Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

ISO 27001 for Ottawa Startups

Ottawa startups get asked for ISO 27001 earlier and more often than founders in most other Canadian cities, because their buyers are the federal government, defence primes, and enterprise vendors who treat the certification as a baseline procurement filter rather than a nice-to-have.

Why Ottawa Founders Hear "Do You Have ISO 27001?" So Early

Ottawa's startup ecosystem sits inside the orbit of one of the largest single buyers of technology in the country: the Government of Canada. Add in the defence and public-sector integrators clustered around Kanata North, the National Capital Region's dense concentration of federal departments, and the security-cleared talent pool that spun many of these companies out in the first place, and you get a market where procurement teams ask for ISO 27001 as a matter of course, not as an exception.

This is different from the SOC 2 conversation that dominates in Toronto or Waterloo, where the pressure usually comes from US enterprise buyers and their vendor security questionnaires. In Ottawa, the pressure often comes from Canadian public-sector and defence-adjacent procurement, where ISO 27001 is either an explicit requirement in the RFP or an unwritten expectation that separates shortlisted vendors from the rest. Founders selling into GC departments, Crown corporations, or the primes that service them (Ottawa is home to a dense defence and aerospace supply chain) will hit this wall whether they are ready for it or not.

ISO 27001 vs. SOC 2: Which One Does an Ottawa Company Actually Need?

The honest answer is often both, eventually, but the sequencing matters. ISO 27001 is an internationally recognized management-system standard, it demonstrates that your organization runs a formal information security management system (ISMS) with ongoing risk assessment, not just a point-in-time set of controls. That international recognition is exactly why it carries weight with government and defence buyers who need a standard that holds up across jurisdictions and audits by their own security teams.

SOC 2, by contrast, is an American Institute of CPAs framework built around an auditor's report on specific trust services criteria. It is the default ask from US SaaS buyers and investors. If your Ottawa company is selling primarily to Canadian public sector or defence-adjacent clients, ISO 27001 is usually the higher-leverage first certification. If you are dual-tracking into the US market, you will likely need both eventually, and building your ISMS first makes the SOC 2 controls easier to layer on afterward rather than the reverse.

What the ISO 27001 Certification Process Actually Involves

Certification is not a document you buy, it is a management system you build and then have independently audited. At a high level, the path runs through a few concrete stages:

  • Scoping and gap assessment, mapping which systems, data, and business processes fall inside the ISMS boundary and where current controls fall short of Annex A requirements.
  • Risk assessment and treatment, the core of the standard, where you identify information security risks and document how each one is treated, accepted, or transferred.
  • Policy and control implementation, building the actual technical and administrative controls the risk treatment plan calls for, along with the evidence trail auditors expect to see.
  • Internal audit and management review, proving the ISMS operates as designed before an external body ever looks at it.
  • Stage 1 and Stage 2 external audits, conducted by an accredited certification body, culminating in the certificate itself.

For most startups, the real work is not the audit, it is building an ISMS that reflects how the company actually operates rather than a binder of policies nobody follows. That is where a lot of DIY attempts and generic SaaS compliance tools fall short, they can generate the paperwork but not the operational judgment about what controls actually make sense for a 20-person engineering team. traztech's ISO 27001 implementation service is built around that gap, doing the risk assessment and control design work with your team rather than handing you a template library and a login.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept. ISO 27001 readiness

Why Ottawa Startups Should Work With a Canadian Partner, Not a Remote Platform

A lot of ISO 27001 "certification platforms" are US-based SaaS products with automated evidence collection and a thin layer of outsourced audit support. That model works reasonably well for straightforward SOC 2 engagements. It works less well when your buyer is a federal department or a defence prime asking pointed questions about data residency, PIPEDA alignment, or how your ISMS accounts for Canadian regulatory context that an American platform was never built to understand.

traztech operates as a boutique Canadian security and compliance consultancy, working directly with founders across the National Capital Region and the wider Canadian tech corridor from Toronto to Waterloo to Ottawa. That means an actual security practitioner reviewing your risk register, not a support ticket queue. For Ottawa companies specifically, that also means someone who understands why a defence-adjacent buyer's questionnaire looks the way it does, and how to scope an ISMS that will hold up under scrutiny from a buyer who has seen a hundred vendor security reviews.

Common ISO 27001 Mistakes Ottawa Startups Make

The most frequent misstep is scoping the ISMS too broadly, trying to certify the entire company when the audit only needs to cover the systems and processes actually touching customer or government data. An overbroad scope multiplies the evidence burden without adding credibility. The second is treating risk assessment as a formality rather than the substance of the standard, auditors can tell the difference between a risk register that was thought through and one that was filled in to check a box. The third is starting the process only after an RFP deadline forces the issue. Certification realistically takes several months from gap assessment to certificate in hand, and rushing it under deadline pressure tends to produce exactly the kind of superficial documentation that experienced auditors flag.

Building a Security Program That Outlasts the Certificate

ISO 27001 is a three-year certification with annual surveillance audits, which means the ISMS you build needs to keep functioning after the certificate is issued, not just survive the initial audit. Companies that treat certification as a broader security and compliance program, rather than a one-time project, tend to renew with far less friction and fewer surprises. traztech's compliance solutions are structured with that lifecycle in mind, so the controls and evidence trail built for your first audit keep paying off in year two and three rather than needing to be rebuilt from scratch.

Get Started on ISO 27001 in Ottawa

If a federal buyer, defence prime, or enterprise procurement team has already asked your company for ISO 27001, or you can see that question coming, the earlier you scope the work the less it costs in both time and rushed engineering effort. Contact traztech to talk through where your Ottawa company stands today and what a realistic path to certification looks like.

The Statement of Applicability is the document that gets read

ISO 27001:2022 carries 93 Annex A controls organized into four themes, sitting on top of the management system clauses 4 through 10. The clauses are the part that certifies you. The Annex A controls are the part your buyers ask about, and the bridge between them is the Statement of Applicability.

The SoA lists every one of the 93 controls, states whether it applies, gives the justification for inclusion or exclusion, and records the implementation status. Auditors read it first because it is the fastest way to see whether an organization thought about its own risk or copied a template. Exclusions are allowed and expected, but each one needs a reason tied to your risk assessment rather than a shrug. A company with no physical office can reasonably scope down parts of the physical controls, and it still has to say something coherent about where staff work and how devices are protected. A company that excludes application security controls while selling software has a problem the auditor will find in the first hour.

Federal and defence buyers in Ottawa often ask for the SoA directly, not just the certificate. That request catches people out, because a certificate is a page and an SoA exposes exactly what you decided not to do. Write it as a document you would be comfortable handing to a security assessor at a department, because in the National Capital Region you probably will.

Choosing a certification body, and what accreditation means

The certificate is only worth what the body issuing it is worth. Look for accreditation from the Standards Council of Canada or an equivalent recognized accreditation body such as ANAB or UKAS, and check the accreditation covers ISO 27001 specifically rather than a general management system scope. Unaccredited certificates exist, cost less, and get rejected by exactly the buyers you are trying to satisfy.

Audit effort is not negotiable in the way people expect. Certification bodies work from published guidance that sets audit days based on the effective number of personnel in scope, adjusted for complexity, and they cannot discount indefinitely. If one quote is dramatically below the others, ask how many audit days it covers and compare like with like. Ask two other questions while you are there. Ask whether the auditor assigned has worked with software companies, because an auditor whose background is manufacturing will spend Stage 2 learning your deployment pipeline on your time. Ask how surveillance audits are scheduled across the three-year cycle, since the recertification audit in year three is a larger exercise than the two surveillance visits and belongs in your budget from the start.

Stage 1, Stage 2, and what a nonconformity actually costs

Stage 1 is a documentation and readiness review. The auditor checks that the ISMS exists on paper, the scope makes sense, the risk assessment has been performed, the SoA is complete, and that internal audit and management review have actually happened. That last point is where most first-timers fail, because you cannot audit a management system that has not run yet. You need at least one internal audit covering the scope and one documented management review meeting with the required inputs and outputs before Stage 1. Scheduling those two events too late is the most common cause of a delayed certificate.

Stage 2 tests whether the system operates. The auditor samples evidence, interviews control owners, and looks for the gap between documented process and daily behavior. Findings come in three kinds. An observation is advisory. A minor nonconformity is an isolated lapse, and you submit a corrective action plan with root cause analysis, usually within 30 days, with evidence of correction accepted before the certificate issues. A major nonconformity is a systemic failure or a total absence of a required process, and it typically blocks certification until closed, sometimes requiring a return visit at your cost.

The useful thing to understand about corrective action is that auditors care more about the root cause analysis than the fix. A finding that access reviews were missed in one quarter, closed with "we did the review", will come back next year. Closed with a change to who owns the review and how it is triggered, it stays closed. Our ISO 27001 implementation work is built around getting that discipline in place before Stage 1 rather than after a finding.

Cost drivers Ottawa founders underestimate

Three things move the number more than anything else. Scope size is the first, and it is the one you control. An ISMS scoped to the production platform, the engineering team, and the systems supporting them is a fraction of the effort of one scoped to the whole legal entity including sales, finance, and a subsidiary. Buyers almost never require the broader scope, they require that the scope covers the service they are buying, so write the scope statement in terms of the service.

The second is evidence maturity. If joiner and leaver records live in email threads, if change approvals happen in conversation, if risk decisions exist only in someone's head, then the implementation project is largely an exercise in creating record-keeping habits. That work is real and it takes months. Companies with a ticketing system, an identity provider, and a code review process already producing dated records move through it far faster.

The third is the number of frameworks running at once. Ottawa companies frequently need ISO 27001 for procurement and eventually SOC 2 for US buyers. The controls overlap heavily, and building the control set once with mappings out to each framework is much cheaper than two separate efforts.

What federal and defence buyers ask that ISO 27001 does not answer

ISO 27001 gets you shortlisted. It does not answer the questions a Government of Canada contracting authority or a defence prime will raise next, and founders who assume the certificate closes the conversation lose time.

Expect questions about data residency and whether protected information stays in Canada, including in backups and in support access paths. Expect questions about personnel screening, and if the contract carries a Security Requirements Check List, you are into the Contract Security Program with its own timelines for organization screening and personnel clearances that run on their own schedule regardless of your certificate. Expect mapping questions against the control profiles departments actually use, since a federal security assessor works from those catalogues rather than Annex A, and being able to hand over a mapping from your controls to the profile they use saves weeks of back and forth.

None of this is a reason to skip ISO 27001. It is a reason to treat the certificate as one artifact in a package rather than the whole answer, and to build the mapping documents while the ISMS work is fresh rather than reconstructing them under an RFP deadline.

Keeping the system alive between audits

The three-year cycle means the ISMS has to produce evidence continuously, not in a burst before each visit. The recurring obligations are specific: risk assessment reviewed at planned intervals and after significant change, internal audit program covering the whole scope across the cycle, management review with documented inputs including audit results, nonconformities, and performance against objectives, corrective actions tracked to closure, and awareness training with attendance records.

Companies that let this lapse discover it in the surveillance audit, and a surveillance finding is more awkward than an initial one because it suggests the system stopped working the moment nobody was watching. Keeping a single register of control owners, review dates, and evidence links is most of the fight, which is why the free traztech Workspace exists, and why the ongoing side of this work lives under engage rather than being sold as a one-off project.

When an Ottawa startup should not pursue ISO 27001

Several situations make certification the wrong spend, and we would rather say so early.

If no buyer has asked and none is in your pipeline, wait. ISO 27001 is not a legal requirement in Canada, and a certificate acquired speculatively costs real money every year to maintain while producing no revenue. Build the underlying controls, keep the evidence, and start the certification when a specific opportunity justifies it. You can be certified within a few months of deciding if the groundwork is already there.

If your buyer is a US SaaS company, check whether they actually want SOC 2 instead. Presenting an ISO certificate to a US enterprise security team that has a SOC 2 checkbox in its vendor system creates work rather than removing it. Ask the buyer which they will accept before choosing.

If the bid you are chasing closes in six weeks, certification will not arrive in time and no consultancy can honestly promise otherwise. What can help is a documented gap assessment, an SoA, and a signed commitment with a dated plan, which some procurement teams accept as evidence of a credible path. That is a much smaller purchase, and it is often the right one.

If you have under a dozen people, no dedicated ops function, and your main risk is that nobody has ever tested the product, spend the money on a penetration test first. Testing starts at $1,000 and tells you something true about your security. A certificate tells buyers you manage security systematically, which is a different claim, and making it before it is true is how companies end up with a binder nobody follows. If you want a straight read on which of those you are, talk to us and we will tell you which one we would buy in your position.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.

ISO 27001 readinessOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.