Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

ISO 27001 for Montreal Startups

Montreal startups need ISO 27001 certification when their buyers, usually enterprise, European, or public-sector customers, require independently audited proof of an information security management system before they will sign a contract. For most Montreal founders, the trigger is a specific deal on the table, not a general sense that security matters.

Why Montreal Founders Keep Getting Asked for ISO 27001

Montreal's startup base skews toward sectors where security certification is table stakes rather than a nice-to-have: AI and machine learning, fintech, gaming, and enterprise SaaS spun out of the city's strong engineering schools. Companies growing out of the Mile End and Plateau tech corridor, or scaling through accelerators tied to McGill and Concordia, tend to land customers in Europe and the United States well before they have the internal security maturity those customers expect.

ISO 27001 comes up specifically, rather than SOC 2, for a few recurring reasons in this market:

  • European buyers and partners default to ISO 27001 because it is the globally recognized standard under ISO, not a US-centric attestation framework.
  • Public sector and government-adjacent procurement in Quebec often references ISO 27001 or maps directly to it.
  • Multinational enterprise customers with existing ISO-certified vendor programs will only add suppliers that hold the same certification.

Founders who assume SOC 2 covers every deal get an unpleasant surprise when a European or public sector prospect asks for an ISO 27001 certificate specifically, not an attestation report.

ISO 27001 and Quebec Law 25: Two Different Obligations That Overlap

Montreal companies carry a compliance layer that founders in Toronto or Vancouver do not: Quebec's Law 25 (formerly Bill 64), which sets mandatory privacy obligations for any organization handling personal information of Quebec residents. Law 25 is not optional and applies regardless of whether a company pursues ISO 27001.

The two frameworks are not the same thing, but they reinforce each other well. ISO 27001's Annex A controls around access management, data classification, incident response, and vendor risk give a company most of the operational backbone Law 25 expects for protecting personal information. Building the ISO 27001 management system first, then layering Law 25-specific requirements (privacy impact assessments, incident notification timelines, consent management) on top, is more efficient than treating them as two unrelated projects. Companies that try to bolt Law 25 compliance onto a security program with no ISMS underneath usually end up redoing the access control and logging work twice.

What ISO 27001 Certification Actually Requires

ISO 27001 certifies an organization's information security management system (ISMS), not a single product or a point-in-time checklist. A certification body audits the ISMS against the standard's clauses and the Annex A control set, then issues a certificate that is typically valid for three years with annual surveillance audits.

For a Montreal startup, the practical work usually breaks into these stages:

  • Scoping the ISMS to the systems, data, and business units that matter to your buyers.
  • Running a risk assessment and building a Statement of Applicability against Annex A controls.
  • Writing and operationalizing policies, not just documenting them for a binder nobody reads.
  • Collecting evidence of the controls operating over time, since auditors want proof, not intent.
  • Passing a two-stage external audit with an accredited certification body.

Founders consistently underestimate the evidence-collection stage. A policy that exists on paper but isn't followed operationally is a guaranteed nonconformity at audit. Our ISO 27001 implementation service is built specifically to close that gap, taking a startup from initial risk assessment through certification-ready evidence without the multi-year timelines that larger consultancies default to.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept. ISO 27001 readiness

Why a Canadian Boutique Beats a Remote-Only Provider

Most ISO 27001 consultancies serving the Montreal market operate entirely remotely, often out of the US or overseas, with no working knowledge of Quebec's regulatory environment or the specific procurement expectations of Canadian and Quebec public sector buyers. That gap shows up in two ways: generic policy templates that ignore Law 25 obligations, and advisors who can't speak to how Quebec's privacy regulator, the Commission d'accès à l'information, actually enforces its rules.

traztech serves Montreal companies directly as a Canadian firm, not as a reseller of an offshore audit mill. Jacob Masse, who leads our engagements, is a published security researcher with five CVEs to his name, including a CVSS 9.1 finding that functioned as a kill-switch for the Mirai botnet. That background means the security work behind your ISMS is grounded in how attackers actually operate, not just checkbox compliance.

We also work across the rest of Canada's tech hubs, so Montreal clients scaling into Toronto, Ottawa, Waterloo, Calgary, or Vancouver get one advisor who understands the whole Canadian regulatory landscape rather than a patchwork of regional specialists.

Timeline: How Long ISO 27001 Takes a Montreal Startup

A startup with reasonably organized engineering practices and founder buy-in can typically move from kickoff to certificate in four to six months. That includes:

  • Two to four weeks for scoping and gap assessment.
  • Six to ten weeks building out policies, controls, and the Statement of Applicability.
  • Four to eight weeks of evidence collection, since auditors want to see controls operating, not just documented.
  • A stage 1 and stage 2 audit with your chosen certification body, usually spaced a few weeks apart.

Startups racing a signed deal with a hard deadline can compress parts of this, but evidence collection is the one stage that resists shortcuts. An auditor cannot certify controls that haven't had time to run.

Building ISO 27001 Alongside a Broader Compliance Program

Founders who treat ISO 27001 as an isolated project often rebuild the same work later for SOC 2, a customer security questionnaire, or a Law 25 privacy audit. It's more efficient to think of ISO 27001 as the foundation of a company's ongoing compliance program rather than a one-time certificate to hang on the wall. The same risk register, access reviews, and incident response process that satisfy ISO 27001 auditors will carry most of the weight for whatever framework a customer asks for next.

Getting Started

If a Montreal enterprise deal, a European contract, or a public sector RFP is waiting on ISO 27001 certification, the sooner the ISMS work starts, the sooner that deal closes. Contact traztech to scope your ISO 27001 timeline with a Canadian team that already understands Quebec's regulatory context and won't hand you off to an offshore audit factory.

Choosing a certification body, and why accreditation matters more than price

The consultant who helps you build the ISMS cannot be the body that certifies it. That separation is the point of the standard, and it means Montreal founders make two separate purchasing decisions. The second one, the certification body, is where a cheap choice does real damage.

A certificate is only worth what the accreditation behind it is worth. Ask any certification body which accreditation board they hold, and expect an answer like the Standards Council of Canada, ANAB in the United States, or UKAS in the United Kingdom. Certificates issued by bodies with no recognized accreditation are sold, and they are cheap, and enterprise procurement teams increasingly check. A European buyer's vendor risk team will look up the accreditation mark on the certificate. If it resolves to nothing, you have paid for a document that fails the exact review it was meant to pass, and you get to redo the whole audit with a real body while the deal sits open.

Beyond accreditation, the questions worth asking during selection are practical. What is the lead time from signed engagement letter to Stage 1, because in busy quarters that alone can be eight to twelve weeks and it will drive your whole schedule. Do they have auditors who work in French, which matters if your policies and records are maintained in French for Quebec operations. What is the day rate and how many audit days do they estimate for your headcount and scope, since certification body pricing is structured around auditor days rather than a flat fee. And what does the three-year cycle cost in total, not just the initial audit, because the surveillance visits in years one and two and the recertification in year three are where the ongoing budget lives.

Stage 1 and Stage 2 are different audits with different failure modes

Founders often hear "two-stage audit" and picture one long assessment split across two visits. They are testing different things.

Stage 1 is a documentation and readiness review. The auditor is checking that your ISMS exists as a system: that you have a defined scope, a risk assessment methodology, a completed risk assessment, a Statement of Applicability with justifications, the mandatory documented information required by clauses 4 through 10, and evidence that internal audit and management review are planned. Stage 1 rarely produces a pass or fail. It produces a list of observations and a judgement on whether you are ready for Stage 2. The common Stage 1 outcome for an unprepared startup is a recommendation to delay Stage 2 by six to eight weeks, which is a schedule problem rather than a certification problem, but it will still blow a deal deadline.

Stage 2 is where the auditor tests whether the controls actually operate. They will sample. Give me the last three access reviews. Show me the offboarding record for these two people who left. Walk me through this change from ticket to deploy to approval. Show me the risk register entry for this Annex A control you marked applicable and the treatment decision behind it. Stage 2 findings are graded, and the grading is what determines your timeline.

A minor nonconformity is an isolated lapse in an otherwise functioning control. You submit a corrective action plan, usually within thirty days, and the auditor accepts it on paper. Certification proceeds. A major nonconformity means a control is absent or systemically failing, or a clause requirement has not been met at all. That requires evidence of correction before the certificate issues, often with a follow-up visit, and it typically costs six to twelve weeks.

The two majors we see most often in first-time startup audits are the same two every time. No internal audit has been performed, because the team read clause 9.2 and assumed it meant the external audit. And no management review has happened, because clause 9.3 asks for a documented leadership review of the ISMS covering specific inputs, and nobody scheduled the meeting or wrote the minutes. Both are entirely avoidable, both take a day of work each, and both are treated as majors because they are clause requirements rather than control preferences.

The Statement of Applicability is the document that gets audited hardest

The Statement of Applicability lists all 93 Annex A controls, records whether each is applicable to your ISMS, and justifies both the inclusions and the exclusions. It is the single document an auditor spends the most time on, because it is the map between the standard and your specific organization.

Two failure patterns dominate. The first is marking everything applicable to look thorough, which commits you to producing evidence for controls you do not actually operate. If you have no physical office and no data centre, some of the physical controls genuinely do not apply, and saying so with a clear justification is stronger than claiming a control you cannot evidence. The second is excluding a control with a one-line justification that does not hold. "Not applicable, we are cloud native" is not a justification for excluding supplier security controls when your entire product depends on suppliers. The justification has to trace back to your risk assessment, and the auditor will follow that trace.

The scope statement matters just as much, because it is the sentence printed on the certificate your buyer will read. A scope written too narrowly to make the audit easier produces a certificate that says something like "the development of the analytics module," which a procurement reviewer will immediately question. A scope written too broadly commits you to evidencing controls across business functions you never intended to include. Write it to cover the product and the operations behind it, name the locations, and read it back as if you were the buyer's vendor risk analyst.

Working in French, and the documentation question nobody raises early

Quebec companies have a language dimension that Toronto and Vancouver companies do not. If you operate in Quebec with employees here, the Charter of the French Language shapes what internal documentation and employment-related communication looks like, and Law 25 obligations sit on top of that. There is no ISO requirement to work in any particular language, but there is a very practical decision to make about which language your ISMS lives in.

Maintaining a single-language ISMS in French and appointing a certification body with French-speaking auditors is clean. Maintaining it in English is clean. Maintaining half of it in each, which is what happens by default when nobody decides, produces a mess at audit time: policies in English that reference procedures in French, awareness training records that do not match the policy version, and an auditor spending billable time reconciling documents. Pick one working language for the management system, translate the artifacts that genuinely need to be bilingual for employee-facing or regulator-facing reasons, and record the decision.

What certification actually costs a Montreal startup

The number founders quote each other is usually only the consultant fee. The real budget has four lines. Certification body fees for the initial two-stage audit, driven by auditor days, plus surveillance audits in years one and two and a full recertification in year three. Advisory support to build the ISMS, which for us starts from a fixed-scope gap analysis rather than an open hourly engagement. Tooling, which may be a compliance platform or may be a well-organized document repository and a ticket system you already pay for. And internal time, which is the line everyone omits and the largest one in practice, typically a few hours a week from a technical lead across four to six months plus concentrated effort during evidence collection.

The place to spend carefully is tooling. Compliance automation platforms are genuinely useful for evidence collection at scale, and they are frequently oversold to twelve-person companies who would be better served by a spreadsheet-driven risk register and a folder structure for six months. If you are considering one, price the three-year commitment, not the first-year promotional rate, and ask whether it supports the ISO clause requirements rather than just Annex A control mapping. The clause 4 through 10 management system work is what platforms handle least well and what auditors weight most heavily.

When ISO 27001 is the wrong purchase right now

Not every Montreal founder reading this should start. Three situations where the honest advice is to wait or do something else.

Your buyer asked for SOC 2 and you are pursuing ISO because it sounds more rigorous. Give the buyer what they asked for. A US enterprise procurement team with a SOC 2 requirement will not accept an ISO certificate without an exception process that costs weeks. Confirm the actual requirement in writing before choosing a framework. If both are eventually coming, our compliance practice can order them so the shared control work is done once, and the vendor risk program is one of the pieces that carries across cleanly.

You have one prospect who mentioned it in passing. A four to six month programme with real cost attached should be backed by a deal with a number on it, or by a pattern of buyers asking. One offhand mention in a discovery call is not a trigger. Ask the prospect directly whether certification is a contractual requirement or a preference, because the answer is often the latter and a well-run security questionnaire response plus a recent penetration test closes the same deal.

Your product is not built yet. Certifying an ISMS around a product that will be re-architected in six months means you will be updating the scope, the risk assessment, and the Statement of Applicability while the ink is drying. If you are pre-launch, spend the money on security engineering and testing instead, and certify once the architecture has settled. The controls you build now still count later, and none of the foundational work is wasted.

The version of this advice that costs us money is the most common one we give: if a single deal is the driver and the buyer will accept a readiness position rather than a certificate, say so and negotiate. We have taken $11,000 off one client's audit quote purely by presenting a documented readiness position that reduced the auditor's estimated days. That kind of conversation is cheaper than starting a programme you were not ready for.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.

ISO 27001 readinessOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.