Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Most companies reach for ISO 27001 because a European or global buyer asked for it. This is a plain-language guide to what the standard actually is, the steps to get certified, a realistic timeline, and what it costs. We are a Toronto prep partner: we get you ready and coordinate the certification body, so you walk into the audit prepared.
Book a discovery callISO 27001 is an international standard for running an information security management system, usually shortened to ISMS. An ISMS is not a document or a tool. It is the ongoing set of policies, processes, and controls you use to keep information secure, plus the habit of measuring and improving them. The standard describes what that system has to include, and an accredited registrar, also called a certification body, audits you against it and issues the certificate if you pass.
The word certificate matters. Unlike SOC 2, which produces an attestation report signed by a CPA firm, ISO 27001 produces a certificate granted by a registrar. Both prove you take security seriously, but they come from different worlds. If you want the full comparison, read our guides on SOC 2 and ISO 27001 for startups and SOC 2 versus ISO 27001. The short version: SOC 2 is the North American default, ISO 27001 is what the rest of the world tends to ask for, and the controls underneath them overlap a great deal.
Certification is a defined sequence. You build the management system, prove to yourself that it works, and then the registrar checks it in two stages. Here is the whole path.
Decide what the management system covers: which products, teams, locations, and systems are in and out. Scope drives everything after it, including cost, so getting this right early keeps the project honest.
Identify the risks to the information in scope, judge how likely and how damaging each one is, then decide what to do about each: reduce it, accept it, transfer it, or avoid it. That set of decisions becomes your risk treatment plan, which is the backbone of an ISO 27001 program.
Work through the Annex A controls and record which ones apply to you, which do not, and why. The SoA is the document a registrar reads first, because it maps your risks to the controls you have chosen to put in place.
Put the Annex A control themes into practice across organizational, people, physical, and technological areas: access control, change management, logging and monitoring, supplier and vendor management, secure development, and incident response. This is where readiness turns into real, working security rather than paperwork.
Before the registrar shows up, you audit yourself. An internal audit checks that the ISMS is actually operating, and a management review puts the results in front of leadership so decisions and improvements are on record. Both are required by the standard, not optional extras.
The registrar reviews your ISMS documentation, scope, SoA, and risk work to confirm you are ready. Think of it as a readiness check that surfaces gaps before the real thing.
The registrar tests whether your controls are working in practice, gathering evidence and interviewing your team. Pass it and the certificate is issued. After that, expect yearly surveillance audits to keep it valid.
For a startup running on modern cloud infrastructure, plan for roughly 16 weeks of readiness work before you sit the Stage 1 and Stage 2 audits. The audits are then scheduled with your registrar and add a few more weeks on top. Older or more complex environments, or a wide scope, push that number up.
In terms of effort, ISO 27001 is comparable to a first SOC 2, but it leans more heavily on documentation. SOC 2 is largely about showing evidence against a set of trust criteria. ISO 27001 asks you to stand up a formal ISMS, produce a risk treatment plan, write the Statement of Applicability, and run an internal audit before the registrar ever arrives. None of that is hard on its own, but it is more process, so building it with someone who has done it before saves weeks.
There are two clearly separate costs, and it helps to keep them apart in your head. The first is the registrar, or certification body, which runs the Stage 1 and Stage 2 audits and the yearly surveillance audits after that. Registrar fees are usually priced in USD and scale with the size and complexity of your scope, so a small, focused scope costs meaningfully less than a broad one. We do not quote the registrar; they are independent from us by design.
The second cost is readiness, which is our part. We price it as a fixed scope so you know the number before you start, rather than an open hourly meter. On top of those two, some teams add compliance tooling to automate evidence collection, which is a smaller, optional line item. For a broader way to think about compliance budgets, our guide to SOC 2 cost uses the same logic that applies here.
Honest note: we do not publish a single sticker price for ISO 27001, because it depends almost entirely on your scope. Anyone quoting a firm number before they understand your scope is guessing.
ISO 27001 and SOC 2 share a large amount of underlying work. Access control, change management, risk assessment, vendor management, and logging and monitoring show up in both. If you have done one, you are not starting the other from zero. The evidence, policies, and control implementations you built the first time carry over, so the second framework is mostly about reframing what you have and filling the gaps that are genuinely specific to it.
That is why teams who expect to need both often plan for it up front and build the evidence once. We walk through exactly how the two line up in our guide on SOC 2 and ISO 27001 for startups.
Be direct about the stakes, because ISO is stricter than SOC 2. Stage 2 findings are graded: a minor comes with a corrective action window, a major nonconformity withholds the certificate until you remediate and the body verifies the fix, at audit days you pay for. You can sit Stage 2 and leave without a certificate.
The majors are predictable, which is the useful part. An undefined ISMS scope, a Statement of Applicability with unjustified exclusions, an internal audit that never ran, a management review that is a calendar invite rather than a record. Those are absences, and absences are what readiness is for.
We are a prep partner, not the registrar. We build the ISMS with you, run the risk assessment and risk treatment plan, draft the Statement of Applicability, implement the Annex A controls, run your internal audit and management review, and coordinate the certification body through Stage 1 and Stage 2. What we do not do is issue the certificate, because keeping readiness and certification separate is how ISO 27001 is meant to work.
What makes us different is that we are unusually technical about it. Our founder is a published security researcher with five published CVEs, including CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet, so the controls we build hold up when a buyer or an auditor starts poking at them. We quote fixed scope, and because we are Canadian, we handle the PIPEDA and Quebec Law 25 overlap so you do not build the same evidence twice.
Tell us your scope, your deadline, and which buyer is asking. We will map the path, quote a fixed scope, and coordinate the registrar so certification is a formality, not a scramble.
Start your ISO 27001 prepIt usually comes down to who is asking. North American buyers tend to ask for a SOC 2 report, while European and global buyers tend to ask for an ISO 27001 certificate. If your customers are naming ISO 27001 in security questionnaires or contracts, that is your answer. Many companies eventually do both, because the underlying controls overlap heavily and evidence you build for one carries into the other.
For a startup on modern cloud infrastructure, plan for roughly 16 weeks of readiness work before you sit the Stage 1 and Stage 2 audits. The audits themselves are scheduled with your registrar and add a few more weeks. The effort is comparable to a first SOC 2, but ISO 27001 is more documentation-heavy because you have to stand up a formal ISMS, a risk treatment plan, and an internal audit.
There are two separate costs. The registrar, or certification body, charges its own fee for the Stage 1 and Stage 2 audits and the yearly surveillance audits after that. Those fees are usually priced in USD and scale with the size and complexity of your scope. Separately, readiness work is a fixed-scope fee that we quote up front. Optional compliance tooling is a third, smaller line item. We do not publish a single number because it depends entirely on your scope.
Yes, more directly than a SOC 2. Stage 2 findings are graded. A minor nonconformity comes with a corrective action window and does not block certification. A major nonconformity means the certificate is not issued until you remediate and the certification body verifies the fix, at additional audit days you pay for. You can sit Stage 2 and leave without a certificate. The usual causes are an undefined ISMS scope, a Statement of Applicability with unjustified exclusions, an internal audit that never ran, and a management review with no record behind it. More on what goes wrong.
No. The ISO 27001 certificate is issued by an accredited registrar, also called a certification body, and only they can grant it. We are your prep partner. We build the ISMS, close the gaps, run the internal audit, and coordinate the registrar so the Stage 1 and Stage 2 audits go smoothly. Keeping readiness and certification separate is how the standard is meant to work.
It is not harder so much as more formal. SOC 2 is a set of trust criteria you show evidence against. ISO 27001 asks you to run an actual management system: define scope, assess risk, write a risk treatment plan, produce a Statement of Applicability, and audit yourself before the registrar audits you. The technical controls overlap a lot, but the paperwork and process discipline are heavier.
traztech Workspace has all 93 Annex A controls and 25 ISMS clauses (4-10) of ISO 27001 written in plain English, with what the standard asks for, what to do about it, and somewhere to attach the proof. You answer them, it scores you, and nothing is locked behind an upgrade.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.