Enterprise readiness

Close the enterprise deal
without stalling in procurement.

The first large customer sends a security questionnaire, a DPA, a request for your VPAT and a question about uptime, all in the same week. This is the checklist, who asks for what, how long each item takes, and where to start. A planning guide, not legal advice.

SOC 2ISO 27001Pen testSecurity questionnaireDPAVPATSLAInsurance

Last updated Published by TryTrustableNot legal advice

Short answer

Enterprise readiness is having the documents and evidence large buyers ask for before they sign, ready before they ask. For a SaaS startup that usually means: a SOC 2 report or ISO 27001 certificate, a recent penetration test summary, answers to a security questionnaire, a data processing agreement and privacy terms, an accessibility conformance report (VPAT) for government and universities, an SLA backed by uptime and load-test evidence, and certificates of insurance. Most take weeks; SOC 2 takes months, so start it first.

01

What is enterprise readiness?

Enterprise readiness is the gap between a product a team loves and a vendor a procurement department can approve. Large companies, governments and universities have a duty to check who they buy from: security, privacy, accessibility, reliability and contract risk. A startup that has the answers ready moves through procurement faster; one that does not can lose a deal the champion already won.

02

Who asks for what, and how long each takes

ItemEnterpriseUS federalUS state, local and public universitiesEU and UK public sectorLead time (planning guide)
SOC 2 reportUsually (US)Sometimes (FedRAMP for cloud services)OftenSometimes (ISO 27001 more common)Type 1: a few months; Type 2: readiness plus a 3 to 12 month window
ISO 27001 certificateOften (EU, UK, Australia)Rarely aloneSometimesOftenMonths, similar to SOC 2
Penetration test summaryUsuallyYesOftenOftenWeeks to schedule and run; book early
Security questionnaireAlmost alwaysYesYesYesDays to weeks per questionnaire
Data processing agreementAlmost always if you process personal dataAgency-specific termsYes (student and resident data)Yes (GDPR Article 28)Days if you have a template
VPAT / ACRSometimesYes (Section 508)Increasingly (ADA Title II)Yes (EN 301 549)Weeks to months: audit, fix, write
SLA and uptime evidenceUsuallyYesOftenOftenDays to draft; months of history to show
Insurance certificatesUsually (cyber, tech E&O, general liability)Contract-specificUsuallyUsuallyDays to weeks with a broker

Who asks varies by buyer and deal size. Lead times are rough planning guidance for a prepared startup, not benchmarks.

03

Security: SOC 2, ISO 27001, pen test and the security questionnaire

Security review is almost always first. US buyers usually ask for a SOC 2 report (Type 2 for larger deals; see Type 1 vs Type 2); buyers in the EU, UK and Australia often accept or prefer ISO 27001. Without a report yet, a readiness letter, your policies and a recent penetration test summary can carry a deal while the audit is under way.

Expect a security questionnaire either way: a standard one or the buyer's own. Answer from evidence, keep the answers in one place, and reuse them. AI and ML startups get extra questions about models and training data; see SOC 2 for AI startups.

04

Privacy: DPA, GDPR and CCPA

If you process personal data for the customer, they need a data processing agreement. Under GDPR Article 28 the contract must contain specific terms, including how sub-processors are approved; California requires similar contract terms with service providers. Have your own DPA ready, publish your sub-processor list, and know where data is stored. See GDPR for SaaS and does the CCPA apply.

05

Accessibility: VPAT and ACR

US federal agencies, state and local governments, public universities and EU public bodies must buy accessible technology, so they ask for an Accessibility Conformance Report on the VPAT template, usually against WCAG 2.2 or 2.1 Level AA. The rules behind it are explained in Section 508 and the ADA and the European Accessibility Act. An honest report with known gaps and a fix plan is accepted far more often than a report that claims everything.

06

Reliability: SLA, uptime and load-test evidence

Buyers want an SLA with a defined uptime commitment and evidence that you can meet it: an uptime history, incident communication, recovery objectives and performance test results. Set internal SLOs tighter than the SLA; see SLA vs SLO vs SLI for the downtime arithmetic and the SOC 2 availability criteria. Load tests with p95 and p99 latency against a target, and Core Web Vitals for the frontend, answer the "how does it perform at scale" question with data rather than adjectives.

08

Where to start: a 90-day order

  1. Weeks 1 to 2: policies, MFA everywhere, a vendor list, a DPA and a sub-processor list. The startup compliance checklist and framework selector help decide scope.
  2. Weeks 2 to 6: start SOC 2 or ISO 27001 readiness; book a penetration test; publish a trust center.
  3. Weeks 4 to 10: set SLOs, schedule load tests and frontend audits, and start collecting the history; draft the SLA.
  4. If you sell to government or universities: commission an accessibility audit and write the ACR.
  5. Ongoing: keep answers, evidence and reports current; buyers check dates.
09

What TryTrustable helps with, and what it does not

ItemDoes TryTrustable help?How
SOC 2 and ISO 27001YesShared controls, policies, risk register and automated evidence from GitHub, AWS and GCP, ready for your auditor. The audit itself is done by an independent firm
Trust centerYesA trust center page to share your security posture and documents with buyers
Reliability evidenceYesAPI load tests and PageSpeed audits against your SLO, scheduled, stored as SOC 2 A1.1 evidence
Vendor recordsYesA vendor register with tiers, reviews and evidence on file, for the buyer's questions about your sub-processors
DPA and questionnaire templatesYes, free templatesA DPA template (written for India's DPDP Act; adapt for GDPR Article 28) and a vendor security questionnaire
Privacy operationsYesConsent and rights request handling for GDPR and CCPA
Security questionnaire answersPartlyYour controls and evidence are in one place to answer from; questionnaires are not filled in automatically
Penetration testNoHire an independent tester; TryTrustable's code and web scanning is not a pen test
VPAT and accessibility testingPartlyAutomated WCAG 2.2 scans and a sealed ACR (VPAT 2.5 WCAG edition) your team completes after manual testing; see the VPAT guide
InsuranceNoUse a broker

TryTrustable helps you prepare for these reviews; it does not make you compliant by itself, and an independent auditor issues SOC 2 reports and ISO 27001 certificates.

Questions

The things people ask us

What do enterprise customers ask for before buying SaaS?

Typically a SOC 2 report or ISO 27001 certificate, a penetration test summary, a security questionnaire, a DPA, an SLA with uptime evidence and insurance certificates. Government and university buyers add an accessibility conformance report (VPAT).

Do I need SOC 2 to sell to enterprises?

Not always, but US enterprise buyers ask for it most often. Without a report, policies, a readiness letter and a pen test summary can carry early deals while the audit runs.

What does a university need from a SaaS vendor?

Usually a security questionnaire (often a higher-education standard one), a DPA covering student data, and an ACR showing WCAG 2.1 or 2.2 AA conformance, since public universities are covered by the ADA Title II rule.

How long does it take to become enterprise ready?

The documents take weeks. SOC 2 takes months: readiness, then either a Type 1 examination or a Type 2 observation window of three to twelve months. Start it first.

Does TryTrustable create VPATs or do pen tests?

It runs automated WCAG 2.2 scans and produces an ACR based on the VPAT 2.5 WCAG edition, which your team completes after manual testing. It does not run penetration tests or provide insurance. It also helps with SOC 2 and ISO 27001 evidence, a trust center, performance evidence and templates.

Is TryTrustable itself SOC 2 certified?

TryTrustable's own SOC 2 and ISO 27001 work is in progress. See the trust page for current status.

Book a walkthrough

Get the security, privacy and reliability evidence ready before the questionnaire arrives.

Thirty minutes on what your next enterprise or public-sector buyer will ask, and which pieces we can have ready for you.