Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Audit Recovery

From $3,000 CAD · scoped to you

A stalled audit is very recoverable, because you now have a professional opinion, in writing, about exactly what is missing. We treat the findings as symptoms and fix the controls that produced them, so you re-enter fieldwork once and finish.

Book a discovery call See pricing

What we do

A read of the auditor's findings against the underlying control design, separating the instances from the causes

A decision on the observation window

whether the existing one is salvageable, or whether a fresh window is cheaper than defending this one

Scope re-examination, since a boundary that was wrong the first time will produce findings the second time
Remediation of the causes, with every control rebuilt to produce a dated artefact with a named owner
A re-evidenced request list, reviewed against what your firm has already said it will not accept
Direct handling of your existing audit firm or certification body, including the conversation about re-entry timing
A written position you can give the buyer waiting on the report, so the second date is credible
Clean Audit Guarantee

If we prepped it and it fails, we fix it free

Go through Phase 1 and Phase 2 with us, the gap analysis and the remediation support, and if your audit or certification returns a qualified opinion, a major nonconformity (MNC), or the equivalent on a control we prepared, we provide the remediation support to resolve it at no charge.

Built for teams that...

  • Your auditor recommended pausing the engagement partway through fieldwork
  • Your SOC 2 report came back with a qualified opinion and the next window is already running
  • An ISO 27001 Stage 2 raised a major nonconformity and the certificate is withheld
  • You are inside a corrective action window with a date you are not confident about
  • A buyer, board or investor has already been given a date that has now moved

What you walk away with

You re-enter fieldwork once, with the evidence in the form your firm has already told you it needs, and the cause of the original finding closed rather than papered over.

Explore related work

The workspace is included, not quoted

The price above covers the work. It also covers where the work lives, which most buyers are quoted separately as an annual platform subscription.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote A documented readiness position the audit firm can scope and price against Nothing. The audit firm prices your readiness, not your tooling

Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.

Frequently asked questions

Can we use the same audit firm?

Usually yes, and usually you should. They know the environment, they have already done the scoping work, and re-entering with a firm that understands what changed is faster than starting a relationship over. The exception is where the relationship has broken down or the original scoping was the problem. We will tell you which situation you are in rather than defaulting to a switch.

Do we have to start the observation window again?

It depends on where the gap sits. If a control simply was not evidenced, the window may hold. If a control was not operating for part of the period, the window covering that period cannot be repaired after the fact, and a fresh one is the honest answer. This is the first thing we determine, because everything else follows from it.

How is this different from your normal readiness work?

The starting point. First-time readiness begins with a gap assessment against the whole control set. Recovery begins with a professional opinion about what is already wrong, which is more specific and more misleading, because the findings are instances and the fixes have to happen at the level of the control that produced them.

Will the exceptions show up in future reports?

The exceptions belong to the report they were written into, and that report does not change. What matters for the next one is that the period it covers is clean. Buyers who read a prior report with exceptions care about the management response and whether the same finding recurs, which is exactly why fixing the cause rather than the instance is the whole engagement.

What does it cost?

It is scoped like any readiness engagement and quoted fixed, from the same published floor. What we will not do is price a premium for urgency. The audit firm fee for re-entering fieldwork is separate and paid to them, as always.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Audit Recovery, on your timeline

Book a free 30-minute call, or send an inquiry. We’ll tell you whether it fits, what it costs, and when we can start.

Book a call Send an inquiry