Skip to main content

Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal

Do you have SOC 2 or ISO 27001? If not, you understand my procurement team will stop reading right there.?

The question a Chief Compliance Officer (CCO) asks.

The short answer

No certificate yet — we're pre-launch, and Type II needs operating history. But all 93 ISO controls are already declared in a tested Statement of Applicability, the controls run as CI gates producing evidence on every commit, and the dated path is Type I in Q4 2026, Type II mid-2027, with a right-to-audit clause bridging the gap.

The full executive answer

No certificate yet — and rather than talk around that, let me show you exactly where we are on the path, because it's further along than "no" usually implies. SOC 2 is an attestation by a licensed CPA firm that your controls operated over a period; ISO 27001 is a certified management system. Neither can be self-issued, we hold neither, and we will never imply otherwise. We are pre-launch; the audit window couldn't have run yet even if we'd started day one, because a Type II report requires months of operating history.

What exists today is unusual for a company at our stage: the control substance, in code. We maintain a full ISO 27001 Statement of Applicability — the document an accredited registrar asks for first — covering all 93 Annex A controls, each declared as implemented, inherited from a certified sub-processor, policy-satisfied, partial, or honestly gap-flagged. In parallel, a control-evidence framework maps each technical control to its SOC 2 Trust Services Criteria and ISO Annex A references. The hardest part of certification for most startups is that controls exist only as intentions; ours exist as CI-enforced gates — tenant isolation, access control, audit logging, change management — that produce evidence automatically on every commit.

The dated path: we're following the standard compliance-automation route (a Vanta/Drata-class platform for continuous evidence collection, bundled with a licensed CPA firm). Engagement is scoped to begin Q3 2026 — this quarter — with a SOC 2 Type I (controls designed correctly, point-in-time) targeted Q4 2026, then the three-month-minimum Type II observation window putting a Type II report in hand around mid-2027. ISO 27001 follows the same evidence base. Until then, what I can offer procurement is the Statement of Applicability, the control-evidence pack, our security whitepaper, and a right-to-audit clause in the contract. Several enterprise buyers bridge exactly this way for pre-certification vendors: contractual controls now, certificate as a contractual milestone.

Grounded in: SOC 2 Trust Services Criteria (attestation, AICPA); ISO/IEC 27001:2022 clause 6.1.3 d (SoA) and Annex A (93 controls).

Want this answered live, on your data?