Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Case Study: Why the Auditor You Pick Changes What the Audit Costs

The client asked us to find their auditor. It is a common request and it is worth explaining why the answer is not simply the cheapest quote.

The introduction is part of the work

We shortlisted four firms and ran the same package past each of them. The one we landed on is both a licensed CPA firm and an accredited certification body, so a single organisation performs the SOC 2 attestation and the ISO 27001 certification. That is one engagement letter, one evidence request process, one set of scheduling constraints and one relationship to manage instead of two running in parallel. They were engaged while remediation was still under way, with a weekly cadence set from the start.

The logistics saving is larger than it sounds. Two separate assessors means two sampling approaches, two views on what evidence is sufficient, and two calendars to reconcile against a single remediation plan. Where the same firm covers both, the overlap between the standards gets assessed once rather than argued twice, and the parts of your programme that serve both frameworks only have to satisfy one interpretation.

That timing is deliberate, and it is covered in more detail in the dual-framework case study. The short version is that scope, sampling and what counts as sufficient evidence are all things you discuss with an auditor rather than receive from one. A team that first speaks to its auditor when it believes it is ready has given that conversation away, and generally finds out during fieldwork that an artefact it spent three weeks producing is not the artefact that was wanted.

There is a structural reason this matters more than people expect, and it shapes everything else here.

Your auditor is not allowed to help you

An audit firm has to remain independent of what it assesses. That means it cannot design your controls, write your policies, build your evidence register or tell you how to fix a gap in any detail that amounts to doing the work. If it did, it would be auditing its own output, and the opinion would be worth nothing.

Companies routinely misread this as unhelpfulness. It is not. It is the constraint that makes the report mean something.

The practical consequence is that there is a gap between "your control will not pass" and "here is a control that will", and somebody has to stand in it. Either you do, with whatever internal capacity you have, or you bring in a firm that is not issuing the opinion and therefore has no independence constraint. That is the role we occupy, and it is why the prep firm and the audit firm are two different organisations rather than an upsell.

What we are actually checking when we vet a firm

Price is one input and rarely the deciding one.

Sector familiarity. An auditor who has done a dozen infrastructure or health engagements asks better questions and wastes less of your time on ones that do not apply. An auditor learning your sector at your expense is a slower audit, and slower is more expensive regardless of the rate.

How they handle evidence. Some firms accept a well-organised register and sample from it. Others insist on their own portal and their own naming convention, which means somebody on your side re-files everything. That cost is real and it never appears in the quote.

Responsiveness. The gap between a question and an answer sets the pace of the entire engagement. A firm that takes a week to come back adds weeks to the timeline whatever the proposal says about duration. This is the single most reliable predictor of whether an audit finishes when it was supposed to.

Willingness to talk before fieldwork. Firms differ on this more than on anything else. Some will discuss scope and sampling openly during preparation, staying comfortably inside their independence obligations. Others treat any question as a request for an opinion they cannot give. The first kind produces a far better outcome for a first-time candidate.

Whether they will say no. An auditor who agrees to everything is not being helpful. You want the one who says a control as designed will not survive sampling, while there is still time to change it.

Capacity and timing. Audit firms have busy periods, and a firm that is at capacity will still take the work and then schedule fieldwork months out. Ask when they can actually start, not whether they can take you.

Licensing and peer review. For a SOC 2, the firm must be a licensed CPA firm and should be able to show a current peer review. For ISO, the certification body should be accredited by a recognised accreditation body. Both are quick to check and occasionally surprising.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

Why a prepared package changes the price

Audit fees are driven substantially by hours, and hours are driven by how much work the firm has to do to get what it needs.

An auditor arriving to a defined scope, a written system description, a populated evidence register and named control owners is doing a different job to one arriving at a company that has not started. The second engagement involves chasing artefacts, explaining what is needed, re-requesting things that came back in the wrong form, and repeating that loop across dozens of controls. All of it is billable.

Firms that price on effort reflect this, and in our experience they will discuss it openly when readiness is demonstrable rather than promised. It is not a discount in the coupon sense. It is a smaller number because there is genuinely less work in it, and a firm quoting honestly will say so.

On this engagement that came to $11,000 off a five-figure quote, across both frameworks. Not negotiated down, and not a gesture. The firm revised its number once we had set out the client's readiness position and confirmed that a prep firm was running the programme.

The mechanism is worth understanding, because it is repeatable rather than lucky. An auditor pricing an unprepared company is estimating a long tail of unknowns: how many artefacts will come back in the wrong form, how many rounds of clarification each control will take, how much of the system description they will end up writing questions about. That uncertainty has to be priced, and it gets priced conservatively, because the firm carries the risk if the estimate is wrong.

Take the uncertainty away and the estimate changes. When the evidence register exists, the control owners are named, the scope is written down and somebody on the client side speaks the auditor's language, the firm can price the work it can actually see. Many are glad to pass that back, because a smooth engagement is worth more to them than a padded one: it finishes on schedule, it does not consume partner time on chasing, and it is the kind of client they want again next year.

Set against the cost of the preparation itself, that single line covered a meaningful share of it before counting anything else the programme produced.

The corollary matters more. A company that goes to audit unprepared frequently pays more than the original quote, because the effort was underestimated when it was priced. Scope creep on an audit is not the firm being opportunistic. It is the estimate meeting reality.

The questions worth asking before you sign

Five that reliably separate firms:

What is your sampling approach for a period of this length, and how many instances will you want per control? How do you want evidence delivered, and will you accept our register? Who is actually on the engagement, and are they the people in this meeting? When can fieldwork start, not when can you take us? What have you seen go wrong most often with companies our size?

The last one is the most revealing. A firm with a good answer has been paying attention across their book. A firm without one has not.

What the client got out of it

Two firms engaged early, both aware of the scope before fieldwork, both working from an evidence register whose shape they had already seen. The timeline was set with their input rather than against their availability, which is the difference between a date you chose and a date you were given.

If you are at the point of choosing, our cost breakdowns covers what the work runs to, why quotes differ covers why quotes for the same scope differ so much, and auditor management and advocacy covers what we do when we sit between you and the firm.

Note. The client is unnamed. Figures are described by what drives them rather than quoted, because audit pricing is specific to scope and we will not publish another firm's numbers.

Red flags in a proposal

Vetting is mostly about what a firm does well. A few things are worth treating as disqualifying regardless of everything else.

A guaranteed opinion. Any firm that tells you the report will be clean before it has looked at anything is either not planning to test properly or does not understand what it is selling. The opinion is the product. A firm that pre-commits to it has told you the product is decorative.

Selling you the readiness too. A firm offering to prepare you and then attest to your preparation is offering a report a sophisticated buyer will discount, and it puts the practitioner's independence in question under the standards they are bound by. Some structure this as separate entities under one brand. Ask whether the same partner group owns both.

The tooling tie. Several firms will only audit clients on a specific compliance platform and take a referral fee for putting you there. The platform may be a fine choice; the problem is that you cannot tell whether it was recommended because it fits you. Ask whether they receive consideration for the referral.

A fixed fee with no scope table. A quote that is one number with no statement of which trust services criteria, which systems, which locations, what period length and how many samples is a quote that will change. Insist on the scope table before you sign, because that table is what you will be arguing about in month four otherwise.

No named engagement team. Partners sell, and junior staff doing the daily work is normal. Refusing to say who is not. Ask for names, ask how many engagements each is running in your window, and ask who reviews their work.

The system description is your document, not theirs

For a SOC 2, the description of the system is written by management and the practitioner opines on whether it is fairly presented. First-time candidates consistently assume the audit firm writes it, discover in week two that it does not, and then produce something in a hurry that causes trouble for the rest of the engagement.

The description covers your services, the supporting infrastructure and software, the people and procedures, the boundaries of the system, your principal service commitments, the controls, and the complementary user entity controls. Two parts do real damage when written casually.

The boundary is the first. Everything inside it gets tested. A description that sweeps in your entire corporate estate because it was easier to write that way has just committed you to evidencing controls over systems nobody intended to include. The second is the service commitments section. Whatever availability, confidentiality or processing commitments you write there become the yardstick your controls are measured against, in exactly the way an overreaching policy commitment does. Write what you actually commit to contractually, not what sounds impressive.

The complementary user entity controls section matters for a different reason. It states on the record what your own customers must do for your controls to work, and your buyers read it. Write it as something you would defend in a security review, because you will.

How sampling actually works, and what happens when one fails

Most disputes in an audit are sampling disputes, and they are avoidable by discussing method before fieldwork rather than after.

The firm establishes a population for each control, agrees it is complete, then selects a sample. Sizes scale with frequency: an annual control might be tested once, a quarterly one at all four, a continuous control at 25 to 40 depending on the firm's methodology. Populations are the fight worth having early. If the firm believes your change population is every merge to main and you believed it was every production deployment, the evidence burden differs by an order of magnitude.

When a sampled item fails, the firm does not automatically write an exception. A common route is to expand the sample and see whether the failure is isolated or representative. If the expanded sample fails too, you have a deviation rate rather than a one-off, and it will be described that way.

What you can do about it depends on where you are in the period. A failure found in month two of a twelve month window can be remediated, and the report can describe a control strengthened partway through. A failure found during fieldwork after the period closed cannot be fixed retroactively, and producing evidence dated inside the period after the fact is a far worse problem than the original failure. This is the strongest argument for engaging the audit firm early, and it has nothing to do with fees.

An exception in the report is not a failure

Teams treat exceptions as catastrophic and buyers largely do not. A Type II report describes what the practitioner tested and found, with exceptions listed alongside management's response. The opinion changes only if the problems are pervasive, and a qualified opinion is genuinely serious. A clean opinion with three described exceptions is what most real reports look like.

What buyers assess is the shape of the exceptions and the quality of the response. Two terminated users retained access for eleven days, caught by the quarterly review, remediated within a day, with a change to the offboarding checklist attached, reads as a company that noticed and fixed something. The same finding answered with a note calling it isolated and requiring no action reads as a company that does not want to look at it. Write management responses as though your largest prospect will read them, because they will.

The honest corollary is that chasing a zero-exception first report is usually the wrong goal. It tends to produce a very narrow scope or a very short period, both of which sophisticated buyers spot immediately. A three month Type II covering the things that matter, with a couple of honest exceptions, is a better commercial artefact than a report scoped down until nothing could go wrong.

Changing auditors, and what it costs

Sometimes the vetting was wrong or the firm changed. The signals that it is time are consistent: fieldwork slipping without explanation, the named team turning over mid-engagement, fees moving repeatedly, or an inability to get a straight answer on scope.

Understand what you are paying to move. A new firm inherits nothing, will want to see the previous report, and will form its own view on your population definitions. Switch between periods and you can leave a coverage gap between the end of one report and the start of the next, which buyers on annual renewals notice before they notice the reason. Time the change so the periods abut, and expect the first period with a new firm to run long.

Moving is sometimes right anyway. A firm that cannot finish is more expensive than a firm that charges more.

When you do not need a firm like ours

Preparation is a real service and there are companies that should not buy it.

If you have hired an experienced compliance or security lead who has taken a company through this before, you have bought the capability. Adding an outside prep firm on top produces two people writing the same evidence register in different formats, and the internal hire loses the ownership that made them worth hiring.

If the driver is one enterprise deal and nobody has asked when the report is needed, ask before you spend anything. A meaningful share of buyers will accept a completed questionnaire, a recent penetration test and a contractual commitment to certify by renewal. That converts a several-month blocker into a short one, and the preparation then happens on your calendar rather than the deal's.

If you are being sold readiness for a framework nobody has requested, stop. Choosing a framework because it was on the price list is how companies end up maintaining two programmes and using neither. Our view on which frameworks belong together is on the compliance side of the practice, and the fixed-scope work and what it costs is on pricing.

And if what you need is somebody to sit between you and the audit firm for the duration rather than a full preparation programme, that is a smaller and cheaper arrangement than most firms will offer unprompted. Ask for it by name. An ongoing retainer covering auditor management and the recurring controls often fits better than a project, particularly for a second or third period where the build work is done and what remains is keeping it running.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.