The deal wall
A growing B2B company reaches the same door. A prospect’s security team will not proceed without a SOC 2 report, or without a questionnaire long enough to be a report in disguise. Sometimes the contract is explicit. Sometimes the deal simply stops moving. The calendar is not waiting on a hiring plan. It is waiting on answers.
SaaS engagements start at that door. The mistake is to treat the report as the work. The report is a consequence of a program that already exists, observed by someone independent. Buying the observation before the program exists produces a painful year and a letter you cannot explain on a call.
Badge first, or program first
Badge-first means shopping for a CPA firm and a software tool in the same week, then discovering that the tool’s checklist and the company’s actual behavior are different documents. Program-first means deciding what you will actually do about access, change, vendors, logging, and incidents, writing that down so an engineer can follow it, and only then inviting someone to test whether you did.
Program-first is slower in the first month and faster in the month a customer asks a follow-up the badge does not answer. Customers do ask. The report gets you into the review. The evidence gets you out of it.
Evidence that survives a security review
A reviewer at the prospect is not grading your prose. They want to see that production access is limited and attributable, that changes are reviewed, that you know your subprocessors, that you would notice an incident, and that you have named what happens next. Screenshots of a setting, a list of who has administrator rights, a vendor inventory, and a short incident plan with real names will do more work than a policy no one has opened.
AI tools in the development path are now part of that review. Prospects have started to ask what code-assistance tools see source, whether customer data is in the prompts, and who approved the tool. You do not need a philosophy of artificial intelligence. You need an inventory and a rule: what is allowed, what data it may touch, and who owns the exception. That is the same shape as any other vendor question. The AI governance quick start exists for the week that question arrives before the rest of the program does.
A fixed-scope path
The sequence that fits the deal in front of you is short. A security maturity assessment, $3,000 to $8,000, scores where you are against NIST CSF 2.0, including supply chain and AI governance, and ranks the gaps that will block the deal. Remediation and documentation, $3,500 to $7,500, produces the policies and the incident response plan a reviewer asks for, mapped to the framework you are actually being held to. Attestation prep is the step after those artifacts exist, scoped to the report type the deal requires, not to a generic “SOC 2 project.”
Self-service kits sit underneath that path for the week you need a document before the engagement starts. They are credited in full toward an engagement booked within 90 days. They are not the report, and they are not a substitute for the assessment if the team is still arguing about what “done” means.
A virtual CISO when the questions keep arriving
A virtual CISO retainer, from $3,000 a month, is standing coverage when customer reviews, a Thursday questionnaire, a board paragraph, or an escalation keep landing. It is the wrong first purchase if you have never been assessed. Use the retainer to carry a program. Do not use it to invent one in the margin of a sales call.
The free readiness assessment is the cheapest way to see which of those steps you are actually on. It will not impress the prospect. It will stop you from buying the badge before you can describe the program the badge is supposed to reflect.