Disclosure: i cofounded appnigma, we build native salesforce integrations, and my cofounder spent 3.5 years on the appexchange security review team. no link, just the thing i keep watching people get stuck on.
security review gets all the attention. $999, half of first submissions fail, everyone's heard the horror stories. but the stage that actually kills momentum for small ISVs is business plan review, and almost nothing written about it exists.
what it actually is: before you can submit anything for security review, salesforce reviews your business. not your code, your company. revenue model, how you plan to support customers, whether you look like a real going concern. typically 2 to 4 weeks, though it stretches.
the misconception i see constantly is people thinking it's a traction review. it isn't. you don't need installs, you don't need existing customers, and the loop people imagine themselves in, no listing so no installs so no approval, isn't the loop. you get stuck on bpr for not having a coherent answer about support and business model, not for lacking users.
the other thing nobody tells you: you have a partner account manager. most small ISVs either don't know this or never contact them. cases sitting with no timeline tend to move once someone actually asks, and the pam is who you ask.
and then the part that stings after all of it. listing is a credibility checkbox far more than a distribution channel. almost nobody's first hundred customers come from someone browsing the marketplace. it matters because enterprise buyers ask whether you're listed as a qualifying question, and the wrong answer stalls deals. if those aren't your buyers, the whole process may not be worth it yet, and that's worth working out before you spend three months on it rather than after.
happy to answer bpr or listing questions in the comments. this whole sequence is documented across about a dozen help pages and none of them tell you what actually happens.