Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Guide

ISO 27001 vs SOC 2: differences and which to pursue

ISO 27001 vs SOC 2 is a choice between two different outcomes. ISO/IEC 27001 certification is a certificate from a certification body saying your information security management system conforms to the standard. A SOC 2 report is an attestation report in which a licensed CPA firm gives an opinion on your system description and controls, measured against AICPA criteria. Start with the one your customers ask for.

Compliance10 min read

By Security Inspect · Sources checked

Key takeaways

  • ISO/IEC 27001 certificates are issued by certification bodies after an audit of your information security management system. ISO and IEC publish the standard, but ISO doesn't certify anyone.
  • SOC 2 reports are issued by licensed CPA firms acting as service auditors, and a Type 2 report covers whether controls operated effectively over a review period.
  • ISO/IEC 27001 scope is a management system and the controls you determine through risk treatment, checked against Annex A. SOC 2 scope is a defined system and the Trust Services Criteria categories you choose.
  • An ISO/IEC 27001 certification runs on a three-year cycle with at least one audit in every calendar year. SOC 2 reports are renewed on the schedule your customers expect.
  • One well-run control set can support both, but the certification body and the CPA firm must stay independent of whoever helped design your controls.

ISO 27001 vs SOC 2: certificate vs attestation report

The main difference between SOC 2 and ISO 27001 is the outcome, and the two outcomes answer different questions. ISO/IEC 27001 certification says an organization's information security management system (ISMS) conforms to the requirements of the standard. A SOC 2 report says whether a service organization's system description is presented in line with the AICPA description criteria and whether its controls were suitably designed, measured against the Trust Services Criteria. A Type 2 report adds whether the controls operated effectively.

Readers use them differently too. A certificate is a short, written assurance that a defined scope meets the standard's requirements. A SOC 2 report is a longer document intended for people who understand the service, and it contains management's description of the system, management's assertion and the service auditor's opinion.

ISO/IEC 27001 certification and a SOC 2 report compared
AspectISO/IEC 27001SOC 2
What you receiveA certificate of conformity for a defined ISMS scopeAn attestation report with the service auditor's opinion
Who issues itA certification body; check whether it's accreditedA licensed CPA firm acting as service auditor
Who writes the criteriaISO and IEC, through subcommittee ISO/IEC JTC 1/SC 27The AICPA's Assurance Services Executive Committee
What is evaluatedThe ISMS requirements and the Annex A controls in your Statement of ApplicabilityYour system description and the controls that address the criteria in scope
Time dimensionA three-year certification cycle with at least one audit every calendar yearType 1 as of a date; Type 2 over a review period
How to check itIAF CertSearch, or ask the certification bodyRead the report, and check the CPA firm's license with its state board

Who issues each, and how to check

ISO says plainly that it doesn't perform certification or issue certificates. Certification is done by external certification bodies, so no organization is certified by ISO itself. Accreditation is the formal recognition by an accreditation body that a certification body operates according to international standards. ISO notes that accreditation isn't compulsory, but it provides independent confirmation of competence.

To check a certificate, search IAF CertSearch, which gathers data from accreditation bodies and certification bodies, or contact the certification body or its accreditation body. Global ACI, which has assumed the former roles of the International Accreditation Forum and the International Laboratory Accreditation Cooperation, runs the arrangement under which signatory accreditation bodies commit to recognizing each other's accreditation programs and competence as equivalent.

Check the edition as well as the name. Under IAF MD 26, every accredited certification to ISO/IEC 27001:2013 had to expire or be withdrawn at the end of the transition period on October 31, 2025, so a current accredited certificate refers to ISO/IEC 27001:2022. Read the scope statement too: it tells you which parts of the organization the certificate covers.

A SOC 2 report can only come from a CPA firm. The AICPA description criteria describe the examination as performed under the AICPA attestation standards, with a CPA acting as the service auditor. Before relying on a report, look at who issued it, confirm the firm's license with the state board of accountancy where it practices, and check the report's date or period.

Scope and structure

ISO/IEC 27001:2022, together with its 2024 amendment on climate action changes (Amd 1:2024), defines the requirements an ISMS must meet: establishing, implementing, maintaining and continually improving it. The standard is built around a risk management process, and your certificate names the scope the management system covers, which can be a whole organization or a defined part of it.

Annex A lists reference controls. With the 2022 edition, the set moved to 93 controls in four clauses, down from 114 controls in 14 clauses in the previous edition. The Statement of Applicability records which Annex A controls you include, whether they're implemented and why, tying your controls to your risk treatment decisions.

SOC 2 scope is a system: the infrastructure, software, people, procedures and data used to provide a service, plus the Trust Services Criteria categories you choose. The common criteria, CC1 to CC9, apply in every SOC 2 report, and availability, processing integrity, confidentiality and privacy each add their own criteria. The criteria describe outcomes; you decide which controls meet them.

A SOC 2 report also spells out its boundaries with vendors and customers. The description can use the carve-out method for a subservice organization, excluding its controls from the examination while describing the controls assumed to run there, and it lists the complementary user entity controls customers must operate. When you read either outcome from a vendor, read its scope and boundaries as closely as its conclusion.

Upkeep over time

ISO/IEC 27001 certification follows the audit program in ISO/IEC 17021-1, the requirements standard for certification bodies. The initial audit has two stages. Surveillance audits follow in the first and second years after the certification decision, and a recertification audit takes place in the third year, before the certificate expires. The first surveillance audit must fall no more than 12 months after the certification decision.

European Accreditation's guidance on that clause puts it simply: in each calendar year there must be at least one audit, whether surveillance or recertification. Between audits, the management system has to keep operating: the standard asks for an ISMS that is maintained and continually improved, not built once.

SOC 2 has no certificate to maintain. Each report covers either a single date (Type 1) or a review period (Type 2), and the AICPA criteria read for this guide set no expiry. Customers decide how recent a report must be, so if they expect continuing coverage, plan consecutive review periods without long gaps.

How to decide what comes first

Start with evidence of demand, not with a view on which framework is better. For a SaaS company or any other service provider, the deciding question is what your current and target customers ask for, in writing: security questionnaires, vendor requirements, requests for proposals and contract clauses.

If requests name one outcome, pursue that one first. If they name both, compare deadlines and the business each outcome unlocks, then plan the second so it reuses the first one's controls and evidence. These questions help you get clear answers:

  • Which outcome do your questionnaires or contracts name: a SOC 2 report, an ISO/IEC 27001 certificate, or either?
  • If SOC 2, do you need Type 1, Type 2 or both, and which categories?
  • If ISO/IEC 27001, which parts of our business must the certificate cover?
  • Is there a renewal, tender or contract date that one of them must meet?
  • Would you accept one outcome now and the other later?

Doing both: one control set, separate issuers

The controls behind the two outcomes overlap in many areas, such as access control, change management, supplier oversight and incident management. Build one control set, map each control to the Annex A controls and the Trust Services Criteria it supports, and keep one evidence library. A second outcome then adds mapping and audit time rather than a second program.

Watch for the differences. ISO/IEC 27001 asks for management system elements, such as a documented ISMS scope and a Statement of Applicability, that a SOC 2 examination doesn't. SOC 2 asks for a system description written to the AICPA description criteria, which ISO/IEC 27001 doesn't. Plan those documents separately.

Keep the issuers independent of the people who build your controls. ISO/IEC 17021-1 bars a certification body, and any entity under its organizational control, from offering or providing management system consultancy, and its activities must not be marketed as linked with a consultancy. For SOC 2, the AICPA Code of Professional Conduct treats accepting responsibility for designing, implementing or maintaining internal control as a management responsibility, and a CPA firm that takes it on impairs its independence.

That leaves three separate roles: the team or advisor that helps you prepare, the certification body that audits the ISMS, and the CPA firm that examines the system. Coordinate their schedules so evidence requests don't collide, but keep the roles apart.

What a shared control set looks like

A shared control set is a single list of controls, each written once and linked to every requirement it helps meet. It keeps owners, frequencies and evidence in one place, so a change to a control is made once and shows up in both programs.

  • One control statement, owner and frequency per control
  • A mapping column for ISO/IEC 27001 (clauses and Annex A) and one for the Trust Services Criteria
  • One evidence location per control, organized by period
  • A single risk register that feeds ISO/IEC 27001 risk treatment and the SOC 2 risk assessment
  • A calendar that shows ISO/IEC 27001 audit dates next to the SOC 2 review period

Where our work fits

  • ISO/IEC 27001 readiness — preparation for certification by an independent accredited certification body.
  • SOC 2 readiness — preparation for an examination performed by an independent licensed CPA firm.
  • Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
  • When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

Questions

Can one audit cover both ISO 27001 and SOC 2?

No. Each outcome has its own issuer and its own rules. A certification body issues the ISO/IEC 27001 certificate after its own audit of your ISMS, and a licensed CPA firm issues the SOC 2 report under the AICPA attestation standards. Even when fieldwork is coordinated, you receive two separate outcomes. Sharing one control set and evidence library is how you avoid doing the work twice.

Do U.S. customers accept ISO 27001 instead of SOC 2?

Some do and some don't, and the only reliable answer comes from the customers you sell to. Check what their security questionnaires, vendor policies and contracts name, and ask directly whether an ISO/IEC 27001 certificate would meet the requirement. Get the answer in writing before you plan around it.

Does ISO 27001 or SOC 2 require a penetration test?

Neither sets a fixed penetration testing schedule in the sources read for this guide. In the Trust Services Criteria, a point of focus under CC4.1 lists penetration testing among the evaluations management can use, and points of focus are guidance. ISO/IEC 27001 is built on a risk management process, so testing decisions follow from your risk assessment and treatment. Contracts and customers may still require a test.

Can our consultant certify us?

No. ISO/IEC 17021-1 bars certification bodies from offering or providing management system consultancy, so the organization that helps build your ISMS can't also be the body that certifies it. For SOC 2, only a licensed CPA firm can issue the report, and a CPA firm that took responsibility for designing or implementing your controls would impair its independence. Your advisor prepares you; an independent party issues the outcome.

Primary sources

Related guides

Terms in this guide

More on this site

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Talk through your situation with a practitioner

Every engagement begins with a written scope and proposal.

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.