Overseas buyers run security review before commercial negotiation. The question is rarely whether to certify — it is in what order, how tightly to draw the scope, and which controls can be built once and reused.
Updated August 2026
North American SaaS procurement commonly asks for a SOC 2 report, large European and Asia-Pacific tenders often list ISO 27001 as a qualification condition, and anything touching payment card data has to meet PCI DSS. These requirements land before contract negotiation, not after.
What actually costs money is rarely a single certificate. It is getting the order wrong — funding a certificate that unblocks nothing, or drawing the scope so wide that systems which could have stayed out get dragged into the audit.
This table is what the sequencing decision rests on. Few companies need all four, but any of the four can be named by some class of buyer.
ISO 27001
Information security management system
SOC 2 Type II
Trust services criteria audit report
PCI DSS
Payment Card Industry Data Security Standard
ISO 27701
Privacy information management system
Work back from the markets you are actually selling into, not from how famous the standard is.
Selling mainly to North American SaaS buyers
SOC 2 Type II first. Their security team wants auditor-backed evidence of operation; an ISO certificate does not answer their questionnaire.
Selling mainly to large European and Asia-Pacific accounts
ISO 27001 first. It is often written directly into tender qualification — without it you do not reach the next round.
Handling acquiring or card data
PCI DSS is a hard gate regardless of market, and no other certificate substitutes for it.
Processing personal data at volume
Layer ISO 27701 onto ISO 27001 rather than standing up a separate privacy programme.
These control areas overlap heavily across standards. Design them once and build the evidence retention alongside, and the marginal cost of each later certificate drops sharply — which is why the later ones are worth planning during the first.
Legal thresholds
GDPR, China's PIPL and US EO 14117 are legal obligations. Without them you cannot enter the market — there is nothing to negotiate, and no buyer needs to ask before they apply.
Trust signals
ISO 27001, SOC 2, PCI DSS and ISO 27701 decide whether procurement can proceed. Their priority depends on who you are selling to, and they can be scheduled.
Effort and audit complexity track the scope almost exactly. PCI DSS shows it most sharply: the less card data your systems touch, the fewer controls you have to prove — tokenisation or a hosted payment redirect can keep your own systems clear of real card numbers and cut the audit scope substantially. The same logic applies to ISO 27001 and SOC 2: keeping unnecessary assets, environments and teams out of scope is far cheaper than adding controls later.
01
Collect the security questionnaires and contract clauses from live deals, confirm the statutory entry requirements of each target market, and build a single list of who asks for what. This decides everything downstream.
02
Order the certifications, draw each scope boundary, give timelines and budget ranges, and mark the controls that carry across standards.
03
Policy, process and technical controls land together, and evidence is retained to audit standard from day one — assembling it just before the audit is the most common and most expensive rework.
04
Auditor liaison, document preparation, on-site response; after certification, maintain through surveillance and reporting cycles with change brought into the process.
This page describes the general requirements of the standards and certifications named. It is not legal advice. Standard versions, transition periods and validation routes change; the current text of each standard and your certification body's requirements govern.
Tell us your target markets, the deals in flight and your current systems, and we will come back with a sequence, scoping advice, timelines and budget ranges.
Book a consultation