Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
SOC 2 · ISO 27001 · Explainer

Can you fail
a SOC 2 audit?

Yes, in three different ways, and the one that costs you most is the one nobody warns you about. An adverse opinion and a disclaimer are both real outcomes that get written into real reports. ISO 27001 will withhold a certificate outright for a major nonconformity at Stage 2. But the outcome an unprepared company usually gets is worse than either: the engagement stalls partway through fieldwork, and you pay for the audit twice.

Find out where you stand Run the evidence simulator

There is no failing stamp. There is an opinion.

SOC 2 is an attestation, not a certification, so nothing is issued or withheld. A licensed CPA firm examines your controls and writes an opinion into the report. There are four of them.

OpinionWhat it meansHow a buyer reads it
UnqualifiedClean. Controls were suitably designed and, for a Type II, operated effectively across the period.The result everyone is aiming for. Goes into the data room without comment.
QualifiedExceptions were found and are listed, but they are not pervasive enough to undermine the report.Readable, and read. Expect follow-up questions from a security reviewer about each exception and your response to it.
AdverseFailures significant enough that the controls cannot be said to meet the criteria.Rare, and damaging. A report you would not want to circulate.
DisclaimerThe firm could not obtain enough evidence to form any opinion at all.Reads as an absence of a report rather than a bad one.

All four happen. Adverse opinions and disclaimers are rarer than the other two, but the reason is not that unprepared companies do well. It is that the engagement usually ends before an opinion is written at all. The firm gets into fieldwork, works through the document request list, finds that a meaningful share of the evidence does not exist in a form it can test, and has the conversation that begins with a suggestion to pause.

People hear that and relax, which is the wrong reaction. A pause is not the audit letting you off. It is the most expensive outcome on the list.

A stalled engagement costs more than a bad opinion

A qualified opinion is a report you can hand a buyer while you answer questions about the exceptions. A paused engagement is not a report at all, and every line below lands at once.

What it costs youQualified opinionPaused engagement
Audit feePaid once. You have a report.Paid, and largely spent. Re-entering fieldwork means paying a firm again, against quotes that commonly run USD 10,000 to 30,000 and up.
Report to give a buyerYes, with exceptions and your management responses attached.None. The deal that triggered this is still blocked.
TimelineIssued on schedule.Reset. If the gap affects a Type II you may need a fresh observation window, which is another three to twelve months before a report can exist.
Readiness workDone, imperfectly.Still entirely ahead of you, now on a compressed schedule with a spent budget.
Internal costA period of evidence gathering.The same period, wasted, plus a second one. Engineering time is the line nobody puts in the business case and everybody pays.
CredibilityExceptions get explained.Your buyer, your board or your investor gets told the date moved, without a document to show for it.

Put plainly. Going to an audit firm before you are ready does not risk a bad report. It risks buying the audit twice and getting nothing the first time. The readiness work is not the cost you avoid by skipping it, it is the cost you defer and then pay at a worse moment.

Stage 2 is where a certificate is genuinely withheld

ISO 27001 works differently, and more strictly. A certification body assesses you in two stages: Stage 1 reviews the management system on paper, Stage 2 tests whether it is implemented and operating. Findings at Stage 2 are graded.

A minor nonconformity is a single lapse against a requirement. You get a corrective action window, usually a few months, and certification proceeds. A major nonconformity is a systemic failure, an absent requirement, or a set of minors pointing at the same broken process. It blocks the certificate. You remediate, the body verifies the remediation, and you pay for the additional audit days that verification takes.

So the answer for ISO is straightforward. You can walk into Stage 2 and walk out without a certificate, and it happens more often than the market talks about. The usual causes are an ISMS scope that was never properly defined, a Statement of Applicability with exclusions that were never justified, an internal audit that was never run, and a management review that exists as a calendar invite rather than a record.

The seven things that stall an engagement

These recur regardless of company size, and none of them are about a company being insecure. They are about the distance between running a control and being able to prove you ran it.

01
Evidence

The control runs, but only in someone's head

The team genuinely does the quarterly access review. They can describe it in detail. There is no artefact: no dated spreadsheet, no ticket, no screenshot, no record of who reviewed what and what changed as a result. For a Type II the auditor needs proof the control operated across the whole period, and a description of the process is not that proof.

What fixes it: designing every control so it produces something dated with an owner's name on it, before the window opens rather than after.

02
Policy drift

The policy promises more than the system enforces

The password policy specifies fourteen characters and quarterly rotation; the identity provider is set to eight and never expires. The access control policy commits to quarterly reviews; the last one was eleven months ago. Auditors test against what your policy says, not against what they think is reasonable for a company your size. Every gap between the document and the configuration becomes an exception, which means an overwritten policy is an act of self-harm.

What fixes it: writing policies against the systems you actually run, and changing the system first where the policy should win.

03
Timing

Controls implemented inside the observation window

A team turns on MFA a fortnight before fieldwork and considers the control covered. In a three to twelve month observation period, that control has a fortnight of evidence and the rest of the window is an exception. This is the most expensive misunderstanding in compliance, because the remedy is usually to move the observation window, and that moves the report by months. It is also the one a first-time candidate is least likely to catch on their own.

What fixes it: fixing the window dates and the control go-live dates in the same conversation, at the start.

04
Scope

The boundary is wrong in one direction or the other

Too narrow, and a system that should have been in scope surfaces during a walkthrough, which reopens scoping after the work has started. Too broad, and you have multiplied the evidence requests, the remediation and the cost for systems no buyer was asking about. For ISO the same problem shows up in the Statement of Applicability, where controls marked not applicable without a documented justification get picked up immediately.

What fixes it: treating the boundary as the first deliverable of the programme rather than an administrative form.

05
Vendors

Third-party management is the last thing anyone does

Thirty SaaS tools in the stack, signed data processing agreements for three of them, and no clear answer on which vendors are subprocessors. SOC 2 asks about this at CC9.2, and ISO 27001:2022 at A.5.19 through A.5.22. It is tedious work with no visible payoff until an auditor asks, so it sits untouched, and it produces exceptions reliably.

What fixes it: a tiered vendor inventory built once, with the assessment depth matched to what the vendor can actually reach. Our third-party risk work is this and nothing else.

06
Tooling

The dashboard is green and the evidence still does not hold

A compliance platform reads what it can reach: cloud configuration, device posture, who has an account. It confirms those look right, and the score climbs. It does not know whether your access review procedure ran, whether your incident response plan has ever been tested, or whether the change management policy you uploaded describes how your team really deploys. The platform measures what it can see, and the exceptions get written in the space it cannot.

What fixes it: treating the platform as an evidence collector rather than a readiness verdict. We work inside Vanta or Drata where a client already has one.

07
Ownership

Nobody inside the company owns the programme end to end

The CTO understands the infrastructure and has not read the Trust Services Criteria. Whoever is running compliance has read the criteria and does not know how the deploy pipeline works. Neither of them is wrong, and the translation between the two is where the schedule goes. When it falls to the audit firm, you are paying audit rates for interpretation work, and they are constrained in how much of it they are allowed to do for you.

What fixes it: someone who reads both, whether that is a hire, a fractional CISO, or the readiness partner.

What clients say after a rough audit

The sentence takes roughly the same shape every time. Somebody should have told us exactly what the auditor was going to ask for, in the format they needed it, before we started paying them.

That is the whole gap. Not framework knowledge, which is published. Not tooling, which is available. Not policies, which are downloadable. It is the translation between what a company does every day and what an examiner will accept as proof of it, done early enough to still be cheap.

Companies that arrive with that work already done have a different audit. The gap analysis ran against the full control set, the evidence was mapped to the request list before the request list arrived, the gaps were closed while closing them was still just work. Fieldwork is shorter, exceptions are few or none, and the audit gets paid for once. On one engagement the firm took $11,000 off a five-figure quote once the readiness position was documented, because there was less uncertainty left to price: how that happened.

What we actually sell. Not help getting SOC 2. We make sure your auditor never has to pause the engagement, reopen the scope, or run fieldwork twice. We are the prep half, and by the independence rules that make the report worth having, it cannot be the same firm that signs it.

Frequently asked questions

Can you fail a SOC 2 audit?

Yes, though not as a pass or fail stamp. A licensed CPA firm issues an opinion, which can be unqualified (clean), qualified (exceptions noted), adverse, or a disclaimer where the firm could not gather enough evidence to opine. Adverse opinions and disclaimers both happen and both are damaging. What happens more often to an unprepared company is worse than either: the firm gets into fieldwork, finds the evidence is not there in a testable form, and recommends pausing. You have paid for an audit that produced no report, the deal that triggered it is still blocked, the readiness work is still ahead of you, and re-entering fieldwork means paying a firm again.

What is a qualified SOC 2 opinion?

A qualified opinion means the auditor found exceptions, meaning instances where a control did not operate as described, but the exceptions are not pervasive enough to undermine the whole report. The exceptions are listed in the report along with management responses. Buyers do read them. A qualified report is not worthless, but it invites questions in a security review that a clean one does not.

Can you fail an ISO 27001 audit?

ISO 27001 is more binary than SOC 2. A certification body runs Stage 1 on your documentation and Stage 2 on your implementation. A major nonconformity at Stage 2 means the certificate is not issued until you remediate and the finding is verified, usually at additional audit days you pay for. Minor nonconformities come with a corrective action window and do not block certification. So yes, you can walk into Stage 2 and walk out without a certificate.

What happens if the auditor pauses our SOC 2 engagement?

You rebuild the evidence position and re-enter fieldwork, which means a second engagement fee against quotes that commonly run USD 10,000 to 30,000 and up, and a fresh observation window of three to twelve months if the gap affects a Type II. Two costs get forgotten in the business case. The first is engineering time, spent once on the failed attempt and again on the real one. The second is that the buyer, board or investor who asked for the report gets told the date moved, with no document to show for the money already spent.

Our Vanta or Drata dashboard is all green. Does that mean we will pass?

It means the checks the platform can automate are passing. A platform reads your cloud configuration and your device fleet. It cannot confirm that your access review procedure actually ran with a named reviewer, that your incident response plan was ever tested, or that your written change management policy matches how your team really deploys. Those are the areas where exceptions get written, and they are the ones a person still has to work.

How early should we implement controls before a Type II?

Before the observation window opens, not before fieldwork starts. A Type II tests whether controls operated across the stated period. Turning on MFA two weeks before the auditor arrives gives you two weeks of evidence in a three to twelve month window, and the exception gets written. This is the most expensive misunderstanding in compliance because the fix is usually to move the window, which costs you months.

Find out before the auditor does

Thirty minutes on your scope, your window and what your buyer is asking for. You will leave knowing which of the seven above apply to you, whether or not you hire us. If the audit has already stalled, audit recovery is the engagement built for that.

Book a free readiness call

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered
$11k
Taken off one client's audit quote by arriving ready

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Want to know what your auditor will ask for?

Short notes on what examiners actually accept as evidence, and where readiness programmes come apart. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.