Yes, the type of company and type/quantity of data will affect the requirement.
Geography also is a big factor here.
In general I am seeing companies needing GDPR/CCPA or similar first, followed by ISO27001 (which covers most of the security questionnaires), and then SOC2.
Specialized ones will depend on industry and country of service: HIPAA, FCA, etc.