Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

ISO 27001 for Waterloo Startups

Yes, Waterloo Region startups need ISO 27001 because their customers, mostly US and enterprise buyers, require independent proof of security controls before signing a contract, and the certificate is the fastest way to clear procurement without slowing down the sales cycle.

Why Waterloo Founders Keep Getting Asked for ISO 27001

If you have raised a seed or Series A round out of the Kitchener-Waterloo corridor, you already know the pattern. A prospect's security team sends a vendor questionnaire, or worse, asks for a completed SOC 2 report or ISO 27001 certificate before they will even schedule a technical call. This is not a Waterloo-specific quirk, it is what happens when a startup built on University of Waterloo engineering talent starts selling into banks, insurers, and larger SaaS platforms that have their own compliance obligations to satisfy.

ISO 27001 tends to win over SOC 2 for companies selling into Europe, the UK, or multinational enterprises with global security standards, because it is an internationally recognized certification rather than a US-centric attestation. For a Waterloo startup chasing a logo in London or a partnership with a European fintech, ISO 27001 often opens doors that SOC 2 alone does not.

The Waterloo Region Tech Ecosystem and Why It Matters Here

Waterloo Region is not a satellite market for us, it is one of the densest concentrations of B2B software companies in Canada. Communitech, the David Johnston Research and Technology Park, and the pipeline of engineering graduates coming out of University of Waterloo have produced a steady stream of startups that scale fast and sell into demanding, security-conscious markets from day one. That speed is the problem. Engineering teams here are used to shipping product quickly, and information security management often gets bolted on only once a deal is stuck in procurement.

We work directly with founders and CTOs across the region, not through a remote support desk. Being a short drive from Kitchener-Waterloo, and regularly working with teams across Toronto, Ottawa, and the rest of southern Ontario, means we understand the specific pressure of a fast-growing startup trying to close an enterprise deal without slowing down product velocity.

Common Waterloo Startup Profiles We See

  • Series A or B SaaS companies with a US enterprise pipeline that has stalled on a security review
  • Fintech and insurtech startups selling to regulated financial institutions that mandate ISO 27001 or an equivalent framework contractually
  • Engineering-heavy teams with strong technical controls already in place but no formal information security management system (ISMS) or documentation to prove it
  • Founders who tried a DIY compliance automation platform and got a dashboard full of red flags with no one to explain what to actually do about them

What ISO 27001 Actually Requires (Beyond the Checklist)

ISO 27001 certifies that your organization has a functioning information security management system, not just a set of technical controls. That means risk assessments, documented policies, employee security awareness training, vendor risk management, and evidence that these processes are actually followed, not just written down. Auditors from an accredited certification body will test whether your ISMS operates in practice over time, which is why a rushed, checkbox-driven approach tends to fail at the surveillance audit stage even if it passes the initial certification.

For a lean Waterloo engineering team, the hardest part is rarely the technical controls, cloud infrastructure teams here are usually already doing access control, encryption, and logging reasonably well. The gap is almost always in governance: risk registers, incident response documentation, and the operational cadence that proves the ISMS is a living system rather than a one-time audit exercise. Our ISO 27001 implementation engagements are built around closing exactly that gap without asking your engineers to become compliance officers.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept. ISO 27001 readiness

ISO 27001 Versus SOC 2 for Ontario Startups

We get this question constantly from founders in the region: should we pursue ISO 27001, SOC 2, or both? The honest answer depends on where your revenue is coming from. If your pipeline is dominated by US mid-market and enterprise buyers, SOC 2 Type II is usually the faster path since it is what American procurement teams expect by default. If you are selling into Europe, the UK, government-adjacent buyers, or multinational enterprises with a global vendor standard, ISO 27001 is often non-negotiable.

Many of the Waterloo companies we work with end up needing both eventually, especially once they cross from Canadian and US customers into European expansion. Rather than treating them as two separate projects, we build the underlying ISMS once and map it to both frameworks, which saves significant time and internal disruption compared to running duplicate compliance efforts a year apart.

PIPEDA, Quebec Law 25, and the Canadian Compliance Layer

ISO 27001 does not replace your Canadian privacy law obligations, it complements them. Startups handling customer or employee personal information still need to meet PIPEDA requirements federally, and if you have any Quebec-based customers or employees, Law 25 brings additional obligations around consent, breach notification, and privacy impact assessments.

Building your ISMS with these Canadian requirements in view from the start, rather than treating ISO 27001 as a purely international exercise, avoids a second round of documentation work later.

Why a Boutique Canadian Partner Beats a Remote Automation Platform

Compliance automation tools have made evidence collection easier, but a dashboard cannot write your risk assessment methodology, negotiate scope with your auditor, or tell you which control gaps actually matter to the enterprise deal sitting in your pipeline right now. Waterloo founders who have tried the software-only route often end up hiring a consultant anyway, months later, once the automation platform surfaces problems it cannot solve on its own.

traztech is led by Jacob Masse, a published security researcher credited with five CVEs, including a CVSS 9.1 vulnerability that functioned as a kill switch against the Mirai botnet. That is the kind of technical depth we bring to control design, not just paperwork assembly. Our broader compliance advisory work is built around getting founders to certification without pulling engineering off the roadmap for months at a time, and we do it as a Canadian firm working directly with Waterloo, Toronto, and Ottawa teams, not as an offshore support queue.

Getting Started with ISO 27001 in Waterloo Region

The startups that move fastest through certification are the ones that scope the project honestly before starting: what's your target certification timeline, which customer deal is driving the urgency, and how much of your existing security work already maps to Annex A controls. A short gap assessment answers all three questions and gives you a realistic roadmap instead of a guess.

If your Waterloo startup has a deal stalled on a security questionnaire, or you know ISO 27001 is coming and want to get ahead of it, contact traztech to talk through your timeline and scope with a Canadian team that works in the region, not around it.

How the Certification Audit Actually Runs

ISO 27001 certification is a two-stage initial audit followed by a three-year cycle. Stage 1 is a documentation and readiness review, usually one to two auditor-days, where the auditor reads your scope statement, your Statement of Applicability, your risk assessment methodology, and your mandatory records, then tells you whether you are ready for Stage 2. Stage 2 is the real test, typically three to six auditor-days for a company under a hundred people, where the auditor interviews control owners and samples evidence to confirm the ISMS operates as documented. Certification, if granted, lasts three years, with a surveillance audit in each of years one and two and a full recertification in year three.

The gap between Stage 1 and Stage 2 is normally four to eight weeks. Use it. Almost every Stage 1 produces a short list of observations, and closing them before Stage 2 is cheap; carrying them into Stage 2 turns them into findings. Waterloo teams that treat Stage 1 as a formality and book Stage 2 two weeks later routinely regret it.

Choose your certification body deliberately. It must be accredited by a recognized accreditation body, the Standards Council of Canada domestically, or ANAB, UKAS, or an equivalent internationally. An unaccredited certificate is a piece of paper, and the enterprise procurement team you are trying to satisfy will check the accreditation mark against the issuing body's register. Also confirm your consultant is not connected to the certification body. Accreditation rules prohibit a body from certifying an ISMS it helped build, and a certificate issued in breach of that independence rule can be withdrawn.

The Two Records That Block More Stage 2 Audits Than Anything Else

Clause 9.2 requires an internal audit of the ISMS, and clause 9.3 requires a management review. Both must have happened, with records, before Stage 2. This is the most common reason a Waterloo startup gets sent away from Stage 1 with a four-week delay, because the team built the controls, wrote the policies, ran the risk assessment, and never held the meeting.

The internal audit does not need to be an outside firm, but it does need to be someone who did not build the thing they are auditing, and it needs a plan, findings, and corrective actions with owners and dates. The management review needs the leadership team in a room or on a call, working through the specified inputs: the status of prior actions, changes in internal and external issues, performance against objectives, audit results, feedback from interested parties, risk assessment results, and opportunities for improvement. Minute it properly. An auditor reading a two-line record of a fifteen-minute meeting will conclude, correctly, that management is not engaged, and top management commitment under clause 5 is not something you can evidence any other way.

Scope Is a Strategic Decision, Not an Administrative One

Your certificate prints a scope statement, and your buyer reads it. A scope that says "the information security management system supporting the design, development, and operation of the company's SaaS platform, including supporting corporate functions, at the Kitchener office and AWS ca-central-1" tells a procurement reviewer what they need. A scope that carves out the very product they are buying gets caught, and it damages trust more than having no certificate at all.

Narrow scope reduces audit days and cost, which is legitimate. What is not legitimate is excluding a system that materially handles customer data in order to avoid fixing it. The test is whether a reasonable buyer, reading the scope on the certificate, would understand which of your services are covered. If you have to explain the scope statement in a sales call, it is drawn wrong.

The Statement of Applicability, and the Controls Teams Forget

The 2022 revision restructured Annex A into 93 controls across four themes, sitting alongside the management system requirements in clauses 4 to 10. Your Statement of Applicability lists every one of the 93, states whether it applies, gives the justification, and points at the implementation. Exclusions are permitted and normal, but each one needs a reason that holds up. "We have no on-premise data centre" justifies excluding some physical controls. "We did not have time" justifies nothing.

The controls introduced in the 2022 revision are the ones engineering-heavy teams most often have not addressed, because they were not on the older checklists floating around: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Secure coding and configuration management are usually already happening in a Waterloo engineering shop, they are just undocumented. Information deletion and data masking are usually genuinely missing, because nobody has ever written down what happens to customer data at the end of a contract or what production data looks like in staging. We keep a worked Statement of Applicability example if you want to see the shape of a defensible one.

The Co-op Cycle Is a Real Access Control Problem Here

Kitchener-Waterloo companies run on University of Waterloo co-op students, and the terms turn over every four months. That means three onboarding and offboarding waves a year, often involving people who get production or repository access on their second day because a senior engineer is unblocking them. Auditors sample joiners and leavers. If your sample includes six co-op students whose GitHub access was revoked three weeks after their term ended, that is a finding against access provisioning and against offboarding, and it will recur at every surveillance audit unless the process changes.

The fix is mundane. Tie account creation and revocation to the term dates in your HR record, give students the same access review treatment as employees, and keep a record of the revocation with a timestamp. Companies that automate this once stop failing on it forever. Companies that handle it manually fail on it every year, because the cycle is faster than anyone's memory.

Nonconformities and What Happens If You Get One

Findings come in two grades. A minor nonconformity is an isolated lapse against a requirement, and you typically get 30 to 90 days to submit a corrective action plan with root cause analysis and evidence of correction; the certificate is usually still issued. A major nonconformity is a total absence of a required process, a systemic breakdown, or a lapse that undermines the ISMS, and it blocks certification until it is closed, sometimes requiring the auditor to return on site. Accumulated minors covering the same clause can be escalated to a major at the auditor's discretion.

Corrective action is where teams do themselves damage. The auditor is not asking you to fix the instance, they are asking for root cause and systemic correction. Responding to a missed access review with "we have now done the access review" earns the same finding again next year. Responding with the calendar entry, the named owner, the escalation if it is missed, and evidence of the first two cycles closes it properly. That distinction is also most of what determines whether your surveillance audits are quiet.

What Drives the Bill

Certification body fees are quoted in auditor-days, and the day count is driven by headcount within scope, number of physical sites, and complexity of the scope. Add the readiness work, the internal audit, any penetration testing your risk assessment calls for, and the ongoing surveillance audits in years two and three. The variable teams underestimate is internal time: control owners answering evidence requests, engineers writing procedures for things they have always done informally, and leadership sitting through the management review. Budget for it explicitly or it comes out of the roadmap without anyone deciding that it should.

When You Should Not Certify, and When You Should Not Hire Us

If every buyer in your pipeline is American and none of them has mentioned ISO 27001, do not certify. SOC 2 will move those deals faster and cost less, and you can build the underlying control set so that ISO becomes a documentation exercise later if Europe arrives. If one European prospect has asked and the contract is small, ask them directly whether a SOC 2 Type II report plus a completed questionnaire satisfies their vendor policy. A meaningful number of European buyers say yes, and the ones who cannot say no clearly, which is information worth having before you spend the budget.

Do not hire us if you have a competent internal security lead with capacity and a straightforward single-product cloud environment. The standard is publicly available, the requirements are legible, and a disciplined team can build the ISMS themselves and hire only the certification body. Where we earn the fee is when the ISMS has to be built without pulling engineers off the roadmap, when scope and the Statement of Applicability need to be argued with an auditor, when a prior attempt produced a documentation set that does not match how the company actually works, or when ISO and SOC 2 have to be built as one control set instead of two. That is what our ISO 27001 implementation work is for, and if your situation is simpler than that, we will say so.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.

ISO 27001 readinessOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.