Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Observation Period (SOC 2 Type II)

The observation period is the window of time a SOC 2 Type II report covers, typically three to twelve months. The auditor samples evidence from across the whole window to confirm each control operated consistently, not just that it existed on the day of testing.

In practice

Controls need to be live and producing dated evidence before the window opens. Anything switched on inside it is only evidenced from the day it started.

Because the window has to elapse, it usually sets your report date rather than the control work does. Plan backwards from the date your buyer needs the report.

// how traztech helps

traztech delivers SOC 2 readiness and audit prep for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

It comes up as a date question and turns into a timeline problem. A Type II report attests that controls operated across a stated period, so the period has to elapse before the report can exist.

The expensive version is a control implemented partway through the window. Turning on MFA a fortnight before fieldwork gives you a fortnight of evidence in a three to twelve month period, and the rest of the window is an exception.

Observation Period (SOC 2 Type II): common questions

How long should the observation period be?

Three months is common for a first Type II and twelve for a mature cycle. Shorter is cheaper and faster, and some enterprise buyers discount it, so the length is a commercial decision as much as a technical one.

What happens if we implement a control mid-window?

The auditor tests the whole period, so the months before implementation are exposed. The usual remedy is to move the window, which pushes the report by months.

Does the observation period start when we sign with an auditor?

No. You set the start date, and it should be after your controls are live and producing evidence. Choosing it well is one of the highest-leverage decisions in the programme.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.