Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →The observation period is the window of time a SOC 2 Type II report covers, typically three to twelve months. The auditor samples evidence from across the whole window to confirm each control operated consistently, not just that it existed on the day of testing.
Controls need to be live and producing dated evidence before the window opens. Anything switched on inside it is only evidenced from the day it started.
Because the window has to elapse, it usually sets your report date rather than the control work does. Plan backwards from the date your buyer needs the report.
traztech delivers SOC 2 readiness and audit prep for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
It comes up as a date question and turns into a timeline problem. A Type II report attests that controls operated across a stated period, so the period has to elapse before the report can exist.
The expensive version is a control implemented partway through the window. Turning on MFA a fortnight before fieldwork gives you a fortnight of evidence in a three to twelve month period, and the rest of the window is an exception.
Three months is common for a first Type II and twelve for a mature cycle. Shorter is cheaper and faster, and some enterprise buyers discount it, so the length is a commercial decision as much as a technical one.
The auditor tests the whole period, so the months before implementation are exposed. The usual remedy is to move the window, which pushes the report by months.
No. You set the start date, and it should be after your controls are live and producing evidence. Choosing it well is one of the highest-leverage decisions in the programme.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.