A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →An independent clause 9.2 internal audit of your management system, ahead of your certification or surveillance audit. You get a report with nonconformities and observations, and we check your corrective actions before it is final.
Scope, criteria, sampling approach, who we will interview and when, agreed with you before fieldwork starts.
Interviews by video, document review, and samples of your records tested against the clauses and controls in scope. We test what you do, not only what the policy says.
Nonconformities, graded major or minor, and observations, each tied to the clause or control it concerns.
You respond with a root cause and corrective actions. We check them once, before the final report, and record what we saw.
Ready for your management review and for the certification body at your next audit.
Clause 9.2 asks for audits at planned intervals, so the programme can be spread across the certification cycle. Pick the scope that fits this audit.
Clauses 4 to 10 and every applicable Annex A control in one audit.
The management system requirements, clauses 4 to 10, without the Annex A controls.
The Annex A controls in your Statement of Applicability, without the clauses.
Selected Annex themes each time, rotated so every clause and control is covered across the certification cycle. We track coverage so nothing is missed before recertification.
A gap analysis tells you what is missing before you build. An internal audit tests whether the system you already run conforms, and only an internal audit counts as clause 9.2 evidence. Not built yet? Start with a gap analysis for ISO 27001 or ISO 42001.
Consultancies and MSPs have the same independence problem with their own clients. We take internal audit referrals on a ring-fenced basis: we audit, report to the client's management, and do not offer them our readiness work. See the MSP partner programme.
The natural next step is next year's internal audit, or the next themes in your rotation.
Yes. Clause 9.2 requires internal audits at planned intervals and an audit programme, and it cannot be excluded the way an Annex A control can. ISO 42001 has the same clause for an AI management system. The certification body will ask for your internal audit records at the certification audit and at each surveillance audit.
Clause 9.2 requires auditors to be chosen so the audit is objective and impartial, and nobody is impartial about controls they operate. So we only offer internal audit where we have not operated your controls. If we run your programme, we will say so and help you find an independent auditor.
Yes. Choose a full audit, the clauses only, the Annex A controls only, or selected Annex themes in a rotating programme. With the rotation we track coverage across the cycle so every clause and control is audited before recertification.
No. Fixing what we audited would end our independence. You, or whoever runs your programme, correct them; we check the corrective actions once before the final report.
Fieldwork is remote: interviews by video, and documents and records sampled through your workspace or a shared screen. The audit plan sets out how each control in scope will be tested.
Tell us the standard, your certification or surveillance date and the scope you have in mind. We will confirm we are independent of your controls and send a fixed price.
Free PDFs, no card
The SOC 2 readiness checklist, the ISO 27001 gap checklist and the vendor security questionnaire, as PDFs you can print or hand to your team. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.