You are correct, in many ways even SOC2 is not a desirable investment for young companies. You can do 5 figure deals with fortune 500 companies without it but the process of closing that deal will require a lot more work. Maybe a good time to start investing in SOC2 or ISO certification is when you have multiple large deals with enterprises in your sales pipe. Before that, running a small security program (annual pentest, security awareness training) and communicating that via security questionnaires will get you first deals.
ISO 27001 and SOC2 are both very valuable ways to communicate your security posture to external partners and customers. Like others have mentioned this will allow you to close deals quicker and prevent a more costly outcome by navigating security reviews more quickly. Source of info: friends at https://pentestiq.com and https://vanta.com that handle security/compliance for many startups.
Sure: Mainly it means that Apple is struggling with their supply chain, which for a hardware manufacturer isn't great. But since this is a brand new product it doesn't impact current revenues, but it does impact outlook.
No, totally understand and that makes a lot of sense. I think there is a lot more to it when someone is looking to get a very professional logo/brand done. Thanks for writing this!