You have three enterprise prospects. One requires SOC 2. Another mentions GDPR. A third is in healthcare and needs HIPAA. You cannot do all three simultaneously. Which one do you tackle first?
The answer depends on your customers, your data, and your market. Here is the decision framework.
SOC 2: The default first choice
For most B2B SaaS startups, SOC 2 should be first. Here is why:
- Broadest applicability. SOC 2 is requested by almost every enterprise buyer in the US, regardless of industry. It covers security practices that apply to any SaaS product.
- Foundation for other frameworks. About 60-70% of SOC 2 controls overlap with GDPR and HIPAA requirements. Doing SOC 2 first means you have already completed a significant portion of the other frameworks.
- Fastest to complete. SOC 2 Type I can be done in 3-4 months. GDPR compliance is ongoing and never "done." HIPAA requires specific technical and administrative safeguards that can take 6-12 months.
- Market expectation. SOC 2 has become table stakes for selling to companies with more than 200 employees. Without it, you are excluded from most enterprise procurement processes.
Cost: $15,000-$40,000 for the audit plus $10,000-$20,000/year for a compliance platform. Timeline: 3-6 months for Type I, 6-9 months for Type II.
GDPR: When you have EU customers
GDPR is not optional if you process personal data of EU residents. The regulation applies based on the location of the data subject, not your company. A startup in San Francisco selling to a customer in Berlin must comply with GDPR.
GDPR compliance involves:
- Data Processing Agreement (DPA): A contract between you and your customers that defines how you process their data.
- Privacy policy: A public document describing what data you collect, why, and how long you keep it.
- Data subject rights: Technical capability to handle access requests, deletion requests, and data portability requests.
- Data protection impact assessments: For high-risk processing activities.
- Breach notification: Ability to notify authorities within 72 hours of discovering a breach.
- Data residency: Understanding where your data is stored and ensuring appropriate safeguards for international transfers.
Cost: $5,000-$20,000 for initial legal review and policy creation. Ongoing compliance is largely operational. Timeline: 2-4 months for initial compliance.
HIPAA: When you touch health data
HIPAA applies if you process Protected Health Information (PHI) for healthcare providers, health plans, or healthcare clearinghouses. If your SaaS product is used by doctors, hospitals, insurance companies, or any entity that handles patient data, you need HIPAA compliance.
HIPAA requires:
- Business Associate Agreement (BAA): A contract with every entity that shares PHI with you.
- Technical safeguards: Encryption, access controls, audit logging, integrity controls, and transmission security for all PHI.
- Administrative safeguards: Security officer, workforce training, access management procedures, and contingency planning.
- Physical safeguards: Facility access controls and workstation security (relevant even for cloud-hosted applications).
Cost: $20,000-$50,000 for initial compliance assessment and implementation. Ongoing compliance requires dedicated attention. Timeline: 4-9 months for initial compliance.
The decision matrix
Start with SOC 2 if: Your customers are US-based enterprises across any industry. This covers the broadest set of sales scenarios.
Start with GDPR if: Your primary market is Europe or you already have significant EU customer data. Note: SOC 2 + GDPR together is common for SaaS companies selling internationally.
Start with HIPAA if: Healthcare is your primary market. Note: You should still do SOC 2. Most healthcare organizations require both HIPAA compliance AND SOC 2.
If you need all three: SOC 2 first (months 1-6), then GDPR (months 4-8, overlapping), then HIPAA (months 6-12). The overlap between frameworks means the incremental effort for each additional framework is smaller than doing it independently.
Need help with compliance?
traztech helps startups navigate SOC 2, GDPR, and HIPAA compliance. We build a unified compliance program that covers all the frameworks your customers require.
Book a free strategy callThe Canadian frameworks the matrix leaves out
If you sell in Canada, or hold data about people in Canada, two more obligations sit underneath everything above and neither is optional in the way a certification is optional.
PIPEDA applies to commercial handling of personal information across most of the country, and its breach reporting requirement is the part that catches startups. A breach creating a real risk of significant harm has to be reported to the Privacy Commissioner and to affected individuals, and you must keep a record of every breach, including the ones you decided not to report. That record is a live obligation. Most companies discover they have never kept one at the moment they need to demonstrate they have.
Quebec's Law 25 goes further and is stricter than most teams expect. It requires a named person accountable for privacy protection whose title is published, privacy impact assessments before certain projects, consent handling requirements that constrain how you design your signup flow, and portability obligations. If you have Quebec customers or Quebec staff, this is not a footnote to your GDPR work. The two overlap substantially but not completely, and the differences land in product decisions rather than in policy documents.
Practically, if you are already building for GDPR you have done most of the structural work. What remains is jurisdiction-specific: the accountable person, the reporting routes, the record keeping, and the consent language. Budget weeks, not months, provided the GDPR foundation is real.
Where the overlap between frameworks stops
The overlap argument is sound and it is also oversold. Control language maps across frameworks. Evidence often does not, and evidence is the expensive half.
Three specific places where the reuse breaks down. First, scope definitions differ. Your SOC 2 scope is a set of systems and a report period you choose. Your health data obligations attach to wherever protected information actually goes, which may be a different and larger set of systems. Second, evidence titles are not canonical. The same underlying activity gets called an access review in one framework, an authorization review in another, and workforce access management in a third, and if you file evidence by framework name rather than by activity you will build three parallel registers of the same work. Organize your evidence by what actually happened, then map it outward to each framework. Third, some requirements are genuinely additive rather than overlapping. Business associate agreements, breach notification clocks, and training content specific to health information have no equivalent elsewhere, and no amount of control mapping will produce them.
The practical rule is that the second framework costs roughly a third to a half of the first if you built the first one properly, and close to the full amount if you built it as a checklist exercise aimed at passing an audit.
What GDPR asks of your engineers, not your lawyers
The policies and the data processing agreement are the cheap part. Four requirements have real engineering weight and they are consistently underestimated.
Deletion that actually deletes. A deletion request has to reach every copy: the primary database, the analytics warehouse, the search index, the support desk, the email service provider, the logs, and the backups. Backups are the hard one, because you cannot surgically edit a snapshot. The workable position is a documented retention window on backups plus a commitment that restored data is re-processed against outstanding deletion requests. Write that down before someone asks, because the answer invented under pressure is usually wrong.
Access requests at volume. One request a year is a manual job. Fifty is a product feature. Build an export path early, and decide what a person is entitled to receive, which is their personal data, not every internal record that happens to mention them.
Lawful basis, decided per processing activity. Not one basis for the whole company. Product functionality, marketing, analytics, and model training may each need a different answer, and consent obtained for one does not cover the others.
International transfers. Know where your subprocessors run, because a support tool with staff in a third country is a transfer, whether or not anyone thought of it that way.
The mistakes that cost the most money
Buying a compliance platform first. Automation tooling collects evidence for controls you have already implemented. Buying it before you have decided your scope, your policies, and your control ownership means paying a subscription to watch a dashboard show red. Get the program designed, then automate the collection.
Setting the audit window before the controls run. A Type II report observes controls over a period. If your quarterly access review has happened once, the observation window cannot honestly start yet. Companies that book the audit against a fundraising deadline rather than against control maturity end up with exceptions in the report, and an exception is permanent in a way a delay is not.
Over-scoping the trust criteria. Every additional criterion beyond security adds controls, evidence, and audit fee. Availability makes sense if you have committed to uptime numbers. Confidentiality and privacy make sense when a buyer specifically requires them. Selecting all of them because more looks better is how a first report becomes twice the work for no commercial gain. Ask your three most important prospects what they need before you decide.
Walking into the audit without a documented readiness position. Auditors price on uncertainty. Arriving with a mapped control set, a defined scope, and organized evidence changes the quote materially. On one engagement that work took $11,000 off the audit fee, which is more than the gap analysis cost.
What it costs to keep, not to get
The figures in the first half of this article cover reaching a position. Holding it is the recurring cost and it is the one that surprises founders in year two.
Every framework here requires periodic activity forever. Access reviews on a stated cadence. Vendor reassessment. Policy review and re-approval. Training on hire and annually. Incident exercises. Risk register review. Evidence collection through the whole observation period rather than in a burst before the audit. For a company of thirty to sixty people this is somewhere between a quarter and a half of a person's time, spread across several people who each think it is somebody else's job.
That is the real argument for a named owner. Not because the work is difficult, but because unowned recurring work does not happen, and a lapsed certification is more damaging commercially than never having had one. Whether that owner is an internal hire or a fractional arrangement from $3,000 a month depends on your size and your pipeline, and either is better than the default, which is that the founder does it at the weekend until they stop.
When to do none of this yet
Compliance work has a cost and a timing, and starting it early is not automatically prudent.
If no buyer has asked and you handle no regulated data, you do not have a compliance problem. Spend the money on the security hygiene that every framework assumes anyway: multifactor authentication everywhere, secrets in a manager, encrypted backups with one tested restore, logging that would let you reconstruct an incident, and a written list of who has access to what. All of that is required later, none of it is wasted, and none of it needs an auditor.
If a single prospect mentioned a framework in passing, ask whether it is a requirement or a preference before committing two quarters. A meaningful share of the time the honest answer from their security team is that a completed questionnaire and a recent penetration test will get you through, and the certification is a renewal-year condition rather than a blocker now.
And if your product is genuinely early, changing shape monthly, with an architecture you expect to rebuild, wait. Controls documented against a system you are about to replace have to be documented again. There is no prize for having been compliant with an architecture that no longer exists.
Where the calculation flips is when a named deal is blocked, when you handle health or payment or regulated financial data, or when your renewal cycle is about to bring the question to every existing customer at once. At that point the delay costs more than the program. If you want a view on which side of that line you are on, our compliance work starts with a gap analysis rather than a contract, and pricing lists what each fixed-scope piece costs before you commit to anything.
The fourth framework the question usually forgets
If you take card payments inside your own product rather than redirecting to a payment provider, PCI DSS is in the picture and it does not wait its turn behind the other three. Scope is determined by how card data flows, not by your revenue, and the difference between a hosted payment field and a form your application renders is the difference between a short self-assessment and a scoping exercise touching most of your stack.
The cheap move is architectural. Push card entry into an iframe or a redirect owned by the processor, never let a primary account number reach your servers or logs, and the obligation collapses to a much smaller questionnaire. Teams that build their own card form and learn this a year later face a remediation project with no commercial upside. If cards are near your product, read our PCI DSS guidance for SaaS before the architecture hardens.
Read the contract, not the framework name
The framework named in a sales conversation is rarely the whole obligation. It lives in the customer's agreement, and the clauses that cost money are the ones nobody reads until renewal.
Audit rights. A right for the customer to audit you directly, at your expense. One enterprise exercising it costs a week of your senior people. Negotiate it down to a report and a questionnaire while you have leverage.
Breach notification clocks. Contractual clocks are frequently shorter than statutory ones, and 24 hours appears more often than founders expect. That is an operational commitment, and it means someone has to be reachable.
Selling while the programme is still in flight
Nobody gets to pause their pipeline for six months, so the practical question is what you hand a prospect before the report exists. A short readiness statement naming your scope, your chosen criteria, your auditor if engaged, and your expected report date, signed by a real person. A current penetration test summary with remediation status. A standard questionnaire kept current so the next one takes an hour. What does not work is a claim of being compliant while still in readiness, because security teams check.
Vendor management is the work that never ends
Every framework here asks the same question about your suppliers, and it is the recurring obligation that decays fastest. You need a list of vendors touching customer data, a risk tier against each, evidence you reviewed the important ones, agreements in place, and a record of who approved the relationship. New tools arrive weekly on a company card, so the list is wrong within a month unless someone owns it. Tie the review to purchasing rather than to a calendar and keep the register somewhere shared, such as the free traztech Workspace, rather than in a personal spreadsheet.
Pick the auditor earlier than feels comfortable
Founders tend to treat the audit firm as the last hire, someone you bring in once the controls are built. That order is backwards. The auditor decides what counts as sufficient evidence, how they sample, and whether your scope statement makes sense, and those answers change what you build. Talking to two or three firms during readiness costs a few hours and routinely saves a quarter.
Ask each one concrete questions rather than for a quote. Who actually performs the fieldwork, and are they in-house or subcontracted. How do they want evidence delivered, because a firm that works inside your compliance tooling behaves differently from one that wants a shared drive of screenshots. How many companies of your shape and stage do they report on in a year. What turns a finding into an exception in their house style, since firms differ more on that than they admit. And what their availability looks like, because audit capacity is seasonal and the firm you like may not have a slot when your window closes.
For SOC 2 the report has to come from a licensed CPA firm, and for ISO 27001 the certificate comes from an accredited certification body, which is a different organisation from whoever helped you prepare. Nobody can both build your programme and issue your opinion on it, so expect two relationships. If you want help running that selection alongside the readiness work, our compliance work starts with an assessment, and pricing lists what each fixed-scope piece costs before you commit.
Handling health data? HIPAA and PHIPA readiness for digital health, scoped to the data you actually touch.
HIPAA readinessOr talk about a retainer