What is the difference between SOC 2 and ISO 27001, and which do we need?
They are not direct equivalents, they work differently. SOC 2 is a US-style attestation report against a set of trust criteria, assessed annually. ISO 27001 is an internationally recognised, certifiable management-system standard. In practice, UK investors and UK enterprise clients typically ask for ISO 27001 rather than SOC 2, so that is usually the more useful one to hold if you are selling or raising in the UK. If you are selling into the US or raising from US investors, SOC 2 may still come up. Commercial Readiness maps out which one actually applies to you before you spend money on either.
When should we start preparing for investor due diligence?
Ideally 60 to 90 days before the round starts, not three weeks into it. Most founders discover the security gap partway through a six-week round, when it is too late and too expensive to fix properly. Commercial Readiness can still help if a questionnaire has already landed, but the options narrow considerably.
How fast can you turn a questionnaire around?
It depends on length and how much evidence already exists, but most Focused Reviews are completed within one to two weeks. Tell us your deadline on the scoping call and we'll tell you honestly whether it's achievable.
Do you fill in the questionnaire for us?
We draft and review answers with you and help you gather the evidence behind them, rather than guessing on your behalf. The answers need to be accurate and defensible, not just complete.
What if we get asked something we genuinely don't have in place yet?
We help you answer honestly, with a credible plan and timeline attached, which is usually far more reassuring to a customer or investor than a vague or evasive answer.
