ISO 27001 A management system, not a checklist. It asks you to decide what matters, write it down, and prove you follow it.
SOC 2 An auditor’s opinion on controls you claim to operate, over a window of time. Evidence collected as you go, or not at all.
EU GDPR Law, not certification. Lawful basis, records, and a defensible answer when someone asks what you hold and why.
Why bother this early
Because the first enterprise deal, the first funding round and the first breach all ask the same questions — and the answers take months to build, not days.
How a consultant helps
You get the judgement of someone who has run these projects before, without hiring for a role you can’t yet keep busy.
WHAT WE DO
Working with a small team
1 Unblock the deal in front of you. The questionnaire or security review currently holding up a contract, answered honestly and quickly — usually the reason anyone calls in the first place.
2 Decide what you actually need. ISO 27001, SOC 2, both or neither. A straight recommendation before you commit budget to a certification your buyers were not asking for.
3 Build the minimum credible programme. Policies, access control, logging and vendor management sized for your headcount rather than copied from a bank and quietly ignored.
4 Run the certification. Evidence, internal audit and auditor liaison through to the certificate, without pulling your engineers off the roadmap for a quarter.
5 Keep it alive. A reporting rhythm light enough that the programme survives your next hire, your next round and your next customer without a rebuild.
If a certification is not the fastest route to the outcome you want, we will say so. A gap analysis that ends in “not yet, and here is why” is still a useful answer.
WHAT GETS ASKED
What buyers and investors actually ask for
The questionnaire Two hundred questions from a buyer’s security team, usually arriving with a deadline attached to a signature.
A certificate ISO 27001 or a SOC 2 report — increasingly a procurement gate rather than a differentiator.
GDPR answers A data processing agreement, a sub-processor list, and a clear account of what you hold and on what basis.
Test evidence A recent penetration test and a vulnerability management process that shows findings are actually closed.
COMMON QUESTIONS
Startups & SMEs, in short
Do we need ISO 27001 or SOC 2?
Possibly neither. ISO 27001, SOC 2, both or neither is a straight recommendation made before you commit budget to a certification your buyers were not asking for. What is the difference between ISO 27001 and SOC 2?
ISO 27001 is a management system, not a checklist — it asks you to decide what matters, write it down and prove you follow it. SOC 2 is an auditor’s opinion on controls you claim to operate, over a window of time, with evidence collected as you go. Why start on compliance this early?
Because the first enterprise deal, the first funding round and the first breach all ask the same questions, and the answers take months to build rather than days. INSIGHTS · STARTUPS & SMES Writing for this sector
All insights →