SHAHEER.
All services

ISO 27001, SOC 2, or a good answer to the questionnaire

Which one your buyer actually requires, and what to do while you decide.

Talk to an expert How we work

In short

A certificate is worth what it unblocks. If one named customer is asking for SOC 2, that is the answer. If several are asking and some are outside the United States, ISO 27001 travels further. If nobody has asked and you are guessing, the questionnaire answered well closes the same deals for a fraction of the work.

Work it out in a minute

Where is your business losing value? →

Nine questions across revenue, capacity and control. Shows which of the three is costing you most, and where to start.

What we take on

Start with who is asking

The right answer is the one that unblocks the deal in front of you. Ask the buyer whether they need the certificate itself or an acceptable answer to their questionnaire. Those are different requirements and only one of them takes a year.

SOC 2 when the buyer is US enterprise

A report a CPA firm writes about how you actually operated over a period. American buyers ask for it by name. Type II needs a window of evidence behind it, which is why collecting evidence early matters more than choosing early.

ISO 27001 when the asks are many

A certificate against an international standard, renewed on a cycle. It is recognized in more countries and more industries, and it asks you to keep running a management system rather than to pass a point in time.

Neither, more often than you would expect

Plenty of companies win enterprise work on a completed questionnaire, a short written summary of how they handle data, and named owners. Weeks rather than quarters, and it is the same groundwork either certificate would need.

The first six weeks are identical

Access reviews, change records, a vendor list, a backup somebody has restored, and a name against each. Every route starts here, so none of it is wasted while the decision is still open.

Who actually signs it

An ISO certificate comes from an accredited certification body and a SOC 2 report from a licensed CPA firm. Nobody else can issue either. Preparation is what a consultant does, and a short audit is what good preparation buys.

What the decision actually turns on

Start with the deal. One named customer asking for SOC 2 makes the decision for you, and it is worth asking their procurement contact directly whether a completed questionnaire and a remediation plan with dates would clear their bar. Below the largest accounts, it frequently does.

If the requests are arriving from several directions, or from outside the United States, ISO 27001 is recognized in more places. It is also the heavier commitment, because it asks you to keep running a management system after the certificate arrives rather than to pass an audit and stop.

SOC 2 comes in two shapes. Type I says the controls existed on a date. Type II says they operated across a period, usually three to twelve months, and Type II is what buyers mean when they say SOC 2. That window is the reason to start collecting evidence before you have chosen a route.

Timelines move with how much groundwork already exists rather than with which route you pick. A company with named owners, a vendor list and a quarterly access review is months from either. A company starting from nothing is not, and no platform changes that.

Compliance platforms are useful and they are not the work. They collect evidence and track controls. They do not decide who owns a process, they do not remove the access somebody kept after they left, and they do not answer the buyer who wants to talk to a person about it.

While the decision is open, do the part that counts either way: who has access to what, what changed and who approved it, which vendors hold your data, and whether the backup restores. That alone answers most of a security questionnaire.

Questions we get

Which one do most small companies actually need?

Neither, at first. Most enterprise deals below the largest accounts clear on a completed questionnaire, a short written summary of how you handle data, and named owners. A certificate becomes worth its cost when the same request arrives from several buyers, or from one large enough to set the terms.

The signal is repetition. One request is a deal. Four requests is a pattern, and a pattern is what a certificate is for.

How long does ISO 27001 take?

From a standing start with nothing documented, plan on the better part of a year, most of it spent building habits rather than writing policies. From a company that already has named owners, access reviews and a vendor list, a few months.

The variable is the groundwork, not the standard.

Can you certify us?

No, and nobody selling consulting can. An ISO certificate is issued by an accredited certification body and a SOC 2 report by a licensed CPA firm, both independent of whoever helped you prepare.

The preparation is the part we do: the system, the owners, the evidence, and the internal audit that finds the gaps before the auditor does.

Is a compliance platform enough on its own?

It is enough to track and to collect. It is not enough to decide. The platform will tell you a control is failing. Somebody still has to own the process, remove the access, chase the vendor and write the answer.

Buy one if it saves your team time. Do not buy one expecting it to make the calls.

What if the customer will not wait?

Ask what they need to proceed. Usually it is the completed questionnaire, a remediation plan with dates against each item, and a named contact. Contract terms often carry the rest while a certificate is in progress.

That conversation tends to be shorter than the one where you say you are working on it.

A questionnaire came back with gaps. What now?

You have a free list of exactly what to fix, in the order the buyer cares about. Put a name and a date on each item and send the plan back.

Buyers accept a dated plan far more often than people expect. What loses deals is silence.

More in the guides and every answer in one place.

Services
Fractional operations Operations assessment AI strategy Process automation Website development App development SEO and search traffic Lead generation PR and billboards Legal operations Business notices Business documents
Who does the work

Shaheer leads the work, with engineers, writers, filers and analysts behind him. C-suite operations for a San Francisco AI company, Six Sigma on the process side, Anthropic certified on the Model Context Protocol, ten years across eight industries. See what we have built

Tell us what you are working on

Building, fixing or improving something. A rough question is enough to start.

A person replies within one business day. Or pick a time, or [email protected]