
IT security for software and technology companies
The customer's security questionnaire decides the deal, not the product. Where we start at software and technology companies.
The situation
In software and IT companies, security is first of all a sales topic. The customer's questionnaire arrives before the contract, and anyone who cannot show an ISO 27001 certificate in a tender is filtered out in pre-qualification without ever presenting.
Internally, security is still nobody's full-time job. The CTO answers the questionnaires personally, because nobody else knows the answers. Those hours are missing from the product and they are the most expensive in the company.
On top of that comes the security debt from growth. Access, environments and the separation of development and production grew with the team, without anyone ever reorganising them. What was pragmatic with five engineers is a finding with thirty.
And customers now ask specifically about AI: which models are in the product, which data goes in and what happens to it. Without an answer to that you lose time in the sales process.
What we find in this industry
- The questionnaire is the real obstacle to the saleIt is not the feature that decides, it is whether you can evidence access control, backup, incident response and supplier management. The customer is assessing your security management, not your roadmap.
- Without a certificate you are not even invitedIn many tenders ISO 27001 is an admission criterion, not a scoring question. That hits providers whose product would objectively be better.
- Security work eats development timeEvery questionnaire ties up senior engineers for days. That time is missing from the product and it is the most expensive in the company. The effort repeats from scratch on every deal.
- Fast growth, accumulated security debtAccess, environments and the separation of development and production grew with the team. Nobody reorganised them, because there was never an occasion to.
- Customer data in the cloud, responsibility split unclearlyBetween the hosting provider, your own operations and the customer runs a line that is rarely documented cleanly. That is the first thing auditors ask about.
- AI in the product and in daily development, without rulesWhat may go into models and assistants and what may not is rarely defined. Customers now ask about it directly, and the answer belongs in the contract, not in a conversation.
Typical trigger
An enterprise deal is stuck in vendor review and the customer wants evidence rather than assurances. Or a tender names ISO 27001 as an admission criterion.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.
Why these services fit
The questionnaire becomes a certificate
We build a lean ISMS and take you to certification without loading a process apparatus onto the engineering team. The scope is cut so that it covers the sale rather than burdening the whole company.
The sales cycle shortens because vendor review no longer starts from zero on every deal.
Someone who holds up in the customer's security review
Where it helps, we sit in the vendor review and answer the technical follow-up questions with the necessary experience.
Your engineers stay in engineering, and the customer gets a counterpart who speaks their language.
Rules for AI that do not slow your team down
We define which data may go into which models, how customer data stays protected, and how that is documented towards customers.
On request as a management system to ISO/IEC 42001, when customers want the formal proof.
Make the security debt visible and pay it down in order
We measure maturity and surface what growth left behind, from access rights to the separation of environments.
That becomes an order of work matched to your development pace, rather than a report nobody implements.
Who it is for
- Software and SaaS providers with enterprise customers
- IT service providers who have to pass vendor reviews
- Growth companies with accumulated security debt
- Providers using AI in the product who are being asked about it
Related engagements
- Zero-Trust cybersecurity programme across all of IT
- Privileged Identity and Access Management with Entra ID
- Cybersecurity strategy and governance from a maturity assessment
Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.
FAQ
How long does ISO 27001 certification take?
Depending on the starting point and scope, usually nine to eighteen months. For sales an earlier point matters more: once the evidence is built you can answer customer questionnaires, even before the certificate arrives.
Is SOC 2 enough instead of ISO 27001?
That depends on your customer base. The European market usually asks for ISO 27001, US business tends towards SOC 2. If you serve both, it makes sense to build one system that carries both.
Will an ISMS slow our engineering down?
Only if the scope is cut wrongly. An ISMS that covers the sale and touches engineering at a few defined points costs less time than the questionnaires it replaces.
Our customers ask about AI in the product. What do they expect?
Usually three things: which data goes into which models, where processing happens, and how you control it. That can be recorded properly once and reused in every sales process afterwards.
Let us talk about your situation
Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.

