Usually it’s not the certification that will make or break a deal, at least in our case.
I've personally gone through certifying a company as SOC2 and it makes you realize how much you want your vendors to have SOC2 controls.
We have signed on a publicly-traded entity without having a SOC2 on hand. It's not impossible to make a deal happen if the customer really wants your product, and you can somehow prove to interested parties that you wont sink their ship in the process. We achieved this with technical deep-dive sessions which involved our customer's IT and security people. Being able to communicate with agility and think outside the box is a good way to get around red tape.
For us, the biggest thing our customers seem to be worried about is the continuity of our business relative to support of the product. Offering source code escrow through some 3rd party is a good way to help alleviate some of these types of concerns.
The article does a great job of cutting through all the noise.
Highlighting here because it is relevant: certification is about sales.
I’d only do it once you either:
1) you spend much more time filling out questionnaires than the time/investment needed to get certified (note, they’ll still ask you to fill out questionnaires though)
2) you want to go after companies that actually care about this (banking, government). Even then, these will have shortcuts through procurement that will lower requirements (ie: innovation projects, small ticket items)
Once you have 1 client in your target industry using your product, it is infinitely easier to get a 2nd client (assuming you can use the 1st as a positive reference).
SOC2 seems like an interview-time item if I were to try to put an analogy around it. Once you have a certain reputation and key players trust you, its a lot easier to navigate around regardless of your specific credentials.
Putting the things mentioned in the article in place will help a lot in answering to those questionnaires.