SOC 2 for cyber security firms: when to add it to ISO 27001
If half your pipeline is US-headquartered, ISO 27001 alone will start losing deals. A pragmatic view on when a cyber firm should add SOC 2, and how to run both without duplicating effort.
If half your pipeline is US-headquartered, ISO 27001 alone will start losing deals. A pragmatic view on when a cyber firm should add SOC 2, and how to run both without duplicating effort.
For a 20–200 person cyber security firm turning over £2m–£20m, SOC 2 has moved from a nice-to-have to a deal-shaping requirement. Enterprise cisos and public-sector procurement now ask for it by name in RFPs, and the absence of a credible answer is enough to lose the deal before a technical conversation ever happens.
The ICP this guide is written for: a 20–200 person B2B tech business turning over £2m–£20m, pursuing SOC 2 (often alongside one or more of ISO 27001, ISO 20000-1, ISO 9001 and ISO 42001) without a dedicated full-time compliance manager. The founder, CTO, COO or Head of Ops usually owns it in practice.
Most cyber firms we speak to are somewhere between two familiar states: an experienced team who genuinely do the right things but cannot prove it to a buyer, and a team with a folder of policies written by someone external three years ago that no one has opened since.
Neither passes a modern audit or a modern buyer review. The starting point isn't 'implement everything' — it's a short, honest gap analysis against the standard, mapped to what already exists.
Without a full-time compliance manager, the trap is trying to do everything. A minimum viable SOC 2 programme for a 20–200 person cyber security firm turning over £2m–£20m is scoped, owned, and evidenced — not exhaustive.
The essential ingredients are the same across sectors: a defined scope, a leadership team that has signed off, a live risk register, the controls the standard requires, policies people actually read, and evidence produced as a by-product of doing the work rather than a separate reporting task.
Cyber firms almost always over-scope. The pentest arm, the SOC, the consultancy and the training business rarely need to be in the same certificate. Split by service line if the risk profiles genuinely differ; over-scoping is the single biggest reason cyber firms lose 6 months to certification.
The second pattern to avoid is treating the standard like a shopping list. The clauses that talk about leadership, planning, evaluation and improvement matter more than the controls themselves — those are what auditors actually test for maturity.
The reason a 20–200 person cyber security firm turning over £2m–£20m without a compliance manager historically failed to certify wasn't will — it was cost. A traditional consultancy-plus-spreadsheet programme runs £30k–£45k in year one. Most of that pays for policy drafting, spreadsheet maintenance and evidence chasing that a modern platform simply removes.
ISO-STANDARD.app ships a ready-to-adopt SOC 2 workspace with the risk register, controls catalogue, policies, evidence store, internal audit programme and audit-ready exports already wired together. What remains is your organisation's genuinely unique work — scope, risk decisions, and evidence — which is where a founder or ops leader's time actually adds value.
For a 20–200 person cyber security firm turning over £2m–£20m, a credible 90-day readiness path exists and is well-worn. Certification itself lands in months 4–6 depending on registrar availability.
ISO-STANDARD.app packages the whole SOC 2 programme — risk register, controls, policies, evidence, audits — into one workspace priced for a 20–200 person cyber security firm turning over £2m–£20m.
ISO-STANDARD.app ships a ready-to-adopt SOC 2 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.