Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Keeping Evidence Fresh: The Register That Survives Two Audits

Direct answer: Evidence is an artefact a control produced, with a date, and it goes stale. The structure that survives is a register where every artefact is attached to the controls it proves, has a named owner, and has a refresh date derived from the control's cadence. Collect once and map to every framework that asks, because the same access review record satisfies SOC 2, ISO 27001 and HIPAA at the same time if it is filed somewhere all three can reach.

What counts as evidence

The distinction that matters: a document describing a control is not evidence of the control. A policy saying access is reviewed quarterly evidences nothing. The completed review, dated, naming the reviewer and showing what changed, evidences the control.

Auditors sample. They pick a period, ask for the artefact that control produced during it, and check that it exists, is dated inside the period, and shows the control doing what the description claims. Everything else is context.

The shapes that get accepted are consistent across firms. Exports with timestamps and the person who ran them. Tickets showing a request, an approval and a completion. Signed or acknowledged records for policies and training. Reports from tools with the configuration visible. Screenshots are the weakest form and are accepted mainly where nothing else exists, because they can be taken at any time and show nothing about the period.

Why evidence goes stale

Every artefact has an implicit expiry driven by the cadence of the control it proves. A quarterly access review record covers a quarter. A penetration test report covers a year, and less than that if the environment changed materially. Training completion covers the cycle it was run in, and not the person who joined last month.

Teams get caught because the artefact still exists and looks fine. The file is there, it is titled correctly, and it is fourteen months old. Nothing about the folder tells you it has expired, which is why refresh dates belong on the record rather than in someone's memory.

Structuring the register

Five fields do almost all the work.

The artefact itself, stored somewhere durable rather than in an email thread or a Slack channel with retention limits.

What it evidences, as a list of controls across every framework in scope, not a single one. This is the field that saves the most time later.

Who owns it, by name, meaning who produces the next one.

When it was produced, from the artefact rather than the upload date, because those differ and auditors care about the first.

When it expires, derived from the control cadence, so the register can tell you what is going stale before somebody asks for it.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

Collect once, count everywhere

Most companies running two frameworks collect the same evidence twice, in two places, because the two programmes were run by different people at different times. The overlap between SOC 2 and ISO 27001 is substantial, and the overlap between either and HIPAA or PCI DSS on the access, change and monitoring controls is real too.

A quarterly access review record can satisfy SOC 2 CC6.2, ISO 27001 A.5.18 and the HIPAA administrative safeguard on access review in one artefact. Producing it three times is pure waste, and it also produces three slightly different records, which is worse than waste when an auditor notices they disagree.

The mapping is the work. Once it exists, adding a framework becomes an exercise in identifying the genuinely new requirements rather than starting over.

What breaks a register

Evidence collected in a burst before fieldwork, which produces artefacts clustered in one month covering a twelve month period. Auditors notice this immediately and it invites a harder look at everything else.

Artefacts with no owner, which means nobody produces the next one. Free-text titles that differ per framework, which is how you end up with the same document filed twice under different names and a register that cannot tell you your real coverage. And storage that the person who leaves owned personally, which is the most common way evidence is lost outright.

The second audit is the test

The value of a well-kept register does not show in the first audit, where everything was collected recently for the project. It shows in the second, where the auditor asks for evidence covering a twelve month period and the answer is either a register that already holds it, or three weeks of reconstruction that will not fully succeed.

Teams that keep the register current spend fieldwork answering questions. Teams that do not spend it manufacturing a record, which is stressful, expensive, and produces exactly the kind of thin evidence that generates findings.

Our workspace holds the register with the mapping and refresh dates built in, and it is free to use whether or not you work with us. Keeping it current across a year is the part that needs a person, which is what an ongoing retainer covers.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.