What security investors check at seed and Series A (UK)
What security due diligence looks like for UK startups at seed and Series A, why customers ask before investors do, and the nine things to sort first.

Stabilise

Security due diligence for UK startups isn't a standard checklist yet. At seed, investors mostly check the legal basics: company records, IP assignment, the cap table. The security questions tend to arrive first from customers, as a questionnaire or a request for Cyber Essentials before they sign. By Series A, both sides ask.
The good news is that the answers overlap almost completely. MFA everywhere, company devices under management, patching you can evidence, access you can review, and a couple of written policies cover most of what investors and customers want to see. Get those in place before a data room exists, not while it's being built.
That's the short version. Here is the detail, including the nine things to sort first.
What investors check at seed
Less than founders fear. Y Combinator publishes its Series A diligence checklist (opens in a new tab), and it's worth a look for what isn't on it. Corporate records, IP assignment, the cap table, employee agreements and litigation are all there. MFA, backups, pen tests and SOC 2 aren't.
That's typical of legal diligence, which is a separate track from security diligence. The legal track is well established. The security track is newer and far less standardised, and nobody in the UK has published a definitive seed-versus-Series-A security checklist that we could find.
So at seed, expect a few questions rather than an audit. The ones that come up are predictable: do you use MFA, who has admin access, and has anything gone wrong.
Why customers ask before investors do
For most startups selling to other businesses, the first serious security questions come from a buyer, not a board.
UK government has asked since 2014. Procurement Policy Note 09/14 made Cyber Essentials a requirement for central government contracts involving personal data or government information. Its replacements, PPN 09/23 (opens in a new tab) and then PPN 014 from February 2025, keep the requirement while telling buyers to apply it proportionately.
Large companies ask their suppliers too. Banks, insurers and big corporates often pass Cyber Essentials, or their own questionnaires, down their supply chains. A 20-person startup selling into a bank will meet a security questionnaire long before a Series A.
US buyers ask for SOC 2. If your pipeline is mostly American enterprise, SOC 2 is the report procurement teams expect. ISO 27001 is more familiar to UK and European buyers.
Cyber Essentials got stricter in April 2026
If Cyber Essentials is your first certificate, the rules changed this year. Version 3.3 of the requirements applies to assessments registered after 26 April 2026, with a six-month window for anyone who started before.
MFA on cloud services is now non-negotiable. The requirements document (opens in a new tab) says authentication to cloud services "must always use MFA". IASME, which runs the scheme, confirms that not having it where it's available is now an automatic fail (opens in a new tab) of the whole assessment.
Patching has a 14-day clock. Updates that fix critical or high-risk vulnerabilities, or anything scoring 7 or above on CVSS, must be applied within 14 days of release. Missing that is also an automatic fail.
Cloud services can't be left out of scope. Your Google Workspace or Microsoft 365, and the SaaS tools your team signs into, are part of the assessment.
We covered the full changes in our Cyber Essentials v3.3 guide. For a startup, the takeaway is simple: the controls Cyber Essentials now insists on are the same ones investors and SOC 2 auditors look for, so it's a sensible first step either way.
What changes at Series A
At Series A the questions get specific, and some investors bring in technical due diligence. From UK technical-DD guidance and law firm advice, the recurring themes are:
- Access control, enforced consistently. Who has access to what, how it's granted and removed, and who holds admin rights. Orrick's founder guidance (opens in a new tab) specifically recommends MFA and auditing privileged accounts.
- Data protection. Where customer data lives, whether it's encrypted, and whether your UK GDPR responsibilities are written down, including agreements with the processors you use.
- An incident record. A register of incidents and known vulnerabilities, even if it's short. An empty register you can show beats a vague "nothing's happened".
- Written policies. An access control policy and a security policy that match what you really do.
- IP and code. Assignment agreements for everyone who has written code, and awareness of the open-source licences you depend on.
None of this needs a security team. It needs the basics running properly and a paper trail that proves it.
A breach is the expensive way to learn this
In March 2026, Mercor, an AI data startup valued at $10 billion after a $350 million Series C, disclosed a breach linked to a compromised open-source tool. Within days, Meta had paused its contracts (opens in a new tab) with the company, according to TechCrunch.
Most startups will never be in the headlines. But the pattern is the one that matters: customers react to a security failure faster than any investor does, and contracts are the first thing to go.
SOC 2 and ISO 27001: when, and how long
Don't start either because it sounds grown-up. Start when a customer or investor asks, or when you can see it coming in your pipeline.
SOC 2 timelines, from a vendor. Vanta, which sells compliance software, puts a SOC 2 Type I (opens in a new tab) at three to five months from a standing start, or 10 to 12 weeks if basic controls are already in place. A Type II needs an observation period of at least three months on top. Vendor estimates, so read them as a rough guide.
The overlap is the useful bit. SOC 2 and ISO 27001 share most of their technical controls. Get MFA, device management, patching, access reviews and logging working properly, and you've done the hard part of either.
The nine things to sort first
In order, roughly by how often they come up:
- MFA on every cloud service. Email, admin consoles, code repositories, remote access. It's an automatic fail in Cyber Essentials now, and the first thing anyone asks.
- Every company Mac under device management. So you can prove disks are encrypted, updates are applied and a lost laptop can be locked.
- Patching within 14 days for critical and high-risk updates, with evidence.
- Admin rights kept to the people who need them, and reviewed.
- A leavers process that removes access. Cyber Essentials requires it and auditors check it. We've written a startup offboarding checklist for this.
- Cyber Essentials, or Cyber Essentials Plus, if you sell to UK government, the NHS or large companies.
- A short incident and vulnerability register.
- An access control policy and a data protection policy that describe what you really do.
- IP assignment signed by everyone who has written code or content for you.
How we help
We're Cyber Essentials Plus certified ourselves, and getting startups through their first questionnaire, Cyber Essentials, Plus, and then ready for SOC 2 or ISO 27001 audits is a big part of what we do. We rolled out phishing-resistant MFA across 196 identities at one AI startup in under two weeks, and the evidence from work like that is exactly what a data room needs.
If you'd rather have the basics running before anyone asks, that's what our IT support for startups is built around.
Frequently asked questions
- Do investors ask about security at seed stage?
- Lightly, if at all. Seed diligence is mostly legal: company records, IP assignment, the cap table and employment contracts. The security questions usually arrive first from customers, when an enterprise buyer sends a security questionnaire or asks for Cyber Essentials before signing. By Series A the questions come from both sides, and a data room without any security evidence stands out.
- Do UK startups need Cyber Essentials?
- It is not a legal requirement, but UK central government contracts that handle personal data or government information have required it since 2014, and large companies often ask their suppliers for it. For a startup selling to UK enterprise or the public sector it is usually the first certificate worth getting, because it is quick and inexpensive compared with SOC 2 or ISO 27001.
- Should a UK startup get SOC 2 or ISO 27001?
- It depends on who you sell to. SOC 2 is what US enterprise buyers tend to ask for; ISO 27001 is more familiar to UK and European buyers. Many of the controls overlap, so the second one is less work once you have the first. If you do not know yet, start with Cyber Essentials and the controls both frameworks share: MFA, managed devices, patching and access reviews.
- How long does SOC 2 take for a startup?
- Vanta, which sells compliance software, puts a SOC 2 Type I at roughly three to five months from a standing start, and a Type II at four to six months in total because it needs at least a three-month observation period. Treat those as vendor estimates. The work before the audit, getting controls in place and evidenced, is the part that decides the timeline.
- What is the single most important security control for due diligence?
- MFA on every cloud service. It is the control investors and customers ask about first, and since April 2026 Cyber Essentials treats missing MFA on a cloud service as an automatic fail. Close behind it: company devices under management, so you can prove they are encrypted, patched and recoverable.


