Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Knowledge base

Privacy & Security Answers

Privacy & security, answered. Clear, expert-reviewed answers to the questions teams actually ask — from SOC 2 and PIAs to breach response and AI governance. Every answer links to the next, so one question leads naturally to the rest.

42 answers · 9 topics

Prefer something shorter? Browse our FAQs or talk to our team.

Browse answers by topic

42 answers

SOC 2 & ISO 27001

7 answers

How much does SOC 2 cost and how long does it take?

How much does SOC 2 cost and how long does it take? Learn the real cost drivers — readiness vs audit fees, scope, Type I vs Type II — and a realistic timeline.

Read

What documents and evidence do you need for a SOC 2 audit?

What documents and evidence do you need for a SOC 2 audit? A plain-language checklist of policies, system descriptions, and proof your controls operate.

Read

What are the most common gaps found in a SOC 2 readiness assessment?

The most common gaps found in a SOC 2 readiness assessment — missing policies, access controls, evidence, vendor reviews, and monitoring — and how to close them.

Read

Can you get ISO 27001 certified without an internal security team?

Can you get ISO 27001 certified without an internal security team? Yes. Learn what the standard requires, how to fill the gap, and what a vCISO does.

Read

What is SOC 2, and does my business need it?

SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one.

Read

What is the difference between SOC 2 Type I and Type II?

SOC 2 Type I assesses control design at a point in time; Type II tests operating effectiveness over months. Compare the two, plus typical timeline and cost drivers.

Read

SOC 2 vs ISO 27001 — which should we pursue first?

SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.

Read

Privacy & security assessments

7 answers

What's involved in a Privacy Impact Assessment: inputs, timeline, and cost?

What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.

Read

When should you do a Privacy Impact Assessment in the product development lifecycle?

When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes.

Read

Does a SaaS company need a PIA before selling to healthcare?

Does a SaaS company need a PIA before selling to healthcare? Usually yes - hospitals and clinics typically require one. Here's when, why, and what's involved.

Read

What privacy and security assessments are required before selling to government?

What privacy and security assessments are required before selling to government? A plain-language guide to PIAs, TRAs, SOC 2/ISO 27001, and pen tests in Canada.

Read

Do you need a TRA before moving sensitive data to a new cloud provider?

Do you need a TRA before moving sensitive data to a new cloud provider? When it's required, what it covers, and how it differs from a PIA — explained plainly.

Read

How much does a penetration test cost (and what affects the price)?

How much does a penetration test cost and what affects the price? Understand the scope, depth, and methodology factors that drive pen test pricing in Canada.

Read

PIA vs TRA: which assessment do you need (or do you need both)?

PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.

Read

Compliance & regulations

6 answers

Virtual Privacy Officer & vCISO

6 answers

AI privacy & governance

4 answers

Cybersecurity basics

4 answers

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.