Most organizations take a calendar year or more to get their ISO 27001 certification. One difference between that and a SOC2 is that you need to show that you are running it continuously. At the end of the first year, you get to have another audit. And you really need to show improvement over that year. And the following year. In the fourth year, you start over again with a full audit. Keep in mind that ISO 27001 will require staffing involvement.
Some deals can work if you show convincingly that you are on the road to getting it.
And no, having both won't make the questionnaires go away (contrary to my hope of obtaining it). They may be slightly reduced, but if you have a lot of large customers, you will find quite often hundreds of questions that don't exactly overlap with the last one you filled out. This make it hard to scale the questionnaire effort. There can be some luck if you prepare a standard one, like starting with the CIS controls.
We decided to get it done before it was a hard requirement, as we wanted to show a better security posture, and pursue international (not just EU) business.
One thought I share with teams building security practice is to obtain a copy of the ISO 27001/27002 standards and read through it. It may give you some ideas of how to measure your own security program. One thing that I like about that standard is documenting the executive commitment to funding and staffing the security effort. If you can wrangle that, you are ahead of the game.
The new (2017) SOC2 standard has new language that goes a bit in that direction, with controls like executive commitment to ethics, and division of responsibilities between the board and management.
With respect to security, in your own enlightened company self interest, don't let the idea of SOC2 or ISO 27001 lead you to think that you have security solved. Didn't SolarWinds have a SOC2? (Don't get me started on Third Party Risk Management.)