Which trust signals matter to security buyers?
A security vendor is held to a higher bar than the companies it protects. Buyers expect you to show your own controls, not just describe theirs. This page covers the signals that carry the most weight and the order in which to build them.
Which trust signals matter to security buyers?
Independent assurance carries the most weight: a SOC 2 report for North American buyers and ISO/IEC 27001 certification for many international and regulated ones. Around those sit a trust centre, a security.txt file, recent penetration test summaries, customer references and a named, visible team.
ShoutEx view: SOC 2 is the most common ask from US enterprise buyers, while ISO/IEC 27001 often matters more in Europe and with organizations that run their own management system. Many Canadian vendors end up needing both, which is why sequencing matters.
SOC 2 Type 1 or Type 2: which do buyers expect?
Most enterprise reviewers expect a Type 2 report, but a Type 1 is a credible first step. According to the summary of System and Organization Controls reporting, SOC 2 reports are issued by licensed CPA firms under AICPA standards. A Type 1 report assesses the design of controls at a point in time. A Type 2 also tests whether those controls operated effectively over a period, often 9 to 12 months.
| SOC 2 Type 1 | SOC 2 Type 2 | |
|---|---|---|
| What it covers | Design of controls on one date | Design and operating effectiveness over a period |
| What it tells a buyer | You have controls in place | Your controls worked over months |
| When it helps most | First enterprise deals, early stage | Larger deals and renewals |
| How to describe it | "SOC 2 Type 1 report dated ..." | "SOC 2 Type 2 report covering ... to ..." |
Reports can cover any of the five trust services categories: security, availability, processing integrity, confidentiality and privacy. Tell buyers which ones yours includes. The report itself is usually shared under NDA; the fact that it exists, its type and its period can be public.
What changed with ISO/IEC 27001:2022?
The current standard is ISO/IEC 27001:2022, the third edition, published in October 2022, with an amendment in 2024 adding climate action changes. The accreditation rules gave certified organizations three years to move over.
Under IAF MD 26 the transition ended on October 31, 2025, and certificates to the 2013 edition were to expire or be withdrawn at the end of that period. In 2026 any valid certificate should name the 2022 edition. Check your own site, your sales deck and your marketplace listings for old references.
- Say "ISO/IEC 27001:2022 certified" and name the scope, such as the product and the teams covered.
- Name the certification body, and keep the certificate available on request.
- Remove any 2013 logos or wording, including in PDFs and partner portals.
- Do not describe a gap assessment or readiness project as certification.
What should a security vendor's trust centre include?
A trust centre is one page, often on its own subdomain, where reviewers find your assurance documents, policies, subprocessors and system status. ShoutEx view: it is now a common vendor practice, and buyers notice when it is missing.
Fictional company and documents. Shown for illustration only.
Decide the access level for each document deliberately. Anything a competitor could not misuse, such as your security overview, subprocessor list and disclosure policy, can be public. Audit reports and test letters usually sit behind an NDA, and contracts or certificates can go out on request so you know who is reviewing you, which is itself a useful buying signal for sales.
Link the trust centre from your footer, your pricing page and your demo request page. The questionnaire workflow it supports is covered in security questionnaires.
Show the date on every assurance claim.
Write "SOC 2 Type 2 report covering the 12 months to June 30, 2026", not just "SOC 2 compliant". Dates tell reviewers the claim is current and specific.
Which smaller trust signals add up?
Certifications take months. These signals take days or weeks, and reviewers check them early:
- security.txt at /.well-known/security.txt with a contact and an expiry date, so researchers know how to reach you. See threat research content for disclosure practice.
- A vulnerability disclosure policy that says how you handle reports and how fast you respond.
- A penetration test summary letter from an independent firm, shared under NDA, dated within the last year.
- Named people with real profiles: founders, security lead, researchers.
- Customer references willing to take a call, especially in the buyer's sector.
- A status page with incident history, not just a green light.
- Plain data residency facts, such as which cloud regions hold customer data.
Services firms add their own layer: the qualifications of the people doing the work, insurance details and sample deliverables. Compliance and vCISO firms often help clients earn these same signals, which makes their own trust page a sales asset too.
Which trust signals should you get first?
Start with what is cheap and fast, then sequence the audits around the deals you are chasing.
| Signal | What it proves | Effort |
|---|---|---|
| security.txt and disclosure policy | You can be reached and take reports seriously | Days |
| Trust centre with public documents | You are organized and transparent | Weeks |
| Independent penetration test letter | Someone outside tested the product | Weeks |
| SOC 2 Type 1 | Controls are designed and in place | Months |
| SOC 2 Type 2 | Controls operated over a period | Months, plus the observation period |
| ISO/IEC 27001:2022 certification | A running management system, externally audited | Months |
Mistakes to avoid
- Saying "SOC 2 compliant" with no report type or period.
- Gating every document, including ones that could be public.
- Letting the subprocessor list drift out of date.
- Starting an audit only after a large deal asks for it.
US buyers add their own expectations, from SOC 2 to federal programs. See US expansion for the sequence.
Frequently asked questions
Do security vendors need SOC 2?
Not legally, but many enterprise buyers in North America ask for a SOC 2 report during vendor review. Without one, expect longer reviews or lost deals.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 assesses the design of controls at a point in time. Type 2 also tests whether they operated effectively over a period, often 9 to 12 months.
Are ISO/IEC 27001:2013 certificates still valid?
The transition to the 2022 edition ended on October 31, 2025, and 2013 certificates were to expire or be withdrawn. Valid certificates in 2026 should be to the 2022 edition.
Can we publish our SOC 2 report?
Usually the report is shared under NDA. You can publicly state the report type, the period covered and the trust services categories included.
What is a trust centre?
A page where a vendor publishes security documents, certifications, subprocessors and status, with access levels such as public, NDA and on request.
What is security.txt?
A small text file at /.well-known/security.txt that tells researchers how to report vulnerabilities. It needs at least a contact and an expiry date.
Should we show certification badges on the homepage?
Only for certifications you currently hold, with the scope and date available on the trust centre. Out-of-date badges cost more trust than having none.
Do services firms need SOC 2 or ISO 27001?
Often, when they handle client data or access client systems. Buyers of MDR and managed services increasingly ask for the same assurance as product vendors.
Sources & further reading
Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.