Knowledge

Nobody fails SOC 2 on encryption

Organizations rarely fail an audit because an engineer could not configure multi-factor authentication. They fail because the exception granted in March was still in place in November, and nobody could say who approved it or why. The technical controls are the easy part. What the audit actually measures is whether an organization can tell the truth about itself, consistently, over a period of months, without anyone having to remember to.

·

9 min

var(--variable-rpcX8dOAk)

What the auditor is actually asking

There is a persistent misreading of what a SOC 2 Type II report is. It is not a security certificate. It is an independent opinion on whether the controls an organization described in its own system description operated as described, throughout a defined observation window. The subject of the examination is not the infrastructure. It is the assertion.

That distinction has consequences. A Type I report speaks to design at a point in time, which is a question about intent and architecture. A Type II report speaks to operating effectiveness across three months, six months, twelve. It asks whether the thing you said you do is the thing you did, every time, including on the Friday before a release, including during the outage, including while the person who owns the control was on leave.

Consistency over time is not an engineering property. It is a behavioral one. Which is why an audit is best understood as a measurement of organizational psychology wearing a technical costume.

Retrofitting is a psychological problem before it is a technical one

Almost every organization approaches this in the same order: build the platform, win the customers, then discover that a prospect’s security questionnaire has become the gate on a deal that was otherwise closed. Compliance work begins as a sales unblocker, under time pressure, against infrastructure that was designed for other objectives.

The technical debt in that situation is real but tractable. The psychological debt is harder. When controls arrive after the fact, every one of them reads as an accusation about work already completed. The engineer who built the deployment pipeline is now being told the pipeline needs approval gates, which they hear, correctly, as a statement that their judgment is no longer sufficient on its own. Resistance at that point is not obstruction. It is a rational response to a change in status that nobody named out loud.

Building the controls in from the start inverts the meaning entirely. A change approval requirement that existed before anyone joined is infrastructure. The same requirement introduced in year three is a verdict. The control is identical. What differs is what it says about the people operating under it, and people respond to what things say about them far more reliably than they respond to policy.

The exception that became the standard

Diane Vaughan’s study of the Challenger accident gave this failure its name: normalization of deviance. A deviation from the specified standard is permitted once, under pressure, for a defensible reason. Nothing bad happens. The deviation is permitted again. The band of what counts as acceptable quietly widens, one justified exception at a time, until the organization is operating well outside its own stated standard and every individual step in the sequence looked reasonable to the person who took it.

In infrastructure this is not abstract. It is the firewall rule opened for a vendor integration in Q2 that nobody closed. The service account created with elevated privileges for a migration that finished eighteen months ago. The break-glass credential that became a convenience. The production access granted to an engineer during an incident, which was correct at the time, and which survived because revoking it would have meant a conversation.

Auditors find these things because they are looking for the gap between the written standard and the observed practice, and this is precisely where that gap lives. More importantly, attackers find them for the same reason.

The countermeasure is not vigilance, because vigilance decays. It is expiry. An exception that must be renewed on a date will either be renewed deliberately or lapse quietly, and both outcomes are correct. An exception with no end date will persist until an incident or an auditor finds it. The design decision is whether the default state of an exception is continuation or termination, and that single choice determines whether the organization drifts.

Evidence is a design property, not an output

The most expensive misconception in readiness work is that evidence is something collected before an audit. Organizations that hold this belief spend the weeks before fieldwork reconstructing history: exporting logs, chasing screenshots, asking a manager to confirm from memory that a quarterly access review happened in a quarter that ended five months ago.

Reconstruction is expensive, it is unreliable, and it fails in a specific way. An access review that happened but produced no artifact did not happen, as far as the examination is concerned. Sincerity is not the standard. Demonstrability is.

The alternative is to design systems so that operating them produces the record as a byproduct. Access reviews that generate a dated, attributable artifact because the review is performed in a system rather than in a meeting. Change approvals that exist because the pipeline will not proceed without them, not because someone remembered the policy. Provisioning and deprovisioning driven by an identity source of record, so that the joiner, mover and leaver evidence is the transaction log rather than a spreadsheet maintained in parallel.

This is the actual meaning of building for compliance rather than toward it. Not more controls. Controls positioned so that the evidence is a consequence of the work instead of an additional task competing with the work.

ISO 27001 and SOC 2 ask different questions

They are frequently discussed as interchangeable. They are not, and the difference is instructive.

SOC 2 asks whether you kept your word. You describe your system and assert your controls, and an independent practitioner tests whether that description held. The framework supplies criteria, not controls. What you are judged against is substantially your own statement.

ISO/IEC 27001 asks whether you have a functioning mind. Clauses four through ten specify a management system: context, leadership, planning, risk assessment and treatment, competence, monitoring, internal audit, management review, continual improvement. Annex A supplies a reference set of controls, and the Statement of Applicability records which apply and why. The certificate attests that the organization possesses a mechanism for identifying risk and acting on it, and that the mechanism runs on a cycle rather than on an occasion.

One tests fidelity to a promise. The other tests capacity for self-correction. An organization can hold a clean SOC 2 report and have no systematic way of noticing a new risk. An organization can hold ISO 27001 certification and still have a control that lapsed between surveillance audits. Run together, on a single control set mapped to both, they cover each other’s blind spot, and the marginal cost of the second framework is a fraction of the first because the evidence is already being produced.

Default deny is a posture, not a firewall setting

The phrase belongs to network engineering, where it means traffic is refused unless explicitly permitted. As an organizational stance it means something broader and more useful: the burden of proof sits with the change, not with the objection.

In most organizations the burden runs the other way. A proposed access grant, integration, or exception proceeds unless someone can articulate a specific harm, on the spot, under time pressure, usually to a person more senior who needs it done. That arrangement guarantees drift, because the cost of objecting is borne immediately and personally by the objector while the cost of the risk is diffuse, deferred, and borne by the organization. Behavioral economics has a name for the underlying asymmetry: humans discount future costs steeply against present ones, and no amount of training corrects it. Structure corrects it. Incentives corrected by structure are the only ones that hold.

Security by default means the person requesting the change carries the burden of justifying it, the justification is recorded, and the grant carries an expiry. It costs a little friction on every change. It removes the class of failure where nobody decided anything and the state drifted anyway.

How Qwalora works

Qwalora is building its own information security management system on a single unified control set mapped to both ISO/IEC 27001 and the SOC 2 Trust Services Criteria, run in parallel rather than sequentially. The scope is the entire company, including the Products pillar, because a scope drawn narrowly to make certification easier produces a certificate that answers a question no client asked.

The program is underway rather than complete. Realistic sequencing is SOC 2 Type I first, ISO 27001 Stage 2 following, and SOC 2 Type II only after its observation window has actually run, because a Type II report with no period behind it does not exist. Certifications are published when they are verified and issued, and not before.

Three practices are already in force, and they are the ones a client can test today.

Evidence discipline in published work. Every figure in Qwalora’s research carries a named primary source and a date, vendor terms are quoted rather than characterized, statutory text is quoted exactly, and what could not be verified is stated as unverified rather than omitted. This is the same discipline an audit demands, applied where anyone can check it.

Independence by structure rather than by assurance. Qwalora earns margin on technology it sources and discloses that margin. Margin is never earned from a client on any product named in that client’s own report, during the engagement or for twelve months after, and supply is contracted separately from advice. The conflict is removed by the shape of the arrangement rather than managed by good intentions, for the same reason exceptions carry expiry dates.

Gates that precede revenue. No engagement is accepted before professional liability and cyber cover are bound. A commitment that binds before the first invoice is a commitment; one adopted after the first difficult quarter is a preference.

The argument of this piece is that compliance outcomes are produced by organizational design rather than by effort. Qwalora is applying that argument to itself first, in public, on a documented timeline, which is the only version of the claim worth making.

Tell us what you are deciding.