Close the enterprise deal
without stalling in procurement.
The first large customer sends a security questionnaire, a DPA, a request for your VPAT and a question about uptime, all in the same week. This is the checklist, who asks for what, how long each item takes, and where to start. A planning guide, not legal advice.
Last updated Published by TryTrustableNot legal advice
Enterprise readiness is having the documents and evidence large buyers ask for before they sign, ready before they ask. For a SaaS startup that usually means: a SOC 2 report or ISO 27001 certificate, a recent penetration test summary, answers to a security questionnaire, a data processing agreement and privacy terms, an accessibility conformance report (VPAT) for government and universities, an SLA backed by uptime and load-test evidence, and certificates of insurance. Most take weeks; SOC 2 takes months, so start it first.
What is enterprise readiness?
Enterprise readiness is the gap between a product a team loves and a vendor a procurement department can approve. Large companies, governments and universities have a duty to check who they buy from: security, privacy, accessibility, reliability and contract risk. A startup that has the answers ready moves through procurement faster; one that does not can lose a deal the champion already won.
Who asks for what, and how long each takes
| Item | Enterprise | US federal | US state, local and public universities | EU and UK public sector | Lead time (planning guide) |
|---|---|---|---|---|---|
| SOC 2 report | Usually (US) | Sometimes (FedRAMP for cloud services) | Often | Sometimes (ISO 27001 more common) | Type 1: a few months; Type 2: readiness plus a 3 to 12 month window |
| ISO 27001 certificate | Often (EU, UK, Australia) | Rarely alone | Sometimes | Often | Months, similar to SOC 2 |
| Penetration test summary | Usually | Yes | Often | Often | Weeks to schedule and run; book early |
| Security questionnaire | Almost always | Yes | Yes | Yes | Days to weeks per questionnaire |
| Data processing agreement | Almost always if you process personal data | Agency-specific terms | Yes (student and resident data) | Yes (GDPR Article 28) | Days if you have a template |
| VPAT / ACR | Sometimes | Yes (Section 508) | Increasingly (ADA Title II) | Yes (EN 301 549) | Weeks to months: audit, fix, write |
| SLA and uptime evidence | Usually | Yes | Often | Often | Days to draft; months of history to show |
| Insurance certificates | Usually (cyber, tech E&O, general liability) | Contract-specific | Usually | Usually | Days to weeks with a broker |
Who asks varies by buyer and deal size. Lead times are rough planning guidance for a prepared startup, not benchmarks.
Security: SOC 2, ISO 27001, pen test and the security questionnaire
Security review is almost always first. US buyers usually ask for a SOC 2 report (Type 2 for larger deals; see Type 1 vs Type 2); buyers in the EU, UK and Australia often accept or prefer ISO 27001. Without a report yet, a readiness letter, your policies and a recent penetration test summary can carry a deal while the audit is under way.
Expect a security questionnaire either way: a standard one or the buyer's own. Answer from evidence, keep the answers in one place, and reuse them. AI and ML startups get extra questions about models and training data; see SOC 2 for AI startups.
Privacy: DPA, GDPR and CCPA
If you process personal data for the customer, they need a data processing agreement. Under GDPR Article 28 the contract must contain specific terms, including how sub-processors are approved; California requires similar contract terms with service providers. Have your own DPA ready, publish your sub-processor list, and know where data is stored. See GDPR for SaaS and does the CCPA apply.
Accessibility: VPAT and ACR
US federal agencies, state and local governments, public universities and EU public bodies must buy accessible technology, so they ask for an Accessibility Conformance Report on the VPAT template, usually against WCAG 2.2 or 2.1 Level AA. The rules behind it are explained in Section 508 and the ADA and the European Accessibility Act. An honest report with known gaps and a fix plan is accepted far more often than a report that claims everything.
Reliability: SLA, uptime and load-test evidence
Buyers want an SLA with a defined uptime commitment and evidence that you can meet it: an uptime history, incident communication, recovery objectives and performance test results. Set internal SLOs tighter than the SLA; see SLA vs SLO vs SLI for the downtime arithmetic and the SOC 2 availability criteria. Load tests with p95 and p99 latency against a target, and Core Web Vitals for the frontend, answer the "how does it perform at scale" question with data rather than adjectives.
Product and legal: SSO, audit logs, insurance
Enterprise IT will also ask about your product's own controls: single sign-on, role-based access, audit logs, data export and deletion. Legal will ask for certificates of insurance, commonly cyber liability, technology errors and omissions, and general liability, with limits set in the contract, plus the right to review your vendors. Ask a broker early; cover can take time to place.
Where to start: a 90-day order
- Weeks 1 to 2: policies, MFA everywhere, a vendor list, a DPA and a sub-processor list. The startup compliance checklist and framework selector help decide scope.
- Weeks 2 to 6: start SOC 2 or ISO 27001 readiness; book a penetration test; publish a trust center.
- Weeks 4 to 10: set SLOs, schedule load tests and frontend audits, and start collecting the history; draft the SLA.
- If you sell to government or universities: commission an accessibility audit and write the ACR.
- Ongoing: keep answers, evidence and reports current; buyers check dates.
What TryTrustable helps with, and what it does not
| Item | Does TryTrustable help? | How |
|---|---|---|
| SOC 2 and ISO 27001 | Yes | Shared controls, policies, risk register and automated evidence from GitHub, AWS and GCP, ready for your auditor. The audit itself is done by an independent firm |
| Trust center | Yes | A trust center page to share your security posture and documents with buyers |
| Reliability evidence | Yes | API load tests and PageSpeed audits against your SLO, scheduled, stored as SOC 2 A1.1 evidence |
| Vendor records | Yes | A vendor register with tiers, reviews and evidence on file, for the buyer's questions about your sub-processors |
| DPA and questionnaire templates | Yes, free templates | A DPA template (written for India's DPDP Act; adapt for GDPR Article 28) and a vendor security questionnaire |
| Privacy operations | Yes | Consent and rights request handling for GDPR and CCPA |
| Security questionnaire answers | Partly | Your controls and evidence are in one place to answer from; questionnaires are not filled in automatically |
| Penetration test | No | Hire an independent tester; TryTrustable's code and web scanning is not a pen test |
| VPAT and accessibility testing | Partly | Automated WCAG 2.2 scans and a sealed ACR (VPAT 2.5 WCAG edition) your team completes after manual testing; see the VPAT guide |
| Insurance | No | Use a broker |
TryTrustable helps you prepare for these reviews; it does not make you compliant by itself, and an independent auditor issues SOC 2 reports and ISO 27001 certificates.
The things people ask us
What do enterprise customers ask for before buying SaaS?
Typically a SOC 2 report or ISO 27001 certificate, a penetration test summary, a security questionnaire, a DPA, an SLA with uptime evidence and insurance certificates. Government and university buyers add an accessibility conformance report (VPAT).
Do I need SOC 2 to sell to enterprises?
Not always, but US enterprise buyers ask for it most often. Without a report, policies, a readiness letter and a pen test summary can carry early deals while the audit runs.
What does a university need from a SaaS vendor?
Usually a security questionnaire (often a higher-education standard one), a DPA covering student data, and an ACR showing WCAG 2.1 or 2.2 AA conformance, since public universities are covered by the ADA Title II rule.
How long does it take to become enterprise ready?
The documents take weeks. SOC 2 takes months: readiness, then either a Type 1 examination or a Type 2 observation window of three to twelve months. Start it first.
Does TryTrustable create VPATs or do pen tests?
It runs automated WCAG 2.2 scans and produces an ACR based on the VPAT 2.5 WCAG edition, which your team completes after manual testing. It does not run penetration tests or provide insurance. It also helps with SOC 2 and ISO 27001 evidence, a trust center, performance evidence and templates.
Is TryTrustable itself SOC 2 certified?
TryTrustable's own SOC 2 and ISO 27001 work is in progress. See the trust page for current status.
Get the security, privacy and reliability evidence ready before the questionnaire arrives.
Thirty minutes on what your next enterprise or public-sector buyer will ask, and which pieces we can have ready for you.