" /> Virtual CISO for a London SaaS: SOC 2 + Cyber Essentials Plus | ITSECOPS
Case study

Virtual CISO for a London SaaS: SOC 2 Type 2 + Cyber Essentials Plus

Oppdatert · aug 2026 By ITSECOPS Gratis · Ingen påmelding

Case study · B2B SaaS · London, United Kingdom

A London SaaS scale-up selling into UK government and US enterprise needed Cyber Essentials Plus and SOC 2 Type 2 at the same time. An ITSECOPS virtual CISO ran both as one program — certification and attestation landed within the same quarter, and procurement blockers disappeared on both sides of the Atlantic.

City of London skyline — virtual CISO for a London SaaS scale-up

The client

A ~90-person B2B SaaS company in Shoreditch, London, selling workforce-management software. Growth had split into two motions with two different compliance gates: UK public-sector frameworks requiring Cyber Essentials Plus, and US enterprise buyers requiring SOC 2 Type 2. UK GDPR obligations ran underneath both.

The challenge

  • Two different assurance regimes (UK technical certification vs US audit attestation) pulling the same small platform team in different directions.
  • A previous SOC 2 attempt with a checkbox tool had stalled — controls existed on paper but nobody owned them.
  • G-Cloud listing review approaching, with Cyber Essentials Plus as a de facto requirement.
  • No security leadership; the CTO was fielding every customer security questionnaire personally.

What we did

  • Virtual CISO, 2 days/week — a single accountable security leader for board, buyers and auditors; remote-first with monthly on-site days in London.
  • Unified control set — Cyber Essentials Plus technical controls, SOC 2 Trust Services Criteria and UK GDPR mapped together; each control implemented once with shared evidence.
  • Technical uplift for CE+ — patching SLAs, hardened builds, MFA everywhere, malware protection and firewall rules brought to assessor-testable state; passed the CE+ audit including on-device testing.
  • SOC 2 Type 2 done properly — controls re-scoped to how the team actually operates, a 6-month observation window with automated evidence collection, auditor managed by the vCISO through fieldwork to a clean report.
  • Questionnaire machine — a maintained trust pack (policies, subprocessors, pen-test summary, certificates) that cut CTO time on security reviews by ~80%.
Leadership meeting — SOC 2 Type 2 and Cyber Essentials Plus program

Results

Metric Outcome
Cyber Essentials Plus Certified — first attempt
SOC 2 Type 2 Clean report after 6-month observation window
UK public-sector motion G-Cloud security gate cleared
US enterprise deals Security reviews closing in days, not months
CTO time on security questionnaires Down ~80% with the vCISO-owned trust pack

FAQ

Can one vCISO handle both UK and US compliance requirements?

Yes — that is the point of hiring a leader rather than a tool. Cyber Essentials Plus, SOC 2 and UK GDPR overlap far more than they differ; a vCISO builds one control set and presents it to each assessor in their own language. ITSECOPS vCISOs work across every region we operate.

Do London SaaS companies need SOC 2 or ISO 27001?

It depends on your buyers: US enterprises usually ask for SOC 2, while UK and EU enterprises lean ISO 27001. Both map onto the same underlying controls — many of our London clients do SOC 2 first for US revenue, then add ISO 27001 as largely evidence reuse.

How long does Cyber Essentials Plus take with a vCISO?

If the technical basics are close, 6–10 weeks including remediation and the assessor’s on-device testing. Run alongside a SOC 2 program, it adds little extra work because the technical controls are shared.

Selling into two markets with two compliance gates?

One virtual CISO, one control set — UK certification and US attestation from the same program.

BOOK A FREE CISO CONSULTATION

Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?

Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.

Bestill en konsultasjon