4 ms·
I was in the same situation and had to get SOC 2 and ISO27001 to keep a juicy account. My suggestion would be "absolutely not until you absolutely must". It's
by e1g 3y ago
I was in the same situation and had to get SOC 2 and ISO27001 to keep a juicy account. My suggestion would be "absolutely not until you absolutely must".
It's a bottomless pit of time and money. All those "automation tools" (e.g., Drata/Vanta) help with 10-20% of the overall workload, and for me, took as many hours to set up as they saved. For ISO27001, your final annual cost will be $20-40k and will eat up 2-4 weeks per year. Implementing and maintaining a compliance program will do nothing to help you discover/solve customer problems or improve your security posture. Doing this work is the equivalent of "I want to do a startup, so I'm learning how to do business registration, taxation, comply with employment laws, and design business cards".
Compliance will waste your already constrained resources, energy, and focus. It will slow you down and has such a negative ROI that you must have significant deals at risk to consider imposing this ongoing tax on your operations. In other words, wait until you're forced to by your customers/prospects.