Key takeaways
- Certifications such as SOC 2 and ISO 27001 prove a defined set of controls exists and was tested within a defined scope. They don’t prove an organization is secure everywhere else.
- In May 2026, Instructure’s Canvas platform was breached twice in a week, five months after renewing its ISO 27001, SOC 2 Type II and PCI DSS 4.0.1 certifications. The exploited feature sat outside the certified scope.
- The AICPA warned in February 2026 that a flood of “fast and easy” SOC 2 tool vendors is pushing accounting firms to check the box rather than test the controls rigorously.
- The same pattern shows up beyond cybersecurity. A U.S. defense contractor paid over $500,000 in June 2026 to settle claims it submitted a false self-assessment score to the Pentagon.
- The answer isn’t to abandon certification. It’s to treat it as a baseline input for a wider, risk-based compliance program, not the final word.
Introduction: when GRC certification becomes destination
At a recent CoreStream GRC webinar on the modern CISO’s compliance stack, the panel was asked a blunt question: are there any regulations, frameworks or certifications that organizations place too much faith in? Tom Cornelius, founder of the Secure Controls Framework and senior partner at ComplianceForge, didn’t hesitate. He named SOC 2 and ISO 27001 directly, and called the market that has grown up around them “a race to the bottom.” As Paul Cadwallader, GRC Strategy Director at CoreStream GRC, explained: the real problem is any certification that rewards a checkbox mentality rather than proving an organization can actually find and fix risk.
That’s a strong challenge to two of the most widely trusted security credentials in business. But it is also, as this guide sets out, an increasingly well-evidenced one.
This doesn’t mean certification is worthless. A SOC 2 report or an ISO 27001 certificate still tells a customer, a regulator or a board something real: that a defined set of controls exists, was assessed by an independent party, and covers a defined scope. The trouble starts when that scoped, point-in-time assessment gets treated as a blanket guarantee, applied well beyond what it was ever designed to prove.
This guide looks at why that gap keeps opening up, what a real-world breach at a widely certified education technology company reveals about it, and what governance, risk and compliance (GRC) teams should be asking instead of “are we certified?”
Why SOC 2 and ISO 27001 became the default governance proof of security
For most buyers, a SOC 2 report or an ISO 27001 certificate is the fastest way to answer a hard question: can we trust this vendor with our data? ISO 27001 sets out requirements for an information security management system, independently audited and certified. SOC 2 reports, defined by the American Institute of CPAs (AICPA), examine a service organization’s controls over security, availability, processing integrity, confidentiality or privacy. Both exist for good reason, and both are now close to a baseline expectation in enterprise procurement.
That is what worries some of the people who built the frameworks GRC teams rely on. Speaking on CoreStream GRC’s webinar, Tom Cornelius argued that SOC 2 lets an organization pick its own controls to be assessed against, while ISO 27001 certification is frequently scoped narrowly enough to exclude the areas that would look worst.
“I really don’t feel they’re worth the money the certificates [are] printed on these days. It’s unfortunate, but it’s just been gamed. It’s a race to the bottom.”
Tom Cornelius, Senior Partner at ComplianceForge, Founder & Contributor at Secure Controls Framework
Paul Cadwallader put the underlying problem more precisely. Too many compliance programs measure activity, not outcomes: tracking whether a policy was reviewed or a training module completed, rather than whether risk incidents are actually being avoided or resolved. The issue isn’t any single framework, he argued, it’s any certification that reinforces a checkbox mentality of compliance, rather than proving an organization is good at identifying and resolving risk based on its criticality.
CoreStream GRC has addressed this in a previous article on The hidden risks of quick‑fix compliance tools in an era of proof‑based regulation. In that March 2026 analysis, the company warned that “SOC 2 matters, but it is often oversold as the golden compliance rubber stamp,” and pointed to PwC’s Global Compliance Survey 2025, which found that:
- Only 7% of organizations consider themselves leading in compliance today, while
- 85% believe compliance requirements have grown more complex over the past three years.
That complexity is exactly what makes a clean certificate so appealing: it promises a simple answer to an increasingly complicated question.
What the Instructure Canvas breach reveals about certification scope and real risk
A recent illustration of the gap between certified and secure comes from education technology.
In December 2025, Instructure, the Salt Lake City-based maker of the Canvas learning management system, announced the renewal of its ISO 27001 certification, its SOC 2 Type II attestation and its PCI DSS 4.0.1 compliance across its core products, saying “At Instructure, security is a central pillar of the trust we build with our customers and partners.”
Five months later, that certification was tested in practice. Over May 1 and again on May 6 to 7, 2026, the cybercrime group ShinyHunters twice gained access to Instructure’s Canvas platform in the same week, defacing the login page millions of students and educators use with a ransom demand, Krebs on Security reported.
Instructure confirmed the exposed data included names, email addresses, student ID numbers and messages between users, and found no evidence that passwords, financial information or government identifiers were affected. Instructure ultimately reached an agreement with the group and received confirmation of data destruction, according to the company’s own incident update (Status Update – 5/11/26).
The incident affected thousands of schools, colleges and school districts across the United States during final exams, disrupting access to grades, coursework and quizzes at institutions including Harvard, Princeton, Columbia and Georgetown, as CNN reported at the time.
Here’s what matters most for GRC teams. Writing in CSO Online in June 2026, cybersecurity executive Ron Baklarz noted that both intrusions involved Instructure’s “Free for Teacher” accounts, a lower-security, self-service version of Canvas. Baklarz reviewed Instructure’s ISO 27001 certificate directly and found that its defined scope, covering Canvas, Studio, Mastery Connect, Impact and several other named products, did not extend to Free for Teacher. The certificate itself was current and accurately described. It simply didn’t cover the feature that was exploited.
“Historically, many third-party risk programs focused heavily on compliance artifacts such as SOC reports, ISO certifications, penetration testing summaries and questionnaire-based responses. While these remain useful, the Canvas incident demonstrates that such controls alone do not guarantee operational security and resilience.”
Ron Baklarz, cybersecurity executive, writing in CSO Online
It’s also worth noting that ShinyHunters had targeted Instructure’s environment before, including a separate, earlier incident affecting the University of Pennsylvania in September 2025. That is a useful reminder for GRC teams more broadly: determined attackers often return to a platform rather than treating a single patch as the end of the story, which is exactly why ongoing monitoring matters as much as the initial certification.

The pressure to cut corners isn’t limited to cybersecurity
The Canvas breach is a scope problem: a real certification that didn’t extend far enough. Elsewhere, the same faith in a badge is breaking down for a more direct reason, the underlying assessment wasn’t rigorous enough to begin with.
In February 2026, the AICPA’s own trade publication, the Journal of Accountancy, reported that a growing number of technology vendors are marketing “fast and easy” SOC 2 examinations, in some cases promising turnaround in days rather than weeks, and cultivating networks of smaller accounting firms to sign off on high volumes of reports. As Sean Linton, audit partner at EisnerAmper LLP and chair of the AICPA’s SOC 2 Working Group, warns:
“[SOC] professionals are seeing indications that ‘fast and easy’ may come at the expense of quality and objectivity.”
Sean Linton, audit partner at EisnerAmper LLP and chair of the AICPA’s SOC 2 Working Group
Fellow SOC 2 Working Group member Terry O’Brien, Director of Schellman put it more bluntly:
“You just know it’s a template. You can compare any five of their reports, and they’re all exactly the same, with a different client logo on it.”
Terry O’Brien, Director, Schellman
Government contracting shows a similar pressure playing out.
In June 2026, DefenseScoop reported that Alabama-based logistics contractor LOGZONE agreed to pay more than $507,000 to settle Justice Department claims that it misrepresented its cybersecurity compliance on two U.S. Navy contracts. LOGZONE had submitted a self-assessment score of 110, a perfect score under the Pentagon’s framework, in 2021. A 2024 review by the Defense Industrial Base Cybersecurity Assessment Center found the company’s actual score was negative 170, close to the bottom of the scale. The case was resolved under the False Claims Act, the same law the Department of Justice used to recover over $52 million from contractors in its 2025 fiscal year alone as part of its Civil Cyber-Fraud Initiative.
Different industries, different frameworks, but the same underlying lesson: a self-reported or lightly scrutinized certification is only as reliable as the process that produced it.
What GRC teams should ask instead of “are we certified?”
None of this means GRC and security teams should stop asking vendors, or themselves, for SOC 2 reports and ISO 27001 certificates. But it does mean that those documents should be the start of a compliance risk assessment, not the end of one.
CoreStream GRC holds SOC 2, ISO 27001, Cyber Essentials Plus and TX-RAMP certifications, and takes the same view internally that it’s asking of its customers: certificates confirm that a management system exists, not that it is embedded everywhere it needs to be. That distinction sits at the heart of the value-based approach to compliance culture CoreStream GRC sets out in its value-based compliance culture guide: a compliance-only mindset “can produce silence, box-ticking and workarounds,” while an integrity-led one “makes speaking up normal, makes decisions defensible, and makes accountability real.”
In practice, that means a small number of sharper questions belong in every vendor risk management workflow and every internal audit program:
- What exactly is in scope? Ask for the certificate’s defined boundary, not just its badge, and check whether the feature, product or team you actually depend on is named in it.
- Is least privilege verified, or just documented? A policy that says access is restricted is not the same as evidence that it is checked.
- What happens after an incident? Ask whether a vendor’s past incidents were closed with a root-cause investigation, or just a patch.
- Where did this finding come from? A healthy compliance risk assessment draws on internal audit, external audit, self-identified issues and incidents, not one source repeating the same result.
- Is this an onboarding check or an ongoing one? Too many vendor risk programs are strong at onboarding, when the questionnaire is fresh, and weak on ongoing monitoring once the relationship goes live. A scoped audit from twelve months ago says less about today’s risk than a live, continuously monitored control environment.
Teams managing multiple vendors under this kind of scrutiny need a way to keep the answers in one place rather than buried in a folder of PDFs.
That’s why CoreStream GRC has partnered with Xapien and SANNOS to transform third-party risk management. Their new TPRM solution includes ongoing monitoring to give GRC, security and compliance teams a live, evidence-backed view of vendor risk, rather than a stack of certificates nobody has time to interrogate. The SANNOS Intelligence Layer can even analyze certificates and reports to identify gaps (ask for more detail).
For organizations managing multiple certification frameworks, the “Assess once. Comply with many” capability of CoreStream GRC x SANNOS x SCF provides real-time visibility across multiple frameworks, in hours, not months, eliminating duplicate testing, reducing manual effort and enabling the focus that Paul Cadwallader promotes: validation and remediation, not administration.
Conclusion: Compliance teams should treat certification as a floor, not a finish line
Certification isn’t the enemy here. Complacency is. A SOC 2 report or an ISO 27001 certificate is real evidence of real work, assessed by an independent party, and it remains one of the fastest ways to establish a baseline of trust with a new vendor or customer. The Instructure Canvas breach didn’t happen because the company’s certifications were fake. It happened because a real, accurately scoped certification was treated as if it covered more than it did.
As Paul Cadwallader put it on CoreStream GRC’s recent webinar, the standards worth trusting are the ones “that support that kind of risk-based approach, rather than checkbox approach”: certifications that prove an organization can find risk quickly and fix it, not just complete a form.
If you’re re-thinking how your organization uses certification, audits and vendor questionnaires as part of a wider compliance risk assessment, CoreStream GRC’s team can help you build a program that treats every certificate as a starting point, not a guarantee.
Book a workshop with CoreStream GRC to review your current approach to vendor and certification risk, or request a demo to see how CoreStream GRC brings certification, evidence and continuous monitoring together in one place with partners like SCF and SANNOS.
FAQ on SOC 2, ISO 27001 and compliance certification
No. ISO 27001 certification confirms that an organization has an information security management system covering a defined scope, and that an independent auditor tested it. It does not guarantee that every product, feature or team is covered, or that the organization is secure outside that scope.
A SOC 2 report, defined by the AICPA, examines a service organization’s controls related to security, availability, processing integrity, confidentiality or privacy, based on criteria the organization itself selects. It is a scoped, point-in-time assessment, not a blanket statement that a company is fully secure.
Certified companies still get breached because certification only covers what falls inside its defined scope, and because some assessments, rushed, templated or self-reported, do not test controls rigorously enough to catch real gaps. Both patterns show up in recent, well-documented cases.
Vendor risk teams should treat these reports as one input into a wider compliance risk assessment: checking exactly what is in scope, asking how incidents were investigated, and pairing point-in-time certificates with continuous monitoring rather than accepting a badge at face value.
A compliance risk assessment evaluates an organization’s actual exposure to risk and the effectiveness of its controls, drawing on multiple sources of evidence over time. Certification is a single, scoped data point that can inform that assessment, but it isn’t a substitute for it.



