Sector view · In preparation

Technology and SaaS

Enterprise procurement asks for a certificate before it asks about your product.

The reality

For a technology company selling to enterprises, a security questionnaire arrives before the contract does, and the answer determines whether the deal proceeds. SOC 2 is the report United States buyers ask for; ISO 27001 is what European and regional enterprises name. Neither is optional once you are selling upmarket.

How the work is organised

Decide which report the buyers actually want before building toward one, because the preparation differs. A SOC 2 Type II tests operating effectiveness across a period, so evidence discipline must begin months before the examination window opens.

The trap we see most often

Starting the observation period before the controls are genuinely running. A Type II examination tests every month of the window, and a control that started late shortens the report or weakens the opinion.

Our position in this sector is still being developed. The regimes listed apply and the assessments cover them, but we have not yet published the depth of sector guidance that the other sectors carry.