I'm currently at a small startup trying to do ISO 27001. A big issue we run into is that there simply aren't enough people . For example, the processes are built around having one person who writes code, and another person who reviews the written code. That's obviously impossible as a solo dev. You also need an internal auditor, who obviously needs to be separate from the operations team. If I recall correctly the mi…
We are a team of 1 developer and 1 sales/marketing and are fully certified. You can hire an external auditor for the internal audit. We have AI code reviews, so we don’t need an extra developer.
Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
101–110 of 164 posts
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#102I am a solo entrepreneur. Don't. I learned that my business is unable to pass pretty much ANY certification or corporate IT security audit. Many of the questions simply do not apply to my business ("do you have documented procedures for revoking employee access") and the default answer is NO. Get even a single NO and you're done. I gave up and these days actively discourage enterprises from even trying to sign up — t…
Early on, I had a potential enterprise account (well known online store) that wanted everything that enterprises wanted in addition to multiple meetings (with all the stakeholders) for a $50/month account (my mistake for not getting that information upfront).
Another time, a large Canadian media company wanted me to agree to an uncapped liability provision. Respectfully turned them down.
All in all, I lost some prestige business but if I took them on, it wouldn't move my profit levels much.
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#103I’ll spend some more time replying to this next week, so circle back to this comment; I’m someone who regularly helps people get past these audits, meet the criteria customers are trying to assess with these certifications, and vet startups who don’t have these certifications or budget. Start by pre-filling your own CAIQ v4 with an earnest “we don’t do this” or “we haven’t even thought about this” attempt: https://cl…
Do you genuinely use em-dashes in your regular writing ? I'm just curious because whenever I type I simply press -
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#104Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…
I will add a few more things to this: - Document your data and security and share that with customers instead. You can say "We don't have SOC2 at the moment but here is all our security and data policy". It works 99% of the time for me. - Very few companies truly have policy to reject a vendor if they don't have SOC2. Those are usually large enterprise or companies in sensitive areas such as Finance/Healthcare etc. E…
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#105Earlier quoted context omitted.
I will add a few more things to this: - Document your data and security and share that with customers instead. You can say "We don't have SOC2 at the moment but here is all our security and data policy". It works 99% of the time for me. - Very few companies truly have policy to reject a vendor if they don't have SOC2. Those are usually large enterprise or companies in sensitive areas such as Finance/Healthcare etc. E…
> It works 99% of the time I would add the caveat "...as long as you have no competition." If you're in a market where alternatives exist, and they have the certification, you're definitely transparently losing sales. From the enterprise side, I can tell you vendor certification takes an order of magnitude more time/money/effort when the vendor says "we don't have cert X but here's a mountain of drivel you can paw th…
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#106Earlier quoted context omitted.
I will add a few more things to this: - Document your data and security and share that with customers instead. You can say "We don't have SOC2 at the moment but here is all our security and data policy". It works 99% of the time for me. - Very few companies truly have policy to reject a vendor if they don't have SOC2. Those are usually large enterprise or companies in sensitive areas such as Finance/Healthcare etc. E…
Fully agree, the only downside is without a SOC2 you will be asked to fill out an insane 200+ questionnaire. Good news is you have all these great LLM tools you can do this work for you, and just check it over.
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#107I am a solo entrepreneur. Don't. I learned that my business is unable to pass pretty much ANY certification or corporate IT security audit. Many of the questions simply do not apply to my business ("do you have documented procedures for revoking employee access") and the default answer is NO. Get even a single NO and you're done. I gave up and these days actively discourage enterprises from even trying to sign up — t…
Same. For my business, the enterprises that want to use my software wouldn't actually be worth the hassle as their usage is not more than my normal business customers (SMB). Just more work and costs on my end. Early on, I had a potential enterprise account (well known online store) that wanted everything that enterprises wanted in addition to multiple meetings (with all the stakeholders) for a $50/month account (my m…
They will pay $50 for your product... And probably $950 for the terms.
(Not saying that would have been the right thing for you but my advice to folks who find themselves in this position is always 20x or 40x the price - if that is enough to make it worth your bother, then go for it. Good chance theyll pay)
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#108either they will use the app without soc2 or they will find an alternative.
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#109I’ll spend some more time replying to this next week, so circle back to this comment; I’m someone who regularly helps people get past these audits, meet the criteria customers are trying to assess with these certifications, and vet startups who don’t have these certifications or budget. Start by pre-filling your own CAIQ v4 with an earnest “we don’t do this” or “we haven’t even thought about this” attempt: https://cl…
Do you genuinely use em-dashes in your regular writing ? I'm just curious because whenever I type I simply press -
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#110I’ll spend some more time replying to this next week, so circle back to this comment; I’m someone who regularly helps people get past these audits, meet the criteria customers are trying to assess with these certifications, and vet startups who don’t have these certifications or budget. Start by pre-filling your own CAIQ v4 with an earnest “we don’t do this” or “we haven’t even thought about this” attempt: https://cl…
Please don't do any extra engineering for your wiki project simply because it appears on the Cloud Security Alliance CAIQ worksheet. These worksheets are built by committees where every member has a bunch of idiosyncratic controls and objectives that they slip into the document.
Compliance is not security, but engineers, especially solo ones tend to have their blinkers on when they’re trying to build something to first work.