Common questions
Straight answers to compliance questions
The questions SMBs actually ask us before signing up. No hedging, no marketing spin.
SOC 2
Do I need SOC 2 to sell to enterprise customers?
For most B2B deals over $100k ACV, yes — SOC 2 is a hard revenue gate. Below $100k, security questionnaires often work as a substitute. Above $250k, Type 2 (not Type 1) is usually required. Start Type 1 the moment enterprise deals enter your pipeline.
How long does SOC 2 take for a startup?
Type 1: 8–12 weeks for a prepared 20-person SaaS team with modern cloud infra. Type 2: add a 3–12 month observation window on top. Most startups target Type 1 first to unblock deals, then roll straight into Type 2.
What happens if I fail a SOC 2 audit?
You don't 'fail' SOC 2 like a certification exam. Auditors issue one of four opinions: unqualified (pass), qualified (some exceptions), adverse (systemic failure), or disclaimer (couldn't complete). A qualified report can still support enterprise deals if the exceptions are narrow and remediated.
How often do you recertify SOC 2?
SOC 2 is not a one-time certification — it's an annual attestation. Type 2 reports typically cover a rolling 12-month window and are re-issued each year. Most enterprise buyers require your report be dated within the last 12 months to remain valid for procurement.
HIPAA
CMMC
Is CMMC required for prime contractors and their subcontractors?
Yes. CMMC 2.0 flows down from prime contractors to every subcontractor that touches Federal Contract Information (FCI, Level 1) or Controlled Unclassified Information (CUI, Level 2). If your contract references DFARS 252.204-7012, you almost certainly need CMMC.
Do I need a vCISO for CMMC?
CMMC does not require a vCISO. But for Level 2 assessments, most SMBs without a full-time security lead benefit from a fractional CISO for 4–6 months during prep — especially through the POA&M and evidence phases. Beyond that, tooling replaces most of the ongoing work.
What is a POA&M in CMMC?
A POA&M (Plan of Action & Milestones) is a formal document capturing control gaps and the plan to close them. Under CMMC 2.0, POA&Ms are permitted at Level 2 assessment — but only for a limited set of controls, and every POA&M item must close within 180 days of assessment.
ISO 27001
Cost & Tooling
Have a question we didn't answer?
Book a live 20-minute walkthrough and we'll answer it in context.
