ISO 27001·10 min read

The SaaS Compliance Stack: ISO 27001 Foundation, SOC 2 Attestation

If you're building SaaS and compliance keeps coming up, here's the opinionated version of the SaaS compliance stack: build ISO 27001 as your management-system foundation, layer SOC 2 on top as the attestation US buyers ask for, and add HIPAA or GDPR only when a customer triggers them. Everything else—PCI, CCPA, VAPT—is customer-specific and can wait.

The order matters. Most guides tell you to chase whichever certificate a buyer named last. Building foundation-first is cheaper and more durable, because the frameworks share most of their controls. For the exact control mapping, see the overlap explorer.


The stack, in order of priority

Layer 1: ISO 27001 — the management-system foundation

Build this first. ISO 27001 is not just a certificate; it is a documented, audited Information Security Management System (ISMS). It defines how you assess risk, set policy, assign ownership, manage vendors, and improve over time. It is the security program itself, formalized to an international standard.

What you're building: a real management system. Risk assessment methodology, a Statement of Applicability, access control, incident response, asset management, supplier governance, and a continual-improvement loop, all documented and independently certified.

Why first: everything else attests to this. Once the ISMS exists, other frameworks are largely re-expressing controls you already run. Building the foundation first means you never rebuild the same control twice.

Timeline: 10–14 months to first certification. Cost: $40–60K. The certificate runs on a three-year cycle with annual surveillance audits.

Typical buyers ask: "Do you hold ISO 27001, or do you have a roadmap to it?"


Layer 2: SOC 2 — the attestation US buyers want, layered on top

Add this to translate the ISMS for the US market. SOC 2 is an attestation report from a CPA firm describing how your controls operated against the AICPA Trust Services Criteria over an observation window. It is the credential US enterprise procurement teams ask for by name.

What you're proving: the same controls your ISMS already runs, evidenced and independently attested for a US audience. Access controls, monitoring, incident response, and change management—reported on, not rebuilt.

Why it's cheaper second: SOC 2 and ISO 27001 overlap roughly 60–70%. With the ISMS in place, SOC 2 is mostly evidence collection and the audit itself, not new control work. We map the shared ground in compliance controls overlap.

Timeline: SOC 2 Type II needs a 6-month observation window, then the audit and report. Cost: $40–60K standalone, but far less incremental effort when it follows ISO 27001.

Typical buyers ask: "Do you have a SOC 2 Type II report we can review?"


Layer 3: HIPAA, GDPR, PCI — customer-triggered, not proactive

Do these when a customer requires them. Unlike ISO 27001 and SOC 2, these are data-handling regimes tied to a specific data type, not general security foundations.

  • HIPAA applies once you handle protected health information for a healthcare customer. Expect $80–150K and 14–18 months, because it adds Business Associate Agreements, breach procedures, and workforce training on top of your security base. See SOC 2 and HIPAA compliance.
  • GDPR applies once you process EU personal data. Expect $30–50K and 6–9 months, mostly legal and policy work: lawful basis, data processing agreements, and data subject rights.
  • PCI-DSS applies only if you store or transmit card data. Most SaaS avoids scope entirely by using a tokenizing processor. See the PCI DSS compliance guide.

These layer onto the foundation. They do not replace it.


Why foundation-first beats certificate-chasing

Most SaaS founders pick frameworks like a buffet: grab SOC 2, ISO 27001, PCI, and HIPAA all at once. That burns cash, delays go-to-market, and rebuilds the same controls under different names.

Foundation-first works because:

  1. ISO 27001 is the program, not a badge. It builds the management system every other framework references.
  2. SOC 2 attests to what you already run. With 60–70% overlap, the second framework reuses the first.
  3. HIPAA and GDPR are customer-specific. You add them when a buyer's data type demands it, not before.

Build once, attest many times. That is the whole argument.

The pragmatic exception: pure US-first go-to-market

Honesty matters here. If your entire early pipeline is US enterprise buyers and speed is everything, many teams get SOC 2 first because that is the exact word procurement uses, then formalize ISO 27001 later. That is a legitimate sequencing choice.

The point is that it changes the order, not the work. Because the two frameworks overlap so heavily, a SOC 2-first team is still building most of the ISMS along the way. Foundation-first simply makes that explicit and avoids rework when the ISO 27001 requirement inevitably arrives from a European or upmarket buyer. For the head-to-head, see ISO 27001 vs SOC 2.

Common mistakes

Chasing HIPAA before the foundation. HealthTech founders assume "we're in health, so HIPAA first." But healthcare buyers still ask for SOC 2 or ISO 27001 to prove your infrastructure is trustworthy; HIPAA is the second question, asked only when they actually send you PHI.

Getting PCI-DSS proactively. PCI only applies if you touch card data. Most SaaS uses a tokenizing processor and never does. Add it only when you genuinely handle cards.

Doing CCPA before GDPR. GDPR is stricter and applies to any EU resident's data; CCPA covers California and is lighter. If both apply, do GDPR first and CCPA largely follows.

Waiting for a customer to force the foundation. ISO 27001 and SOC 2 are proactive. HIPAA and GDPR are reactive. Confusing the two either stalls your sales pipeline or spends money before you need to.

Timeline: how this plays out

MonthActionWhy
1–4ISO 27001 risk assessment + ISMS buildEstablish the management-system foundation
5–10ISMS operating + internal auditControls run long enough to be auditable
11–14ISO 27001 certification auditCertified ISMS; European and upmarket deals unlock
8–14SOC 2 observation window (overlaps the ISMS)Same controls, evidenced for a US audience
15SOC 2 Type II report deliveredUS enterprise deals close on the report
18+Customer triggers HIPAA or GDPRLayer the data-handling regime onto the foundation

For the frameworks themselves, see the ISO 27001 service page and the SOC 2 service page. To see exactly where the two overlap, use the overlap explorer or read compliance controls overlap. Still deciding which frameworks apply at all? Start with which compliance framework your SaaS needs.


Frequently Asked Questions

Should we get ISO 27001 or SOC 2 first? If you're building to last and sell globally, ISO 27001 first: it establishes the management system everything else attests to. SOC 2 then attests to controls your ISMS already runs. US-first teams sometimes flip the order for speed, but with 60–70% overlap you're building most of the same controls either way.

Does SOC 2 replace ISO 27001? No. SOC 2 is an attestation report describing how your controls operated over a period; ISO 27001 is a certified management system. US buyers recognize SOC 2, while European, regulated, and M&A buyers expect ISO 27001. Mature SaaS companies hold both.

If we already have ISO 27001, how much extra work is SOC 2? Less than expected. With 60–70% control overlap, an established ISMS means SOC 2 is largely attesting to controls you already operate. The incremental work is evidence collection and the audit, not new controls.

When do we add HIPAA or GDPR? When a customer triggers it: HIPAA once you handle PHI, GDPR once you process EU personal data. These are data-handling regimes that layer onto your security foundation, not the foundation itself.

How much does the whole SaaS compliance stack cost? ISO 27001 and SOC 2 together typically run $80–100K, since the overlap keeps the second one cheaper. Customer-triggered frameworks add more when needed, roughly $30–50K for GDPR and $80–150K for HIPAA.


Ready to Build Your Compliance Stack?

Build the ISO 27001 foundation, attest with SOC 2, add HIPAA or GDPR when customers trigger them. This is the stack that lets you sell globally without rebuilding the same controls three times.

Schedule a scoping call →