That's true, but lot of startups actually die before they become enterprises. That implies your churn might be high. You might be in a situation where you allocated support resources for an org that runs out of money.
Also, I think the pricing is very low. For $2.5 per user, for an org of 100 users, ACV is $3000, that implies for a 1M ARR, you need around ~340 SMBs, which I think is possible but it is on the higher side and it is lot of effort. You are pricing implies Bottoms up, But for adoption you need the whole org's buys in which I think does align at scale. Just to put things to perspective, smaller orgs (20-50) pays $5000-$6000 to drata, vanta and others for SOC2/Compliance.
Again from customer point view it is cheap and great but economics may not workout.
Just food for thought. I wish you success.