A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →What pre-Series-A through Series-B startups are spending on security, what they are skipping, and the compliance gaps that still cost the most enterprise deals. Observation-based findings from our engagements, paired with cited industry data. Honest read; no vendor pitch.
The report below is a point-in-time analysis. This band is not. It is pulled automatically every hour from public security and regulatory feeds, filtered to what bears on a startup selling into an enterprise security review, and shown newest first. Headlines and summaries are each publisher's own words; follow the link for the full story.
Recurring in this batch: breach · saas · settlement · ransomware
The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network. (www.darkreading.com)
Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang. (therecord.media)
Valley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated (www.hipaajournal.com)
A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer. (therecord.media)
“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said. (therecord.media)
The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health. (therecord.media)
Most recent item 9 October 2026. Selection is automatic and unedited, so nothing here carries our opinion. For the version that does, we send a weekly read of what these stories mean for a Canadian company selling into the US: The Compliance Brief.
Free weekly email
These stories, with a take on each, every Tuesday
The Compliance Brief picks the five that matter for a security review and says what to do about each. Free, one email a week.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
The figures below come from our own engagements and from the control libraries behind traztech Workspace. Each links to where the detail lives.
If you are running security at a startup in 2026, three things are different from the prior decade. Compliance is now table stakes for enterprise sales, AI features have created an entirely new attack surface, and the talent market for senior security leadership is impossibly tight. Founders are responding by combining lightweight in-house ownership with embedded operators and ruthless tool consolidation.
This report distils what we have seen across our engagements over the past 18 months. We do not present this as survey data. There is no survey. These are observations from hands-on engagements at startups ranging from pre-seed to Series B, supplemented by publicly available industry benchmarks where appropriate (citations inline).
Of the startups we engaged with in the past year, roughly two-thirds already had at least one enterprise deal in flight. In every one of those engagements, the customer's procurement team requested a SOC 2 report or, in its absence, a 200-question security questionnaire as a substitute. There is no version of the future where this gets less common. The trajectory is the opposite.
Founders consistently underestimate the timeline. A common pattern: founder closes verbal agreement on a $150K ACV deal, customer's security team kicks the questionnaire over, deal stalls for 90 days while founder scrambles. By the time the founder is audit-ready, two of three things have happened: the deal pricing has eroded, the customer's quarter has rolled and the stakeholder has moved on, or a competitor with a SOC 2 report on hand has quietly closed it instead.
SOC 2 Type I is commonly a few months from start to report, and a Type II adds a 3, 6 or 12 month observation window. The gaps found and the audit firm's schedule drive the rest. If a deal is gating on it, that is the conversation to have; book a call and we'll scope it.
By our count, every startup we onboarded in 2025 had shipped at least one AI feature in production. The fraction that had performed any kind of adversarial testing on it: under 20%. The fraction that had a documented threat model for the AI surface: under 10%.
We performed initial AI security assessments on a subset of these in 2025 and 2026. The most common findings were not exotic. They were the same authorization and input-validation failures that have plagued web applications for two decades, surfacing in new wrappers:
None of these are theoretical. We have seen working exploits for each at production startups. The reason they ship is structural: AI feature teams move fast, security review is not in the loop, and the surface looks novel enough that traditional pentest scope doesn't cover it.
The startups handling this well share a structure: AI features have a documented threat model before they go GA, an external adversarial assessment within 60 days of launch, and a mid-engagement check-in three months later. The cost is small relative to the cost of a public incident; the goodwill with enterprise security buyers is large.
We bundle our remediation strategy with adversarial testing from our global and Canadian testing partners, whichever gives you the best value on the scope. Two firms, one engagement. The testing window is agreed at scoping.
The single most common security gap we walk into: no documented incident response plan. Or more precisely: a plan written for a SOC 2 audit that has never been tested and no one on the team has read.
According to the IBM & Ponemon Cost of a Data Breach Report 2024, organizations with a tested IR plan reduced breach cost by an average of $2.66M compared to those without. For a 50-person startup, that delta is more than the entire engineering payroll for a year.
Despite this, IR is consistently de-prioritized at the seed and Series A stage. Founders rationalize the deferral on three grounds:
Among our 2025 and 2026 engagements, the fastest-growing service line was incident response retainers, covering agreed response times, runbook ownership, and quarterly tabletops. The economics make sense: a single avoided escalation pays for years of retainer fees, and customer security teams now ask about IR retention status and ongoing vulnerability management during diligence.
Five years ago a fractional security leader was largely a bridge solution: a placeholder until the startup could hire the full-time role. In 2026, we are seeing the model entrench permanently for a specific category of startup. Those founders are strong on domain expertise but lack a peer technical co-founder, and they need senior judgment on architecture, security posture, and engineering culture.
Three observations from our portfolio:
The pattern that breaks these engagements is predictable: founders who hire a fractional CISO expecting them to implement the controls themselves end up disappointed. The role delivers judgment, ownership and accountability to buyers, not throughput. It works when the engineering capacity to act on it already exists or is bought alongside it.
The "best of breed" SaaS sprawl that defined 2018 to 2022 has reversed. Across our engagements, the average startup we walked into had fewer security tools in 2026 than in 2023, and the dollar value spent had reallocated toward fewer, deeper integrations.
Three drivers:
The net: a typical 30-person startup we audit in 2026 runs roughly 8 to 12 security/DevOps SaaS tools, down from a 2023 baseline of 15 to 20. The dollar spend per tool is up; the total spend is roughly flat.
Buyers treat the readiness quote as the variable cost and the audit fee as a fixed market rate. Our engagement record says the reverse is closer to the truth.
On one engagement we took a single, identical scope to four audit firms. The quotes differed by a large multiple. Same company, same systems, same criteria, same observation window. The spread was not explained by firm size or by brand: it was explained by how much uncertainty each firm believed it was pricing, and by how much of the work each assumed it would have to do itself.
That has a direct consequence. On a separate engagement, an audit firm revised its own quote down after the client's readiness position was documented and a preparation firm was confirmed. Nothing about the company changed between the two numbers. What changed was the amount of unknown work the firm was pricing against.
What this means in practice. Get audit quotes before committing to a readiness budget, take the same written scope to every firm, and tell them what state your programme is in. A first-time buyer comparing proposals side by side sees none of this, which is why the audit is the largest number most companies control least.
Detail in the four-firm pricing comparison and the vetting engagement.
Compliance automation is sold as the starting point. In our engagements it is more often the last thing that should be bought, and occasionally it should not be bought at all.
One client had a five-figure annual compliance platform subscription priced, approved and budgeted. They ran the entire programme in our workspace instead, kept the evidence at the end, and paid nothing for the licence. The platform was a real option that had been genuinely evaluated. It simply was not the thing that produced the report.
This tracks what the tooling does and does not do. Automation is good at continuous evidence collection, which is a real cost saver once you are maintaining a report across years. It does not decide what your controls should be, write them, fix what is broken, or answer an auditor. Those are what consume the calendar on a first programme, and they are the reason a dashboard full of green ticks does not equal a passed audit.
Detail in the platform cost engagement.
A venture-backed security company with no compliance programme reached a SOC 2 Type II with zero exceptions, while serving millions of daily requests through the observation window.
The instructive part is what produced that result. It was not more effort during the window. It was building controls whose evidence is a by-product of how people already work. The change-management control was a pull request approval flow where the safe path was also the fast path, so the audit trail existed without anybody remembering to create it. Any control that depends on somebody logging something manually will eventually produce an exception, because the week it matters is the week everyone is busy.
The second lesson is about ordering. On that programme the policy set was written before the asset inventory was finished, and several policies had to be revised once the real scope was known. The inventory is the cheapest work in a compliance programme and it constrains everything downstream. It should come first.
Detail in the full walkthrough.
Companies sequence frameworks because sequencing feels lower risk. Our engagement data suggests it is the more expensive path.
A data centre operator ran SOC 2 Type II across Security, Availability and Confidentiality alongside ISO 27001:2022 including the Climate Action Amendment, with physical and environmental controls in scope at three separate sites. A large share of Annex A maps onto the SOC 2 common criteria, so the overlapping control and evidence work was done once rather than twice. What ISO adds on top is the management system: risk methodology, Statement of Applicability, internal audit and management review.
The same engagement produced a second finding worth more than it sounds. The client was placed with a single firm that was both a licensed CPA firm and an accredited certification body. That meant one engagement letter, one evidence request process, one set of scheduling constraints and one relationship, instead of reconciling two assessors with two sampling approaches and two views of what evidence is sufficient.
Detail in the dual-framework engagement.
Adding Availability to a SOC 2 report brings A1.2 and A1.3 into scope, which means backups, recovery infrastructure and recovery testing all get sampled. Most companies decide this in a five-minute conversation and then live with it for years.
It is frequently the right call. For infrastructure and platform products, leaving Availability out invites the buyer question of why it was left out, and a narrow scope that prompts a question is worse than a wider scope that answers it. Processing Integrity is the opposite case: it applies to systems processing transactions on a customer's behalf, and stretching it to fit adds ongoing evidence obligations with no buyer asking for them.
The rule we apply: add the criteria your buyers ask about and leave out the ones they do not, because every criterion added is a set of controls somebody operates every week for the life of the report.
The readiness work and the audit are two separate costs. A SOC 2 gap analysis starts from $3,000 with us, with remediation and audit support scoped from the gap; the audit itself is billed by an independent CPA firm. Audit quotes for one identical scope vary widely between firms, so compare assumptions rather than headline numbers.
SOC 2 Type I is commonly a few months from start to report, and a Type II adds a 3, 6 or 12 month observation window. What drives it is the gaps found, the observation period and the schedule of the audit firm. For a Type II the binding constraint is usually the observation period rather than the control work, because the report attests that controls operated across a period and that period has to elapse.
A Type I attests that controls are suitably designed at a point in time. A Type II attests that they operated effectively across a period. Type I gets a defensible artefact into a sales conversation now; the same control set then runs through an observation window and becomes the Type II, provided the controls were designed to produce evidence.
If your customers are mostly North American, SOC 2 is usually the shorter road. Once European or Middle Eastern buyers are involved, or you are selling into enterprises that work from an approved standards list, the ISO certificate does work the attestation does not. Running both together is frequently cheaper than sequencing them, because a large share of ISO 27001 Annex A maps onto the SOC 2 common criteria.
Artefacts a control produced, not documents describing a control. A first document request list is built around your scope and covers governance, people, identity and access, change management, monitoring and response, and data and vendors. A policy saying access is reviewed quarterly evidences nothing; the completed review, dated, with the reviewer named, evidences the control.
Not for a first or second readiness programme. Automation genuinely covers a minority of controls, and they tend to be the ones companies already pass. What fails audits is organisational: reviews that never ran, controls nobody owns. traztech Workspace is free and holds the control sets, evidence register, policy templates and readiness scoring, and you keep it when an engagement ends.
No. An audit firm has to stay independent of what it assesses, so it cannot design your controls, write your policies or build your evidence register. That constraint is what makes the report worth handing to a buyer, and it is why preparation and audit are two different firms.
The observation window being chosen after the work starts rather than before it. A Type II covers a period, so evidence has to exist across that period, and a control implemented last week cannot produce three months of history.
More than buyers assume. Quotes from different firms for one identical scope can differ by a large multiple, and a firm looking at a documented readiness position has less uncertainty left to price, so its quote comes down. Take the same written scope to every firm and tell them what state your programme is in.
Usually not on a first programme. One client had a five-figure annual subscription priced and approved, ran the programme in our workspace instead, kept the evidence and paid no licence fee. Automation is good at continuous evidence collection, which earns its cost once you maintain a report across years. It does not decide, write or fix anything.
Generally yes. A large share of ISO 27001 Annex A maps onto the SOC 2 common criteria, so overlapping control and evidence work happens once. We have run both in parallel across three physical sites. What ISO adds is the management system: risk methodology, Statement of Applicability, internal audit and management review.
Add the criteria your buyers ask about. Availability brings A1.2 and A1.3 into scope, so backups, recovery infrastructure and recovery testing get sampled. For infrastructure products it is usually right, because leaving it out invites the question of why. Every criterion added is a set of controls somebody operates every week for the life of the report.
This report draws on:
This is not survey research. We do not claim representativeness beyond our portfolio. Where we present a percentage, it reflects the share of our engagements exhibiting a behaviour, not the broader market.
Compliance is no longer a moat; it is table stakes. AI features have created a serious, under-tested attack surface that will produce its first wave of public incidents this year. Incident response remains the most underpriced investment a startup can make. And the fractional leadership model has graduated from stopgap to durable structure.
The startups that win on security in 2026 are not the ones with the largest team. They are the ones who got the systems in place early, kept the tooling tight, and bought senior judgment in the right shape (embedded, fractional, or retainer) for their stage.
Want a designed PDF version to share with your team or include in board materials? Drop your details and we'll email it within one business day.
Two-thirds of the founders we engage with start with one of the gaps in this report. The first conversation is free; the diagnosis is honest; the path forward is concrete, with clear pricing for every engagement.
Free templates
The SOC 2 readiness checklist, ISO 27001 gap checklist, incident response plan and vendor security questionnaire. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.