Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →An audit is not a review of your policies. It is a series of requests to prove that a control actually ran, on dates inside the observation window. Pick your framework, mark what you could produce this week, and see what an auditor would come back on.
The request list changes with the framework.
A Type II opinion covers a period, so evidence has to exist across it.
Be honest. The point of a rehearsal is to find this now rather than during fieldwork.
Answer the requests to see where you stand.
Nothing marked yet.
It is the auditor asking you to prove a control ran. Not that a policy exists, but that the thing the policy describes actually happened during the observation window, with dated artefacts such as a ticket, a log export, an approval, or a signed acknowledgement.
It varies by framework and scope. A first SOC 2 Type II commonly runs to well over a hundred individual requests once sampling is applied, because the auditor will ask for several instances of the same control across the window rather than one example.
A Type II opinion covers a period, so evidence has to exist across that period. A control you implemented last week cannot produce three months of history. This is the single most common reason a readiness project slips: the window was chosen after the work started rather than before. Our SOC 2 in 75 Days track sets the window first for exactly this reason.
To a degree, yes. Scope, sampling sizes, and which artefact satisfies a request are all discussed with the auditor rather than dictated. Teams who treat the auditor as a counterparty rather than an examiner generally have a smoother engagement.
Yes, free and no signup. It is a rehearsal, not an audit, and the request list is representative rather than the exact list any given firm will send.
Before you go
I send a few short notes on getting through an audit: what auditors actually accept as evidence, and where the time goes. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Auditor Management and Advocacy
We handle the auditor relationship and the evidence requests so your team can keep working.
Explore Auditor Management and Advocacy →We manage the relationship, work the request list, gather the evidence, and push back where something falls outside the agreed scope.
See Auditor Management Book a callThis gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.
Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.