HireACISO

Our biggest deal is blocked on security

Most blocked deals are blocked on one or two specific findings, not on the absence of a certificate. Find out which, in writing, before you spend anything. The fix is usually four to eight weeks of work, not a nine month audit.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Your largest deal has stopped in the customer's security review and nobody inside your company owns security. Get the blocker in writing from the reviewer before you commit to anything. In most stalled reviews at 15 to 80 people the blocker is one or two named findings, closed in four to eight weeks for $10,000 to $40,000 CAD. If it is a SOC 2 Type 2 report, that is nine to twelve months, and no money compresses it below a three month observation window.

The expensive mistake is assuming the second case when you are in the first. Founders panic-buy a compliance platform and a first audit, then lose the deal six months before the report exists, over a finding that was a two week fix.

4 to 8 weeks Typical fix for a specific finding

9 to 12 months First SOC 2 Type 2, if that is truly the blocker

1 email What it costs to find out which one you are in

How do you find out what is actually blocking it?

Ask the reviewer, not your champion. Your champion wants the deal and will paraphrase, and the paraphrase is where "they want better access controls" becomes "they want SOC 2". Send the reviewer one email with three questions.

  1. Which specific findings are open, and which of them block signature as opposed to being recommendations?
  2. What evidence would close each one, and would a written commitment with a date be accepted in place of the evidence?
  3. Is there an exception or conditional approval process, and who approves it?

The third question gets skipped and it unblocks the most deals. Large buyers almost all have a risk acceptance path, usually needing a named internal sponsor and a remediation plan with dates. Nobody offers it. You have to ask.

What each kind of blocker costs to clear

Every figure is Canadian dollars and assumes you have engineering capacity to do the work. If you do not, add the implementation cost, usually the larger number.

Common security review blockers, time to clear and cost in CAD
Blocker as the reviewer wrote itTime to clearCost, CAD
No multi-factor authentication on production or admin access Days Near zero
No named individual accountable for security One meeting Zero, or a retainer if you want it to be real
No documented policies 2 to 4 weeks $3,000 to $12,000
No incident response plan or no tabletop record 2 to 3 weeks $4,000 to $12,000
No recent independent penetration test 3 to 6 weeks including scheduling $8,000 to $25,000
No access reviews or offboarding evidence 2 to 6 weeks to build a record $2,000 to $8,000
Data residency outside Canada for a Canadian public or health buyer 4 to 12 weeks Engineering time, sometimes substantial
SOC 2 Type 1 report required 3 to 5 months $25,000 to $60,000 all in
SOC 2 Type 2 report required, your first audit 9 to 12 months $40,000 to $90,000 all in
Most stalled reviews at 15 to 80 staff, in total4 to 8 weeks$10,000 to $40,000

Everything above the SOC 2 rows is work you can finish before the customer's next quarter starts. The two SOC 2 rows are the only ones with a clock you cannot influence. The Canadian audit numbers are on SOC 2 cost in Canada, and Type 1 against Type 2 is settled on Type 1 versus Type 2.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What to offer when the real answer is nine months

If the buyer requires a report you cannot produce this year, you are negotiating, not remediating. Four things unblock deals in this position, and they combine.

  • A remediation plan with dates and an owner. Not a roadmap slide. A table of findings, the fix, the date and a named person, signed by an executive. Reviewers accept these far more often than founders expect, because it is the artifact their own risk process asks them to file against an exception.
  • Contractual commitments instead of a certificate. A right to audit, a breach notification window, a security addendum committing you to the report by a named date, sometimes a price remedy if you miss it. That moves the conversation from procurement to legal, often the faster path.
  • An independent assessment now. A gap assessment or a penetration test from a third party gives the reviewer something external to point at. It is not a report, and it is not nothing.
  • A named security owner who will take their call. Reviewers are assessing whether a problem will be handled when it arrives. A person they can phone is a real answer to that, which is why a fractional owner is often bought at exactly this moment rather than at a headcount threshold.

Do not let the deal set the framework

One customer asking for ISO 27001 while three others ask for SOC 2 is not a reason to start ISO 27001. Make the framework decision once, against where your next twenty customers are. It costs a year to get wrong. European and UK buyers ask for ISO 27001, North American buyers overwhelmingly ask for SOC 2. Decide on the pattern, not on the loudest deal.

Who does the work while this is happening?

Somebody is about to spend 40 to 120 hours on this, and by default it lands on the technical founder or the person running engineering, on top of their existing job. What no security person actually costs a 30 person company puts a number on it.

Buy a fixed-scope project with an acceptance test, not a monthly retainer. The outcome is defined: the reviewer signs off. That is $15,000 to $40,000 CAD for a typical unblock at this size, and the models are compared on engagement models. A retainer bought because a deal is stuck means paying monthly for something that had an end date.

Unblock a specific deal

Send us what the reviewer wrote. We will tell you whether it is a four week fix or a nine month program, and put the scope in front of Canadian providers who do that specific work.

Get matched

Common questions

The customer says they need SOC 2. Can we get one in two months?

No. A Type 2 report covers a window of operation, and the shortest window an auditor will normally sign is three months, with readiness work before it and report production after. A Type 1 is faster at three to five months because it tests design on a single date, and some buyers will take a Type 1 with a committed Type 2 date. Ask the reviewer whether a Type 1 plus a dated commitment closes the item, because quite often it does.

Should we buy a compliance platform to get through this faster?

Only if you have already committed to an audit. A platform at $8,000 to $30,000 CAD a year collects and monitors evidence, which is valuable across a twelve month program and does nothing for a deal closing in six weeks. For a single blocked deal the money is better spent on the specific finding, whether that is a penetration test, a policy set or engineering time.

Can we name our fractional security lead as the accountable person?

Yes, and most engagements include it. Confirm two things in the contract before you put the name in front of a customer: that this specific individual is contractually committed to your account, and what their response time is for a customer call. A named contact who cannot get on a call within a week reads worse to a reviewer than an internal VP of engineering who answers the same day.

How much of this can we do without spending money?

More than most founders expect. Multi-factor authentication, naming an owner, an access review, a written offboarding process, an incident response plan and a vendor list are all internal work. That is often four of the six open findings. Security work that costs nothing is the list, in the order that closes the most findings first.

Is it worth telling the customer we have no security person?

Do not volunteer it, and do not lie about it. Answer the question they asked, which is who is accountable, with a real name and title. Reviewers at this size expect a supplier of 30 people to have a founder or an engineering leader in that seat rather than a CISO, and saying so plainly is normal. What damages a review is discovering later that the name given was decorative.