SOC 2 vs. ISO 27001: which one do you need?
Both prove you take security seriously, but they work differently. What each one is, who asks for which, how the audits work, and how to decide.
Sooner or later, a customer’s security team sends the question: “Can you share your SOC 2 report?” Or, if they’re in Europe: “Are you ISO 27001 certified?”
Both are ways of proving you run security properly. They overlap a lot, but they’re not the same thing, and picking the wrong one first can cost you months. I’ve taken an IT department through both at the same time. Here’s how I explain the difference.
The short version
| SOC 2 | ISO 27001 | |
|---|---|---|
| What you get | An audit report (an attestation) | A certificate |
| Who issues it | An independent CPA firm | An accredited certification body |
| Where it’s expected | Mostly US customers, especially SaaS buyers | Europe, global enterprises, and regulated industries |
| What it covers | Controls mapped to the Trust Services Criteria | A full information security management system (ISMS) |
| How it’s shared | Usually under NDA — it’s a detailed report | Publicly — the certificate is meant to be shown |
| How long it lasts | Typically renewed every year | Three-year cycle, with yearly surveillance audits |
SOC 2 in plain English
SOC 2 is a framework from the AICPA, the US accounting body. An auditor checks your controls against the Trust Services Criteria. Security is always included; availability, processing integrity, confidentiality, and privacy are optional, and you only add them if they matter to your customers.
There are two types:
- Type I looks at whether your controls are designed properly at a single point in time. It’s faster, and a common first step.
- Type II looks at whether those controls actually operated over a period, usually three to twelve months. This is what most enterprise buyers really want.
The result is a report that describes your system, your controls, how the auditor tested them, and any exceptions they found.
ISO 27001 in plain English
ISO 27001 is an international standard. Instead of starting from a list of controls, it asks you to build an information security management system: a repeatable way of finding risks, deciding how to treat them, and improving over time.
In practice, that means:
- Defining the scope of what’s covered
- Running a risk assessment and choosing how to treat each risk
- Writing a Statement of Applicability that says which Annex A controls apply and why
- Running internal audits and management reviews
Certification happens in two stages: a documentation review, then an audit of whether you actually work that way. After that, a lighter surveillance audit happens each year.
How to decide
Start with whoever is asking. Seriously. The right answer is almost always the one your customers ask for.
- Selling mostly to US companies, especially tech buyers? Start with SOC 2.
- Selling into Europe, or to large global enterprises? ISO 27001 is often expected.
- Both? Pick the one blocking the most revenue, and design your controls so the second one is a smaller step. The overlap is substantial: access control, device management, logging, backups, vendor management, and incident response show up in both.
Mistakes I see teams make
- Buying a compliance platform before scoping. Tools like Vanta and Drata are genuinely useful, but they’ll happily show you 200 failing checks without telling you which 20 matter.
- Copy-pasting policies nobody follows. Auditors test what you do, not what you wrote. A short policy you follow beats a long one you don’t.
- Scoping too wide. You don’t need every system in scope for your first audit. Scope to the product customers are asking about.
- Treating it as a one-time project. Type II and ISO surveillance audits mean the controls have to keep running. Build them into how you already work.
Where to start
A gap assessment tells you where you stand today, which framework fits, and a realistic timeline. It’s the first thing I do with every SOC 2 & ISO 27001 readiness engagement, and it usually saves more time than it costs.