the shared drive for the auditor. That used to be a scramble.”
Common questions from Canadian companies pursuing SOC 2 attestation. If yours isn't here, ask us directly — we'll answer in writing.
From a cold start with no formal controls, 6 to 8 months to readiness, then a 3 to 12 month observation window your auditor picks. A Series A with reasonable engineering hygiene can compress readiness to 4 months.
Type 1 is useful when a specific deal is time-critical and a Type 1 will unlock it. Otherwise skip Type 1 — buyers increasingly ask for Type 2 anyway, and the readiness work is identical for either report.
We work with several CPA firms that audit SaaS at your scale. We introduce you and step back — the audit relationship is yours, we're not part of the auditor's team. Independence matters and we respect it.
Scope is defined by the system description you and the auditor agree on. Usually it's the product plus its supporting infrastructure and the teams operating it. We help you draw the boundary in a way that's defensible and doesn't overreach into functions you don't need attested.
Yes — this is our most common shape. SOC 2 is a US-originated attestation, but the audit is done by a Canadian or US CPA firm and the report is universally recognised. Cross-border data flows are handled in the system description and privacy controls.
Annual auditor fees plus our maintenance retainer, which covers continuous evidence collection, quarterly control reviews, and readiness for the next observation window. Renewal is materially cheaper than the first year.
We use best-of-breed GRC tools where the ROI is clear — Drata, Vanta, or similar — and skip them when a shared drive and clean checklists are more efficient. Recommendation is based on your team size and audit cadence, not on kickbacks.
GRC tools automate evidence collection — they don't design the controls, don't run the security operations behind those controls, and don't argue with your auditor on a Friday afternoon. We do all three. Tooling is an accelerant, not a substitute.
Tell us the trust services criteria in scope, the audit firm (if any) already engaged, and the deadline. We'll come back with a scoped readiness plan — not a sales sequence.
22 Frederick Street, Suite 700, Kitchener ON N2H 6M6 · +1 (647) 476-5259 · Mon-Fri 8am-6pm, managed clients 24/7.
We reply within one business day. We do not share your data.