Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Every framework page explains what a standard asks for. This one explains what the work involves: the four phases, the evidence you will be asked for, what we do against what you do, and the workspace you run it in. If you are deciding whether to start, this is the page that tells you what you are agreeing to.
The shape is the same whichever framework you are pursuing. What changes is the length of phase three, because that is where the observation window lives.
The first decision is the boundary: which systems, which sites, which people. It sounds administrative and it is the most consequential choice in the programme. An ISMS needs a defined scope, SOC 2 needs a system description, and an auditor will hold you to both. Get it wrong and you either do work you never needed, or find in month three that something in production was never inside it.
Then the assessment itself: current state against every control in scope, with the gaps written down and ranked. If you are pursuing two frameworks we map them against each other here, because the overlap is where the savings are and you cannot bank them once two separate programmes exist.
We do the assessment, the mapping and the findings. You do one scoping conversation and point us at the systems.
The instinct is to work top down by severity. Better to clear anything blocking evidence collection first. An access review with no owner is one finding; if it also means you cannot produce a single completed review when the auditor samples the period, it has quietly eaten your timeline too.
Policies get written here, but writing policies is the small part. The work is making the control actually run, on a schedule, with an owner, producing something dated.
We do the design, the drafting and the chasing. You do the decisions only you can make, and approve the policies.
This is where the programme becomes concrete. We issue a document request list covering every artefact needed to evidence your controls. On a recent SOC 2 engagement that ran to 84 items, which is typical rather than unusual.
The number surprises people, so it is worth being blunt about why. An auditor does not accept a policy as evidence that a control operates. They want the artefact the control produced. A policy stating that access is reviewed quarterly evidences nothing; the completed review, dated, with the reviewer named and the resulting changes recorded, evidences the control. One control routinely needs several artefacts.
The audit firm is engaged during this phase rather than after it. Scope, sampling approach and what counts as sufficient evidence are all matters you discuss with them, not instructions you receive. A team that first speaks to its auditor when it believes it is ready has given that conversation away.
We do the request list, the review, and the auditor relationship. You do the retrieval, with us telling you exactly what will and will not pass.
The audit firm performs its own work and issues its own opinion. We cannot influence that and would not want to, because the independence that stops them helping you is the same thing that makes the report worth handing to a buyer.
What we do during fieldwork is absorb it. Sampling requests come to us, evidence goes back in the form they asked for, and questions get answered without pulling your engineers into a thread they have no context for.
Arriving prepared also changes the number. On one engagement the firm took $11,000 off a five-figure quote once the readiness position was set out and a prep firm was confirmed on the programme. That is not a negotiated discount; it is a smaller estimate because there was less uncertainty to price.
We do the sampling responses and the coordination. You do very little, which is the point.
Taken from a real SOC 2 document request list. Yours will differ by framework and scope, but the categories hold, and so does the ratio: most items are artefacts a control produced, not documents describing a control.
If you want to know where you stand before talking to anyone, the auditor evidence request simulator runs the same exercise against your own answers and gives you the gap list.
The programme runs in a workspace we do not charge for: 10 frameworks with every control explained in plain English, an evidence register, 40 policy templates, a risk register and vendor questionnaires. It is the same register we work from, so a requested artefact lands against the control it evidences rather than in an email thread. You keep all of it when the engagement ends.
Each row is tied to the controls it evidences, so a single artefact can satisfy several at once and you are not uploading the same document five times. The status is what we work from during phase three, and it is what tells you honestly how far along you are, rather than a percentage that moves when you upload anything at all.
That translation layer is a large part of what a first-time candidate is paying for anywhere. If the tool does not do it, a person has to, and that person bills. The rest of the workspace is covered on the traztech Workspace page, and it is free to use whether or not you work with us.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Our SOC 2 track is 75 days of preparation, and we have hit that window every time we have run it. ISO 27001 typically runs longer because the management system, internal audit and management review have to exist before a certification body will assess you. The binding constraint is usually the observation window for a Type II rather than the control work itself.
Less than most people expect, but not nothing. You need one person who can make decisions about scope, and named owners for the controls we identify. Most of the evidence already exists somewhere in your systems; the work is finding it, judging whether an auditor will accept it, and filling the gaps. We do not ask engineers to fill in compliance spreadsheets.
It is the list of artefacts needed to evidence your controls. On a recent SOC 2 engagement it ran to 84 items. The number surprises people because an auditor does not accept a policy as evidence that a control operates; they want the artefact the control produced, and one control frequently needs several.
No. traztech Workspace is free and holds the control sets, the evidence register, the policy templates and the readiness scoring. You keep it when the engagement ends, which matters at the next audit cycle. If you already run a commercial platform we will work inside it instead.
During remediation, not after it. Scope, sampling and what counts as sufficient evidence are all things you discuss with an auditor rather than receive from one. Bringing them in early also means a disagreement about evidence surfaces in week three rather than during fieldwork.
Failing outcomes are real: adverse opinions, disclaimers, and a major nonconformity at ISO 27001 Stage 2 that withholds the certificate. But plan against the paused engagement, because it costs more. The firm reaches fieldwork, finds nothing testable, and stops, so you have bought an audit with no report and pay again to re-enter. The point of preparation is that the question is settled before anyone is sampling for an answer. Where a control will not pass as designed, we say so and rebuild it, which an audit firm is barred from doing for you by the independence rules that make their opinion worth having.
Before the observation window opens, not before fieldwork starts. A Type II tests whether each control operated across the whole stated period. A control switched on partway through is only evidenced from that day, and the usual remedy is to move the window, which moves your report by months. We set the window start and the control go-live dates in the same conversation, in phase one.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
A few short notes on getting through a readiness programme, including what auditors actually accept as evidence. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.