Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

ISO 27001 for Vancouver Startups

ISO 27001 certification for a Vancouver startup typically takes three to six months and requires building an information security management system (ISMS), running a formal risk assessment, and passing a two-stage external audit by an accredited certification body. The scope, cost, and timeline depend on how mature your existing security controls already are, but the framework itself is the same whether you're a five-person SaaS shop in Gastown or a 60-person biotech spinout near UBC.

Why Vancouver Founders Keep Getting Asked for ISO 27001

If you've raised a seed round or landed a first enterprise pilot in the last two years, you've probably already had a prospect's procurement team send over a security questionnaire that name-drops ISO 27001 in the first line. This isn't a coincidence specific to Vancouver, but it hits BC founders in a particular way. The city's tech and life sciences base, clean tech, health tech, gaming, and SaaS companies clustered around Yaletown, Mount Pleasant, and the UBC and SFU research corridors, sells disproportionately into US enterprise, Asia-Pacific markets, and government-adjacent buyers. All three of those buyer categories treat ISO 27001 as the default proof of a working security program, the way SOC 2 dominates in pure US SaaS deals.

For companies straddling both worlds, which describes a lot of Vancouver's cross-border trade and logistics tech, ISO 27001 is often the more useful certification because it's recognized globally, not just in North America. A single ISMS built to the standard also gives you a foundation you can extend toward SOC 2 or sector-specific frameworks later without starting over.

What ISO 27001 Actually Requires

ISO/IEC 27001 is a management systems standard, not a checklist of technical controls. It asks you to prove three things to an independent auditor: you understand your information security risks, you've chosen and implemented controls proportionate to those risks (drawn from Annex A's 93 controls), and you continuously monitor and improve the system. That last part matters, certification isn't a one-time event, it's an ongoing commitment verified by annual surveillance audits and a full recertification every three years.

In practice, the work breaks down into a few concrete phases:

  • Scoping and gap assessment, deciding which parts of the business, products, and infrastructure the ISMS covers, and comparing current practice against the standard.
  • Risk assessment and treatment, formally documenting the risks to information assets and the controls chosen to address them.
  • Policy and control implementation, from access management and vendor risk to incident response and business continuity.
  • Internal audit and management review, required evidence that the ISMS is operating, not just written down.
  • Stage 1 and Stage 2 external audit, conducted by an accredited certification body, culminating in the certificate.

Our ISO 27001 implementation service is built around exactly this sequence, with a fixed scope so founders know what they're buying before the first invoice.

Where Vancouver Startups Usually Get Stuck

We see the same handful of bottlenecks across BC tech companies going through this for the first time. Engineering teams that grew fast on GitHub, AWS, and a scattered mix of SaaS tools often have no central asset inventory, which is one of the first things an auditor asks for. Remote and hybrid teams, common across Vancouver's talent pool that stretches into the Fraser Valley and Vancouver Island, need documented access control and offboarding processes that hold up under audit, not just a Slack message when someone leaves. And founders juggling fundraising and product work tend to underestimate how much of the ISMS is organizational discipline (documented decisions, review cadence, evidence trails) rather than new security tooling. None of that is unique to Vancouver, but the pace of the local funding environment, with rounds closing fast and enterprise pilots demanding proof of controls before contracts get signed, means startups here often need to compress a normally unhurried process into a tight window tied to a specific deal.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept. ISO 27001 readiness

Canadian Privacy Law Still Applies Alongside ISO 27001

ISO 27001 covers information security management, it doesn't replace your privacy law obligations. BC-based companies handling personal information are still subject to PIPEDA federally, and BC's own Personal Information Protection Act provincially. If you have customers or a presence in Quebec, Law 25 adds its own consent and breach notification requirements on top. A well-built ISMS makes all of these easier to answer consistently, since the risk assessment, data inventory, and incident response process you build for ISO 27001 double as the backbone of your privacy compliance story. We fold this into scope planning so Vancouver clients aren't building a security program and a privacy program as two disconnected projects. See our broader compliance advisory work for how these pieces fit together for companies operating under multiple Canadian and international frameworks.

Why a Canadian Boutique Beats a Faceless SaaS Compliance Tool

Compliance automation platforms are useful for evidence collection once you have a working ISMS, but they don't tell you which controls actually matter for your risk profile, they don't write your risk treatment plan, and they won't sit on a call with your auditor when a Stage 2 finding needs a real answer. traztech is a small Canadian firm, led by a working security researcher, not a support queue routed through a platform. We work directly with Vancouver and BC tech companies, understand the local buyer landscape from Toronto-based enterprise procurement teams to Asia-Pacific partners, and build ISMS documentation that reflects how your company actually operates rather than a generic template. We serve founders across the country, Toronto, Waterloo, Ottawa, Calgary, Montreal, and Vancouver, but ISO 27001 work for BC companies gets the same direct, hands-on attention: real conversations about your architecture, your vendor list, and your actual risk exposure, not a chatbot walking you through a questionnaire.

What Certification Costs and How Long It Takes

Timelines depend heavily on starting maturity. A startup with reasonably tight access controls, documented processes, and a small, well-understood infrastructure footprint can realistically target Stage 2 audit in three to four months. Companies with more sprawl, multiple product lines, legacy infrastructure, or several vendors touching customer data, should plan for five to six months. Certification body audit fees are separate from implementation cost and scale with headcount and site count, so getting an accurate quote requires a short scoping call rather than a generic price list. The single biggest cost driver we see isn't the framework, it's how much of the ISMS has to be built from nothing versus adapted from controls you already have informally in place.

Start With a Scoping Conversation

If a customer, investor, or partner has asked your Vancouver startup for ISO 27001 certification, the fastest path forward is a short conversation about your current scope, infrastructure, and deal timeline, not a generic sales pitch. Contact traztech to talk through what certification would actually take for your company, and where it fits against the deals or fundraising milestones driving the request.

Clauses 4 to 10 Are Where First-Time Certifications Fail

Founders fixate on the 93 Annex A controls because they read like a technical to-do list. Auditors spend most of Stage 2 somewhere else, in the management system clauses, and that is where first attempts come apart. Clause 4 asks you to define the context of the organization and the interested parties whose requirements the ISMS has to satisfy, which for a Vancouver company usually means naming your enterprise customers, your regulators, and your investors rather than writing something abstract. Clause 5 wants leadership involvement you can evidence, including an information security policy the executive actually approved and roles with named holders. Clause 6 covers the risk assessment methodology and the security objectives, and it requires those objectives to be measurable, which quietly rules out "improve our security posture".

Clause 7 covers competence, awareness and documented information control, so version history and approval records on your policies matter as much as their content. Clause 8 is operational planning, meaning the risk treatment actually got executed. Clause 9 is monitoring, internal audit and management review. Clause 10 is nonconformity, corrective action and continual improvement. A startup that has implemented every technical control but has never run an internal audit or held a management review has not built an ISMS. It has built a control set, and Stage 2 will say so.

The practical consequence for a compressed timeline is that you cannot skip the operating period. The internal audit has to happen before the external one, the management review has to consider the internal audit output, and corrective actions raised internally need to show progress. That chain takes weeks of calendar time regardless of how fast your engineering team moves, and it is the most common reason a three-month plan becomes a five-month one.

The Statement of Applicability Is the Document Read Hardest

The Statement of Applicability lists every Annex A control, whether you have applied it, why, and where the implementation lives. It is the map an auditor uses to plan sampling, and a weak one generates findings before anyone looks at a system. Three things go wrong with it regularly.

Excluding a control for the wrong reason. "Not applicable" has to follow from your risk assessment or from a scope boundary, not from inconvenience. Excluding secure development controls because your team is small is not a justification. Excluding physical entry controls for a data centre you do not operate, and pointing at your cloud provider's own certification for that scope, is.

Including everything to look thorough. If you mark all 93 as applied, the auditor will sample the ones you have not actually built, and a control claimed but absent is a stronger finding than a control excluded with reasoning.

Leaving the implementation reference vague. "Covered by our access policy" invites a follow-up. Naming the specific policy section, the ticket queue, or the system that enforces it shortens the audit and reduces the number of live demonstrations you get asked for. Our ISO 27001 implementation work treats the Statement of Applicability as a deliverable in its own right for exactly this reason.

Choosing a Certification Body, and the Accreditation Trap

Your certificate is only worth what the accreditation behind it is worth. Certification bodies are themselves accredited by national bodies, the Standards Council of Canada in this country, ANAB in the United States, UKAS in the United Kingdom, and their equivalents elsewhere. A certificate issued by a body with no recognized accreditation is cheap, fast, and rejected by exactly the enterprise procurement teams you bought it for. Ask for the accreditation body and the scope of accreditation, and verify it on the accreditation body's own register rather than taking a logo at face value.

Beyond accreditation, ask about sector experience with software companies, whether audits are remote or on-site for your locations, lead time to book Stage 1 and Stage 2, and how surveillance is scheduled. Lead time is the item that ruins timelines. Booking a Stage 2 for a specific month can require several months of notice, so the auditor conversation belongs at the start of the project rather than after the controls are built. Note also that your implementation partner cannot be your certification body. Independence rules prohibit it, which is why a firm that offers to both build and certify your ISMS is telling you something about the value of the certificate.

What Happens When Stage 2 Raises a Nonconformity

Most first certifications collect findings, and that is normal rather than a failure. Findings come in two grades. A minor nonconformity is a lapse in an otherwise working control, a missed access review, an unapproved policy version, and it usually gets a corrective action plan with evidence submitted afterwards, with the certificate issued once the plan is accepted. A major nonconformity means a requirement is absent or a control has broken down systemically, and it generally blocks certification until it is closed and verified, sometimes with a follow-up visit.

What matters here is the response quality. A corrective action that fixes the instance and not the cause tends to reappear at the next surveillance audit, now as a repeat finding with worse consequences. Auditors expect root cause analysis, a correction, a preventive change, and evidence the change is operating. Companies that treat findings as paperwork spend the following year re-litigating them. This is also the moment where having someone who has sat through these conversations pays for itself, because the difference between a minor and a major is frequently how the situation is explained and evidenced in the room.

Life After the Certificate

The certificate runs on a three-year cycle with a surveillance audit in each of the intervening years and a full recertification at the end. Surveillance audits are narrower than Stage 2, but they always look at internal audit, management review, corrective actions from last time, and any changes to scope. The failure pattern is predictable. The ISMS operates beautifully for two months after certification, then the access reviews stop, the risk register goes stale, and the vendor reviews never happen, and nine months later the surveillance audit finds a management system that exists only in documents. Continual improvement is a clause, not a slogan, and an auditor can tell the difference between a risk register that was maintained and one that was refreshed the week before the visit.

Two practical notes for BC companies. First, certificates issued against the 2013 edition are no longer valid; the transition to ISO 27001:2022 closed at the end of October 2025, so any certificate you are shown by a vendor should be against the current edition. Second, if privacy is a driver, ISO 27701 extends your existing ISMS into a privacy information management system and reuses most of the same evidence, which is often a cheaper answer for PIPEDA and BC's Personal Information Protection Act questions than building a separate privacy program.

When ISO 27001 Is the Wrong Purchase

We turn this work down more often than you would expect. If every buyer asking is a US software company, and none of them mentioned ISO by name, SOC 2 is usually the faster and cheaper route to the same unblocked deal, because it does not carry a certification body, an accreditation cycle, or a three-year commitment. If a single prospect asked and the deal is worth less than the certification will cost over its first cycle, say so out loud before you start; a documented security posture and a completed questionnaire have closed plenty of contracts that opened with an ISO request.

If you are pre-product or under about ten people with no customer data of consequence, the honest advice is to spend the money on the basics that every framework assumes anyway: single sign-on, MFA everywhere, removal of standing production access, real logging, and a backup you have actually restored from. Those close most of the findings you would otherwise pay a consultant to write up. And if you are certain both ISO 27001 and SOC 2 are coming, run them together rather than in series, because the overlap between Annex A and the common criteria means one evidence collection can serve both. What you should not do is buy certification because a competitor has it. Buy it because a named buyer, a regulator, or a market you are entering requires it, and if you want a blunt second opinion on which of those applies to you, ask us.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.

ISO 27001 readinessOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.