SOC 2·11 min read

Which Compliance Framework Does Your SaaS Actually Need?

Picking a compliance framework feels like choosing from a menu where every item applies to you. SOC 2? Maybe. ISO 27001? Possibly. HIPAA? Only if you touch health data. GDPR? If you have EU users. This guide cuts through the noise with a decision tree based on who you sell to, what data you handle, and where they operate.


The quick version: A 30-second flowchart

  1. Do you sell B2B SaaS to enterprises? → Start with SOC 2 Type II.
  2. Do your buyers operate in Europe or are they regulated (banking, insurance, government)? → Add ISO 27001.
  3. Do you handle patient health data? → Add HIPAA.
  4. Do you process personal data of EU residents? → Add GDPR.
  5. Do you process California residents' data? → Add CCPA/CPRA.
  6. Do you process payment card data? → Add PCI-DSS.

Most SaaS companies need 1–2 frameworks, not all six. The sequence above is ordered by adoption cost and ROI.

By customer type

Enterprise SaaS (B2B, Series A-C)

Start here: SOC 2 Type II

Enterprise procurement teams ask for SOC 2 before anything else. It's the baseline. If you don't have it, you're not getting past the security RFQ.

  • Cost: $40–60K
  • Timeline: 9–10 months
  • Why: Universal, auditable, vendor-agnostic proof of secure infrastructure

Add if: European buyers, government contractors, or Fortune 500 accounts ask for it.

  • Cost: Add $40–60K for ISO 27001 (60% overlap means some work reuses SOC 2 controls)
  • Timeline: 12–18 months (parallel with SOC 2)

HealthTech (patient data)

Start here: SOC 2 Type II, then HIPAA

Don't be fooled: clinics want SOC 2 first because it proves your infrastructure is secure. Then, if they're sending you patient data, they layer HIPAA on top.

  • SOC 2: $40–60K, 9–10 months
  • HIPAA: Add $80–150K (more because of BAAs, breach procedures, workforce training)
  • Timeline: Run in parallel; be SOC 2 attested in 10 months, HIPAA-ready by 16–18 months

Skip: GDPR/CCPA/PCI unless your specific customers need it. Most patient data workflows don't touch payment card data or EU personal data.

Consumer SaaS (B2C, with EU/California users)

Start here: GDPR and/or CCPA

If you have EU users—even one—you need GDPR. If you have California residents, CCPA/CPRA applies.

  • GDPR: $30–50K (legal + technical), 6–9 months
  • CCPA/CPRA: $20–40K (lighter than GDPR, but still legal + retention policies)
  • Timeline: Do GDPR first (stricter), then CCPA overlaps significantly

Add later: SOC 2 if you sell to enterprise B2B customers, but consumer SaaS often skips it.

FinTech / Payment Processing

Start here: PCI-DSS + SOC 2 Type II

PCI-DSS is non-negotiable if you process credit cards. SOC 2 adds confidence around your entire platform.

  • PCI-DSS: $15–40K (depends on integration depth), 3–6 months
  • SOC 2 Type II: $40–60K, 9–10 months
  • Timeline: PCI can move faster; do it first, SOC 2 in parallel

Add if: You hold customer data in Europe (GDPR) or California (CCPA).

SaaS for Government / GovTech

Start here: SOC 2 Type II, FedRAMP if federal contracts

Government contractors must have SOC 2 and often FedRAMP (if federal). State/local contracts less strict.

  • SOC 2 Type II: $40–60K, 9–10 months
  • FedRAMP: $200K+, 12–18 months (much heavier)
  • Add: ISO 27001 if you want to sell internationally

By data type (if it's not about customer type)

You process or store health data (PHI)

HIPAA required. No negotiation. Even if you're just hosting it, you need a BAA signed before data arrives.

You process payment card data

PCI-DSS required. Compliance is mandated by card networks, not optional.

You handle personal data of EU residents

GDPR required. No exceptions: if you have EU users and collect their data (email, IP address, location, behavior), GDPR applies.

You handle California resident data

CCPA/CPRA required. Similar scope to GDPR but lighter enforcement (so far).

You handle general customer/employee data (no health, payments, or special categories)

SOC 2 Type II. Add ISO 27001 if you want to sell globally or to risk-averse enterprises.

By geography

US-first, enterprise B2B

SOC 2 Type II. It's the gold standard. ISO 27001 is a nice-to-have if you ever want to sell to Europe.

US + Europe

SOC 2 + ISO 27001. 60% overlap means the second one is easier. Budget $80–100K total, 12–16 months.

US + Europe + APAC

SOC 2 + ISO 27001, plus local requirements. Asia-Pacific doesn't have a single standard (unlike GDPR), but Singapore (PDPA), Australia (Privacy Act), and India (DPDPA) add requirements if you operate there. Plan for $120–150K total.

Europe-first

ISO 27001 + GDPR are both needed. SOC 2 is less critical for EU-centric businesses unless selling to US tech buyers.

The efficiency play: Do them in sequence or parallel?

Sequence (one at a time):

  • Post-SOC 2 (month 10) → HIPAA starts (takes another 8–10 months)
  • Total: 18–20 months, lower operational overhead during remediation

Parallel (overlapping):

  • SOC 2 remediation (months 2–8) + ISO 27001 assessment (months 1–3)
  • Both audit in months 9–12
  • Total: 12–14 months, but requires coordinating two audits + higher team load

Most teams do parallel for framework pairs (SOC 2 + ISO 27001) and sequential for unrelated ones (SOC 2 + HIPAA, because HIPAA's assessment uncovers different gaps).


Frequently Asked Questions

Q: Can I get away with just SOC 2? Maybe. If you're enterprise B2B and your customers don't operate in Europe, don't handle health data, and don't process payments, SOC 2 is sufficient. The moment a customer says "We need HIPAA" or "We're in Germany," you need more.

Q: How do I know which framework a customer actually needs from us? Ask: "Do you process [health data / payment cards / EU personal data] through our platform, or do you use our software as a tool?" The answer determines the framework.

Q: Is ISO 27001 just a more expensive SOC 2? No. SOC 2 audits your controls over 12 months. ISO 27001 is a certification showing your management system meets an international standard. They overlap significantly (60%) but serve different markets: SOC 2 for US/enterprise, ISO 27001 for Europe/regulated sectors/M&A.

Q: What if I get it wrong? If you get SOC 2 but a customer needs ISO 27001, they ask you to get certified. It's not wasted work—60% of controls overlap. You'll remediate the remaining 40% and get certified. Sequence wrong (get CCPA before SOC 2) and you've spent money on a framework that doesn't help you close enterprise deals.


Ready to Pick Your Framework?

The right framework depends on your customer type, not on how many you can stack. Start with the table at the top—pick your industry—and execute that sequence.

Schedule a scoping call →