Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Compliance Software for Small Business

Direct answer: A small business usually needs three things: somewhere to record which controls apply and whether they are in place, somewhere to keep policies with approval and acknowledgement history, and somewhere to hold evidence with dates. All three are available free. Paid platforms add continuous automated evidence collection, which earns its cost once you are maintaining a report across years rather than getting a first one.

What a small team actually needs

NeedWhy it mattersFree?
Control library and self-assessmentYou cannot plan what you have not scopedYes
Policy set with approval historyAuditors sample the approval and the acknowledgement rosterYes
Evidence register with datesUndated evidence is close to uselessYes
Risk registerRequired outright by ISO 27001, expected by SOC 2Yes
Vendor records with the reports attachedTheir SOC 2 becomes your problem in an auditYes
Continuous automated evidenceSaves real hours on Type II maintenanceNo

Where the money actually goes

For a first SOC 2 the three buckets are the licensed CPA auditor, tooling, and the readiness work. The readiness work is usually the largest and the most often left out of the plan. Tooling is the smallest of the three, which is why choosing a platform first is the wrong order.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

A sensible sequence for a small team

  1. Find out which framework your buyer actually wants. Do not guess, ask them.
  2. Run the self-assessment free and get the real count of what is missing.
  3. Fix the cheap technical items yourself. MFA, logging, access reviews, backups.
  4. Decide whether the remainder is a people problem. If it is, get it scoped and priced.
  5. Buy tooling when recurring evidence collection is the bottleneck, not before.

The free option

traztech Workspace covers the first four items in the table: fourteen frameworks with every control in plain English, an evidence register that maps one artefact to every control needing it, a policy library with approval and acknowledgement tracking, a risk register, vendor records with the actual reports attached, and a security testing register. No card, no trial clock, no locked features. It does not do continuous automated evidence collection. We build it, so verify that for yourself rather than taking our word.

Frequently asked

Is free compliance software good enough for an audit?

The audit tests your controls and your evidence, not your tooling. Plenty of companies have passed with a document store and someone organised.

When should a small business buy a platform?

When manual evidence collection is genuinely costing more than the subscription, which usually means Type II maintenance rather than a first report.

What if we have no security person?

That is the normal case at this size. Somebody still has to own it. A fractional or part-time arrangement is the usual answer, and it is cheaper than a bad first audit.

What automated evidence collection actually collects

The paid tier of every compliance platform is sold on automation, and the word covers a narrower range of work than the demo implies. It is worth knowing exactly which of your evidence a platform can gather on its own, because that is the only part of the subscription you are really buying.

Platforms are good at things a read-only API can observe on a schedule: cloud configuration state, MFA enrolment across your identity provider, endpoint agent health, whether backups ran, whether encryption is on, open vulnerabilities from a connected scanner, and whether your list of employees in the HR system matches your list of accounts. These checks run daily, produce a timestamp automatically, and are exactly the evidence that is tedious to gather by hand across a twelve month observation window. That is a genuine saving and it is why Type II maintenance is the point where paying starts to make sense.

Platforms are poor at anything that involves judgement or a human artefact. Your risk assessment, your scope narrative, your system description, the reasoning behind an exception, a vendor review where somebody actually read the SOC 2 report, evidence that a change was approved by the right person for the right reason, board or management review minutes, and anything produced by a tool with no integration. In practice this is most of the work in a first report, which is why teams who buy a platform first are surprised at how much is still left.

The useful evaluation question is not how many integrations a vendor lists. It is which of your systems they connect to and what specifically they read from each. Ask for the field-level detail for your three most important systems before you sign. A vendor that connects to your cloud provider but not to the ticketing tool where all your change approvals live will automate a smaller share of your evidence than the marketing suggests.

The spreadsheet is fine until three specific things break

Running this on documents and a spreadsheet is a legitimate choice and we have watched small teams get clean reports that way. It stops working for reasons that are predictable, so you can watch for them rather than guessing.

Nobody can tell which version is current. The moment there are two copies of the control matrix and an argument about which one the auditor was sent, the tracking has failed. This is usually the first break and it usually happens when a second person joins the effort.

Evidence loses its date. A screenshot in a folder called Q3 is not evidence that a review happened in Q3. Auditors will accept a spreadsheet, but they will not accept an artefact whose date cannot be established from the artefact itself. Once you are collecting recurring evidence across a window, the date discipline is what fails first.

The ownership map lives in one person's head. When the person who has been driving the effort takes two weeks off and nobody else can say which controls are outstanding, you have a single point of failure on the thing that is meant to demonstrate you do not have single points of failure.

Any of those three is a reason to move to a structured tool. None of them is a reason to move to a paid one, which is the distinction the market blurs.

How to evaluate a platform demo without being sold to

Compliance platform demos are unusually well rehearsed. Four requests will tell you more than an hour of the standard walkthrough.

Ask them to connect to your actual environment on a trial rather than showing you their reference tenant. The gap between what the integration reads in a clean demo account and what it reads in a real company with legacy naming conventions is where the disappointment lives.

Ask what happens to a control that has no integration. Watch how manual evidence gets attached, dated, and re-requested next quarter, because that workflow is where most of your team's time will actually go.

Ask how you get everything out. Request a sample export of the evidence set, the policies with their approval history, and the control mapping, in a format that is usable without the product. A vendor that can only export a PDF summary has designed for retention rather than for you.

Ask what the renewal price is. Compliance tooling is commonly discounted heavily in year one against a list price that reappears at renewal, once your evidence history is inside the product and moving is painful. Get year two and year three pricing in writing before signing year one.

Lock-in is the cost nobody prices

The switching cost of a compliance platform is not the migration of documents. It is the history. Your second Type II report covers a window, and if the evidence for the first half of that window sits in a product you have left, you are reconstructing rather than exporting. This is why the practical time to change platforms is immediately after a report is issued and never mid-window.

Two habits reduce the exposure cheaply. Keep policies in a source you control, with the platform holding a copy rather than the original. And export the evidence register quarterly to your own storage as a matter of routine, so that leaving is a decision rather than a project. Neither costs anything and both are worth doing from the first week, including if you are using a free tool such as our own Workspace. We would rather you could walk away from it.

Where the platform does not help at all: the auditor relationship

A recurring assumption in the small business market is that buying the tool the auditor recommends will make the audit go faster. Partly true, and it hides the larger effect. What moves auditor effort, and therefore auditor cost, is how well defined your position is when the fieldwork starts: a settled scope, a control set that matches your actual environment, evidence that is dated and complete, and a written explanation for anything unusual.

That work is not a software feature. It is somebody sitting down and doing it. On one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which we wrote up in the auditor vetting case study. The lesson small teams should take from it is about ordering rather than about the number. Preparation changes what the audit costs. Tooling mostly changes what the preparation feels like.

It is also worth knowing that auditors do not certify tools. Some firms have preferred platforms because their staff know where to click, and that familiarity can shave a little fieldwork time. None of them will accept a platform's internal pass or fail marker as evidence in place of the underlying artefact. If a vendor implies that their green ticks are the evidence, that is a misunderstanding of what the auditor's job is.

Do not overlook the security of the compliance tool itself

A compliance platform holds an unusual concentration of sensitive material: your architecture, your gaps, your risk register, your open findings, and read access into your identity provider and cloud account. It is a high-value target and it should go through your own vendor review rather than being waved through because it is a security product.

Ask for their own report, look at the permissions the integration requests rather than accepting the default install, and check whether the access is read-only. Then put the platform into your own access review, because the accounts created during an implementation project have a habit of outliving the people who created them.

When you should not buy any of this

Several situations that look like a tooling problem are not one, and buying software will make them worse by producing activity.

If nobody has asked you for a report yet, do not buy a platform in anticipation. Frameworks and scopes change with the buyer, and an annual subscription bought before you know which framework you need is money committed to a guess.

If you have fewer than about twenty employees, one cloud account, and no dedicated person, the honest configuration is free tooling plus a few days of expert time to define the scope and the control set correctly. The failure mode at this size is not disorganisation, it is scoping the wrong thing thoroughly.

If your real bottleneck is that nobody owns the work, a platform will not fix it. It will send reminders to a person who is already not doing the task, and you will renew a subscription against a half-finished implementation. Fix ownership first, with a part-time internal owner or a fractional arrangement, and buy the tool once there is somebody to operate it.

And if you are getting a first Type I report, the automation you are paying for barely applies, because there is no observation window to collect across. Get the report, then decide about tooling with a year of real evidence load to reason from. If you want a straight answer about which of these describes you, our compliance work starts with scoping precisely that, and the starting prices are published so you can compare it against a subscription before committing to either.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.