SOC 2 Type I · Legal/SecOps
Next: Engage AICPA firm; freeze Type I control set from evidence vault · ETA ~90d · Blocker: Independent auditor letter
Route5
Fortune 500 pathway
Fortune 500 standards = 100% product controls + 100% process pathway. Seals stay pathway until auditors/counsel sign.
Standards = every product control buyers can test, plus every process item with an owner, evidence template, request path, and ETA. Seals (SOC 2 / ISO / BAA / pentest PDFs) stay at 0% until real signed artifacts exist — we will not fake them. Becoming a Fortune 500 company also needs commercial scale; that path is listed below.
279/279
Product & hybrid controls built
19/19
Process pathway gates complete
8
External seal artifacts awaiting
None. Every product and hybrid control is built and testable.
Each gate is pathway-complete (owner · evidence · next action · ETA). Closing them raises seal percent — not standards percent.
SOC 2 Type I · Legal/SecOps
Next: Engage AICPA firm; freeze Type I control set from evidence vault · ETA ~90d · Blocker: Independent auditor letter
SOC 2 Type II · Legal/SecOps
Next: Start observation window after Type I; collect continuous evidence · ETA ~180d · Blocker: Observation period + auditor report
ISO 27001 · Legal/SecOps
Next: ISMS scope freeze; stage-1 readiness against control map · ETA ~180d · Blocker: Accredited certification body
ISO 27701 · Legal/Privacy
Next: Align PII inventory to ISO 27701 annex after 27001 path · ETA ~210d · Blocker: Accredited certification body
SCCs · Legal
Next: Counsel review of SCC annex; countersign with customer DPA · ETA ~30d · Blocker: Counsel countersignature
BAAs · Legal/Sales
Next: BAA packet under NDA for covered PHI deals only · ETA ~45d · Blocker: Executed BAA
Pentesting · SecOps
Next: Schedule third-party pentest against published scope · ETA ~60d · Blocker: Firm report PDF
TAM / CSM support · Sales/CS
Next: Name TAM/CSM on Enterprise order form · ETA ~14d · Blocker: Signed Enterprise order
Penetration test summary · SecOps
Next: Publish customer-safe summary after remediations close · ETA ~75d · Blocker: Firm-issued summary
Tax docs · Finance
Next: Issue W-9 / tax packet on procurement request · ETA ~5d · Blocker: Finance fulfillment
DUNS / business verification · Finance
Next: Provide DUNS / business verification IDs in vendor packet · ETA ~10d · Blocker: Registry confirmation
HR policy set · HR
Next: Adopt HR policy set from evidence pack; counsel review · ETA ~45d · Blocker: Internal HR adoption
Employee handbook basics · HR
Next: Publish employee handbook basics from template · ETA ~45d · Blocker: Internal HR adoption
Security awareness training · HR/SecOps
Next: Quarterly security awareness curriculum + completion log · ETA ~30d · Blocker: Training completions
Background checks for privileged staff · HR
Next: Background check vendor for privileged roles · ETA ~30d · Blocker: HR vendor process
Offboarding process · HR/IT
Next: Execute offboarding checklist; revoke via SCIM + sessions API · ETA ~14d · Blocker: Operational HR/IT cadence
Endpoint management for staff · IT
Next: Roll out endpoint baseline from HR/endpoint pack · ETA ~60d · Blocker: Staff device fleet
MDM · IT
Next: MDM enrollment for company devices · ETA ~60d · Blocker: MDM tenant + enrollment
Laptop encryption · IT
Next: FileVault/BitLocker policy enforcement via MDM · ETA ~45d · Blocker: MDM policy push
Close Enterprise MSA + order form with named TAM/CSM
Run SOC 2 Type I → Type II observation with auditor
Complete ISO 27001/27701 with accredited body when ready
Scale ARR / customers — Fortune 500 ranking is commercial, not a checkbox