Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

SOC 2 or ISO 27001 First? A Guide for Canadian Startups

If your buyers are American, start with SOC 2. If your buyers are European, government, or ask for a certificate rather than a report, start with ISO 27001. Most Canadian SaaS startups selling into the US should do SOC 2 first, then layer ISO 27001 later if a deal genuinely requires it.

This is one of the most common questions founders bring to us at traztech, and it rarely has a one-size answer. The right framework depends on who is asking for it, not which one sounds more rigorous. Below is how we walk Canadian founders through the decision, and what it looks like to eventually hold both.

Why the Question Even Comes Up

SOC 2 and ISO 27001 cover a lot of the same ground: access control, encryption, incident response, vendor management, employee security training. Buyers in enterprise procurement often treat them as interchangeable proof that you take security seriously. But the frameworks themselves are structured differently, and more importantly, the market that asks for each one is different.

SOC 2 is a Type II attestation report produced by an independent CPA firm, built around the AICPA's Trust Services Criteria. There is no "SOC 2 certificate", you get an auditor's report, but sales teams still say "we need SOC 2 certification" because that is how the market talks about it. ISO 27001 is an international standard with an actual certificate, issued after an accredited body audits your information security management system (ISMS) against a fixed set of controls.

SOC 2 First: The Default for Canadian SaaS Selling Into the US

For a Canadian SaaS company whose pipeline is mostly US mid-market and enterprise buyers, SOC 2 is almost always the right first move. It is the framework American procurement teams, security questionnaires, and vendor risk platforms default to asking about. If your growth plan depends on closing US logos, a signed SOC 2 Type II report removes a recurring deal blocker faster than anything else you can produce.

SOC 2 also tends to be faster to a first report. Type I can be issued almost immediately after controls are documented and operating, and Type II typically requires a three to six month observation window rather than a full annual cycle. For a startup trying to unblock a stalled enterprise deal, that speed matters.

  • Buyer says "SOC 2" or "SOC 2 Type II" specifically in a security questionnaire
  • Your ICP is US-based B2B SaaS, fintech, or healthtech
  • A single enterprise deal is stuck in procurement right now
  • You need something CPA-audited that maps cleanly to AICPA Trust Services Criteria

ISO 27001 First: When It Makes More Sense

ISO 27001 usually jumps the queue when your buyers are European, when you are selling to government or regulated public sector bodies, or when a larger multinational's procurement standard is simply "ISO certified vendors only". It is also the stronger choice if you are building or already run an information security management system that needs to flex across multiple frameworks over time, since ISO's ISMS structure is designed to layer additional controls (privacy, AI governance) on top later.

  • Buyers or partners are headquartered in the EU, UK, or Asia-Pacific
  • RFPs explicitly require an ISO 27001 certificate, not an attestation report
  • You are pursuing public sector or government contracts
  • You want a management-system foundation you can extend toward ISO 42001 for AI governance down the road
Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept. ISO 27001 readiness

The Canadian Context: PIPEDA and Quebec Law 25

Neither SOC 2 nor ISO 27001 is a Canadian legal requirement, but both interact with obligations Canadian companies already carry. PIPEDA sets the federal privacy baseline for personal information, and if you have customers or employees in Quebec, Law 25 layers on stricter consent, breach notification, and privacy impact assessment requirements. A SOC 2 or ISO 27001 program does not replace PIPEDA or Law 25 compliance, but the access control and incident response work you do for either framework directly supports it.

We work with founders across Canada's tech hubs, Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal, and the pattern holds regardless of city: Canadian startups selling south of the border default to SOC 2, while those with European, government, or multinational buyers lean ISO 27001. Montreal companies with cross-border EU ties are the one segment where we see ISO come up first more often, given the francophone market's ties to European partners.

Can You Just Do Both?

Yes, and eventually most companies that scale past a certain size do. The good news is the frameworks overlap enough that doing one first makes the second meaningfully cheaper and faster. Access control policies, vendor risk assessments, encryption standards, and incident response plans built for SOC 2 map onto a large share of ISO 27001's Annex A controls, and vice versa. Companies that try to build both programs from scratch simultaneously usually end up duplicating work and burning out their engineering team on evidence collection for two separate auditors at once.

The practical sequencing we recommend: get your first framework's controls operating and evidenced, get through your first audit cycle, then map the gap to the second framework rather than starting over. A control library built with both frameworks in mind from day one saves the most time, even if you are only pursuing one certification initially.

How traztech Approaches the Decision

We do not sell a framework, we sell the outcome your buyers are actually asking for. That starts with a fixed-scope gap analysis against whichever framework fits your buyer profile, so you know exactly which controls you already have, which need remediation, and roughly how long the work will take before you commit to an audit timeline. From there we scope the remediation work itself and coordinate with an independent CPA auditor for SOC 2, or an accredited certification body for ISO 27001, so you are not managing two vendor relationships on top of your own product roadmap.

Our full compliance services page covers how the gap analysis, remediation, and audit coordination work fits together, including what a fixed-scope engagement looks like for a startup with a handful of engineers versus a fifty-person company. If you are further along and want to know what CPA-audited security work looks like as an ongoing program rather than a one-time push, our security services overview covers the adjacent work most SOC 2 and ISO 27001 clients end up needing anyway.

If you are stuck deciding between SOC 2 and ISO 27001, or you know you need one and do not know where to start, get in touch with traztech for a straight answer based on what your actual buyers are asking for, not a generic framework pitch.

The Scope Decision Costs More Than the Framework Decision

Founders spend weeks agonizing over SOC 2 versus ISO 27001 and then about ten minutes on scope, which is backwards. Scope is what determines your price, your timeline, and how much of your engineering team gets pulled off the roadmap. Under SOC 2 the scope lives in your system description: which product, which environments, which supporting infrastructure, and which of the five Trust Services Criteria you elected. Security is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional, and every one you add drags in new controls, new evidence, and new auditor sampling. Most early-stage Canadian SaaS companies need Security alone. Adding Availability because a prospect mentioned uptime, without that prospect actually requiring it in writing, is a common and expensive reflex.

ISO 27001 handles this differently and, for a first-timer, less forgivingly. You write a scope statement that defines the boundary of the ISMS, and then you write a Statement of Applicability covering all 93 Annex A controls, justifying each one you include and each one you exclude. The certification body reads the SoA before anything else. A scope statement that says "the provision of the company's SaaS platform" with no boundary conditions invites the auditor to walk into your corporate IT, your laptops, your HR onboarding and your office access. A scope statement that carves out too much invites a buyer to notice the certificate does not actually cover the product they are buying, which is worse than not holding it.

The practical test we use: read your draft scope statement out loud as if you were a procurement analyst who wants a reason to reject you. If the boundary is ambiguous, tighten it before an auditor does it for you.

Where the Money Actually Goes

The audit fee is rarely the largest line. On a first SOC 2, the CPA firm's fee is one cost, the readiness and remediation work is another, and the tooling you end up buying to produce evidence is a third. Then there is the cost nobody quotes: engineering hours. Access reviews, log retention changes, backup restore tests, MDM rollout, secrets management cleanup and infrastructure-as-code documentation all land on the same two or three people who were shipping features. On a ten-person company that is usually the single biggest real expense, and it never appears in a proposal.

ISO 27001 shifts the mix. The certification body charges for a Stage 1 and a Stage 2 audit in year one, then surveillance audits in years two and three, then recertification in year three or four. That is a three-year commitment with an annual cash cost, whereas SOC 2 is a fresh engagement each year with no formal surveillance in between. ISO also demands management-system machinery that SOC 2 does not: a documented risk assessment methodology applied consistently, internal audits performed by someone independent of the work, and a management review meeting with minutes. Those are not hard, but they are recurring, and a startup that has never run an internal audit programme will underestimate the calendar discipline required.

Our fixed-scope readiness work starts at a $3,000 gap analysis precisely so that the scoping conversation happens before anyone signs an audit engagement letter. The published pricing is on our pricing page, and the reason it is published is that the most expensive compliance decisions are the ones made without a number in front of you.

What the Auditors Actually Test, and Where First-Timers Fail

A SOC 2 Type 2 auditor picks samples from your observation window. If you claim quarterly access reviews over a six-month window, they want two reviews with dates, named reviewers, and evidence of what changed as a result. If you claim every change is peer-reviewed before merge, they will pull a sample of pull requests and look for the ones that were merged by the author at 11pm on a Friday. The failure mode is almost never a missing control. It is a control that existed on paper for four months and started operating in month five, which produces an exception in the report even though the company is genuinely secure today.

ISO 27001 fails differently. Stage 1 is a documentation review, and its job is to tell you whether Stage 2 is worth booking. Auditors routinely raise findings at Stage 1 for an SoA with copy-paste justifications, a risk register that has never been updated since the day it was created, or objectives that are not measurable. Stage 2 tests operation, and the outcomes are nonconformities graded minor or major. A minor gets a corrective action plan and a deadline. A major stops certification until it is closed and re-verified, which can push your certificate out by six to ten weeks. The most common major we see is an internal audit programme that either never ran or was run by the person who wrote the controls.

Neither framework has a concept of "pass." SOC 2 can be issued with a qualified opinion listing exceptions, and that report is still a real report you can hand a buyer. Most buyers read the exceptions section, decide whether the exception matters to them, and move on. Founders are far more frightened of exceptions than procurement analysts are.

Subservice Organizations, Carve-Outs, and the Question That Blindsides People

If you run on AWS, Azure or Google Cloud, your SOC 2 report will use either the carve-out method or the inclusive method for those subservice organizations. Almost everyone uses carve-out, which means your report explicitly excludes your cloud provider's controls and lists complementary subservice organization controls you rely on them to perform. That is normal and expected. What catches people is the second half: complementary user entity controls, the things your report says your own customers must do for the controls to work. Write those carelessly and you will spend the next year explaining to buyers why your report puts obligations on them.

ISO 27001 pushes the same problem into supplier management under Annex A. You need a supplier register, risk-rated, with evidence you actually reviewed the important ones. A register with forty SaaS tools all marked "low risk" and no supporting assessment is a finding waiting to happen. Rate three or four as high, do real reviews on those, and document why the rest are low.

The Gap Between Reports, and Why Buyers Ask for Bridge Letters

A SOC 2 Type 2 covers a defined window that ends before the report is issued and long before the next one starts. If your window ended 31 March and a buyer is reviewing you in September, they will ask what happened in between. The answer is a bridge letter, sometimes called a gap letter, signed by management, stating that no material changes to the control environment occurred since the period end. Have a template ready. Companies that do not, lose a week to legal review at exactly the point in the sales cycle where momentum matters.

ISO certificates are cleaner here because the certificate carries a validity date, but the surveillance audit is the equivalent trap. Skip one and the certificate can be suspended, and a suspended certificate discovered mid-deal is far more damaging than never having held one.

When You Should Not Buy Either One Yet

There are real situations where the honest answer is to spend nothing with us. If no buyer has asked in writing, do not start. Anticipatory compliance is the most common way pre-seed companies burn runway. A named prospect with a named security requirement is the trigger. A board member's general anxiety is not.

If your only asking buyer is a single mid-market customer who has not yet signed anything, ask them directly whether a completed security questionnaire, a recent penetration test summary and a documented policy set would let the deal proceed while your audit runs. A surprising number of buyers say yes, especially when the alternative is waiting four months for a report. That path costs a fraction of an audit and buys you the revenue that funds the real programme later.

If you have fewer than five people, no production customer data of consequence, and a product still changing shape every sprint, an ISO 27001 ISMS will not survive contact with your own roadmap. Management reviews and internal audits assume a company stable enough to have a process worth auditing. Come back when you have one.

And if what your buyer actually wants is assurance that your application is not trivially exploitable, a penetration test starting at $1,000 answers that question far faster and more directly than either framework does. We would rather sell you the test than an audit you do not need. Our security services cover that work, and compliance is there when the audit requirement is genuinely real.

Running Both Without Paying Twice

The teams that end up holding both frameworks cheaply are the ones that built a single control library from the start, with each control tagged to the SOC 2 criteria and the Annex A references it satisfies, and each piece of evidence stored once with a clear owner and a refresh cadence. The teams that pay twice are the ones with a SOC 2 evidence folder, an ISO evidence folder, and no idea which is authoritative.

Two practical rules make the difference. First, name a single owner per control, a person and not a team, because "engineering owns it" produces evidence nobody collected. Second, decide your evidence titles once and keep them stable across frameworks, since free-text titles that drift between audits are the reason register rows duplicate and overlap claims fall apart. If you want somewhere to hold that library without buying a platform, the free traztech Workspace is built for exactly this, and if you want the ISMS built properly the first time, our ISO 27001 implementation track is the fixed-scope version of that work.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.

ISO 27001 readinessOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.