The SaaS trust centre that measurably shortens sales cycles

A trust centre isn't a marketing page — it's a procurement tool. The right structure turns week-long security reviews into a self-serve pass and moves deals into legal review faster.

Michael McCarroll 15 min read Updated June 2026

Why trust centre matters for B2B SaaS companies

For a 20–200 person B2B SaaS company turning over £2m–£20m ARR, trust centre has moved from a nice-to-have to a deal-shaping requirement. Enterprise buyers, regulated industries and procurement now ask for it by name in RFPs, and the absence of a credible answer is enough to lose the deal before a technical conversation ever happens.

The ICP this guide is written for: a 20–200 person B2B tech business turning over £2m–£20m, pursuing trust centre (often alongside one or more of ISO 27001, ISO 20000-1, ISO 9001 and ISO 42001) without a dedicated full-time compliance manager. The founder, CTO, COO or Head of Ops usually owns it in practice.

  • You are past the stage where 'we take security seriously' answers a questionnaire
  • Your average enterprise sales cycle now includes an infosec assurance step
  • You cannot justify a £120k head to own compliance — but the work is real

Where firms in this sector typically start

Most saas firms we speak to are somewhere between two familiar states: an experienced team who genuinely do the right things but cannot prove it to a buyer, and a team with a folder of policies written by someone external three years ago that no one has opened since.

Neither passes a modern audit or a modern buyer review. The starting point isn't 'implement everything' — it's a short, honest gap analysis against the standard, mapped to what already exists.

  • A 60–90 minute internal walkthrough of what already exists
  • A gap register scoped to the standard's mandatory clauses first, then Annex controls
  • An owner and a target certification window — 4–6 months is realistic for this sector

The minimum viable programme

Without a full-time compliance manager, the trap is trying to do everything. A minimum viable trust centre programme for a 20–200 person B2B SaaS company turning over £2m–£20m ARR is scoped, owned, and evidenced — not exhaustive.

The essential ingredients are the same across sectors: a defined scope, a leadership team that has signed off, a live risk register, the controls the standard requires, policies people actually read, and evidence produced as a by-product of doing the work rather than a separate reporting task.

  • Scope statement (single page, signed by the CEO)
  • Risk register with owners, treatment plans and review dates
  • Controls / Annex mapping showing what applies, what doesn't, and why
  • Policies drafted for adoption, not for a shelf
  • Evidence store linked directly to controls and audits
  • A calendar of internal audit, management review and improvement actions

Sector-specific pitfalls in SaaS firms

SaaS firms typically try to certify the whole company when they should certify the product and its operational surroundings. A tight product-and-platform scope is more defensible, cheaper and more useful to buyers than a company-wide certificate that has to cover HR laptops in the same breath as production.

The second pattern to avoid is treating the standard like a shopping list. The clauses that talk about leadership, planning, evaluation and improvement matter more than the controls themselves — those are what auditors actually test for maturity.

How ISO-STANDARD.app changes the economics

The reason a 20–200 person B2B SaaS company turning over £2m–£20m ARR without a compliance manager historically failed to certify wasn't will — it was cost. A traditional consultancy-plus-spreadsheet programme runs £30k–£45k in year one. Most of that pays for policy drafting, spreadsheet maintenance and evidence chasing that a modern platform simply removes.

ISO-STANDARD.app ships a ready-to-adopt trust centre workspace with the risk register, controls catalogue, policies, evidence store, internal audit programme and audit-ready exports already wired together. What remains is your organisation's genuinely unique work — scope, risk decisions, and evidence — which is where a founder or ops leader's time actually adds value.

  • Consultancy-led baseline: ~£30k–£45k in year one
  • Templates + spreadsheets baseline: ~£20k–£25k with heavy internal hours
  • ISO-STANDARD.app: from £39/month plus focused internal effort

A 90-day path to readiness

For a 20–200 person B2B SaaS company turning over £2m–£20m ARR, a credible 90-day readiness path exists and is well-worn. Certification itself lands in months 4–6 depending on registrar availability.

  • Days 1–14 · Scope, leadership sign-off, gap analysis, register the workspace
  • Days 15–45 · Populate the risk register, adopt policies, assign control owners, close top-priority gaps
  • Days 46–75 · Collect evidence for each control, run the first internal audit, remediate findings
  • Days 76–90 · Management review, Stage 1 documentation submission, book Stage 2

Frequently asked questions

Do we really need trust centre to sell into enterprise?
For a 20–200 person B2B SaaS company turning over £2m–£20m ARR, yes — increasingly so. It's the fastest way to get through the infosec section of an RFP or vendor onboarding without a bespoke justification. Firms that don't have it either lose deals or spend disproportionate founder time answering questionnaires that a certificate would answer once.
Can we certify trust centre without hiring a compliance manager?
Yes, and most firms in this ICP do exactly that. What you need is a nominated owner (typically the COO, CTO or Head of Ops) with 4–6 hours a week for the programme, an executive sponsor, and a platform that removes the spreadsheet and drafting work. A part-time fractional practitioner for 4–8 days total is often enough.
How long does it realistically take?
For a 20–200 person B2B tech firm with a tight scope and an integrated platform: 90 days to readiness, 4–6 months to certificate (governed by UKAS registrar availability). Longer programmes almost always suffer from over-scoping, not from complexity of the standard.
How much will it cost in year one?
All-in with ISO-STANDARD.app: roughly £8k–£15k for a small scope (registrar + platform + focused internal time). Traditional consultancy-plus-spreadsheet programmes for the same scope typically run £30k–£45k. Recertification and surveillance run £4k–£8k a year afterwards.
How does trust centre fit if we're also pursuing ISO 27001 / ISO 9001 / ISO 42001?
Well, if you use one integrated management system. The clauses on leadership, planning, support, operation, evaluation and improvement are near-identical across ISO management system standards. Duplicated risk registers, audit programmes and policies are the biggest source of wasted effort — an integrated workspace collapses them into one.

Ship trust centre without a full-time compliance manager

ISO-STANDARD.app packages the whole trust centre programme — risk register, controls, policies, evidence, audits — into one workspace priced for a 20–200 person B2B SaaS company turning over £2m–£20m ARR.

ISO-STANDARD.app ships a ready-to-adopt trust centre workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →