Apicus · chapter no. 03

Compliance: when, not just what. SOC 2 too early burns runway. Too late burns deals.

One of the hardest founder calls is when to pursue SOC 2, ISO 27001, and their cousins versus pouring those months into product and sales. The resolution: certification is a sales artifact, not a security artifact. You pursue it when it unblocks revenue, you prepare for it long before that, and you never confuse it with actually being secure.

0 blocked enterprise deal is the classic trigger
0 typical path to a SOC 2 Type I
0 typical path to ISO 27001
0 certifications needed pre-PMF, unless you touch regulated data

No. 01 · The timing call

Sales, product, or compliance?

The mistake runs both directions. Certify at idea stage and you spend a quarter of runway proving controls for customers you don't have. Wait until procurement asks and you're six months from a signature the deal needed last month. The market tells you when; you just have to read the signals honestly.

Is it time? Check what's true today

Signals it's time to certify

  • A deal died in security review. That's the market pricing the certification for you: it now pays for itself.
  • Questionnaires arrive before demos. When prospects ask about SOC 2 in the first call, the report has become table stakes in your segment.
  • You're moving upmarket. Enterprise procurement gates on attestations; entering that motion without one adds months to every cycle.
  • Your data class demands it. Health data means HIPAA obligations from day one. Card data means PCI scope from the first transaction. Government means the clock starts years before revenue.

Signals it's too early

  • No enterprise pipeline. SMB and consumer buyers almost never ask. Certifying for an imagined future buyer is runway spent on theater.
  • Pre-product-market fit. If the product may pivot, the audit scope pivots with it and the money is gone. Do the security basics instead.
  • Nobody has asked. Not once, not softly. Compliance pulled by no customer is a founder anxiety purchase.
  • You'd be certifying to avoid selling. An audit has a checklist and a finish line; sales doesn't. Beware which one feels more comfortable.

No. 02 · The alphabet

The frameworks, decoded

Two useful distinctions. Attestations and certifications (SOC 2, ISO 27001) are voluntary and exist to win deals. Regulations (HIPAA, PCI DSS, GDPR) are not optional and attach the moment you touch the data. A note on cost: the ranges vendors quote assume you outsource the preparation. Build the controls and collect the evidence in-house and you pay little beyond the auditor's fee and your own time.

FrameworkWhat it isWho asks for itTypical costWhen it applies
SOC 2 Type IAuditor attests your security controls exist, at a point in timeUS B2B software buyersAudit from ~$5k with in-house prep; $15k – $40k outsourcedwhen sales demand it
SOC 2 Type IISame controls, observed operating over 3–12 months. The one enterprises actually wantUS enterprise procurement$10k – $30k audit with in-house prep; more outsourcedwhen sales demand it
ISO 27001Certified information security management system, audited against the international standardEuropean and global enterprise$10k – $40k for the audits; the ISMS build is yours to do cheaply or expensivelywhen sales demand it
HIPAAUS law for protected health information (PHI). Not a certificate: obligations plus BAAs (business associate agreements) with every partner that touches the dataHealthcare customers and the lawLegal + engineering timeday one with PHI
PCI DSSCard-industry security standard, leveled by transaction volumeCard networks and processorsMinimal if you scope cards out to your processor: typically an annual SAQ A self-assessmentday one with card data
GDPR / state privacyPrivacy law that attaches when you target or monitor people in the EU, wherever you sit; US state laws (CCPA and a growing list) add their own thresholdsRegulators, plus enterprise DPAs (data processing agreements)Legal + engineering timeday one with EU / covered users
FedRAMPUS federal cloud authorization; agency sponsorship is the standard pathFederal agency buyers$250k+years before gov revenue
CMMCDoD contractor requirement, restructured from five levels to three (the transitional levels are gone). Level 1, for federal contract info, is an annual self-assessment; third-party assessment arrives at Level 2 for controlled unclassified information (a minority of Level 2 contracts still allow self-assessment)DoD contracting officers and primesNear zero at Level 1: a self-assessment posted to SPRS (the DoD's Supplier Performance Risk System). Assessment costs start at Level 2when the contract clause requires it

Standard sources: AICPA (SOC 2), ISO 27001, HHS (HIPAA), PCI Security Standards Council, FedRAMP. Automation platforms can collect audit evidence for you, but the attestation comes from an auditor and the security comes from your practices; no tool confers either. One scoping note: a SOC 2 audit covers the Trust Services Criteria you choose; Security is mandatory and the rest (Availability, Confidentiality, Processing Integrity, Privacy) are optional add-ons. Start Security-only unless a buyer demands more.

No. 03 · The real cost is months

What each path actually takes

Dollar costs are survivable; the months are the strategic price. Every timeline below is founder and engineering attention that isn't going into product or pipeline, which is exactly why the timing call matters.

Typical time from start to report in hand

SOC 2 Type Ithe bridge: controls in place, point-in-time
~3 mo
SOC 2 Type IIincludes the observation window
~9 mo
ISO 27001ISMS build + stage 1 and 2 audits
~12 mo
FedRAMPauthorization, agency sponsor required
~18–24 mo

Common sequencing: start SOC 2 Type I as the bridge that unblocks deals in months, begin the Type II observation window immediately behind it, and add ISO 27001 only when European or global enterprise pipeline justifies a second audit regime. SOC 2 refreshes annually; ISO 27001 runs a three-year certification cycle with lighter annual surveillance audits. Compliance is a subscription, not a purchase. CMMC Level 1, by contrast, is an annual self-assessment a small team can complete in days.

No. 04 · The middle path

Compliance-ready without certifying

The resolution to the timing dilemma: practice security from day one so that certification, whenever sales demands it, is a formality instead of a rebuild. All of this is cheap now and expensive to retrofit; doing it yourselves means certification later costs an audit fee, not a consulting engagement.

The technical basics

SSO and MFA everywhere, encryption at rest and in transit, least-privilege access, offboarding that actually revokes, logging on, backups tested. This is most of a SOC 2 before an auditor ever appears.

The paper basics

A short security policy, an incident response plan, a vendor list with what data each one touches, and access reviews on a calendar. Auditors call these controls; customers call them answers.

A security page and a filled questionnaire

One public page describing your practices, plus a completed standard questionnaire (CAIQ or SIG, the two forms buyers circulate) you can return within a day. This alone carries many mid-market deals past review without any certification.

The cheaper unblock: a pen test

Many mid-market security reviews accept a recent third-party penetration test (roughly $5k to $25k, weeks not months) plus your questionnaire answers. It's often the fastest way through a stalled deal while a SOC 2 window runs.

Scope discipline

Keep regulated data out of your systems where you can: cards stay with the payment processor, health data stays out until healthcare is truly the market. The cheapest compliance is the scope you never take on.

Inherit your cloud's certifications

AWS and Azure already carry SOC 2 reports plus ISO 27001, PCI DSS, and FedRAMP certifications at the infrastructure layer and you inherit those controls for everything they operate: data centers, physical security, much of the platform. Auditors accept the providers' own reports, downloadable from AWS Artifact ↗ and Microsoft's Service Trust Portal ↗; the full program lists live at AWS compliance programs ↗. For HIPAA, sign the provider's BAA and stay on the eligible services; for government, build in the already-authorized regions (GovCloud, Azure Government) instead of authorizing your own stack. Google Cloud offers the equivalents.

Know the shared responsibility line

Provider certification covers compliance of the cloud; you still own compliance in it: your code, your access controls, your configurations, your data handling. A misconfigured storage bucket on certified infrastructure is still your breach. The inheritance shrinks your audit scope to what you build, which is exactly the point.

No. 05 · How it goes wrong

The compliance pitfalls

  1. 01

    Certifying before anyone asked.

    A quarter of runway and your best engineer's attention, spent to impress customers who buy on product. Let a blocked deal or a regulated data class pull it; don't push it.

  2. 02

    Treating Type I as the finish line.

    Enterprises read Type I as "started, not finished." Begin the Type II observation window the day Type I lands, or you'll re-stall in the same procurement queue next quarter.

  3. 03

    Compliance theater.

    Dashboards full of green checks with MFA half-deployed and offboarding by memory. Auditors sample evidence; breaches sample reality. The practices are the product; the report is the receipt.

  4. 04

    Letting the audit freeze the roadmap.

    Scope the audit to the product boundary that customers touch, not the whole company. A well-scoped audit runs beside development; a badly scoped one stops it.

  5. 05

    Forgetting it renews.

    SOC 2 and ISO 27001 are annual. Budget the audit, the evidence upkeep, and the calendar reviews as a permanent operating cost from the first engagement, because that's what they are.

Next chapter · No. 04

Advisors & board construction

Advisor equity norms, seat math by stage, and who really controls the company.

Previous chapter · No. 02

Intellectual property in the US

The four protections, the clocks that kill rights, and who actually owns the code.