Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →ISO 27001 is an international standard for an Information Security Management System, or ISMS, that specifies how to manage information security through risk assessment and continual improvement. An accredited body audits and certifies organizations against it. Unlike SOC 2, ISO 27001 results in a formal certificate recognized worldwide.
ISO 27001 is process-led. It requires you to build a risk-based management system, select controls (drawn from Annex A and ISO 27002), and prove you operate and improve them over time.
It is often preferred by buyers in Europe, the UK, and Asia, where SOC 2 carries less weight. Many companies pursue both, mapping the heavily overlapping controls once and presenting them to each audience.
traztech delivers ISO 27001 readiness leadership for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
ISO 27001 usually enters the conversation when a buyer outside North America, or a procurement team working from an approved standards list, asks for a certificate rather than a report.
The part that surprises SOC 2-experienced teams is the management system. A defined scope, a risk assessment methodology you can show your working for, a Statement of Applicability, internal audit and management review are all required and have no direct SOC 2 equivalent.
Not harder, different. The control overlap is substantial. What ISO adds is the management system: risk methodology, Statement of Applicability, internal audit and management review, all evidenced.
Three years, with surveillance audits in between. It is a cycle rather than a one-off, which is worth budgeting for at the outset.
A 2024 amendment requiring climate change to be considered in your analysis of interested parties and their requirements. Certification bodies expect to see it reflected, and older template documentation predates it.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.