Strategy and trust

Which trust signals matter to security buyers?

A security vendor is held to a higher bar than the companies it protects. Buyers expect you to show your own controls, not just describe theirs. This page covers the signals that carry the most weight and the order in which to build them.

By the ShoutEx Team · Updated October 2026 · Facts checked October 7, 2026
If you sell security, your own security is part of the product. Show it before anyone asks.Marketing for Cybersecurity Companies · Updated October 2026
5
SOC 2 trust services categories: security, availability, processing integrity, confidentiality, privacy
Oct 31, 2025
End of the transition from ISO/IEC 27001:2013 to the 2022 edition
1 page
A trust centre that answers the first round of vendor review questions

Which trust signals matter to security buyers?

Which trust signals matter to security buyers?

Independent assurance carries the most weight: a SOC 2 report for North American buyers and ISO/IEC 27001 certification for many international and regulated ones. Around those sit a trust centre, a security.txt file, recent penetration test summaries, customer references and a named, visible team.

ShoutEx view: SOC 2 is the most common ask from US enterprise buyers, while ISO/IEC 27001 often matters more in Europe and with organizations that run their own management system. Many Canadian vendors end up needing both, which is why sequencing matters.

SOC 2 Type 1 or Type 2: which do buyers expect?

Most enterprise reviewers expect a Type 2 report, but a Type 1 is a credible first step. According to the summary of System and Organization Controls reporting, SOC 2 reports are issued by licensed CPA firms under AICPA standards. A Type 1 report assesses the design of controls at a point in time. A Type 2 also tests whether those controls operated effectively over a period, often 9 to 12 months.

SOC 2 Type 1SOC 2 Type 2
What it coversDesign of controls on one dateDesign and operating effectiveness over a period
What it tells a buyerYou have controls in placeYour controls worked over months
When it helps mostFirst enterprise deals, early stageLarger deals and renewals
How to describe it"SOC 2 Type 1 report dated ...""SOC 2 Type 2 report covering ... to ..."

Reports can cover any of the five trust services categories: security, availability, processing integrity, confidentiality and privacy. Tell buyers which ones yours includes. The report itself is usually shared under NDA; the fact that it exists, its type and its period can be public.

What changed with ISO/IEC 27001:2022?

The current standard is ISO/IEC 27001:2022, the third edition, published in October 2022, with an amendment in 2024 adding climate action changes. The accreditation rules gave certified organizations three years to move over.

Under IAF MD 26 the transition ended on October 31, 2025, and certificates to the 2013 edition were to expire or be withdrawn at the end of that period. In 2026 any valid certificate should name the 2022 edition. Check your own site, your sales deck and your marketplace listings for old references.

  • Say "ISO/IEC 27001:2022 certified" and name the scope, such as the product and the teams covered.
  • Name the certification body, and keep the certificate available on request.
  • Remove any 2013 logos or wording, including in PDFs and partner portals.
  • Do not describe a gap assessment or readiness project as certification.

What should a security vendor's trust centre include?

A trust centre is one page, often on its own subdomain, where reviewers find your assurance documents, policies, subprocessors and system status. ShoutEx view: it is now a common vendor practice, and buyers notice when it is missing.

Example · trust centre mock-up
trust.signalpine.example
Signalpine Trust CenterSecurity, privacy and compliance documentation
All systems operational
Compliance
SOC 2 Type 2ISO/IEC 27001:2022CSA STAR Level 1Annual third-party penetration test
Documents
Security overviewPublic
Subprocessor listPublic
Vulnerability disclosure policyPublic
SOC 2 Type 2 reportNDA
Penetration test summary letterNDA
ISO/IEC 27001:2022 certificateRequest access
Data processing agreementRequest access
Subprocessors
Microsoft AzureHosting, Canada CentralOktaWorkforce identityZendeskCustomer support

Fictional company and documents. Shown for illustration only.

Trust centre mock-up: public documents answer early questions without a call; NDA documents open once a non-disclosure agreement is signed; requested items route to a named owner. Signalpine is fictional, and the subprocessors are examples of the format.

Decide the access level for each document deliberately. Anything a competitor could not misuse, such as your security overview, subprocessor list and disclosure policy, can be public. Audit reports and test letters usually sit behind an NDA, and contracts or certificates can go out on request so you know who is reviewing you, which is itself a useful buying signal for sales.

Link the trust centre from your footer, your pricing page and your demo request page. The questionnaire workflow it supports is covered in security questionnaires.

ShoutEx rule

Show the date on every assurance claim.

Write "SOC 2 Type 2 report covering the 12 months to June 30, 2026", not just "SOC 2 compliant". Dates tell reviewers the claim is current and specific.

Which smaller trust signals add up?

Certifications take months. These signals take days or weeks, and reviewers check them early:

  • security.txt at /.well-known/security.txt with a contact and an expiry date, so researchers know how to reach you. See threat research content for disclosure practice.
  • A vulnerability disclosure policy that says how you handle reports and how fast you respond.
  • A penetration test summary letter from an independent firm, shared under NDA, dated within the last year.
  • Named people with real profiles: founders, security lead, researchers.
  • Customer references willing to take a call, especially in the buyer's sector.
  • A status page with incident history, not just a green light.
  • Plain data residency facts, such as which cloud regions hold customer data.

Services firms add their own layer: the qualifications of the people doing the work, insurance details and sample deliverables. Compliance and vCISO firms often help clients earn these same signals, which makes their own trust page a sales asset too.

Which trust signals should you get first?

Start with what is cheap and fast, then sequence the audits around the deals you are chasing.

Trust signals by effortRough order for a young product vendor
SignalWhat it provesEffort
security.txt and disclosure policyYou can be reached and take reports seriouslyDays
Trust centre with public documentsYou are organized and transparentWeeks
Independent penetration test letterSomeone outside tested the productWeeks
SOC 2 Type 1Controls are designed and in placeMonths
SOC 2 Type 2Controls operated over a periodMonths, plus the observation period
ISO/IEC 27001:2022 certificationA running management system, externally auditedMonths
Source: ShoutEx view, based on our work with B2B technology companies.

Mistakes to avoid

  • Saying "SOC 2 compliant" with no report type or period.
  • Gating every document, including ones that could be public.
  • Letting the subprocessor list drift out of date.
  • Starting an audit only after a large deal asks for it.

US buyers add their own expectations, from SOC 2 to federal programs. See US expansion for the sequence.

Frequently asked questions

Do security vendors need SOC 2?

Not legally, but many enterprise buyers in North America ask for a SOC 2 report during vendor review. Without one, expect longer reviews or lost deals.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 assesses the design of controls at a point in time. Type 2 also tests whether they operated effectively over a period, often 9 to 12 months.

Are ISO/IEC 27001:2013 certificates still valid?

The transition to the 2022 edition ended on October 31, 2025, and 2013 certificates were to expire or be withdrawn. Valid certificates in 2026 should be to the 2022 edition.

Can we publish our SOC 2 report?

Usually the report is shared under NDA. You can publicly state the report type, the period covered and the trust services categories included.

What is a trust centre?

A page where a vendor publishes security documents, certifications, subprocessors and status, with access levels such as public, NDA and on request.

What is security.txt?

A small text file at /.well-known/security.txt that tells researchers how to report vulnerabilities. It needs at least a contact and an expiry date.

Should we show certification badges on the homepage?

Only for certifications you currently hold, with the scope and date available on the trust centre. Out-of-date badges cost more trust than having none.

Do services firms need SOC 2 or ISO 27001?

Often, when they handle client data or access client systems. Buyers of MDR and managed services increasingly ask for the same assurance as product vendors.

Sources & further reading

Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.