I worked for a telecomms/webcasting company for about 5 years as a product manager. I can tell you from personal experience that a significant portion of the Fortune 500 (if not all of them) required ISO 2700X certification to even be considered.
The certification burden increases in proportion to the level of PII you are storing. The burden was much higher for government or med/bio contracts (FedRAMP/HIPPA, etc.). It's also worth it to mention that we had whole teams dedicated to working through RFPs/RFCs as they can get VERY time consuming.
Bottom line is that if you are going to work with the big fish, you will probably need this level of certification to show them you are serious.