Case study · B2B SaaS · London, United Kingdom
A London SaaS scale-up selling into UK government and US enterprise needed Cyber Essentials Plus and SOC 2 Type 2 at the same time. An ITSECOPS virtual CISO ran both as one program — certification and attestation landed within the same quarter, and procurement blockers disappeared on both sides of the Atlantic.

The client
A ~90-person B2B SaaS company in Shoreditch, London, selling workforce-management software. Growth had split into two motions with two different compliance gates: UK public-sector frameworks requiring Cyber Essentials Plus, and US enterprise buyers requiring SOC 2 Type 2. UK GDPR obligations ran underneath both.
The challenge
- Two different assurance regimes (UK technical certification vs US audit attestation) pulling the same small platform team in different directions.
- A previous SOC 2 attempt with a checkbox tool had stalled — controls existed on paper but nobody owned them.
- G-Cloud listing review approaching, with Cyber Essentials Plus as a de facto requirement.
- No security leadership; the CTO was fielding every customer security questionnaire personally.
What we did
- Virtual CISO, 2 days/week — a single accountable security leader for board, buyers and auditors; remote-first with monthly on-site days in London.
- Unified control set — Cyber Essentials Plus technical controls, SOC 2 Trust Services Criteria and UK GDPR mapped together; each control implemented once with shared evidence.
- Technical uplift for CE+ — patching SLAs, hardened builds, MFA everywhere, malware protection and firewall rules brought to assessor-testable state; passed the CE+ audit including on-device testing.
- SOC 2 Type 2 done properly — controls re-scoped to how the team actually operates, a 6-month observation window with automated evidence collection, auditor managed by the vCISO through fieldwork to a clean report.
- Questionnaire machine — a maintained trust pack (policies, subprocessors, pen-test summary, certificates) that cut CTO time on security reviews by ~80%.

Results
| Metric | Outcome |
|---|---|
| Cyber Essentials Plus | Certified — first attempt |
| SOC 2 Type 2 | Clean report after 6-month observation window |
| UK public-sector motion | G-Cloud security gate cleared |
| US enterprise deals | Security reviews closing in days, not months |
| CTO time on security questionnaires | Down ~80% with the vCISO-owned trust pack |
FAQ
Can one vCISO handle both UK and US compliance requirements?
Yes — that is the point of hiring a leader rather than a tool. Cyber Essentials Plus, SOC 2 and UK GDPR overlap far more than they differ; a vCISO builds one control set and presents it to each assessor in their own language. ITSECOPS vCISOs work across every region we operate.
Do London SaaS companies need SOC 2 or ISO 27001?
It depends on your buyers: US enterprises usually ask for SOC 2, while UK and EU enterprises lean ISO 27001. Both map onto the same underlying controls — many of our London clients do SOC 2 first for US revenue, then add ISO 27001 as largely evidence reuse.
How long does Cyber Essentials Plus take with a vCISO?
If the technical basics are close, 6–10 weeks including remediation and the assessor’s on-device testing. Run alongside a SOC 2 program, it adds little extra work because the technical controls are shared.
Selling into two markets with two compliance gates?
One virtual CISO, one control set — UK certification and US attestation from the same program.