ISO 27001, G-Cloud and SOC 2: How to vet a sovereign cloud provider
A procurement officer at a mid-sized financial services firm spent six months last year negotiating with a cloud provider that turned out not to hold the certification it had implied in its sales deck. The contract collapsed during legal review. The firm lost the time, the provider lost the deal, and somewhere in the middle, a senior engineer learned the difference between "compliant with the principles of" and "audited to the standard of.".