- Job title
- Penetration testing specialist
- Organization type
- a company within a holding
- Joined
- Nov 2023
- Message
- 154
We are a 9-person B2B software company based in London. We build a platform that streamlines HR workflows. Up until now, we've only worked with SMBs of 20 to 50 employees, and security never came up beyond standard, baseline questions. But last week, we reached the handshake stage on an £85,000/year licensing deal with a corporate retail chain that has 4,000 employees across the UK.
Before signing their procurement department stated that their infosec team needs to audit us and they sent over a massive 180-question vendor risk assessment questionnaire. We don't have SOC 2 or ISO 27001 certifications yet. Is there a concrete security audit checklist we should prepare so we don't lose the deal and can pass this enterprise review with flying colors? What kind of evidence and documentation do enterprise clients expect from smaller software vendors?