If you're a company doing B2B sales, how often do prospective customers ask about the certificate? Does it ever make or break a deal? When did you decide that it's time to get it done?
Thanks!
1–10 of 104 posts
If you're a company doing B2B sales, how often do prospective customers ask about the certificate? Does it ever make or break a deal? When did you decide that it's time to get it done?
Thanks!
It can take a long time to complete an audit, especially that first one. You’re going to need to show a lengthy paper trail of policies and documented compliance.
I think it can bring good discipline to an organization when embraced, but that is often not how it gets done. And in some organizations the discipline is stifling. You’ll want to pay attention to how it is impacting teams.
A previous company I worked for used Process Street for procedure completion and tracking, but I always wondered if all auditors would be OK with such a flexible system.
The certification burden increases in proportion to the level of PII you are storing. The burden was much higher for government or med/bio contracts (FedRAMP/HIPPA, etc.). It's also worth it to mention that we had whole teams dedicated to working through RFPs/RFCs as they can get VERY time consuming.
Bottom line is that if you are going to work with the big fish, you will probably need this level of certification to show them you are serious.
My advice to you is gradually improve your infosec posture and policies etc but rather than kicking off the certification, wait until a customer asks you for it during vendor due dilligence, then say "we're working towards it" and immediately after the meeting commission one of the outside firms who do the evaluation for you.
The evaluation process takes a while and in my experience customers are understanding about that especially given b2b sales aren't exactly quick normally.
A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it.
Your real problem as a small vendor is deciding when this is necessary, because you might be getting customers just fine when you're small and dealing with people who care about actual security, not paper security. At some point you are gonna have to pull a few people out to get all this paperwork done. I spent last summer doing a whole pile of "Information Security" policies for a friend I was helping. Luckily there are consultants who can get you most of the way there.
You could also start the process and ask your certifying consultant to give you a certificate saying it's in progress which is also good in many cases but follow through to complete it.
It depends on what kind of clients you have, if you are working with customers in regulated industries, then I believe it's worth it.