There's a moment in the life of almost every software company that founders remember vividly. The product is working, early customers are happy, and then a genuinely big prospect appears: a bank, a hospital group, a university, a government agency. The demo goes brilliantly. The champion is sold. And then procurement sends over a spreadsheet with three hundred security questions, and the deal that was closing this quarter quietly slides into next year.
We call it the ISO 27001 wall, and if you sell software to organisations bigger than yourself, you will hit it. The only real question is whether you hit it prepared or unprepared.
Why buyers ask, and why it's fair
It helps to see the questionnaire from the buyer's side. Your product is going to hold their data, plug into their systems and sit inside their risk profile. If you get breached, it's their name in the incident report and their regulator asking questions. So before they sign, they need evidence that you manage security deliberately, as a system, rather than heroically, as a series of late-night saves by your best engineer.
The questionnaire is their imperfect tool for getting that evidence. And here's the thing founders often miss: the buyer doesn't enjoy it either. Their security team has to read your three hundred answers, chase the vague ones, and make a judgement call with incomplete information. Everyone in that transaction is looking for a shortcut they can trust.
What ISO 27001 actually signals
ISO 27001 certification is that shortcut. It tells a buyer that an accredited, independent body has audited how you manage information security risk, not once, but on a continuing cycle. Not just whether you encrypt data, but whether you know what data you hold, who can access it, how you vet suppliers, what happens when someone leaves the company, how you'd detect and respond to an incident, and whether leadership actually reviews any of this.
In practice, certification changes the sales conversation in three ways. Security reviews get shorter, because many buyers accept the certificate in place of large sections of the questionnaire. Deals stop dying in procurement, because the security question has a clean, verifiable answer. And doors open that were previously closed: plenty of government and enterprise tenders simply require certification, so uncertified vendors never see those opportunities at all.
'We'll do it when a customer forces us to'
This is the most common strategy, and we understand the logic: certification costs money and time, and until a deal demands it, other things feel more urgent. But the economics rarely work out. Building an information security management system under deal pressure means doing six to nine months of work in a panic, with an enterprise deal hanging on the outcome and every shortcut tempting. Meanwhile the deal itself cools. Champions change jobs. Budgets get reallocated. The competitor who already had the certificate wins.
Compare that with building the system while you're small. A twenty-person company has a handful of systems, a short supplier list and simple access control. Documenting how that company manages security is genuinely not a big job, and the habits formed scale with you. The companies that find ISO 27001 painful are almost always the ones who waited until they were a hundred people with five years of undocumented decisions.
What the path actually looks like
A realistic sequence looks like this. First, someone owns it; security systems without an owner don't get built. Second, you work out what you're protecting: the data you hold, where it lives, which systems and suppliers touch it. Third, you do an honest risk assessment and decide which controls matter for your actual situation, not a template's imagined one. Fourth, you write down how you do things, keeping it as short as truth allows, and start running the routines: access reviews, supplier checks, incident drills, management reviews. Then an internal audit to find the gaps before the real auditors do.
When the system has been running long enough to generate evidence, usually a few months, you're ready for certification. Stage 1 reviews the design of your system. Stage 2 tests whether it genuinely operates. Then you're certified for a three-year cycle, with a short surveillance audit each year to keep everyone honest.
Many companies use a consultant for the build phase, and that's fine. Just know that the certification body has to be independent of whoever built the system, which is exactly as it should be. You want the certificate to mean something when your customer's security team checks it.
When to start
Our honest advice: if your roadmap includes enterprise, healthcare, finance, education or government customers within the next eighteen months, the right time to start is now, while nothing is on fire. You'll build a better system, negotiate from strength when the big prospect arrives, and walk into security reviews with the one answer that ends them quickly.
EVO certifies SaaS and technology companies in Australia and internationally, with auditors who understand cloud infrastructure, modern toolchains and how small teams actually work. If you can see the wall coming, get in touch and we'll tell you exactly what certification would involve for a company your size. It's usually less than founders fear.