Enterprise clients put contracts on hold over security when their procurement or legal teams identify gaps between what a vendor claims and what they can prove. The most common triggers are missing certifications, incomplete documentation, or an inability to demonstrate that security practices are actively maintained rather than periodically reviewed. This article walks through the most important questions organisations face when a deal stalls over security, from how enterprise due diligence actually works to who is responsible for unblocking it. If you want to talk through your specific situation, feel free to get in touch with us and we will help you move forward.
What makes enterprise clients pause a contract over security?
Enterprise clients pause contracts over security when a vendor cannot provide sufficient evidence that their data, systems, or operations will be protected to an acceptable standard. This typically happens during procurement reviews, third-party risk assessments, or legal sign-off processes, where security gaps become visible for the first time. The pause is not always about a specific incident — it is often about the absence of proof that governance is real and ongoing.
The most frequent triggers include the lack of a recognised certification such as ISO 27001, incomplete or outdated security documentation, no clear data processing agreement, or an inability to answer detailed questionnaires about access controls, incident response, or subprocessor management. Enterprise procurement teams are increasingly systematic about this. They use standardised security questionnaires, and a vendor who cannot respond in full raises immediate concerns about operational maturity.
What makes this particularly frustrating for growing companies is that the security gap is often not technical — it is structural. The organisation may have reasonable practices in place, but those practices are not documented, assigned, or verifiable. From the enterprise client’s perspective, undocumented governance is the same as no governance. That is the core reason contracts stall: not incompetence, but invisibility.
How does enterprise security due diligence actually work?
Enterprise security due diligence is a structured review process that assesses whether a vendor’s security posture meets the buyer’s internal risk standards before a contract is signed. It typically involves a combination of questionnaires, document requests, and sometimes on-site or virtual assessments. The process is owned by the buyer’s procurement, legal, or information security function, and the vendor is expected to respond in full.
The questionnaire phase
Most enterprise buyers start with a standardised security questionnaire, often based on frameworks like SIG (Standardised Information Gathering) or a proprietary version. These questionnaires cover dozens of control areas including access management, encryption, business continuity, incident response, and supply chain security. Vendors who have maintained structured governance documentation can answer these quickly. Those who have not often spend weeks trying to compile responses from scratch.
The evidence and certification review
Beyond the questionnaire, enterprise clients typically request supporting evidence. This includes audit reports, certification certificates with valid dates, data processing agreements, and records of recent security reviews. If a vendor holds an ISO 27001 certificate, for example, the enterprise client will check whether it covers the relevant scope and whether it is current. A certificate that expired six months ago, or one that covers only a narrow part of the business, will not satisfy the review.
The process concludes with a risk rating. The enterprise client’s security team assigns the vendor a risk tier based on the data they will access and the adequacy of the vendor’s controls. If the risk rating is too high, the contract is paused until the vendor remediates specific gaps — or it is cancelled altogether.
Which security certifications do enterprise clients most commonly require?
The security certifications enterprise clients most commonly require are ISO 27001 for information security management, SOC 2 Type II for service organisations operating in North American markets, and increasingly ISO 42001 for organisations handling AI systems. For organisations operating in the EU, GDPR compliance documentation and NIS2 readiness are also frequently required alongside formal certifications.
ISO 27001 remains the most universally recognised certification in European enterprise procurement. It signals that an organisation has implemented a structured information security management system, had it independently audited, and maintains it through annual surveillance reviews. Enterprise clients trust it because the certification process is rigorous and the scope is clearly defined.
SOC 2 Type II is more common in deals involving US-headquartered enterprise clients or SaaS vendors serving North American markets. It evaluates security, availability, processing integrity, confidentiality, and privacy controls over a defined period, typically six to twelve months, which makes it a stronger signal than a point-in-time audit.
In 2026, AI governance certifications are becoming a new procurement requirement for vendors who use AI in their products or processes. ISO 42001 provides the framework for AI management systems, and enterprise clients subject to the EU AI Act are beginning to ask vendors for evidence of AI governance as part of their standard due diligence. Organisations that get ahead of this requirement now will avoid a new wave of contract delays in the near future.
What’s the difference between a one-off security audit and ongoing governance?
A one-off security audit is a point-in-time assessment that identifies gaps and produces a report. Ongoing governance is a permanent operational capability that keeps security controls active, documented, and verifiable at all times. The difference matters enormously in enterprise procurement: an audit tells you where you were; continuous governance demonstrates where you are.
Many organisations invest in a security audit to prepare for a certification or to respond to a specific client request. That is a reasonable starting point, but it creates a structural problem. The audit produces findings, some of which get remediated, and then the organisation moves on. Six months later, controls drift, responsibilities become unclear, and documentation falls out of date. When the next enterprise client asks for evidence, the organisation is back to square one.
Continuous governance prevents this cycle by treating security, privacy, and quality management as living systems rather than periodic projects. Roles are assigned and maintained, controls are monitored on an ongoing basis, and documentation is updated as the organisation changes. This is the model that enterprise clients are increasingly looking for, because it demonstrates that security is embedded in how the organisation operates, not bolted on when a deal requires it.
The practical distinction also shows up in certification cycles. ISO 27001 certification, for example, runs on a three-year cycle with annual surveillance audits. Organisations that only engage with governance around audit time consistently struggle with those surveillance audits. Organisations that maintain continuous governance through a structured service pass them with far less disruption and cost.
How long does it take to unblock an enterprise contract held over security?
Unblocking an enterprise contract held over security typically takes between four and sixteen weeks, depending on the nature of the gap. Documentation gaps and missing policies can often be resolved in two to four weeks. Certification gaps, where the enterprise client requires ISO 27001 or an equivalent, take significantly longer because the certification process itself requires an implementation period followed by an external audit.
The fastest resolutions happen when the vendor already has most of the governance infrastructure in place but lacks documentation or a formal certification. In those cases, a focused effort to structure and evidence existing controls can satisfy the enterprise client’s requirements within a few weeks. The vendor essentially needs to make visible what already exists.
The slowest resolutions happen when governance infrastructure is genuinely absent. Building an information security management system from scratch, implementing the required controls, and completing a certification audit is a process that realistically takes six to twelve months under normal conditions. Trying to compress that timeline to save a single deal is possible but expensive and risky — shortcuts taken under pressure tend to produce certifications that do not survive the first surveillance audit.
The most effective approach is to treat enterprise security readiness as a continuous state rather than a reactive sprint. Organisations that maintain structured governance year-round are never more than a few weeks away from satisfying any reasonable enterprise requirement, because the evidence already exists and the controls are already operational.
Who inside a company is responsible for fixing security blockers?
Responsibility for fixing security blockers sits with management, not the IT department. While technical teams play an important role in implementing controls, the governance gaps that cause enterprise contracts to stall are organisational and structural, not purely technical. Fixing them requires decisions about accountability, documentation, resource allocation, and risk ownership that only management can make.
In practice, the person who feels the pressure most acutely is usually the commercial lead or account executive whose deal is on hold. But that person rarely has the authority or the expertise to resolve the underlying issue. This creates a common and painful situation: the sales team is pushing for a fast fix, the IT team is unclear on what the enterprise client actually needs, and management has not yet recognised that the blocker is a governance problem rather than a technical one.
The resolution requires a clear owner at management level, typically a CISO, COO, or a designated information security officer, who has both the authority to make governance decisions and the accountability to see them through. In organisations that do not have that role filled internally, an external governance partner can take on that function and drive the remediation process with the necessary expertise and continuity.
What enterprise clients are ultimately assessing is whether management takes security seriously as an organisational responsibility. A vendor who can demonstrate that accountability is clearly assigned, maintained, and evidenced will consistently perform better in enterprise due diligence than one who treats security as a technical task delegated to a junior team member.
Security blockers in enterprise deals are almost always governance problems in disguise. The organisations that resolve them fastest, and stay unblocked permanently, are the ones that build governance into how they operate rather than treating it as a response to a crisis. If your organisation is facing a stalled contract or wants to get ahead of enterprise security requirements, contact us and we will help you build the governance foundation that keeps deals moving.
Frequently Asked Questions
Can we pass enterprise due diligence without a formal certification like ISO 27001?
It depends on the enterprise client and the sensitivity of the data involved. Some buyers will accept a well-documented security posture, a completed questionnaire, and a credible roadmap to certification as a temporary measure — particularly if the contract value justifies the risk exception. However, for regulated industries or deals involving personal or sensitive data, formal certification is increasingly non-negotiable. If you are regularly pursuing enterprise contracts, treating certification as optional is a short-term position that will cost you deals over time.
What should we do immediately when a contract is put on hold over security?
The first step is to get precise clarity on exactly what the enterprise client requires — not a general sense of concern, but a specific list of gaps, questions, or documents they need addressed. Ask for the security questionnaire responses that were flagged, the risk rating assigned, and any remediation conditions they have set. With that information, you can triage quickly: some gaps can be closed in days with the right documentation, while others will require a longer remediation plan that you communicate transparently to the client to keep the deal alive.
How do we handle a security questionnaire when we don't have formal documentation in place?
Do not guess or overstate your controls — enterprise security teams are experienced at spotting inconsistencies, and a misrepresentation discovered later can permanently damage the relationship. Instead, answer accurately based on what you actually have, and where gaps exist, note them alongside a concrete remediation timeline. A vendor who is honest about current gaps but demonstrates a structured plan to close them is far more credible than one whose answers are inconsistent or unverifiable. Use the questionnaire as a diagnostic tool to identify exactly what governance work needs to be prioritised.
What is a subprocessor, and why do enterprise clients ask about them?
A subprocessor is any third-party organisation that processes personal data on your behalf as part of delivering your service — for example, a cloud hosting provider, an analytics platform, or an email delivery service. Enterprise clients ask about subprocessors because under GDPR and similar frameworks, they are accountable for the entire data processing chain, not just the primary vendor. You should maintain an up-to-date subprocessor list, ensure each subprocessor has appropriate data processing agreements in place, and be prepared to share this documentation during due diligence.
If we're a small or early-stage company, is enterprise-grade security governance realistic for us?
Yes, and the earlier you build it, the cheaper and less disruptive it is. Enterprise-grade governance does not require a large security team — it requires clear ownership, documented policies, and controls that are proportionate to your actual risk profile. A small company with well-structured, consistently maintained governance will outperform a much larger company with ad hoc practices in enterprise due diligence. The key is to build governance into your operating model from the start rather than retrofitting it when a deal demands it.
How do we avoid landing in the same situation with the next enterprise client?
The most effective preventative measure is to treat your security posture as a continuous, auditable state rather than something you prepare for deal by deal. This means maintaining live documentation, assigning named owners to each control area, scheduling regular internal reviews, and keeping certifications current. Practically, this often involves either a dedicated internal resource or an external governance partner who ensures the programme does not drift between procurement cycles. Organisations that do this consistently find that enterprise due diligence becomes a competitive advantage rather than a recurring obstacle.
What is the difference between a Data Processing Agreement (DPA) and a security certification, and do we need both?
A Data Processing Agreement is a contractual document that defines how personal data is handled between two parties — it is a legal requirement under GDPR whenever a processor handles data on behalf of a controller. A security certification such as ISO 27001 is an independently audited attestation that your information security management practices meet a defined standard. They serve different purposes and enterprise clients typically require both: the DPA establishes legal accountability, while the certification provides operational assurance. Having one without the other will usually leave a gap in the due diligence review.
Related Articles
- What is the difference between governance policies and governance procedures?
- What is the difference between governance and risk management?
- How does a subscription-based governance model align with certification renewal cycles?
- What does a potential acquirer look for during security due diligence?
- What is the difference between proactive and reactive governance?