Articles tagged: SaaS
13 articles on SaaS from the Top Floor insights library.
2026-08-25
How Long Does a Customer Security Review Take?
From the seller's side, a customer security review takes as long as the buyer's process plus your own response latency, and only the second half is yours to move. The reviews that stall are rarely stalled by a missing control.
2026-08-23
Does HIPAA Apply to My Health App?
For most direct-to-consumer health apps the answer is no, and founders treat that as good news. It usually is not: falling outside HIPAA drops you into the FTC's Health Breach Notification Rule, which has no risk-assessment off-ramp.
2026-08-22
SAQ A Got Stricter by Getting Shorter
The Council removed three requirements from SAQ A and added an eligibility criterion in their place. Iframe merchants now have to confirm something before they may use the questionnaire at all. Redirect merchants do not.
2026-08-20
How Much Does GDPR Compliance Cost a US Company?
The most-quoted GDPR cost figure is USD 1.7 million a year for a small business, and it is from 2018. We price the line items you can actually buy at published rates, work the arithmetic, and land somewhere very different.
2026-08-20
Cloud Penetration Testing: What AWS, Azure, and GCP Allow
None of the three major providers require pre-approval to test your own resources, and all three prohibit denial-of-service testing. The harder question is scope: a network test pointed at cloud IP addresses misses the risks that are actually cloud risks.
2026-08-20
How to Answer the AI Questions on Security Questionnaires
Enterprise reviewers ask three AI questions, and you do not need a certificate to clear them. Four documented artifacts do most of the work: an AI policy, an AI system inventory, a sub-processor list that names your model providers, and a written framework alignment statement.
2026-08-16
Does the EU Cyber Resilience Act Apply to Your Product?
If you place hardware or software on the EU market and it connects to anything, assume yes and work backwards. The scoping traps are remote data processing, the Annex III important classes, and products already on the market.
2026-08-16
What the EU Cyber Resilience Act Requires in an SBOM
Annex I Part II makes a machine-readable software bill of materials a legal requirement, with top-level dependencies as the floor. It is documentation you hold and produce on request, not a file you publish.
2026-08-16
Do You Need a BAA? A Decision Guide for SaaS Vendors
If protected health information can sit on your systems, plan on signing one, even encrypted, even if you never look at it. HHS said so in the Omnibus preamble in 2013 and the conduit exception is narrower than almost everyone assumes.
2026-08-16
Which PCI SAQ Do You Need? A Decision Guide
Your SAQ follows how card data touches your systems, not how big you are. The Council publishes several, each with its own eligibility criteria, and the boundary between the two most common ones is an engineering decision on your checkout page.
2026-08-16
Do You Need PCI Compliance If You Use Stripe or Shopify?
Yes. Stripe's own documentation says PCI compliance is a shared responsibility that applies to both Stripe and your business, and that you must attest annually. Using a processor shrinks the obligation; it does not transfer it.
2026-08-16
Merchant or Service Provider? The PCI AOC Your Customers Want
A merchant accepts cards for its own goods. A service provider handles or can affect the security of card data on someone else's behalf. Many SaaS companies are both, and sending the wrong attestation is how a vendor review stalls.
2026-01-15
SOC 2 for Startups: What You Actually Need in 2026
Enterprise buyers increasingly require SOC 2 before signing contracts, and investors view it as a signal of operational maturity. This guide breaks down what startups actually need to know about SOC 2 in 2026, from choosing between Type I and Type II to avoiding the most common (and expensive) mistakes.