A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Every control area an auditor actually checks, in plain English, with what to do about each one. Read the whole thing here for free. When you want the editable version to track progress with your team, grab it below.
SOC 2 feels huge until you realise it is really a finite list of things you either do or you do not. An auditor is checking whether you manage access, control changes, protect data, watch your systems, and can respond when something goes wrong. Get those in order and the report mostly writes itself.
This is the checklist we use to get startups audit-ready. It is organised by the areas an auditor groups their questions into. Work top to bottom, be honest about what is missing, and you will have a real gap list by the end of an afternoon.
Get this checklist as an editable tracker you can share with your team and tick off as you go. We will send it over and include a couple of the templates we use.
Auditors want written policies that match how you actually work, plus evidence someone owns security.
The single most common source of findings. Prove that the right people, and only the right people, can reach your systems and data.
Show that code and infrastructure changes are reviewed and traceable, not pushed straight to production on a whim.
The basics of not leaving the doors open. Auditors and buyers both look here.
Prove customer data is encrypted, backed up, and recoverable.
You cannot detect or investigate what you do not log. Auditors want evidence you would notice something going wrong.
Your subprocessors are part of your attack surface, and buyers will ask about them.
The people controls that surround access and data handling.
A plan you have actually tested, not a document nobody has read.
For the availability criteria, show your service can survive a bad day.
That is the shape of SOC 2. If you can honestly tick most of these, you are closer than you think. If large sections are blank, that is normal at the start, and it is exactly the work we do. For the bigger picture, see SOC 2 for Canadian SaaS, or how the whole program runs on our compliance page. If you want a fractional CISO to own the program end to end, we do that too.
It depends on how many items above you already have in place. A team that already enforces MFA, centralises logging and manages access is close; a team starting from a blank checklist has more to build. Readiness itself is usually a few months of work. A SOC 2 Type I can be issued shortly after, while a Type II adds an observation window of 3, 6 or 12 months. Working through this checklist honestly gives you the gap list that sets your real timeline.
The areas an auditor groups their questions into: governance and policies, access control and identity, change management, data protection and encryption, monitoring and logging, incident response, vendor and subprocessor management, people and HR security, and availability and continuity for the availability criteria. The list above walks through each with what to actually do.
The gap work on this checklist is something a capable team can do. Where teams stall is making policies match how systems are really configured, producing evidence in a form an auditor can test, and getting scope and the observation window right before the clock starts. Those are the places a prep partner saves the most time, and the places unprepared companies lose money at the audit.
A checklist tells you what good looks like. A gap assessment measures your company against it and produces a prioritised, scoped list of what is missing, which is Phase 1 of a readiness engagement. This page is the checklist; the gap assessment is the same list run against your actual systems with the findings written down.
Send us your gaps and your deadline, and we will scope the fastest honest path to audit-ready. Fixed price, no invented numbers.
Book a free readiness callEvery item here exists as a control in traztech Workspace, with what the standard actually asks for, what to do about it, and somewhere to attach the proof. It scores as you answer, so you can see where you stand instead of counting ticks in a document.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.