Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

A Compliance Calendar That Reflects What Actually Recurs

Direct answer: Roughly fifteen things recur in a mature compliance programme, and each one is only useful if it produces a dated artefact with a named owner. Monthly items are access and vulnerability work. Quarterly items are reviews: vendors, policies, risk. Annual items are the expensive ones: penetration test, training, recovery testing, risk assessment refresh, and the audit itself. A calendar without owners and artefacts is a list of intentions.

Why most compliance calendars fail

The usual version is a spreadsheet with dates, built during readiness, never opened again. It fails for a specific reason: it records when something is due but not who does it, what it produces, or where that artefact goes. When the date arrives, nobody is accountable and there is nothing to file, so the entry gets moved rather than done.

A calendar entry that works has four parts. What the activity is, who owns it by name, what artefact it produces, and which controls that artefact evidences. The last part is what turns a chore into evidence.

Monthly

Access review of privileged systems. Not every system every month, but production, cloud console and identity provider are worth a monthly pass at most companies, with the full review quarterly. Produces: a dated record naming the reviewer, the accounts examined, and what changed.

Joiner and leaver evidence. Produced per event rather than on a schedule, but reviewed monthly to catch anything missed. Produces: provisioning and deprovisioning records with timestamps.

Vulnerability scan triage. The scan may be continuous. The triage is the control. Produces: findings with severity, owner, and either a fix with a date or an accepted risk with a rationale.

Backup verification. Confirming backups completed is monthly. Confirming they restore is annual and different. Produces: backup job records with failures explained.

Quarterly

Full user access review. Every system in scope, including the ones nobody thinks of, like the billing platform and the analytics tool with customer data in it. Produces: the review record, plus the tickets for revocations that came out of it.

Vendor and subprocessor review. Which vendors touch what data, tiered by that rather than by spend. Reports collected where the vendor claims one. Produces: an updated register with report expiry dates.

Policy review. Not every policy every quarter, but on a rotation so each is reviewed annually and the reviews are spread. Produces: version history and a re-approval record.

Risk register review. Owners confirmed, treatments progressed, new risks added from incidents and changes. Produces: an updated register showing movement rather than an identical copy of last quarter.

An exercise. A tabletop, a failover test, or a restore. Rotating the type across the year covers more ground than repeating one. Produces: an after-action record with what broke.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

Annual

Penetration test. Scoped to what customers ask about, with retesting of the findings. The retest is the part that turns a report into evidence of remediation. Produces: the report, the remediation record, and the retest.

Security awareness training. Everyone, with completion tracking, including the people who joined mid-year. Produces: completion records by person and date.

Risk assessment refresh. The full methodology, not the quarterly register review. Produces: the assessment document and whatever it changes in the register.

Business continuity and disaster recovery test. An actual restore into an actual environment. Produces: the test record, the recovery time achieved, and the gaps found.

Internal audit. Required for ISO 27001, and a good idea regardless. Produces: findings and corrective actions, which the certification body will look at.

Management review. Also an ISO requirement, and the one most often faked. Produces: minutes showing leadership actually considered the ISMS and made decisions.

The audit or surveillance cycle itself. Fieldwork, sampling, evidence requests, and the report. Produces: the report, and the exception list that becomes next year's first priority.

Framework-specific additions

ISO 27001 adds the internal audit and management review above, plus Statement of Applicability maintenance whenever scope changes. PCI DSS adds quarterly external scanning by an approved vendor and annual attestation. HIPAA and PHIPA add workforce training with specific content and a documented risk analysis. Quebec Law 25 and PIPEDA add privacy impact assessments triggered by projects rather than dates, which is why they get missed. CPCSC and CMMC add an annual affirmation that somebody senior has to sign.

Making it survive contact with a real year

Put the artefact, not the activity, in the calendar entry. "Q3 access review" is a task. "Q3 access review record filed against CC6.2 and A.5.18, owner Priya, due 30 September" is an obligation with a shape.

Schedule the annual items early in the cycle rather than late. A penetration test in month eleven leaves no room to remediate and retest before the period ends, and the finding you cannot close becomes an exception.

Review the calendar itself quarterly. Cadences drift as the company changes, and a calendar that no longer matches your system description is worse than none, because the description is what the auditor holds you to.

If nobody internally has the calendar as an actual job, it will slip, and it will slip invisibly. That is the specific gap an ongoing retainer exists to close: the cadence is operated on a schedule that is somebody's responsibility, and the artefacts land against the controls as they are produced.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.