Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A Type II report covers a period, and the auditor samples across all of it. So the binding date is not when you start the work, it is the last day every control has to be live and producing dated evidence. Give it your deadline and it works backwards.
Fill in the two dates above and the plan appears here.
This is arithmetic, not advice. It does not know your scope, your control maturity, or what your auditor will accept as evidence, and those decide whether the plan survives contact. The evidence simulator covers the second one, and what actually goes wrong in an audit covers why the window matters this much.
It is the period a Type II report covers, typically three to twelve months. The auditor samples evidence from across the whole window to confirm each control operated consistently, rather than confirming it existed on the day of testing.
Before the window opens. A control switched on partway through is only evidenced from the day it started, so the earlier part of the window is exposed and the exception gets written. This is what the planner is calculating: the last date everything has to be running and producing dated records.
You have three levers, in rough order of preference. Shorten the window, since three months is accepted by many buyers for a first report. Issue a Type I now and follow with the Type II, which unblocks a deal while the window runs. Or move the date with the buyer, which is usually easier before you have promised one than after.
Because it varies by firm, by scope and by how prepared you are when fieldwork starts, and we would rather you use your own auditor's answer than our average. Ask them during scoping. If you have no figure yet, the default here is a planning allowance, not a promise.
Shorten the window, issue a Type I now and follow with the Type II, or move the date before you have promised one. Which is right depends on who is asking and why. Thirty minutes will tell you.
Talk through your datesTrack record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
Short notes on sequencing a readiness programme, including the two places the schedule usually slips. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.