Defence contractors do not believe their own CMMC scores
August 25, 2026. From issue 3 of The Compliance Brief, 2 stories for companies buying a SOC 2 audit.
Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. 2 of its 5 stories bear on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for companies buying a SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Infosecurity
US defence contractors are reporting doubts about the accuracy of their own self-assessment scores under CMMC Phase I. Those scores have reached an all-time high at the same time.
Our take, in short
Self-scoring drifts upward when there is money attached, which is the whole reason assessment phases exist. For Canadian firms this matters twice: if you subcontract to a US prime your inflated score becomes their problem in an audit, and CPCSC is arriving with the same structure at home.
Read the full take on traztech.ca
SickKids gets hit through somebody else's software
Source: BleepingComputer
Toronto's Hospital for Sick Children disclosed a security incident that exposed personal information belonging to some current and former employees and job applicants. The hospital attributes the exposure to a flaw in third-party software.
Our take, in short
Read that reporting from the other side of the contract, because in a story like this you are the third-party software. Your notification clock, your evidence obligations and your willingness to be named are set by whatever your MSA says today, and most Canadian SaaS contracts I read are vague on all three.
Read the full take on traztech.ca
Related on GetSOC2
- Best SOC 2 auditors in Canada, honestly
- The SOC 2 common criteria, CC1 to CC9
- What drives a SOC 2 quote
- Why audit quotes differ for one company
Also in issue 3
Outside SOC 2 audits, auditors and vendor reviews, but in the same email:
- Microsoft patches a 10.0 in Entra ID
- Rust crates that ran malware at compile time
- CareCloud's count goes from 350,000 to 3.7 million
Older: issue 2 All issues on GetSOC2 Newer: issue 4
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.