> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
There's a very recently announced ( https://security.googleblog.com/2021/10/launching-collaborat... ) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.
https://cloudsecurityalliance.org/artifacts/consensus-assess...