It is not legally mandatory in most jurisdictions, but many enterprise customers expect it. For SaaS providers handling sensitive or regulated data, ISO 27001 often becomes a competitive requirement.