Waiting that 12 months to really demonstrate you have a working security program with efficient controls really pays off. It's something I look for when doing vendor reviews and I assume others do the same.
I have all sorts of issues with Vanta/Drata "compliance as a service" tools, but adequate for something like this, at this point in time.
Most of my employment has been in the security auditing/testing space, and the difference between “bolting it on later” and “building it in from the start” is incredible from both a purely technical and a process standpoint.