Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Several frameworks require your programme to be audited by somebody who did not build it. ISO 27001 asks for it twice, in clause 9.2 and again in control A.5.35. SOC 2 asks for a separate evaluation under CC4.1. HIPAA requires a periodic evaluation outright. We are the independent auditor for that requirement, whether we did your readiness work or, more often, whether somebody else did.
If we built your ISMS, we will not audit it. Clause 9.2.2 requires auditors selected so that objectivity and impartiality are ensured, and A.5.35 asks for independence explicitly. Auditing a management system we designed would not survive a certification body's first question about it, so we refer that work out and say so up front.
Internal audit is one of the few requirements that appears, in some form, in nearly every framework we work in. The wording differs and so does what an assessor will accept as evidence.
| Framework | Reference | What it requires | Evidence expected |
|---|---|---|---|
| ISO/IEC 27001:2022 Clause 9.2 (9.2.1, 9.2.2) |
Internal audit | The ISMS must be audited at planned intervals against both the standard and your own requirements. Clause 9.2.2 requires an audit programme covering frequency, methods, responsibilities and reporting, and requires auditors to be selected so that objectivity and impartiality of the audit process are ensured. | An audit programme, an audit plan per cycle, evidence the audit was performed, nonconformities with corrective actions, and results reported to management. |
| ISO/IEC 27001:2022 A.5.35 |
Independent review of information security | Your approach to managing information security and its implementation must be reviewed independently at planned intervals, and when significant changes occur. This is a separate control from clause 9.2 and auditors do check them separately. | A documented independent review, its scope, who performed it and why they were independent, plus what changed as a result. |
| ISO/IEC 42001:2023 Clause 9.2 |
Internal audit of the AI management system | The AI management system carries its own internal audit requirement on the same pattern as ISO 27001. If you are running both, the audit programme can cover both, but the AIMS scope has to be genuinely audited rather than assumed. | An audit programme covering AIMS clauses and Annex A controls, with findings tracked to closure. |
| SOC 2 (TSC 2017) CC4.1 and CC4.2 |
Monitoring activities | The Trust Services Criteria adopt COSO Principle 16, which requires ongoing and/or separate evaluations to determine whether the components of internal control are present and functioning. A periodic internal audit is the most defensible form of separate evaluation. | Evidence that a separate evaluation was performed, what it covered, what it found, and that deficiencies were communicated to those who can act on them. |
| HIPAA Security Rule 45 CFR 164.308(a)(8) |
Evaluation | Covered entities and business associates must perform a periodic technical and nontechnical evaluation establishing the extent to which their security policies and procedures meet the Security Rule. It is a required implementation specification, not an addressable one. | A dated evaluation against the administrative, physical and technical safeguards, with gaps and remediation. |
| NIST SP 800-171 / CMMC / CPCSC 3.12.1 and 3.12.3 |
Security assessment | Security controls must be periodically assessed to determine whether they are effective in their application, and monitored on an ongoing basis. This feeds the plan of action and milestones and, for CMMC, the annual affirmation. | An assessment against the practice set, a current POA&M, and evidence the monitoring is genuinely continuing. |
| EU AI Act Article 17 |
Quality management system | Providers of high-risk AI systems must operate a quality management system that includes internal audit procedures, with findings and closures retained. | Internal audit procedures, audit records, and the corrective actions that followed. |
| PCI DSS v4.0 12.4.2 |
Quarterly reviews | Service providers must perform quarterly reviews confirming personnel are following security policies and operational procedures, and those reviews must be performed by personnel other than those responsible for performing the given task. | Quarterly review records, sign-off, and evidence the reviewer was not the person performing the work. |
Most teams read clause 9.2 and conclude that somebody in-house can run the audit. Often they can. The constraint is narrower than "must be external": the auditor must not audit their own work, and you must be able to justify the selection. A one-person security team cannot audit the ISMS that one person built. A compliance manager can audit engineering's controls but not their own policy set. Where the segregation exists internally, use it. Where it does not, the requirement is what drives this purchase.
A gap analysis asks what is missing against a standard you are working toward. An internal audit asks whether the management system you already operate is conforming to its own documented requirements and to the standard, using sampling and evidence rather than a questionnaire. The outputs differ too: a gap analysis produces a work plan, an internal audit produces nonconformities with root causes and corrective actions. Certification bodies accept the second as evidence of clause 9.2 and do not accept the first. If you need the earlier one, that is our gap analysis.
Written so a certification body, a CPA firm or an enterprise customer's security team can pick it up and follow it without you in the room.
A risk-based programme covering what gets audited, how often, by whom and against which clauses and controls. This is the artifact most first-time ISO clients are missing entirely, and clause 9.2.2 asks for it by name.
Per cycle: scope, criteria, sampling approach, interviewees and dates, agreed before fieldwork so nothing lands as a surprise.
Interviews, document review and evidence sampling against the actual criteria. We test what you do, not what your policy says you do, because that is the gap a certification body will find.
Nonconformities graded major or minor, plus observations and opportunities for improvement, each written against a specific clause or control so there is no argument about what it maps to.
Root cause, correction, corrective action and a verification date for each nonconformity. A finding without a closed corrective action is worse than no finding, because it documents that you knew.
The inputs clause 9.3 expects, assembled so your management review is a decision meeting rather than a scramble to build a deck.
For A.5.35, a documented statement of scope, method, independence basis and conclusion, which is the part teams usually improvise and auditors usually probe.
Every framework below reserves its final opinion for a specific kind of licensed or accredited firm. Any consultancy claiming otherwise is worth checking carefully.
| Deliverable | Who can issue it | What we do instead |
|---|---|---|
| SOC 2 report | A licensed CPA firm | We prepare you, run the internal audit, and sit in the audit with you. We do not issue the opinion. |
| ISO 27001 or ISO 42001 certificate | An accredited certification body | We run the internal audit and the management review inputs. The certificate comes from the CB. |
| CMMC Level 2 certification assessment | An authorised C3PAO | We do the gap assessment, the POA&M and the internal assessment against 800-171. |
| PCI DSS Report on Compliance | A Qualified Security Assessor | We prepare the environment and run the 12.4.2 quarterly reviews independently. |
| PCI DSS external vulnerability scans | An Approved Scanning Vendor | We coordinate the ASV and remediate what the scan returns. We are not an ASV. |
| EU AI Act high-risk conformity assessment | A notified body, where one is required | We build the Article 17 quality management system and run its internal audit procedures. |
For consultancies and MSPs. If you run readiness programmes, you have the same independence problem we do, on every client you serve. We take internal audit referrals on a strictly ring-fenced basis: we audit, we report to your client's management, and we do not pitch readiness work into your account. If you would rather send it somewhere with that in writing, start here, or read how we already work alongside other firms on MSP overflow.
A SOC 2 Type II across 76 controls, built in house from nothing on a team of 15, passed with zero exceptions. Knowing what a clean audit actually looks like from the inside is what makes an internal audit useful rather than performative. Read it.
A dual-framework programme across three data centre sites, with physical and environmental controls in scope at each, alongside a datacenter platform, an AI compute platform and a self-hosted collaboration stack. Read it.
Four firms quoted identical scope and the highest number was 2.1 times the lowest. Separately, a documented readiness position took $11,000 off a quote. That is the same judgement an internal audit needs. Read it.
It is an internal audit of your management system performed by an external firm rather than by your own staff. The audit is still "internal" in the sense the standard means: it is your audit, of your system, against your criteria, reported to your management. Outsourcing it solves the practical problem that most companies under a few hundred people do not have anyone who is both qualified to audit the ISMS and independent of it.
Yes. Clause 9.2 is a mandatory clause and it is not subject to the Statement of Applicability, so you cannot exclude it the way you can exclude an Annex A control. You must audit the ISMS at planned intervals, run an audit programme, and report results to management. A certification body will ask for internal audit records at stage 1 and will raise a nonconformity if they do not exist.
Clause 9.2 is the internal audit of the ISMS against ISO 27001 and your own requirements. A.5.35 is an independent review of your approach to managing information security and its implementation. They overlap but they are not the same requirement, they sit in different parts of the standard, and auditors test them separately. A well-scoped engagement satisfies both and says clearly which evidence answers which.
They should not, and this is the constraint that catches most companies. Clause 9.2.2 requires auditors to be selected so that objectivity and impartiality of the audit process are ensured, and A.5.35 asks specifically for independence. Somebody auditing a management system they designed is not impartial in any sense a certification body will accept. This is also why we will not do both for the same client: if we built your ISMS, we will refer the internal audit out.
ISO 27001 says planned intervals rather than naming a number. In practice most certified organisations run a full cycle annually, with the whole scope covered across each three-year certification period, and more frequent partial audits on higher-risk areas. If you are heading into a stage 1, you need at least one completed internal audit and one management review before the certification body arrives.
SOC 2 does not use the phrase, but CC4.1 adopts COSO Principle 16, which requires ongoing and/or separate evaluations of internal control. A periodic internal audit is the cleanest way to evidence a separate evaluation, and it is materially easier to defend than pointing at your monitoring tooling and calling it an evaluation. It also surfaces the exceptions before your auditor does, when they are still cheap to fix.
The engagement is led by a published security researcher with six disclosed CVEs, including a CVSS 9.1 kill-switch in the Mirai botnet, who built a SOC 2 Type II across 76 controls to zero exceptions and has run dual-framework programmes across multiple physical sites. Internal audit under ISO 27001 does not require a specific certification, but it does require competence in the criteria and genuine independence from the work being audited, and clause 9.2.2 requires you to be able to justify the auditor selection.
Yes, and it is worth asking any firm this. Physical and environmental controls are in scope on a lot of ISO 27001 certificates and a lot of SOC 2 reports, and a remote-only auditor cannot test them. We have run a dual-framework programme across three data centre sites with physical and environmental controls in scope at each.
It will find things, and that is the point of doing it first. A nonconformity you raised yourself, with a root cause and a closed corrective action, is evidence the management system works. The same issue found by a certification body is a nonconformity on your certificate. The internal audit is the cheaper place to discover it.
No, and no firm doing your readiness or internal audit can. An ISO 27001 certificate is issued by an accredited certification body. A SOC 2 report is issued by a licensed CPA firm. A CMMC Level 2 certification assessment is performed by an authorised C3PAO. We do the internal audit and the preparation, and we tell you plainly which parts we cannot sign.
It is scoped to the size of the management system, the number of sites, and how many frameworks are in scope. It is a fraction of a certification audit and a fraction of a full readiness engagement, which is why it also works as a standalone purchase for companies who did their readiness elsewhere or in house. Ask us for a fixed number rather than a rate.
Yes, and that is the most common version of this engagement. You keep your existing consultant or run the programme in house, and we come in once a cycle as the independent auditor. Nothing about your current arrangement has to change.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.
That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.
Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.
The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.
For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
What certification bodies actually sample, how nonconformities get written, and what a management review needs to contain. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.