Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Compliance Calendar Builder

Pick your frameworks and a start month. You get a 12-month calendar of the recurring activities auditors expect to see evidence of, spread out so they do not all land in the same week.

Frameworks

0
MonthActivities
What to keep as evidence, and the framework reference
Continuous compliance, From $1,500/mo CAD
Typical cadences, set by your own policies. Where a framework fixes a frequency, the reference says so. Otherwise your policy sets it, and the auditor tests against your policy.

Questions

Where do these cadences come from?

Some are written into the framework, such as PCI DSS quarterly scans and yearly training. Most are not: SOC 2 and ISO 27001 leave the frequency to you, and auditors then test that you did what your own policy says. The cadences here are the ones most programmes settle on.

What happens if we miss a month?

For a SOC 2 Type II or an ISO surveillance audit, a missed control is an exception or a nonconformity, so it is better to set a cadence you will keep than an ambitious one you will not. Record the late run with its date rather than backdating it.

Why are the yearly activities spread across the year?

Bunching them into one month before the audit is the most common reason they get done badly. Spreading them also gives the risk assessment time to feed the policy review, and the internal audit time to feed the management review.

How does this relate to continuous compliance?

This calendar is the work. Continuous compliance is having someone run it with you each month, collect the evidence as it happens and chase what slips, so the audit is a review of a year already documented.

Is this calendar free?

Yes, free and no signup. Your choices stay in your browser.

Not ready for a call yet?

Get your calendar by email

Your calendar and evidence list to keep, then a few short notes from Jacob on keeping a programme running between audits. Unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

Continuous compliance

We run the calendar with you each month and keep the evidence audit-ready.

Explore Continuous compliance →

A calendar only works if someone runs it.

With continuous compliance we run this calendar with you every month, collect the evidence as each activity happens, and chase what slips before the auditor finds it. From $1,500/mo CAD.

Talk about continuous compliance Book a call

Want the full picture?

This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

Start your free assessment See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.