Browse / SaaS / Objection
SaaS Sales Objection

We require SOC 2 Type II before signing any new vendor — you do not have that certification.

3 responses
anchor
Thanks

"We are working toward SOC 2 Type II — I will send you our current security documentation, the audit timeline, and our existing controls framework. Many companies in your situation use that package to initiate an exception process."

probe
Thanks

"What is the SOC 2 requirement based on — procurement policy, a specific risk framework, a customer contract requirement? The source might tell us whether an exception or alternative documentation is viable."

reframe
Thanks

"SOC 2 is a maturity signal, not a minimum bar. We have completed a third-party security assessment, GDPR compliance, and a detailed control inventory. Does your security team accept alternative attestations?"