Insight

29 September 2026

SOC2 / ISO Buyer Insurance Questionnaire Pack for UK Startups

Read More

Insight

29 September 2026

SOC2 / ISO Buyer Insurance Questionnaire Pack for UK Startups

Read More

UK SaaS startups selling into buyers that require SOC 2 or ISO 27001 (or similar security attestations) often hit an insurance questionnaire pack — rows that ask which covers you hold, limits, insurers, and certificate evidence tied to the buyer’s security / compliance review. This page owns the SOC2 / ISO buyer insurance questionnaire pack for UK startups job. It is not a second MSA / vendor security questionnaire evidence page, not a second cyber product hub, not a second “when do I need cyber” timing page, not a second fundraising COI page, and not a second startup pack map.

Generic MSA / vendor security questionnaire certificates sit on MSA Security Questionnaire Insurance Evidence for UK Startups. Cyber timing is When UK startups need cyber insurance. Cyber product depth is Cyber Insurance UK. Fundraising data-room COIs are Fundraising Insurance Certificates for UK Startups. Pack map: Startup Insurance UK. Use those pages for MSA evidence, cyber timing/product, raise COIs, and the wider map. Use this page when the question is "our enterprise buyer’s SOC2 / ISO (or equivalent) security questionnaire includes insurance rows — what pack do we assemble?"

Meshed is an FCA-regulated UK broker. Mesh'd Limited trading as Meshed is authorised and regulated by the Financial Conduct Authority under firm reference number 1033248. We place commercial covers for UK limited companies, partnerships, and sole traders, from a panel of insurers. Broker fee is a flat 10%, with no admin add-ons. We do not invent "from £X a month" SOC2 questionnaire prices. Named customer quotes are off.

Why SOC2 / ISO buyers ask about insurance on the questionnaire

Security and compliance reviewers often treat insurance as a control neighbour, not the attestation itself. Founders and security leads worry about:

  • Questionnaire rows asking for cyber, PI / tech E&O, PL, EL (and sometimes crime) with named limits

  • Confusion between SOC2 / ISO evidence (auditor reports, policies, controls) and insurance certificates

  • Confusion with a generic MSA insurance schedule (contract exhibit) vs a security questionnaire insurance section

  • Buyers who want certificates before they accept your SOC2 Type II or ISO certificate as sufficient

  • Gaps when you have SOC2 controls but unbound or under-limited commercial covers

Those are related conversations — not the same product job. Do not assume the MSA evidence page or the cyber hub answers every SOC2/ISO buyer insurance questionnaire. Placement and evidence quality decide.

This page vs related hubs (do not confuse them)

Question

This page

MSA security questionnaire evidence

When UK startups need cyber

Cyber Insurance UK

Fundraising certificates

Startup Insurance UK

SOC2 / ISO buyer insurance questionnaire pack

Yes — owns that job

No — generic MSA / vendor pack

No — timing

No — product depth

No — raise COIs

Pack map only

MSA / vendor security questionnaire certificates

Link out

Yes — owns that job

Link out

Link out

Link out

Link out

When does enterprise / cyber become non-optional?

Link out

Link out

Yes — owns that job

Link out

Link out

Link out

How cyber insurance works as a product

Link out

Link out

Link out

Yes — owns that job

Link out

Link out

Fundraising / data-room COIs

Link out

Link out

Link out

Link out

Yes — owns that job

Link out

Full startup cover map

Link out

Link out

Link out

Link out

Link out

Yes — owns that job

If MSA Security Questionnaire Insurance Evidence for UK Startups mentions SOC2 in passing, that is context. This page owns the SOC2 / ISO buyer insurance questionnaire pack job.

When the SOC2 / ISO insurance questionnaire pack typically becomes relevant

  1. Buyer security review — questionnaire lists insurance next to SOC2 / ISO / Cyber Essentials rows

  2. Renewal of an enterprise customer — new security pack asks for refreshed certificates mapped to attestation year

  3. First SOC2 Type II or ISO 27001 — auditors finish controls; buyers still want commercial cover proof

  4. Limits mismatch — questionnaire names £Xm cyber / PI and your schedules are lower

  5. Multi-product ask — cyber + PI + PL + EL in one pack (do not upload one vague PDF)

What "belongs" depends on the buyer template. Some only want cyber + PI certificates; others name EL once you have staff and PL for on-site work.

What "good" looks like in a SOC2 / ISO insurance questionnaire pack

  1. Clear buyer template (SOC2 questionnaire extract, ISO supplier pack, or security portal rows)

  2. Current certificates and schedules for each named line

  3. Mapping note: which policy answers which questionnaire row (broker letter optional)

  4. Honest gap list if a limit is below the buyer’s ask (negotiate or place before upload)

  5. Keep attestation PDFs (SOC2 report, ISO certificate) separate from insurance PDFs

  6. Related jobs already live: MSA evidence, cyber timing, cyber hub — deep-link, do not clone

  7. Honest expectations: we cannot invent unbound certificates; named customer quotes stay off

Founders, sole traders, and early Ltds

Many SaaS teams are Ltds; some founders still operate early B2B sales as sole traders. Sole traders are in scope where the risk fits. If a buyer’s SOC2 / ISO questionnaire includes insurance rows, speak to us with the questionnaire extract and current certificates — we will say what we can place or evidence, and what we cannot.

What to send a broker before you chase the pack

  1. Companies House name and structure (or sole trader status)

  2. SOC2 / ISO / security questionnaire insurance rows (screenshot or extract)

  3. Any linked MSA insurance schedule (if separate)

  4. Current certificates / schedules

  5. Target upload / go-live date

  6. Headcount and one-line product description

  7. Whether the buyer wants additional insured, cancellation notice, or wording extracts

How Meshed helps

We advise UK SaaS startups on how SOC2 / ISO buyer insurance questionnaire packs sit relative to MSA vendor evidence, cyber timing, and the cyber product hub, and we place or evidence cover from a panel where the risk fits. Mesh'd Limited trading as Meshed is authorised and regulated by the Financial Conduct Authority under firm reference number 1033248. Broker fee is a flat 10%, with no admin add-ons. We do not invent monthly "from £" SOC2 questionnaire prices. Named customer quotes are off.

What to send: questionnaire insurance rows, current covers, structure, upload date.

MSA evidence: MSA Security Questionnaire Insurance Evidence for UK Startups. Cyber timing: When UK startups need cyber insurance. Cyber product: Cyber Insurance UK. Pack map: Startup Insurance UK. Then speak to us with the questionnaire.

Mesh'd Limited t/a Meshed / Meshed Cover · FCA FRN 1033248 · flat 10% broker fee · Ltd, partnerships, and sole traders · no fake prices · Speak to us

FAQs

What is a SOC2 / ISO buyer insurance questionnaire pack?

It is the set of certificates, schedules, and mapping notes a UK SaaS startup uploads when an enterprise buyer’s SOC2 / ISO (or equivalent) security questionnaire includes insurance rows. This page owns that pack job.

Is this the same as MSA security questionnaire insurance evidence?

Not the same job. MSA Security Questionnaire Insurance Evidence for UK Startups owns the generic MSA / vendor evidence pack. This page owns the SOC2 / ISO buyer questionnaire insurance pack.

Is this the same as "when do I need cyber"?

No. When UK startups need cyber insurance owns timing. Product depth is Cyber Insurance UK. The questionnaire pack is owned here.

Do we upload the SOC2 report in the same folder as insurance PDFs?

Usually keep attestation documents and insurance certificates clearly separated — different questionnaire rows, different evidence. Do not rely on a SOC2 report alone to answer insurance limit questions.

Are sole traders and founders in scope?

Yes for placement where the risk fits. Speak to us about your structure and the buyer’s questionnaire.

Will you quote a "from £X a month" SOC2 insurance price?

No. Premium depends on covers, activities, headcount, and underwriting. We place from a panel at a flat 10% broker fee and will not invent a marketing price. Named customer quotes are off.

Are you an insurer?

No. Meshed is a broker. Mesh'd Limited trading as Meshed is authorised and regulated by the Financial Conduct Authority under firm reference number 1033248.

Vincent Liu

Co-founder & CTO