पाठशाला Pathshala · संचालन Sanchālan, Operations · Lesson 25 · Scale

SOC 2, ISO 27001 and compliance as a sales tool

A security report is a sales asset with an expiry date. Choose the one your buyers ask for, start the evidence clock early, and put the report where the deal stalls.

Pathshala, The Founder Library · 11 October 2026 · 7 min read

A long brick fort wall at Lakhpat running across the dry flat land of Kutch under an open sky.
Photograph: Setu Chhaya · Pexels

The enterprise deal rarely dies in the demo. It dies in the eleventh week, in a spreadsheet of three hundred security questions sent by someone the founder has never met, and it dies quietly. A security report signed by an auditor is how a company stops losing deals in that room.

This lesson treats certification as what it is for a growing company: a sales asset. It covers what the buyer is really asking for, the difference between SOC 2 and ISO/IEC 27001, which to choose first, the programme month by month with a timeline you can adjust, what it costs, and how to use the report so it pays back. It assumes the basics in [security before the first enterprise customer](/library/security-basics-before-first-enterprise-customer) are already in place.

What an enterprise buyer is actually asking for

A large company that buys software inherits the vendor’s risk. If the vendor leaks the customer’s data the customer answers for it to its own regulators and customers. So procurement runs a vendor review, and the review has two ways to get comfortable: interrogate the vendor directly, which means questionnaires, calls and sometimes a visit, or rely on someone independent who has already done that work. The report is the second route. It does not make the vendor safe. It makes the buyer’s reviewer able to say yes without doing the work again.

In India the pressure is written into regulation for one large group of buyers. The Reserve Bank’s Directions on Outsourcing of Information Technology Services of 10 April 2023, in force from 1 October 2023, require banks and other regulated entities to keep the right to audit their technology vendors and to give the RBI the same access. They also allow the regulated entity, depending on its risk assessment, to rely on globally recognised third-party certifications made available by the vendor, while staying responsible for assurance. That sentence is the commercial case for a certificate when selling to a bank or an NBFC: it is the document their compliance team is permitted to lean on.

SOC 2 and ISO 27001, side by side

SOC 2 is an attestation report issued by a CPA firm under the American Institute of CPAs’ System and Organization Controls framework. It reports on a service organisation’s controls against trust services criteria in five categories: security, availability, processing integrity, confidentiality and privacy. Security is the one every report covers; the others are added when customers need them. There are two kinds. A Type I report assesses whether the controls are designed properly at a single point in time. A Type II assesses design and operating effectiveness over a period, an observation window that typically runs three to twelve months. The report is long, carries the auditor’s opinion and is shared under a non-disclosure agreement.

ISO/IEC 27001 is an international standard that defines the requirements an information security management system must meet: how a company finds its risks, chooses controls and keeps improving them. The current edition is ISO/IEC 27001:2022, which replaced the 2013 version, and ISO asks that it be cited in full rather than as ISO 27001. Certification is optional and is issued by a certification body; a certificate from a body accredited by a national accreditation body carries more weight. ISO’s own survey counted over 70,000 certificates in 150 countries in 2022. The certificate is a single page that can be shared freely, which is part of its appeal.

The practical difference is in what each proves. SOC 2 Type II says an auditor tested your controls over months and found they worked. ISO/IEC 27001 says an auditor found you run a management system that identifies risks and treats them, and will keep checking. Which one a buyer asks for depends on where its procurement team learned the habit, and the only reliable guide is the buyers in your own pipeline.

Choosing the first one

Do not choose by reading comparison articles. Choose by reading your own lost and stalled deals. Pull every enterprise opportunity from the last four quarters that reached a security review and write down what the buyer asked for by name. If most named SOC 2, start there. If most named ISO/IEC 27001, start there. If they were split, start with the one your largest three prospects named, because the first report should unblock specific revenue rather than a market in general.

Two further rules settle most cases. If the target buyers include Indian banks or NBFCs, expect the RBI’s audit clauses in the contract whatever certificate you hold, and ask their compliance teams early which certification they will rely on. If the company sells mainly to American mid-market software buyers, a SOC 2 Type I can open doors within a quarter while the Type II window runs. Many companies eventually hold both; the controls overlap heavily, so the second takes far less work than the first.

The programme, month by month

Weeks one to four: scope and owner. Name one owner, usually the engineering lead or a first security hire, and give them the decision rights to change how access is granted. Decide the scope: which product, which environments, which offices and which people. A narrow scope that covers what customers actually buy is faster and still useful. Weeks four to twelve: readiness. Write the policies the framework needs, and then make them true: access reviews every quarter, joiner and leaver checklists, logging, encryption, a vendor register, background checks, security training, an incident plan. A compliance automation platform can collect much of the evidence from cloud and identity systems; it does not do the work of changing behaviour.

A pile of rusty metal keys of different shapes and sizes lying together.
Most of the readiness work is unglamorous: knowing who holds which key and taking it back when they leave. The auditor checks that it happened every time. Photograph: Nikita Belokhonov · Pexels

The window. For a Type II the observation window starts once the controls are running, and nothing shortens it. Three months is the minimum most auditors accept; six is common for a first report. For ISO/IEC 27001 the equivalent is the two-stage audit: stage one reviews the documents, often remotely; stage two tests that the system runs in practice. Fieldwork and report. The auditor tests samples, raises exceptions and drafts the report. A first Type I typically takes three to six months end to end and a first Type II six to fifteen, by one vendor’s published estimate. Move the sliders to see where your own plan lands.

Two things fall out of the figure. Readiness is the only phase the company controls, so shortening it is where the founder’s attention belongs; a team that takes twenty weeks to switch on access reviews has added five months to every deal waiting on the report. And the observation window means the cheapest decision is to start it early: a company that expects enterprise deals in eighteen months should begin the controls now, because evidence cannot be produced after the fact.

A security report is not proof that a company is safe. It is proof a buyer’s reviewer can use to say yes without doing the work again.

What it costs, and what it does not buy

The visible cost is the auditor. One compliance-software vendor puts audit fees at roughly $7,500 to $60,000 for a Type I and $12,000 to $100,000 or more for a Type II, with the range driven by scope and the firm chosen. Get two or three quotes, including from Indian firms that issue SOC reports and from accredited certification bodies. Add the platform, any penetration test the auditor expects, and the larger cost nobody budgets: engineering and operations time during readiness, often a large share of one senior person for a quarter.

Weigh it against the pipeline. If ₹3 crore of enterprise pipeline is waiting on a security review and the company wins a quarter of what it pitches, ₹75 lakh of expected bookings depends on the report, and every week of slip delays that money. The arithmetic usually favours starting. What the report does not buy is security itself. A company can pass an audit of a narrow scope and still be breached outside it, and the incident obligations in India, CERT-In’s six-hour reporting and the duties under the [DPDP Act](/library/dpdp-act-what-it-requires-of-your-product), apply whatever certificate hangs on the wall.

Using the report to sell

A report kept in a shared drive earns nothing. Build three things around it. A trust page on the website listing the frameworks held, the scope, the audit period and how to request the report under NDA, so prospects find it before procurement asks. An answer pack: the company’s completed responses to the two or three questionnaires buyers send most often, kept current by the security owner and sent the same day a questionnaire arrives. A seat in the deal: the security owner joins the call when a large prospect’s security team engages, and sales tracks security review as a named stage in the pipeline with its own conversion rate. When that stage’s conversion rises and its duration falls, the programme is paying back. Bring the same evidence to [Indian enterprise buyers](/library/selling-to-indian-enterprises), whose procurement teams increasingly send the same questionnaires as global ones.

The compliance calendar after the first report

Monthly: the security owner reviews the automated evidence and closes any control that drifted, because a gap found by the auditor in month eleven becomes an exception in the report. Quarterly: access reviews, vendor review, a tabletop of the incident plan, and a line in the board pack on controls, exceptions and the security-review stage of the pipeline. Annually: the SOC 2 Type II renewal, since buyers expect a report no older than twelve months, or the ISO/IEC 27001 surveillance audit in years two and three and recertification in year three. Before every large deal: check the report’s period covers what the buyer needs and send a bridge letter if the next report is not yet out.


Audit fees and timelines vary with scope and auditor, and regulation changes; figures were checked on 11 October 2026. Nothing here is legal advice.

Sources

  1. Reserve Bank of India, Master Direction on Outsourcing of Information Technology Services, 10 April 2023, in force 1 October 2023: audit rights, regulator access and reliance on third-party certifications (checked 11 October 2026)
  2. AICPA and CIMA, System and Organization Controls: SOC suite of services, including SOC 2 on security, availability, processing integrity, confidentiality or privacy
  3. ISO, ISO/IEC 27001:2022 Information security management systems: edition 3, October 2022; optional certification; over 70,000 certificates in 150 countries in the ISO Survey 2022
  4. Drata, SOC 2 Type 1 vs Type 2: observation periods of three to twelve months, first-report timelines and published audit cost ranges (vendor estimate, checked 11 October 2026)
  5. CERT-In, Directions under section 70B of the Information Technology Act 2000, 28 April 2022: incidents reported within six hours of noticing them (checked 11 October 2026)
  6. Drata, ISO 27001 certification process: stage 1 and stage 2 audits, three-year certificate, annual surveillance audits, recertification (checked 11 October 2026)