The deal you thought you had just paused
A UK SaaS founder closes a long enterprise sales motion. The contract is in late-stage procurement. Then the email arrives: a 40-question security questionnaire from the buyer's vendor risk team. SOC 2 or ISO 27001 evidence is requested. The founder does not have it.
The deal pauses. Three to six months minimum. Often the deal never returns.
This is the pattern playing out across UK SaaS scaleups in 2026. Around 83 per cent of UK enterprise buyers now treat security certifications as a binary procurement filter, rising to 91 per cent at enterprises with more than 5,000 employees. Typical deal value lost when the certification gate cannot be cleared: between £150,000 and £400,000.
If your first enterprise security questionnaire has just arrived and you do not have certifications in place, this is the practitioner read on what those questionnaires actually contain, why your deal stalled, and what to do next.
What enterprise security questionnaires actually ask
Enterprise security questionnaires are not generic. They are structured to elicit specific evidence about your information security management system. The questions break down into seven recurring categories.
1. Organisational security. Is there a documented information security policy approved by leadership? Who is accountable for security? When did your board last review information security risk?
2. Personnel security. Are background checks performed on staff with access to customer data? Is there mandatory security awareness training? What happens when an employee leaves and how quickly is access revoked?
3. Access control. How are user accounts provisioned, reviewed, and de-provisioned? Is multi-factor authentication enforced across all systems holding customer data? How is privileged access managed?
4. Data protection. Is customer data encrypted at rest and in transit? What encryption standards are used? Where is customer data stored geographically and is there a data processing agreement in place?
5. Vendor and supplier risk. How are sub-processors vetted? Do you maintain a list of sub-processors with access to customer data? Are sub-processor risks reviewed periodically?
6. Incident management. Do you have a documented incident response plan? Has it been tested? How quickly will you notify customers of a security incident affecting their data?
7. Audit and assurance. Do you hold a current SOC 2 Type II report or ISO 27001 certificate? Can you provide it under NDA? When was your last independent security audit?
The last category is where most UK SaaS deals fail. The answer to "do you hold SOC 2 or ISO 27001" determines whether the rest of the questionnaire even gets read.
Why your deal stalled: the procurement reality
Enterprise procurement teams treat security certifications as upstream qualifiers. The vendor either has them, or does not. There is rarely room for "we are working towards it" or "we plan to certify next year." If your deal sits in procurement and the questionnaire returns without SOC 2 or ISO 27001 evidence, the deal moves to a holding pattern until you can produce it.
Three things drive this hardening at procurement.
Regulatory pressure compounding. NIS2 transposition has hardened supplier vetting across EU member states. DORA has done the same for financial services from January 2025. The DSPT-CAF deadline for NHS-adjacent suppliers landed in June 2026. Every regulated buyer is adding upstream filters, and the bar is rising not falling.
Procurement teams have a binary filter. When a procurement team receives a questionnaire response with no certification evidence, they cannot continue the assessment. The internal process forces them to pause the deal until evidence is provided. This is not personal judgement, it is workflow.
Buyer security teams need an off-ramp. Buyer security teams are themselves accountable for the vendors they approve. If they approve a non-certified vendor and an incident occurs, they carry the consequence. Certification provides them with the assurance they need to sign off internally.
What to do when the questionnaire arrives and you do not have certifications
Three honest options.
Option 1: Respond now, certify later
Some buyers will accept a detailed self-assessment response showing your controls in place, even without formal certification, particularly if you are early-stage and the deal is strategic for them. This is rare but it happens. Your response should:
- Be detailed and specific (vague answers fail)
- Map your controls to the framework the buyer references (SOC 2, ISO 27001, or NIST CSF)
- Include a credible certification timeline you can stand behind
- Be supported by evidence (policies, screenshots, vendor list)
This route works perhaps one time in five. The other four times, the deal pauses anyway.
Option 2: Accelerated SOC 2 Type 1
SOC 2 Type 1 is an attestation of controls at a point in time, not over an extended observation period. It can typically be achieved within two to three months from a standing start.
For UK SaaS targeting US enterprise customers, SOC 2 is the default standard. Around 80 per cent of US enterprise procurement teams require a SOC 2 report. A Type 1 report gets you back to the table while you continue working towards Type 2 (which requires a six- to twelve-month observation period).
Typical UK cost for SOC 2 Type 1 implementation including audit: £15,000 to £25,000.
Option 3: ISO 27001 implementation
If your customer base is UK and EU rather than US-anchored, ISO 27001 is the framework the procurement team expects. ISO 27001 covers an entire information security management system across 93 controls.
ISO 27001 implementation for UK SaaS at startup stage typically takes four to six months from kickoff to Stage 2 audit. UK SME costs for year one (consultancy plus UKAS-accredited certification) run £12,000 to £25,000.
SOC 2 or ISO 27001 first: geography decides
The framework choice almost always comes down to geography of your highest-value open deal.
- US enterprise pipeline: SOC 2 first. ISO 27001 is rarely accepted as a substitute in US procurement.
- UK and EU pipeline: ISO 27001 first. SOC 2 has limited recognition in UK and EU enterprise procurement.
- Hybrid pipeline: Start with whichever framework matches the highest-value open deal. Add the second framework within twelve to eighteen months.
Founders who try to "do both at once" without senior practitioner support typically miss both target dates. The structured approach is to lock the first framework with audit completed, then move to the second when the management system is bedded in.
What good looks like in 90 days
For a UK SaaS startup of 5 to 25 employees with one enterprise deal paused on security:
- Weeks 1-2: Decide framework (SOC 2 or ISO 27001) based on the open deal. Engage a senior practitioner. Begin gap assessment.
- Weeks 3-6: Policy library build. Control implementation. GRC platform setup (Drata, Thoropass, or similar).
- Weeks 7-10: Evidence collection. Internal review. Pre-audit readiness.
- Weeks 11-12: External audit (SOC 2 Type 1) or Stage 1 audit (ISO 27001).
This compressed timeline requires senior practitioner-led delivery and a single framework focus. It does not work as a part-time effort or with junior-led platform onboarding.
The structural answer
UK SaaS startups facing their first enterprise security questionnaire need a fixed-scope, time-boxed compliance programme led by a senior practitioner. The market norm of buying a GRC platform first and then trying to figure out the management system afterwards inverts the sequence: it is the management system that the certification audit assesses, not the platform.
Goldline Consultancy delivers the Compliance Foundation programme for UK SaaS startups in this exact position. Fixed monthly retainer. Structured 12-month programme. One framework. Designed to close the enterprise deal that has paused and to make every subsequent enterprise deal land faster.
Book the Free Diagnostic to scope your specific situation.
