GetSOC2

Defence contractors do not believe their own CMMC scores

August 25, 2026. From issue 3 of The Compliance Brief, 2 stories for companies buying a SOC 2 audit.

Last reviewed 2026-08-25Written by Jacob Masse, TrazTech Inc.

Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. 2 of its 5 stories bear on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Infosecurity

US defence contractors are reporting doubts about the accuracy of their own self-assessment scores under CMMC Phase I. Those scores have reached an all-time high at the same time.

Our take, in short

Self-scoring drifts upward when there is money attached, which is the whole reason assessment phases exist. For Canadian firms this matters twice: if you subcontract to a US prime your inflated score becomes their problem in an audit, and CPCSC is arriving with the same structure at home.

Read the full take on traztech.ca

SickKids gets hit through somebody else's software

Source: BleepingComputer

Toronto's Hospital for Sick Children disclosed a security incident that exposed personal information belonging to some current and former employees and job applicants. The hospital attributes the exposure to a flaw in third-party software.

Our take, in short

Read that reporting from the other side of the contract, because in a story like this you are the third-party software. Your notification clock, your evidence obligations and your willingness to be named are set by whatever your MSA says today, and most Canadian SaaS contracts I read are vague on all three.

Read the full take on traztech.ca

Also in issue 3

Outside SOC 2 audits, auditors and vendor reviews, but in the same email:

Older: issue 2 All issues on GetSOC2 Newer: issue 4