Enquire Us

ISO 27001 vs SOC 2

ISO/IEC 27001 and SOC 2 are the two security assurance artefacts that customers ask for most often, and they are not the same kind of thing. ISO/IEC 27001 is a certifiable international standard published jointly by ISO and IEC; an accredited certification body audits an information security management system and issues a certificate. SOC 2 is an attestation examination performed by an independent licensed CPA firm under the attestation standards of the American Institute of Certified Public Accountants; the output is a report, not a certificate, and no accreditation body sits behind it.

What is ISO/IEC 27001?

ISO/IEC 27001:2022, the third edition, is titled Information security, cybersecurity and privacy protection, Information security management systems, Requirements. It specifies how to establish, implement, maintain and continually improve an information security management system.

  • Management system. Requirements covering context, leadership, planning, support, operation, performance evaluation and improvement, in ISO’s harmonised structure.
  • Annex A. 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. Applicability is decided by risk assessment and recorded in the Statement of Applicability.
  • Audit. A Stage 1 readiness review followed by a Stage 2 audit of the operating system, carried out by a certification body accredited by a national accreditation body.
  • Outcome. A certificate normally valid for three years, subject to annual surveillance audits, with recertification before expiry. A customer can verify it with the certification body and its accreditation body.

What is SOC 2?

SOC 2 is a report on controls at a service organisation relevant to security, availability, processing integrity, confidentiality or privacy. The engagement is an attestation examination, not an audit of a management system, and it must be performed by an independent licensed CPA firm under AICPA attestation standards.

  • Scope. Set by the Trust Services Categories selected. Security, the common criteria, is always included; availability, processing integrity, confidentiality and privacy are added where relevant to the service commitments made to customers.
  • Type 1. Reports on the description of the system and the suitability of the design of controls as at a specified date.
  • Type 2. Reports on design and on operating effectiveness throughout a specified period, commonly three to twelve months, and includes the tests performed and their results.
  • Outcome. A report containing the practitioner’s opinion and management’s description. There is no certificate, no accreditation and no public register. The customer reads the report itself.

ISO 27001 vs SOC 2 compared

AttributeISO/IEC 27001SOC 2
Type of assuranceCertification of a management systemAttestation examination reported on by a practitioner
Published or governed byISO and IEC jointlyAmerican Institute of Certified Public Accountants (AICPA)
Who performs the assessmentA certification body accredited by a national accreditation bodyAn independent licensed CPA firm
Assessment processStage 1 readiness review and Stage 2 auditA single examination covering a specified date or period
Control setAnnex A, 93 controls in four themes, scoped by the Statement of ApplicabilityTrust Services Criteria, with security as the required common criteria
OutputA certificateA report with the practitioner’s opinion and management’s description
VariantsOne certification, scoped by the ISMS scope statementType 1 for design, Type 2 for design and operating effectiveness
ValidityThree years, with annual surveillance auditsNo formal expiry, but customers expect a current annual report
Verification by a customerCertification body and accreditation body recordsReading the report itself, often under a non disclosure agreement
Strongest market demandEurope, the Middle East, Africa and Asia, and international tendersUnited States buyers of cloud and software services

Holding both, and reusing the work

Plenty of technology and services companies hold both, usually because different customers ask for different things. The good news is that the underlying control work overlaps substantially. Access control and joiner mover leaver processes, change management, vulnerability management, logging and monitoring, incident response, backup and recovery, supplier due diligence and physical security all serve both.

What does not transfer is the assurance mechanism. An ISO 27001 certificate does not satisfy a customer who has asked for a SOC 2 Type 2 report, and a SOC 2 report is not a certificate that a tender panel can verify with an accreditation body. Practically, most organisations build the ISMS once, then map the controls to the Trust Services Criteria for the CPA firm’s examination and to Annex A for the certification body’s audit. Where a customer questionnaire asks for both, the two documents are supplied side by side.

A note on sequencing. The ISMS work, particularly scope definition, risk assessment, policy set and internal audit, tends to be the heavier lift, and it produces most of the evidence a SOC 2 examination will want. Doing ISO 27001 first and adding SOC 2 afterwards is often less duplicated effort than the reverse.

Which one applies to you?

  • ISO/IEC 27001 if you sell in Europe, the Middle East, Africa or Asia, if tenders ask for an accredited certificate, or if a regulator or a large enterprise procurement process names the standard.
  • SOC 2 Type 2 if your customers are United States based, particularly if you are a SaaS or cloud service provider whose buyers run vendor risk reviews and expect a report they can read rather than a certificate they can look up.
  • Both if your customer base spans those markets. Build one control environment and produce two forms of assurance from it.
  • Watch the language. There is no such thing as SOC 2 certification and no SOC 2 certificate. The accurate claim is that an independent CPA firm has issued a SOC 2 report of a named type covering named categories for a stated period.

Frequently Asked Questions

Is SOC 2 a certification like ISO 27001?

No. ISO/IEC 27001 certification results in a certificate issued by a certification body that is accredited by a national accreditation body. SOC 2 results in an attestation report issued by an independent licensed CPA firm under AICPA attestation standards. There is no SOC 2 certificate and no accreditation body in the SOC 2 scheme.

Which do customers ask for more often?

It depends on the market. Buyers in Europe, the Middle East, Africa and much of Asia typically ask for ISO/IEC 27001 certification, because an accredited certificate is easy to verify. United States buyers of cloud and software services more often ask for a SOC 2 Type 2 report, because it sets out the controls tested and the results.

How long does each one last?

An ISO 27001 certificate is normally valid for three years, subject to annual surveillance audits and a recertification audit before expiry. A SOC 2 report has no expiry date because it covers a fixed date or period, but customers normally expect a current report, which in practice means an annual Type 2 cycle.

Can one set of controls support both?

Largely, yes. Access control, change management, vulnerability management, logging and monitoring, incident response, backup and recovery, supplier due diligence and physical security all serve both. The management system elements specific to ISO 27001, such as the Statement of Applicability, internal audit and management review, are additional, and the SOC 2 examination requires management’s description of the system in the AICPA format.

Which should we do first?

For most organisations, ISO/IEC 27001 first is the more efficient order. Defining scope, running the risk assessment, writing the policy set and establishing internal audit produce most of the evidence a SOC 2 examination will look for. The reverse order works, but tends to leave more management system work to do later.

Who performs each assessment?

ISO/IEC 27001 certification audits are performed by a certification body accredited by a national accreditation body, in a Stage 1 and Stage 2 sequence. SOC 2 examinations are performed by an independent licensed CPA firm under AICPA attestation standards. The two cannot be combined into a single engagement or a single opinion.

Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.