Startup compliance checklist: what you need, and when
A staged checklist for new companies, from incorporation to your first enterprise customer and your first new market. Each item says what it is, why it matters, whether a law or a buyer requires it, and where to check if it applies to you. Nothing you tick leaves your browser.
A start-up needs a privacy notice, cookie consent, vendor data processing agreements and an incident plan as soon as it collects personal data, because privacy laws apply from the first user. SOC 2, ISO 27001, MDM and access reviews are not legal requirements: buyers ask for them, usually from the first business or enterprise customer. Add sector and market rules as you enter them.
Stage 1: Incorporated, pre-launch7 items
Nothing here is a filing or a certificate. These are the habits that cost hours now and months later, and that every security questionnaire will ask about.
Stage 2: First users and data9 items
The moment real people sign up, privacy law starts to apply. Which laws depends on where your users are, not where you are incorporated.
Stage 3: First business customers8 items
Business buyers send security questionnaires before they sign. None of this is a law; all of it decides whether the deal closes.
Stage 4: First enterprise or regulated customer8 items
Enterprise and regulated buyers want independent assurance, not answers. This is where a report or certificate usually becomes necessary.
Stage 5: Raising funding or due diligence5 items
Investors and acquirers may run security and privacy diligence. Have evidence you can hand over in a day.
Stage 6: Selling in the EU, India or US healthcare7 items
New markets bring laws with them. Each item applies only when you enter that market or sector.
Your stage and ticks are saved in this browser only. Nothing is sent to us.
What is legally required, and what buyers require
Every item above carries one of four labels, because the difference decides what you do first.
- Legal duty: a law requires it where that law applies to you. Privacy notices, processor contracts, breach reporting and the CERT-In logs are in this group. Whether the law reaches you depends on where your users are and, for the CCPA, on thresholds. The checkers linked on each item answer that.
- Contractual: no statute names you, but a customer, card scheme or regulated buyer must impose it on you by contract. PCI DSS, DORA's ICT contract terms and the data processing agreement you sign for customers are here.
- Buyer-driven: no law and no mandatory clause, but buyers will not sign without it. SOC 2, ISO 27001, MDM, access reviews and the security questionnaire are here.
- Good practice: nobody will ask you for it by name, but every audit and incident goes better if it is in place.
A common mistake is to start with the buyer-driven work because it has a certificate at the end, and to leave the legal basics, a notice, a processor contract, an incident plan, until a customer's lawyer finds the gap. Do stage 2 before stage 4.
How to use this checklist
Pick your stage at the top. Earlier stages stay in scope, because a company with enterprise customers still needs MFA and a privacy notice. Tick only what you could show a reviewer today: a setting, a signed contract, a dated review. Then use See my gaps for a report of what is open, Print / save PDF for a board pack, or Copy as text to paste the open items into your tracker. If you do not know which frameworks apply at all, start with the framework selector.
Sources
- EUR-Lex: GDPR, Regulation (EU) 2016/679
- EUR-Lex: ePrivacy Directive 2002/58/EC, Article 5(3)
- California Civil Code §1798.140 (CCPA definitions)
- CERT-In: Directions of 28 April 2022
- MeitY: Digital Personal Data Protection Act, 2023
- MeitY: DPDP Rules 2025
- eCFR: 45 CFR 164.502 (disclosures to business associates)
- PCI Security Standards Council: about the Council and compliance programmes
- NCSC: Cyber Essentials overview
Facts checked against these sources in October 2026. Laws, thresholds and dates change: check the source before you rely on a figure. Not legal advice.
The things people ask us
What compliance does a startup need?
From the first user: a privacy notice, cookie consent where you use non-essential cookies, data processing agreements with vendors, and an incident plan with the reporting deadlines. From the first business customer: answers to security questionnaires, access reviews and device management. From the first enterprise customer: usually SOC 2 or ISO 27001.
Does a startup need SOC 2?
Only when its buyers ask for it. No law requires SOC 2. Start-ups selling to US mid-market or enterprise buyers usually need one before a large deal closes; those selling to small businesses or consumers rarely do. Putting the basic controls in early means a Type 1 report later takes weeks, not months.
What does DPDP compliance mean for a startup?
The DPDP Act has no size threshold, so a start-up processing personal data in India, or offering services to people there, has the same core duties as a large company: notice and consent, security, breach reporting, erasure and rights, from 13 May 2027. Section 17(3) allows the government to exempt classes such as start-ups from some duties, but only by notification.
Is cookie consent legally required for a startup?
In the EU, storing or reading cookies needs prior consent unless the cookie is strictly necessary for a service the user asked for, whatever your size. The UK has its own rules. In California, covered businesses must let people opt out of sharing for advertising.
When should a startup get ISO 27001 or SOC 2?
When a deal depends on it, or just before. US buyers mostly ask for SOC 2; buyers in Europe and India more often for ISO 27001. Most controls overlap, so the second one costs much less than the first.
Do startups need an AI policy?
No law requires a standalone AI use policy, but business buyers often ask which AI tools your staff use and what data goes into them. A one-page policy and a list of approved tools answer the question.
Where is my progress stored?
In your own browser, using local storage. Nothing is sent to us and there is no account. In a private window, or if your browser blocks site storage, ticks are forgotten when you close the page, so copy your gaps first.
The checklist records what you believe. The platform records what is true.
TryTrustable connects to your cloud, code and devices and keeps evidence for every control current, so the next questionnaire answers itself.