Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A major nonconformity is a Stage 2 finding serious enough to block ISO 27001 certification: a required element of the management system is absent, a control has failed systemically, or several minor findings point at the same underlying process failure. The certificate is withheld until the finding is remediated and verified.
The distinction matters commercially. Minors are normal and get a corrective action window. A major moves your certification date and adds audit days to the invoice.
Most majors are avoidable at the readiness stage, because they are absences rather than weaknesses. The internal audit either happened or it did not.
traztech delivers ISO 27001 implementation and Stage 2 readiness for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
It comes up at Stage 2, which is the point where ISO 27001 stops being a documentation exercise. A certification body grades what it finds, and the grade decides whether a certificate is issued that day.
It also comes up in planning, because the majors are predictable. A scope that was never properly defined, a Statement of Applicability with unjustified exclusions, an internal audit that never ran and a management review that exists only as a calendar invite account for a large share of them.
More directly than SOC 2, yes. A major nonconformity at Stage 2 blocks certification until you remediate and the body verifies the fix, usually at additional audit days you pay for.
A minor is an isolated lapse and comes with a corrective action window without blocking the certificate. A major is a systemic failure, an entirely absent requirement, or several minors pointing at the same broken process.
Certification bodies typically set a window of a few months and then verify. The practical cost is the delay and the extra audit days, not the finding itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.