Privacy & security assessments
What privacy and security assessments are required before selling to government?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
Selling to government in Canada centres on a Privacy Impact Assessment (PIA), which public bodies are legally required to complete before launching a system that handles personal information, and a Threat and Risk Assessment (TRA), routinely required for systems that touch government data. Buyers also commonly expect a recognized security attestation such as SOC 2 or ISO 27001, a recent penetration test, and evidence of data residency, access controls, and incident response. Exact requirements depend on the jurisdiction, data sensitivity, and procurement.
On this page
- What assessments does a government buyer expect from a vendor?
- Why is a Privacy Impact Assessment required to sell to government?
- What does a Threat and Risk Assessment (TRA) cover, and how is it different from a PIA?
- Do you also need SOC 2, ISO 27001, or a penetration test?
- How much do these assessments cost and how long do they take?
- Frequently asked questions
What assessments does a government buyer expect from a vendor?
Government buyers expect vendors to support two assessments the public body must complete — a Privacy Impact Assessment (PIA) and a Threat and Risk Assessment (TRA) — and to back them with independent evidence that your security controls work. The PIA and TRA belong to the institution, but you supply most of the inputs, so in practice they become a shared requirement that can stall a contract if you are unprepared.
Beyond those two, procurements increasingly ask for a recognized security attestation, recent technical testing, and clear answers on where data lives and who can access it. The precise list is set by the procurement documents and the sensitivity of the information involved, so always read the requirements for the specific opportunity rather than assuming a generic checklist.
- Privacy Impact Assessment (PIA) — the public body assesses how your solution affects individuals' privacy before launch; you provide data flows, retention, and safeguards.
- Threat and Risk Assessment (TRA) — a structured evaluation of threats to the system and the controls that reduce them, frequently required for any system touching government data.
- Security attestation — a SOC 2 report (Type II preferred) or ISO 27001 certification proving an independent party reviewed your controls.
- Penetration test — a recent, independent test of the application and infrastructure exposed to the buyer.
- Data residency and access evidence — where personal information is stored and processed, and who can reach it.
- Incident response and breach notification capability — a documented, tested plan and contractual notification commitments.
Why is a Privacy Impact Assessment required to sell to government?
A Privacy Impact Assessment is central because Canadian public bodies are legally bound to complete one before a program or system uses personal information to make decisions about individuals or undergoes a major change. The Office of the Privacy Commissioner of Canada describes a PIA as "a risk management process that helps institutions ensure they meet legislative requirements and identify the impacts their programs and activities will have on individuals' privacy." At the federal level, the Treasury Board Standard requires PIAs in those circumstances; the Canada Revenue Agency conducts them under the Treasury Board Directive on Privacy Impact Assessment; and in British Columbia, FOIPPA (s.69) makes PIAs mandatory for public bodies, to be completed during development and before launch.
Importantly, the OPC "does not approve, endorse or sign off on PIA reports" — the institution owns the assessment and its risk decisions. As a private-sector vendor you are generally not bound by these public-sector mandates yourself, but you cannot be onboarded until the buyer's PIA is complete, and that PIA depends almost entirely on information only you can provide: what personal data you collect, how it flows, where it is retained, how it is disposed of, and what safeguards protect it. Preparing this material in advance is the single biggest factor in how quickly a government contract can move forward.
What does a Threat and Risk Assessment (TRA) cover, and how is it different from a PIA?
A TRA covers the security side of the picture: it identifies threats to the system and its data, evaluates the likelihood and impact of those threats, and documents the controls that bring residual risk to an acceptable level. Where a PIA asks "how does this affect individuals' privacy?", a TRA asks "how could this system be compromised, and are the safeguards sufficient?" Government programs frequently require a TRA for any solution that processes or stores their information, and the two assessments are complementary — a PIA may identify a privacy risk such as over-retention that a TRA then addresses with a specific technical or procedural control.
A solid TRA examines your architecture, hosting and data residency, identity and access management, encryption in transit and at rest, logging and monitoring, vulnerability management, and your supply chain. Findings are tied to remediation owners and timelines so the buyer can see that known risks are managed rather than ignored. Because a TRA maps directly to the evidence a buyer's security team wants, completing one early tends to surface gaps while you still have time to fix them.
Do you also need SOC 2, ISO 27001, or a penetration test?
In most cases, yes. Government and broader-public-sector buyers increasingly treat an independent security attestation and a recent penetration test as table stakes, even when they are not named in legislation. A SOC 2 Type II report or an ISO 27001 certificate lets a buyer's security team rely on an external auditor's review instead of re-verifying every control themselves, which shortens their risk-acceptance process. A penetration test performed by a qualified third party within the last 12 months demonstrates that your application and infrastructure stand up to real-world attack techniques.
These are not interchangeable. SOC 2 reports on whether your controls are suitably designed (Type I) and operating effectively over a period (Type II) against the trust-services criteria you select; ISO 27001 certifies that you operate a defined information security management system. A penetration test is a point-in-time technical examination, not a certification. Many vendors pursue a combination — for example, SOC 2 Type II plus an annual pen test — because together they answer most of what a government security questionnaire asks.
- SOC 2 Type II — ongoing evidence that controls operate effectively over a period; often the strongest single attestation for North American buyers.
- ISO 27001 — internationally recognized certification of a managed information security program; frequently expected by buyers with global or interprovincial scope.
- Penetration test — independent, recent (typically within 12 months) testing of your live application and infrastructure.
- Supporting evidence — policies, access reviews, data flow diagrams, and a tested incident response plan to satisfy the questionnaire.
How much do these assessments cost and how long do they take?
Costs and timelines vary widely and depend on scope rather than a fixed price, so be cautious of any quote given before your scope is understood. The main drivers are the number of systems and integrations in scope, the sensitivity of the data, how mature your existing documentation and controls already are, and whether you are paying only for advisory and readiness work or also for third-party audit-firm or testing fees. A SOC 2 engagement, for example, separates internal readiness effort from the independent audit firm's fee, and a Type II costs more than a Type I because it observes controls over a monitoring period.
A realistic sequence is to complete or refresh your PIA inputs and TRA early, close the gaps they reveal, then pursue the attestation and pen test the specific procurement requires. Privacy Horizon publishes two fixed-price entry points — Minimum Viable Privacy (MVP) at CAD $5,499/year and the Virtual Privacy Officer (VPO) starting at CAD $2,200/month — while PIA, TRA, SOC 2, ISO 27001, and penetration-testing engagements are scoped to your environment. For a tailored estimate and a realistic timeline, book a consultation so the work can be sized to the opportunity you are pursuing.
Frequently asked questions
The public body is legally responsible for completing and owning the Privacy Impact Assessment, and the Office of the Privacy Commissioner does not approve or sign off on it. As the vendor, you supply the inputs the assessment relies on — data flows, retention, disposal, and safeguards — so the buyer cannot finish the PIA without your cooperation.
The PIA mandate binds the government institution, not your company directly, so you are not the legal author of record. In practice, however, you cannot be onboarded until the buyer's PIA is complete, and that PIA depends on information only you can provide, making your participation effectively mandatory.
Neither is universally required — read the specific procurement. SOC 2 Type II is often the strongest single attestation for North American buyers, while ISO 27001 carries more weight with buyers operating across multiple jurisdictions. Some vendors hold both, but starting with the one named in your target opportunities is the most efficient approach.
Most government and enterprise reviewers expect an independent penetration test conducted within the last 12 months against your live application and infrastructure. Tests older than a year, or that exclude the systems the buyer will use, are commonly rejected, so schedule testing to stay current with your sales cycle.
Prepare your PIA inputs and complete a TRA early, then remediate the gaps they expose before you pursue an attestation or pen test. Having data flow diagrams, access controls, retention schedules, and a tested incident response plan documented in advance lets you respond to procurement requirements in days rather than scrambling mid-bid.
Keep exploring
All Privacy & security assessmentsPIA vs TRA: which assessment do you need (or do you need both)?
PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.
ReadSOC 2 & ISO 27001SOC 2 vs ISO 27001 — which should we pursue first?
SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadSOC 2 & ISO 27001What is SOC 2, and does my business need it?
SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one.
ReadPrivacy & security assessmentsWhat's involved in a Privacy Impact Assessment: inputs, timeline, and cost?
What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.
ReadPrivacy & security assessmentsWhen should you do a Privacy Impact Assessment in the product development lifecycle?
When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes.
Read