Pipeline playbook

How to build new logo pipeline for SOC 2 readiness consulting

You are good at the work. The problem is that the companies who need you do not know they need you until a customer blocks a deal, and by then they are searching, not listening. This is how to find them in that window.

Who actually signs

Almost nobody who buys SOC 2 readiness work has a security leader. That is the point. At a company between 25 and 150 people, the person who signs is the CTO or the head of engineering, and at the small end it is often the CEO directly.

They are not buying compliance. They are buying the removal of a blocker on a deal that is already in their forecast. This changes everything about how you write to them. A message about frameworks and controls reaches someone who does not think about frameworks and controls. A message about the enterprise deal that just stalled reaches the person whose quarter depends on it.

The one sentence version

Your buyer is a technical founder who just discovered that a customer's procurement process is going to cost them six weeks, and who has no idea how much of that is avoidable.

The triggers, and where each one is visible

This niche has unusually good public signal, because the thing that creates demand also creates a press release. Six sources, in rough order of how well they convert.

  • Job posts that name SOC 2 as a requirement or a nice to have. Companies advertise for it months before they have it, and a posting that says 'help us achieve SOC 2' is a buying signal with a date on it. Check the company careers page and the major boards weekly.
  • A first enterprise or regulated logo announced. A press release about landing a bank, a hospital system or a Fortune 500 means a vendor security review has already happened or is about to. Company blog and news pages carry these.
  • A trust center or security page that does not exist yet. If a company sells to enterprise and has no /security page, they have not been through this. If the page exists but shows no report, they started and stalled.
  • Series A and Series B announcements. The round is what funds the move upmarket, and the move upmarket is what surfaces the requirement. Six to nine months after the round is the sweet spot.
  • A first security engineer or head of security req. The hire is often posted because someone was told to fix compliance and does not want to own it personally.
  • Compliance automation vendor customer directories. Companies that just adopted a tool but have no report yet are mid project and frequently stuck, because the tool collects evidence and does not write policy.

Two of those are stronger than the rest. The job post naming SOC 2 and the newly announced enterprise logo are both dated, both public, and both mean somebody at that company is already thinking about this. Start there and you will not need the other four for a while.

Qualify in sixty seconds

Most names that match a filter are not prospects. Four checks, all of which you can do from their website in a minute.

  • Do they sell to companies that run vendor security reviews? If their customers are all small businesses, nobody is going to ask.
  • Is there any evidence of a report already? A badge, a trust center, an audit firm mentioned. If yes, they are a renewal or an ISO 27001 conversation, not a readiness one.
  • Is there someone in house who would obviously own this? A VP of Security or a compliance team means you are selling into an existing function and competing differently.
  • Is the trigger dated within the last ninety days? A job post from March is a company that already solved it or gave up.

The angle that gets replies

Lead with the deal, not the framework. The structure that works is one observable fact about their company, one consequence they have not thought about yet, and one specific thing you would do about it. Short, and no attachment.

Three openers you can adapt

  • On a job post naming SOC 2"Saw the platform engineer post asking for SOC 2 experience. Worth knowing that the hire usually cannot start the clock, because the observation window depends on controls being live first. Most teams lose a month there. Happy to send the order I would run it in."
  • On a new enterprise logo"Congratulations on the announcement. Their vendor review usually lands about six weeks after signature, and the questionnaire asks for two things most teams at your stage do not have written down yet. Here is what they are, in case it saves you a scramble."
  • On a Series B with no security page"You raised in April and the site is now pointed at enterprise buyers. The first serious procurement team you meet will ask for a Type II, and the observation window means that is a calendar problem, not a budget one. Rough timeline attached to nothing, just the dates."

Notice what none of them do. None asks whether they are compliant. None offers a call. Each one gives away something small and true that they can check, which is what makes the reply happen.

What not to send

  • "Are you SOC 2 compliant?" They know the answer and the question tells them you know nothing about their situation.
  • A timeline promise like "SOC 2 in six weeks." Anyone who has been through it knows the observation window makes that impossible for a Type II, and you have just identified yourself as someone who has not.
  • Fear framing about breaches and fines. SOC 2 is not a regulation and there is no fine. Your buyer knows that even if the copywriter did not.
  • A capabilities deck. Nobody at a 60 person company opens a PDF from a stranger.

The objection you will hit

It is almost always the same one: we already bought a compliance automation tool, so we are covered.

The tool is real and it does genuinely useful work. It collects evidence, monitors controls and keeps the dashboard green. What it does not do is decide the scope of the audit, write policies that survive an auditor reading them closely, make the judgment calls where the framework is ambiguous, or manage the auditor relationship when a finding lands.

The answer is not to argue with the tool. It is to name the three decisions the tool cannot make for them and ask which of the three they have already made. Most have made none, and that is the conversation.

A second one shows up at the small end: no customer has asked us yet. That is a real objection and sometimes they are right. The honest answer is that the cost of starting early is spreading the same work over four months instead of six weeks, and the cost of starting late is a deal slipping a quarter. Say it that way and you will lose some of them, which is correct.

Deal shape

  • Readiness engagement: commonly $12K to $35K depending on scope and how much has to be built from nothing.
  • Cycle: short by consulting standards. Two to eight weeks from trigger to signature, because the demand is urgent when it exists at all.
  • Signer: the CTO, or the CEO below about 50 people. Finance is rarely involved at this size.
  • The audit itself is a separate purchase from a CPA firm, and independence rules mean you cannot be both. Say so early. It builds more trust than it costs.
  • Expansion: the annual renewal, then ISO 27001 for their first European buyer, HIPAA for their first health customer, penetration test coordination, and vendor questionnaire support as a retainer.

The renewal is the reason this niche rewards outbound more than it looks. A one time $20K engagement that becomes a $30K annual relationship changes what you can afford to spend to win it.

A cadence you can actually run

  • Once a week, pull new job posts naming SOC 2 and new enterprise logo announcements in the segments you serve. An hour, tops.
  • Qualify against the four checks. Expect to keep roughly half.
  • Write one message per account, from the trigger. Twenty accounts a week is plenty for a solo practice.
  • Three touches over two weeks, each carrying a different observation. Not three reminders of the first one.
  • Anyone who replies with a question gets a real answer and no calendar link in the first reply.
  • Anyone who says not yet goes into a ninety day list, because the trigger will come.

The whole program is about two hours a week. The reason most practices do not run it is not the two hours, it is that the two hours disappear the moment a client engagement starts.

The sending mechanics most people get wrong

Everything above is about who and what. This is about how, and it is where most outbound in this niche quietly dies. Seven rules. None of them are optional.

1.Three to five sentences. That is the whole email.

Your reader is on a phone between meetings. One observable fact about their company, one consequence they have not thought about, one specific thing you would do. Anything past five sentences is a memo, and memos get archived unread.

2.Lead with a technical differentiator that turns into a number.

The messages that work best name something concrete you do differently and translate it into time or money saved. In this niche the differentiator is almost always time. A control sequencing method that starts the observation window in week two instead of month three is worth stating as the number of weeks it saves. A policy set delivered as a versioned repository the auditor can read as a diff is worth stating as the number of auditor questions it removes.

Most services firms do not have a technical differentiator, and pretending to have one reads as exactly that. The substitute is a verticalized case study: a company like theirs, what you did, what happened, in one sentence. For SOC 2 the line is something like: a 40 person healthtech company, zero to Type II in five months, no security hire, first enterprise contract signed before the report was even issued. Three facts and an outcome, and every one of them checkable.

3.Ten to twenty emails a day per mailbox. Not a hundred.

Sender reputation is scored per mailbox and per sending domain. One inbox pushing a hundred cold emails a day looks like exactly what it is, and the penalty lands on the domain, which means it lands on your client correspondence too.

If the math says you need more volume, the answer is more mailboxes on more warmed sending domains, separate from the domain you invoice from. It is never more volume per mailbox. The cadence above, twenty accounts a week at three touches each, works out to about twelve emails a day, which one warmed mailbox can carry on its own. Double the accounts and you need a second mailbox before you need anything else.

4.Write ten versions of every step and test them.

Versions A through J, not A and B. Rotate subject lines and bodies. You learn which angle is actually working instead of guessing, and there is a second reason that matters more: identical bodies going out over and over is one of the patterns postmaster tools flag. Variation is a deliverability tool as much as a testing one.

Subject line seeds for this niche, each of which should become several variants: "the SOC 2 req", "your Acme announcement", "the observation window". Lower case, no punctuation tricks, and nothing that would look odd in a reply from a colleague.

5.Stop at three.

Most replies arrive on the first and second email. The third is already thin. Every touch past that raises the odds the whole thread gets classified as spam, and that classification follows the mailbox to the next person you write to. The long cadence is over. Three touches, each with something new in it, then leave them alone for ninety days.

6.Know what good looks like.

A one percent reply rate with a quarter of those replies positive is a healthy trigger based program. Anyone quoting you double digit reply rates is counting out of office messages or selling a course.

7.LinkedIn Sales Navigator is not optional.

Every other data source tells you who held a title at some point. Sales Navigator tells you who holds it today, because the person maintains it themselves. That is the difference between a three percent bounce rate and a fifteen percent one, and bounces are scored against the mailbox the same way spam complaints are. Verify the name there before anything goes out.

It is also the cheapest trigger detector you will own. The job change filter surfaces people who arrived in a role in the last ninety days, which is the moment they have budget and no incumbent. The posted recently filter surfaces companies talking about the exact problem you solve. Account lists with headcount growth alerts tell you who is scaling before the press release does. For this niche the saved search is headcount 25 to 150, titles CTO, VP Engineering, Head of Engineering and founder, with the job change alert on for those titles and a keyword alert on SOC 2 across job posts and company updates. That one search, checked weekly, replaces most of the trigger hunting described above.

Use it for the research and the verification, not for the message. InMail reply rates are a fraction of email, and the person who replies to a thoughtful email is the same person who ignores a connection request with a pitch attached. Pull the work email from a data provider once Navigator has confirmed the person is real and current.

None of this is specific to your niche. All of it is specific to whether anyone ever reads the angle you spent an hour getting right.

If you would rather not run it yourself

That is what we do. ExpertLayer runs this exact loop for expert led firms: the weekly trigger pull, the qualification, the angle per account, the sending, and the reply reading. You take the conversations.

The first step is free and it is the same research described above. Send us your website and we will come back with 10 companies that hit these triggers right now, with the date, the contact and the opening line for each.

Questions from people running this

Is cold outbound worth it when the buyer only moves once a deal is stuck?+

That is exactly why it works here. The trigger is public and dated, and the window between a security review landing and the founder searching for help is usually two or three weeks. Nobody else is writing to them in that window, because most compliance consultants wait for referrals.

How many accounts do I need in the pipeline?+

Fewer than in most niches. A readiness engagement is urgent and short cycle, so the constraint is finding companies inside the window rather than staying in front of a slow committee. Thirty to fifty trigger matched accounts a month keeps a solo practice busy.

Do I write to the CTO or to whoever owns security?+

Below roughly 150 people there is nobody who owns security, which is the whole reason they need you. Write to the CTO or the head of engineering. At the small end write to the CEO, because at a 30 person company the stalled deal is on their forecast.

Does mentioning a specific customer of theirs cross a line?+

Referencing a logo they announced publicly on their own site is fine and shows you did the work. Referencing something you learned privately, or naming a deal you have no public basis for, is not. Stay inside what they published.

Related

Start with 10 free targets.

Send us your website and the kind of customers you want. We come back with 10 bullseye prospects, why each one is relevant, and the outreach angle we would use. No charge, no obligation.

See how the review works