Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Maintaining SOC 2 in Year Two: What Actually Changes

Direct answer: Year two is usually cheaper and harder. Cheaper because the controls, policies and scope already exist. Harder because nobody is running a project any more, and the controls now have to operate for twelve unbroken months while everyone is busy with something else.

What gets easier

Scope is settled. Policies exist and need reviewing rather than writing. Your auditor knows the environment, which shortens fieldwork. The system description needs updating, not drafting. Most companies see readiness effort drop substantially in the second cycle.

What gets harder

In year one somebody owned compliance full time, at least informally. In year two that person is back on their real job and the quarterly access review has no calendar entry. This is where almost every second-year exception comes from: the control still exists, nobody performed it on schedule, and there is no record.

The second failure is drift. You migrated a database, added a subprocessor, moved to a new identity provider, hired in a new country. Each is a normal business change and each one silently invalidates something in the system description or the vendor list.

Keeping it true is the hard part. Continuous compliance on a monthly retainer: the reviews, the evidence and the calendar operated for you, so the next audit is a review rather than a rebuild. See how a retainer works

The four things to put on a calendar

Quarterly access reviews with a named owner and a stored artefact. An annual policy review with a date and a signature. Vendor reassessment for anything material. A risk assessment refresh. If those four are scheduled with an owner rather than remembered, most of year two takes care of itself.

Watch the observation window

Type II reports cover a period, and buyers want a current one. If your window ends in December and your biggest renewal is in April, you will be writing bridge letters every year. Moving the window is easiest between cycles, and worth doing once rather than papering over annually.

What to tell your auditor early

Material changes, before fieldwork rather than during it. A new production region, a new subprocessor handling customer data, a change of identity provider. Auditors handle these routinely when told in advance and treat them as findings when discovered late.

Year two is where a compliance programme either becomes part of how the company runs or quietly decays into an annual scramble. If yours is drifting toward the second, that is what our compliance readiness engagements pick up, and the free Workspace keeps the evidence register live between audits rather than rebuilt each year.

A realistic year-two calendar

The controls do not change, but the rhythm has to be deliberate now that nobody is running a project. What follows is the shape that survives a real year.

The first month after the report is issued, do three things: read the exceptions and assign each one an owner with a date, confirm who owns the programme by name, and put every recurring control into a calendar with a person attached rather than a team.

Each quarter, run the full access review, review vendors, rotate through the policy set so each policy gets reviewed once in the year, and reassess the risk register. Each of those produces an artefact, and the artefact is the point.

Annually, and preferably not in the last two months of the window, run the penetration test, complete security awareness training, refresh the risk assessment properly, and test a restore. The reason for not leaving these late is remediation time: a finding in month eleven cannot be closed and retested before the window ends, and it becomes an exception.

Updating the system description

The system description is your own representation of how the service works, and it is the document an auditor holds you to. In year one it was written from scratch and was accurate. In year two it is usually the most out-of-date artefact in the programme.

Anything that changes infrastructure, data flows, subprocessors, or the boundary of the system needs to be reflected. The practical way to make this happen is to attach it to something that already occurs: a quarterly review where whoever owns the programme reads the description and asks whether it is still true. It takes half an hour and it prevents the single most awkward conversation in fieldwork.

What the second audit costs

Readiness effort usually drops considerably, because the build is done. Audit fees often stay flat or rise slightly with headcount, since the auditor's work is driven by scope and sampling rather than by how prepared you feel.

What changes the number most is how clean the evidence is when fieldwork starts. A disorganised client takes longer to audit and firms price that in. Arriving with a complete evidence package is worth real money, and on one engagement we saw an audit firm reduce its own quote by $11,000 once the readiness position was documented and a preparation firm was confirmed.

Exceptions from year one

Prior-period exceptions are the first thing an auditor checks in year two. Each one needs a root cause, a corrective action, evidence the action happened, and evidence it worked across the period. Closing an exception in month one and never testing that it stayed closed is a common way to see the same finding twice, which reads much worse than seeing it once.

Signals you have a problem

Watch for these, because each one is quiet and each one is expensive later. Two consecutive months where a control produced no evidence. An access review record that arrives without any removals, which usually means it was performed as a formality. A vendor list that has not changed while the company has obviously adopted new tools. Policies whose review dates all fall in the same week, which means they were reviewed in a batch to satisfy a date rather than read.

None of those are dramatic and all of them are visible if somebody is looking. The reason they usually go unnoticed is that after year one, nobody is. Whether that person is internal or on a retainer matters less than whether they exist and whether the time is genuinely protected.

What the auditor does differently in year two

The second audit is not a repeat of the first, and knowing where the emphasis shifts helps you prepare for the right things.

Sampling gets deeper. In a first Type II with a three month window, the auditor may sample one or two instances of a quarterly control. Across twelve months they will sample all four, and a missing quarter is no longer something that might go unnoticed. The same applies to monthly controls: twelve chances to have a gap instead of three.

Prior-period exceptions get specific attention. The auditor already knows where you were weak and will test whether the corrective action held across the whole period rather than at the moment it was implemented.

The system description gets compared against a year of change. In year one the description was written days before fieldwork and matched reality. In year two the auditor is walking an environment that has moved and comparing it to a document that may not have.

The handover problem

Most second-year failures trace back to a handover that never happened. The person who ran readiness has moved on, changed roles, or simply stopped being the owner when the project ended, and what they knew was never written down.

What that person held in their head is usually: why a control is scoped the way it is, which systems are deliberately out of scope and on what basis, what the auditor accepted last time and what they pushed back on, and which of the policies say something the company does not actually do.

Capturing that is a two-hour exercise and almost nobody does it. A short internal note per control area, covering scope rationale, evidence location, owner, and known weaknesses, converts private knowledge into something the next person can operate.

Budgeting the year properly

Year two has three cost lines and companies routinely budget for one. The audit fee, which is visible and quoted. The external support, if any, which is a decision. And the internal time, which is invisible and real.

The internal time is the one that gets underestimated. Somewhere between two and five hours a week outside audit periods, considerably more during fieldwork, spread across whoever produces evidence. If it is not budgeted, it is taken from engineering, which is how compliance quietly becomes unpopular internally.

Worth also budgeting the annual items with real numbers rather than intentions: the penetration test, the training platform if you use one, and any tooling. A programme that runs out of budget in month nine skips the recovery test, and the skipped test is an exception.

When scope should change

Year two is the natural point to reconsider what the report covers, in both directions.

Expanding usually comes from buyers asking for an additional criterion, or from a product launched during the year that customers assume is covered. Both are legitimate, and both require the controls to have operated across the period rather than from the date you decided to include them.

Contracting is less discussed and sometimes correct. A criterion added optimistically in year one, that no buyer has ever asked about, is a set of controls somebody operates every week for no commercial return. Removing it is a conversation with your auditor and a note in the description, and it can meaningfully reduce the ongoing load.

Making year three easier than year two

The compounding version of this programme looks like a register that never goes stale, a calendar with names on it, a description reviewed quarterly, and exceptions closed with evidence rather than intent. Each year then starts from a better position than the last, and audits stop being events.

The degrading version looks like a burst of activity eight weeks before fieldwork, evidence collected in a cluster, a description updated retrospectively, and the same exception appearing twice. That version gets more expensive every cycle, because the gap between the document and reality widens each year.

Which version you get is decided by whether somebody owns the cadence in the quiet months, not by how hard anyone works in the loud ones.

When you discover a missing quarter mid-year

This is the most common emergency of the second cycle and it usually surfaces in month eight, when somebody finally goes looking for the Q2 access review and it is not there.

The first thing to establish is whether the control ran and went unrecorded, or did not run at all. Those are different problems. If a manager genuinely reviewed access in June and simply never exported the record, there may be a contemporaneous trace: tickets for the removals that came out of it, a Slack thread, a calendar invitation with attendees. That is not as good as a signed record and it is a great deal better than nothing, and an auditor will usually accept it as partial evidence with a note.

If the control did not run, it did not run. Perform it now, date it now, and record that the prior instance was missed. Then decide, with your auditor rather than alone, whether to disclose in advance or let it surface in sampling. Advance disclosure almost always produces a milder outcome, because the auditor is then assessing a company that monitors itself against one that does not.

What you must not do is produce a document in month eight bearing a June date. Auditors sample tickets, exports, and log entries alongside documents, and those artefacts carry timestamps that will not match. A missed control instance is an exception. A fabricated record is a different category of finding and it changes how everything else in the report gets read.

Changing audit firms in the second cycle

Year two is when the invoice from year one has been absorbed and somebody asks whether the fee is competitive. Switching is legitimate and it has costs that are rarely quoted.

A new firm has to learn the environment, which means a longer planning phase, more questions during fieldwork, and usually a larger initial evidence request than your incumbent would have sent. They will also form their own view on scope, and occasionally that view is broader than your previous auditor's, which is a genuine risk if the difference surfaces after you have signed. Ask any prospective firm directly how they would scope the system boundary, and get the answer before the engagement letter rather than after.

The reasons that justify a move are mostly not price. Missed deadlines on report issuance, partner turnover so severe that nobody at the firm remembers your environment, an inability to explain a finding in terms your engineers can act on, or a firm that has grown past caring about an account your size. Price is the reason people cite and rarely the reason that improves the relationship, because a quote that drops without the readiness position changing usually reflects a thinner audit rather than a better deal.

If you do move, do it between cycles, not mid-window, and hand over the prior report, the exception remediation evidence, and the system description together.

Adding a second framework without doubling the work

The second year is when a European buyer asks for ISO 27001 or a payments partner raises PCI DSS, and the instinct is to treat it as a second programme. It should not be.

ISO 27001 is 93 Annex A controls plus the management system requirements in clauses 4 to 10. A large share of the Annex A control set is already satisfied by what your SOC 2 controls produce, and the artefacts genuinely transfer: the access reviews, the vendor register, the risk assessment, the training records, the incident records. What does not transfer is the management system layer, which SOC 2 has no equivalent of. Internal audit, management review with recorded decisions, the Statement of Applicability, and documented objectives are new work, and they are the work that first-time ISO candidates underestimate.

The practical approach is to keep one evidence register and tag each artefact against every control it serves across both frameworks, rather than maintaining separate stores that drift apart. Run the activity once and reference it twice. Where the frameworks genuinely differ on frequency or content, add the stricter requirement to the calendar rather than keeping two cadences.

Timing matters as well. Adding a framework in the middle of a Type II window means the new controls have not operated across the period, so plan the certification cycle to start where your SOC 2 window closes. Our ISO 27001 readiness work is usually scoped around an existing SOC 2 rather than beside it for exactly that reason.

When you should not renew

Renewal is treated as automatic and sometimes it should not be.

If you obtained the report for one enterprise deal, that customer has since churned, and nobody in your current pipeline has asked for it, you are paying an audit fee and several hours a week of internal time for a document nobody reads. Ask your sales team how many deals in the last twelve months required it. If the answer is none, letting it lapse deliberately is a defensible commercial decision, and it is cheaper than discovering the same thing after paying for a third cycle.

If your buyers are European or your growth is in regulated European sectors, ISO 27001 may serve you better than SOC 2 and running both is a real ongoing cost. Choosing one is allowed.

If the honest position is that the controls have not operated across the year, do not push into fieldwork hoping the sampling misses it. A report full of exceptions is worse in a buyer's hands than no report and a credible plan, because exceptions are permanent and a plan is forward-looking. Restart the window, fix the cadence, and issue a clean report later.

And if what you need is somebody to notice the drift rather than somebody to run the whole programme, buy the smaller thing. A quarterly review of the evidence register and the calendar, with a named person on the other end, catches most of what goes wrong in year two. That is a fraction of what a fractional CISO engagement costs, and for a company whose controls are already sound it is often all that is missing.

Keeping it true is the hard part. Continuous compliance on a monthly retainer: the reviews, the evidence and the calendar operated for you, so the next audit is a review rather than a rebuild.

See how a retainer worksOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.