I’ve been working on a product for startups and small tech companies around ISO 27001 certification for information security, but got zero reaction on validation posts elsewhere, so please:
In a small company, everyone is his own administrator. There is no central AD for employees' computers; everything is as flexible as possible, which leads to the fact that it is tough to find uniform rules for all but even more challenging to make them follow.
I am building a security SaaS (https://www.daito.io) and thought that I really, really needed ISO 27001. Turns out that I don't need it, at least, not yet. Not acting too fast on a hunch saved me lots of $$$.
So far 0 leads and 0 customers have asked if and when I will have the certification done. But with more growth and customers, that day will eventually come.
To add on: my customer group is small & medium business, not enterprise, and that is probably the main reason ISO27001 is not deemed important (yet).
Thanks Jan, for the elaborate answer. I’ve been looking for feedback in the wrong places.
The drive for ISO27001 certification comes from larger organizations with compliance requirements, who push this down their supply chain.
Smaller suppliers who are forced to go for certification in this way do exist – I’ve advised several of them – but it’s unlikely I’ll find them on the Indie Hacker and bootstrapping forums.
Stupid thing is, I kind of already knew this.