Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Audit Opinion (Unqualified, Qualified, Adverse)

An audit opinion is the conclusion a licensed CPA firm writes into a SOC 2 report. An unqualified opinion is clean. A qualified opinion notes exceptions that are not pervasive. An adverse opinion states the controls do not meet the criteria. A disclaimer means the firm could not gather enough evidence to conclude at all.

In practice

Unqualified is the target and qualified is survivable. Adverse opinions are rare, largely because an engagement heading that way tends to be paused before an opinion is written.

A paused engagement is the outcome to plan against. The audit fee is already spent, the buyer waiting on the report has to be told the date moved, and fieldwork gets paid for twice.

// how traztech helps

traztech delivers What actually goes wrong in a SOC 2 audit for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

It comes up when somebody asks whether you can fail a SOC 2. The honest answer is yes, in more than one way. There is no pass or fail stamp, there is an opinion, and two of the four possible opinions are outcomes you would not want to hand a buyer.

It also comes up when a report lands with exceptions in it. An exception is not automatically fatal to a deal, but it is read, and the management response printed underneath it is read too.

Audit Opinion (Unqualified, Qualified, Adverse): common questions

Can you fail a SOC 2 audit?

Yes, though not as a stamp. Adverse opinions and disclaimers are both real outcomes. What usually happens to an unprepared company is worse than either: the engagement stalls during fieldwork and the firm recommends pausing, so you have paid for an audit that produced no report and re-entering fieldwork means paying again.

Does a qualified opinion kill a deal?

Usually not on its own. It invites questions. A reviewer will want to know what the exception was, why it happened and what changed, so the management response matters as much as the finding.

Who decides the opinion?

The licensed CPA firm performing the examination, independently. A readiness partner cannot influence it, which is exactly why the report is worth something.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.