Answer a few yes/no questions and find out whether your B2B SaaS is likely to need ISO 27001, SOC 2, both or, to start, a DPA-first baseline to pass your enterprise customers' vendor security reviews. The result is an initial orientation, not legal advice and no substitute for a case-by-case review.
Find out in a few questions whether your B2B SaaS needs ISO 27001, SOC 2, both or, to start, a DPA-first baseline to pass your customers' security reviews. Indicative, not legally binding.
Every enterprise customer checks you before they buy. In the vendor security review, procurement and risk management send you security questionnaires such as CAIQ or SIG plus their own spreadsheets, demand a signed data-processing agreement and ask about ISO 27001, SOC 2, a trust center, recent penetration-test reports, your sub-processor list, data residency and AI. Which evidence you need depends on who you sell to and what data you process.
This self-check does not replace a case-by-case review. It gives you a first, honest tendency and a starting point for the conversation. All answers stay in your browser; no input is transmitted.
Answer every question with yes or no. You receive an instant, indicative classification together with the next steps.
We reply within one business day. If it is urgent, book a call directly.
We turn the indicative tendency into a solid roadmap, tailored to your target markets and your customers' questionnaires.
The fixed-fee SaaS Security & Compliance baseline assessment is the clean next step. We capture your target markets, your customer questionnaires and your data flows, and map them to the right baseline: ISO 27001, SOC 2 readiness, both or a DPA-first layer. You receive a prioritised, board-ready roadmap that shows which evidence unlocks which deal.
After that, SIDD delivers the roadmap: a certification-ready ISMS for ISO 27001, SOC 2 readiness with mapping to the Trust Services Criteria and a coordinated attestation through a licensed auditor, the legal DPA and processor layer, penetration tests and vulnerability scans, and a trust center that answers your questionnaires faster. For AI features we add the AI Governance Check and the AI Officer.
The right baseline is first a question of your target markets and contracts. That is exactly where we connect law, ISMS and technology.
We build the certification-ready ISMS for ISO 27001 and deliver the SOC 2 readiness with mapping to the Trust Services Criteria. The ISO certification is issued by an accredited certification body, the SOC 2 report is issued by a licensed auditor, and we coordinate both steps for you.
Data-processing agreements, sub-processor lists and data residency are reviewed by doctorate-level lawyers with CIPP/E, under the nFADP and the GDPR. So your contracts pass the legal check in the vendor review, not just the technical one.
Our vCISO builds your trust center and answers CAIQ, SIG and spreadsheet questionnaires with audit-ready evidence. Instead of starting each review from scratch, you answer fast and consistently and keep deals from stalling in procurement.
Penetration tests for web, network and API to OWASP and PTES, plus vulnerability scans, deliver exactly the recent reports enterprise buyers ask for in the vendor review. For AI features we add AI Security with LLM, RAG and agent pentests.
We advise in German, French and English, relevant for CH, EU, UK and US customers. Because we do not sell an in-house SOC, we recommend only the evidence that genuinely unlocks your deals.
You start with the fixed-fee SaaS Security & Compliance baseline assessment and a board-ready roadmap that clarifies baseline, evidence and sequence. So you invest first in the evidence that unlocks the next deal, instead of everything at once.
We map your target markets and customer questionnaires to the right baseline, with a prioritised roadmap and a clear sequence of evidence.