Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Major Nonconformity (ISO 27001)

A major nonconformity is a Stage 2 finding serious enough to block ISO 27001 certification: a required element of the management system is absent, a control has failed systemically, or several minor findings point at the same underlying process failure. The certificate is withheld until the finding is remediated and verified.

In practice

The distinction matters commercially. Minors are normal and get a corrective action window. A major moves your certification date and adds audit days to the invoice.

Most majors are avoidable at the readiness stage, because they are absences rather than weaknesses. The internal audit either happened or it did not.

// how traztech helps

traztech delivers ISO 27001 implementation and Stage 2 readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

It comes up at Stage 2, which is the point where ISO 27001 stops being a documentation exercise. A certification body grades what it finds, and the grade decides whether a certificate is issued that day.

It also comes up in planning, because the majors are predictable. A scope that was never properly defined, a Statement of Applicability with unjustified exclusions, an internal audit that never ran and a management review that exists only as a calendar invite account for a large share of them.

Major Nonconformity (ISO 27001): common questions

Can you fail an ISO 27001 audit?

More directly than SOC 2, yes. A major nonconformity at Stage 2 blocks certification until you remediate and the body verifies the fix, usually at additional audit days you pay for.

What is the difference between a major and a minor?

A minor is an isolated lapse and comes with a corrective action window without blocking the certificate. A major is a systemic failure, an entirely absent requirement, or several minors pointing at the same broken process.

How long do you get to fix a major?

Certification bodies typically set a window of a few months and then verify. The practical cost is the delay and the extra audit days, not the finding itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.