September 11 is coming up fast, and I've had the same conversation with four different founders this month: "does the Cyber Resilience Act apply to us?" Every one of them assumed yes. Two of them were wrong.
I run penetration testing and AI red teaming for SaaS companies at Faultline Security, so this is squarely in my lane, and I wanted to write the honest version of this instead of the vendor version, because the vendor version says "everyone is in scope" and that's just not accurate.
What's actually happening on September 11
The CRA's reporting obligations become enforceable. If you're a manufacturer of a "product with digital elements," you now have to report actively exploited vulnerabilities and severe security incidents through a single platform, on a real clock: 24 hours for the early warning, 72 hours for a fuller notification, then a final report within 14 days (vulnerabilities) or a month (severe incidents). Fines for getting reporting wrong run up to 15M or 2.5% of global turnover.
Microsoft announced two new security products at a small San Francisco event yesterday: MAI-Cyber-1-Flash, the company's first cybersecurity-specialized AI model, and Perception, an agentic security platform that deploys teams of AI agents to find and fix vulnerabilities.
The preview opens November 3. That's the useful clock.
What the two products do
MAI-Cyber-1-Flash is built specifically for finding vulnerabilities in complex codebases. It powers MDASH, Microsoft's harness for software vulnerability identification and remediation.
SOC 2 is the right starting point for most SaaS startups selling to US-based businesses. ISO 27001 becomes relevant when you are selling to enterprise customers in Europe, the UK, or regulated industries that specifically require it. You rarely need both at the same stage, and choosing the wrong one wastes significant time and money.
TL;DR SOC 2 is the US standard, faster to achieve (3 to 9 months for Type I or II), and what most US SaaS buyers ask for. ISO 27001 is the international standard, more rigorous, takes longer (9 to 18 months), and is expected by European enterprise buyers and regulated industries. Start with SOC 2 unless your primary market or a specific large customer requires ISO 27001. Both frameworks expect penetration testing in a complete program. One engagement from 3,000 can often support both if the same systems are in scope for your SOC 2 and ISO work (the SOC 2 in-scope system and the ISO 27001 ISMS boundary are not always identical, so align this with your auditors in scoping).
What Is SOC 2?
SOC 2 (System and Organization Controls 2) is a security audit framework developed by the American Institute of Certified Public Accountants (AICPA). It is not a certification but an audit report, produced by an independent CPA firm, that attests to whether your security controls meet the Trust Services Criteria.