Startup Daily
  • News
  • Topic
    • Accelerator
    • Ag Tech
    • ASX
    • Business
    • Climate Tech
    • Cryptocurrency
    • Cyber security
    • Data
    • Fintech
    • Events
    • Funding
    • Global tech
    • Other tech
    • People
    • Politics
    • Quantum Computing
    • Social Media
    • Space
    • Venture Capital
  • Advice
    • Business strategy
    • Diversity
    • Investing
    • Leadership
    • Opinion
    • Pitching
    • Women in tech
    • Workplace
  • After Hours
    • Beauty and fashion
    • Food and drink
    • Gadgets
    • Gaming
    • Life hacks
    • Luxury
    • Motoring
    • Property
    • Toys
    • Travel
  • Featured
    • Secrets of AI Innovators: How to scale like the best eBook
    •  EY Entrepreneur of the Year
    • Startup World Cup
    • Startup 360
    • Newsletter Subscribe
  • Contact
Startup Daily ‘It prevents startups from closing a deal’: the compliance ‘blockers’ that slow founders building a unicorn
  • News
  • Topics
    • Accelerator
    • AI
    • ASX
    • Business
    • Climate Tech
    • Cryptocurrency
    • Cyber security
    • Data
    • Fintech
    • Funding
    • Global tech
    • Other tech
    • People
    • Politics
    • Space
    • Ag tech
    • Events
    • Quantum Computing
    • Social Media
    • Venture Capital
  • Advice
    • Business strategy
    • Diversity
    • Investing
    • Leadership
    • Opinion
    • Pitching
    • Women in tech
    • Workplace
  • After Hours
    • Beauty and fashion
    • Food and drink
    • Gadgets
    • Gaming
    • Luxury
    • Motoring
    • Property
    • Toys
    • Life hacks
    • Travel
  • Featured
    • Featured
      • Secrets of AI Innovators

        Want to scale your AI solution smarter? Tap into some of the world’s leading AI thinkers and doers with our FREE downloadable guide to learn how to scale like the best. DOWNLOAD NOW.

      • Join us for Growth Summit 2026

        Unlock the secrets to business success. Learn from founders and industry experts how to level up your business in a competitive market. EARLY BIRD TICKETS NOW ON SALE.

      • Meet the 2025 national finalists

        Each year, EY Entrepreneur Of The Year recognises ambitious leaders who are driven by a relentless urge to bring their bold vision to life. MEET THE FINALISTS

  • Contact
Small Business & Finance Network
Advertise

Latest » Partner Content » ‘It prevents startups from closing a deal’: the compliance ‘blockers’ that slow founders building a unicorn

Cyber security

‘It prevents startups from closing a deal’: the compliance ‘blockers’ that slow founders building a unicorn

Adam Bub - November 5, 2024 4 MIN READ
oscar watson-smith
Oscar Watson-Smith speaking at Unicorn Day at The Timber Yard, Port Melbourne, on October 24. Image: Startup Daily.

Supported by

There were plenty of important topics covered at the recent Startup Daily and AWS Unicorn Day in Melbourne from venture capital to impact startups to scaling to a billion-dollar business. One particular session on compliance demonstrated how paying attention to the small details can help founders close the biggest deals.

When Oscar Watson-Smith, sales engineer at compliance automation platform Vanta, asked the room how many startups had been through or heard of SOC 2 or ISO before, many hands were raised.

Any startup going global, working with government or heavyweight clients with tight data protocols would know that certifications like ISO and SOC 2 are essential.

But they’re not just nice-to-haves – they’re deal-breakers, according to Watson-Smith.

“Startups often come to me and say, ‘Hey, we’ve got product-market fit. We have this excellent product and a customer we’re about to sell to. We’re about to sign on the dotted line. And then they said to us, ‘Where’s your SOC 2? Where’s your ISO?’ And it prevents them from closing a deal,” he said.

“So they come to us in a bit of a tizz sometimes and they need help immediately to prove that they are compliant in order to win some sort of larger business.”

Rapid-fire summary of ISO and SOC 2

ISO stands for the International Organization for Standardization, a global federation of national standards bodies.

One of the most common standards you’ll see is ISO 27001 for information security management and customer data privacy protection. This must be verified by a third-party auditor, and often requires action across different parts of a business, from leadership to HR to IT.

SOC 2, which stands for Service Organization Control Type 2, is an information security compliance framework created by the American Institute of Certified Public Accountants (AICPA). Widely used across the US and the SaaS industry, SOC 2 helps organisations verify their security and reduce the risk of a breach.

The wheels of compliance move slowly

At least, traditionally they do. For startups used to working at speed, the compliance process can grind progress to a halt.

“It can take anywhere between six to 24 months, particularly for ISO and SOC 2, but there’s a lot more frameworks than that,” explained Watson-Smith.

“And it’s a lot of multiple steps like researching… you’re going to need guidance. You’re probably going to have to bring a consultant or an auditor or a virtual CSO to help you in getting ready for this audit.

“Then you’ve got the actual audit costs, which can be extremely expensive, especially if they have to go through a lot of manual evidence that’s in disparate locations.

“Then we have the evidence gathering, putting it all together, and in the end, you’ve spent a lot of valuable time on something that isn’t very interesting or exciting, but it’s very important for you to be able to generate revenue for your business.”

Startups need faster action

Watson-Smith explained that a lack of certifications is a “common blocker” to startup growth.

The time and expertise needed to prove you’re compliant is onerous, which is why automated compliance platforms like Vanta have seen a surge in popularity.

“We’ve reduced that timeline from 24 months to anywhere between one to six months,” he said.

Founded in the wake of high-profile data breaches back in 2018, the San Francisco-based security and compliance-based platform has rapidly attracted more than 8000 companies to use it services, including Atlassian, Quora and ZoomInfo.

In July 2024, Sequoia Capital-backed Vanta announced its $150 million Series C funding, raising it to a $2.45 billion valuation – up from its $1.6 billion valuation in 2022.

Vanta has a Sydney office of 30 staff, including Watson-Smith.

“We test, we remediate, we get you audit ready, we get you through the audit, and then we make sure that you stay compliant when you’re outside of that audit window,” he said.

“So when the next one comes around, it’s really easy for you to just bang it out very quickly.”

Security and compliance are a long game

Watson-Smith pinpointed two key factors that benefit startups playing a long game: integrations into a single platform and the process of continuous compliance.

Vanta’s API accommodates more than 360 integrations with everything from AWS to Xero.

“We run these [API checks] once an hour and that’s where that continuous compliance comes in because we can keep checking if you’re compliant,” he explained.

“If you spin up a new instance, a new database, for example, and someone forgot to put an IP range restriction on it, we’re going to notify you immediately that you’re now out of compliance.”

Startups can access Vanta’s Trust Center every day to see their security postures and controls at any given moment.

“If have a really specific security questionnaire they want answered, we can actually automate the answering of them with all the information we have about your organisation in the platform using Gen AI,” he said.

“So we plug the questionnaire in and we answer all the questions for you, and then you can just vet that the answers are correct. And we’re using your compliance documents as that source of truth.”

Watson-Smith told Startup Daily that when global sales and marketing platform ZoomInfo implemented their security questionnaire automation and Trust Center, they reduced the amount of questions they had to answer manually by around 90%.

In Oscar’s own words below:

 

Keep an eye out for more highlights from Unicorn Day, which included fireside chats with Zeller CEO Ben Pfisterer, Canva Head of Design Andrew Green and former Aconex founder turned Saniel Ventures CEO Leigh Jasper.

Make sure to sign up to the Startup Daily newsletter for updates on our next events.


This article is brought to you by Startup Daily, supported by Vanta.

Previous article Breakthrough Victoria posts $3 million loss
Next article Kiwi scaleup Crimson Education swots up on NZ$67 million Series D
Via Cyber security
Tags analysisCompliancecybersecuritydata securityscaling
Adam Bub

Adam Bub is the Head of Commercial Media at SmartCo Media (formerly Pinstripe Media), managing digital and TV partner content for Business Builders, Startup Daily, SmartCompany, Flying Solo and Your Money & Your Life. Previously an editor at Nine Digital and Mamamia, Adam is a strategic storyteller who loves creating value for audiences and brands. Adam has led content-driven media campaigns for 100s of global and local brands, including IKEA, Amazon and Dell Technologies. Adam interviews entrepreneurs on the Business Builders podcast First Act.

Share This
  • COMMENTS
SUBSCRIBE TO StartupDaily

Daily startup news and insights, delivered to your inbox.

  • We'll sometimes send messages from our partners. You can opt-out anytime.

Latest News

Ticker, shares, investor Advice Why your investor updates are not working
Scott Handsaker - January 23, 2026
Funding Cheque-in: four ANZ startups raised $307.1 million in mid-January
Tegan Jones - January 23, 2026
Business A software engineer fired after refusing to return to the office 3 days a week lost his unfair dismissal claim
Denham Sadler, Information Age - January 23, 2026
Food and drink Get into Clare Valley wines with a new podcast on the people making them
Startup Daily - January 23, 2026
Business Financial crimes regulator AUSTRAC demands an external auditor for Airwallex over AML/CTF concerns
Simon Thomsen - January 22, 2026
Opinion Founder memo: No, Australian startup media doesn’t work like Men in Black
Simon Thomsen - January 22, 2026
Business Sendle staff were worried about its US plans before the parcel logistics platform collapsed
David Adams - January 22, 2026
AI/Machine Learning Paladin backs AI security startup Dam Secure’s $6.1 million Seed round
Simon Thomsen - January 21, 2026

Copyright 2025 Pinstripe Media - Digital Publishing and Video Production Agency Sydney ABOUT US / CONTACT | ADVERTISE

Loading
Loading
Loading