3 ms·
> First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them. Getting an ISO 27001 certificat
by quicksilver03 5y ago
> First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them.
Getting an ISO 27001 certification can take months of effort, and not all deals can be stretched this far without significant repercussions.
Just a data point, I lead the certification project at my current company and it took us 8 months (~65 people in total, of which 3 full-time in IT): the auditors were a little hesitant at first because the system wasn't "battle-tested" as much as they'd liked.
- tptacek 5y agoRight. The short answer to the question this post asks is: "if you're a North America startup, do not get ISO 27001, and be wary of any advisor that says you should do so without a 7 figure purchase order closed and contingent on it." SOC2 is a little bit trickier, but not much trickier: the strategy is the same: wait until you have to, and then get it to close the deal.