DataAigis
Going global

Compliance certification roadmap

Overseas buyers run security review before commercial negotiation. The question is rarely whether to certify — it is in what order, how tightly to draw the scope, and which controls can be built once and reused.

Updated August 2026

Certification is a gate in the buying process, not homework after the product ships

North American SaaS procurement commonly asks for a SOC 2 report, large European and Asia-Pacific tenders often list ISO 27001 as a qualification condition, and anything touching payment card data has to meet PCI DSS. These requirements land before contract negotiation, not after.

What actually costs money is rarely a single certificate. It is getting the order wrong — funding a certificate that unblocks nothing, or drawing the scope so wide that systems which could have stayed out get dragged into the audit.

What each certificate actually settles

This table is what the sequencing decision rests on. Few companies need all four, but any of the four can be named by some class of buyer.

ISO 27001

Information security management system

What it proves
That the security management system is written down, running, and improving
Who asks for it
Frequently a qualification condition in large European and Asia-Pacific tenders
What it covers
93 controls in the 2022 Annex A across organisational, people, physical and technological themes
Upkeep
Certificate valid three years, with annual surveillance

SOC 2 Type II

Trust services criteria audit report

What it proves
That controls actually operated across an observation period, not just on paper
Who asks for it
A standard ask in North American SaaS procurement; buyer security teams read it line by line
What it covers
Security, availability, processing integrity, confidentiality and privacy
Upkeep
No official expiry; market practice is a fresh report each year covering the preceding period

PCI DSS

Payment Card Industry Data Security Standard

What it proves
That cardholder data protection meets the payment industry's mandatory requirements
Who asks for it
Contractually enforced by acquirers and card brands, regardless of target market
What it covers
Twelve requirements; four levels by annual transaction volume, level 1 the strictest
Upkeep
Validated annually according to level, with scanning and testing on their own cycles

ISO 27701

Privacy information management system

What it proves
That privacy obligations exist as an auditable system, not as the claim "we comply with GDPR"
Who asks for it
When you process personal data at volume and face GDPR or PIPL due diligence
What it covers
Maps statutory obligations to controls and separates controller from processor duties
Upkeep
Maintained on the same cycle as the ISMS; extends one you already have

How to sequence it

Work back from the markets you are actually selling into, not from how famous the standard is.

Selling mainly to North American SaaS buyers

SOC 2 Type II first. Their security team wants auditor-backed evidence of operation; an ISO certificate does not answer their questionnaire.

Selling mainly to large European and Asia-Pacific accounts

ISO 27001 first. It is often written directly into tender qualification — without it you do not reach the next round.

Handling acquiring or card data

PCI DSS is a hard gate regardless of market, and no other certificate substitutes for it.

Processing personal data at volume

Layer ISO 27701 onto ISO 27001 rather than standing up a separate privacy programme.

Why the second certificate costs much less

These control areas overlap heavily across standards. Design them once and build the evidence retention alongside, and the marginal cost of each later certificate drops sharply — which is why the later ones are worth planning during the first.

  • Access control and periodic entitlement review
  • Encryption policy and key management
  • Log retention and anomaly monitoring
  • Change management and approval gates
  • Vendor and third-party processing agreements
  • Incident detection, escalation and review

Do not rank these two on the same list

Legal thresholds

GDPR, China's PIPL and US EO 14117 are legal obligations. Without them you cannot enter the market — there is nothing to negotiate, and no buyer needs to ask before they apply.

Trust signals

ISO 27001, SOC 2, PCI DSS and ISO 27701 decide whether procurement can proceed. Their priority depends on who you are selling to, and they can be scheduled.

Scope decides what this costs

Effort and audit complexity track the scope almost exactly. PCI DSS shows it most sharply: the less card data your systems touch, the fewer controls you have to prove — tokenisation or a hosted payment redirect can keep your own systems clear of real card numbers and cut the audit scope substantially. The same logic applies to ISO 27001 and SOC 2: keeping unnecessary assets, environments and teams out of scope is far cheaper than adding controls later.

How we run it with you

  1. 01

    Map target markets and buyer requirements

    Collect the security questionnaires and contract clauses from live deals, confirm the statutory entry requirements of each target market, and build a single list of who asks for what. This decides everything downstream.

  2. 02

    Set the path and the scope

    Order the certifications, draw each scope boundary, give timelines and budget ranges, and mark the controls that carry across standards.

  3. 03

    Build the system and retain evidence

    Policy, process and technical controls land together, and evidence is retained to audit standard from day one — assembling it just before the audit is the most common and most expensive rework.

  4. 04

    Audit support and annual upkeep

    Auditor liaison, document preparation, on-site response; after certification, maintain through surveillance and reporting cycles with change brought into the process.

This page describes the general requirements of the standards and certifications named. It is not legal advice. Standard versions, transition periods and validation routes change; the current text of each standard and your certification body's requirements govern.

Talk through your certification roadmap

Tell us your target markets, the deals in flight and your current systems, and we will come back with a sequence, scoping advice, timelines and budget ranges.

Book a consultation