Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Free tool · No signup

Observation window planner

A Type II report covers a period, and the auditor samples across all of it. So the binding date is not when you start the work, it is the last day every control has to be live and producing dated evidence. Give it your deadline and it works backwards.

The date on the contract, the renewal, or the procurement deadline.
Three months is common for a first report. Some enterprise buyers discount anything shorter than six.
Be honest here rather than optimistic. A control that exists but leaves no record does not count as live.
Fieldwork plus drafting plus review. Ask your auditor for their figure; the default is a planning allowance, not a published number.

Fill in the two dates above and the plan appears here.

This is arithmetic, not advice. It does not know your scope, your control maturity, or what your auditor will accept as evidence, and those decide whether the plan survives contact. The evidence simulator covers the second one, and what actually goes wrong in an audit covers why the window matters this much.

Questions about the window

What is a SOC 2 observation window?

It is the period a Type II report covers, typically three to twelve months. The auditor samples evidence from across the whole window to confirm each control operated consistently, rather than confirming it existed on the day of testing.

When do controls need to be live?

Before the window opens. A control switched on partway through is only evidenced from the day it started, so the earlier part of the window is exposed and the exception gets written. This is what the planner is calculating: the last date everything has to be running and producing dated records.

What if the dates do not work?

You have three levers, in rough order of preference. Shorten the window, since three months is accepted by many buyers for a first report. Issue a Type I now and follow with the Type II, which unblocks a deal while the window runs. Or move the date with the buyer, which is usually easier before you have promised one than after.

Why is the report issuance time an input rather than a fixed number?

Because it varies by firm, by scope and by how prepared you are when fieldwork starts, and we would rather you use your own auditor's answer than our average. Ask them during scoping. If you have no figure yet, the default here is a planning allowance, not a promise.

There are usually three ways out

Shorten the window, issue a Type I now and follow with the Type II, or move the date before you have promised one. Which is right depends on who is asking and why. Thirty minutes will tell you.

Talk through your dates

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
$11k
Taken off one client's audit quote by arriving ready

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Want the rest of the timeline?

Short notes on sequencing a readiness programme, including the two places the schedule usually slips. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.