ISO 27001 vs SOC 2: certificate vs attestation report
The main difference between SOC 2 and ISO 27001 is the outcome, and the two outcomes answer different questions. ISO/IEC 27001 certification says an organization's information security management system (ISMS) conforms to the requirements of the standard. A SOC 2 report says whether a service organization's system description is presented in line with the AICPA description criteria and whether its controls were suitably designed, measured against the Trust Services Criteria. A Type 2 report adds whether the controls operated effectively.
Readers use them differently too. A certificate is a short, written assurance that a defined scope meets the standard's requirements. A SOC 2 report is a longer document intended for people who understand the service, and it contains management's description of the system, management's assertion and the service auditor's opinion.
| Aspect | ISO/IEC 27001 | SOC 2 |
|---|---|---|
| What you receive | A certificate of conformity for a defined ISMS scope | An attestation report with the service auditor's opinion |
| Who issues it | A certification body; check whether it's accredited | A licensed CPA firm acting as service auditor |
| Who writes the criteria | ISO and IEC, through subcommittee ISO/IEC JTC 1/SC 27 | The AICPA's Assurance Services Executive Committee |
| What is evaluated | The ISMS requirements and the Annex A controls in your Statement of Applicability | Your system description and the controls that address the criteria in scope |
| Time dimension | A three-year certification cycle with at least one audit every calendar year | Type 1 as of a date; Type 2 over a review period |
| How to check it | IAF CertSearch, or ask the certification body | Read the report, and check the CPA firm's license with its state board |
Who issues each, and how to check
ISO says plainly that it doesn't perform certification or issue certificates. Certification is done by external certification bodies, so no organization is certified by ISO itself. Accreditation is the formal recognition by an accreditation body that a certification body operates according to international standards. ISO notes that accreditation isn't compulsory, but it provides independent confirmation of competence.
To check a certificate, search IAF CertSearch, which gathers data from accreditation bodies and certification bodies, or contact the certification body or its accreditation body. Global ACI, which has assumed the former roles of the International Accreditation Forum and the International Laboratory Accreditation Cooperation, runs the arrangement under which signatory accreditation bodies commit to recognizing each other's accreditation programs and competence as equivalent.
Check the edition as well as the name. Under IAF MD 26, every accredited certification to ISO/IEC 27001:2013 had to expire or be withdrawn at the end of the transition period on October 31, 2025, so a current accredited certificate refers to ISO/IEC 27001:2022. Read the scope statement too: it tells you which parts of the organization the certificate covers.
A SOC 2 report can only come from a CPA firm. The AICPA description criteria describe the examination as performed under the AICPA attestation standards, with a CPA acting as the service auditor. Before relying on a report, look at who issued it, confirm the firm's license with the state board of accountancy where it practices, and check the report's date or period.
Scope and structure
ISO/IEC 27001:2022, together with its 2024 amendment on climate action changes (Amd 1:2024), defines the requirements an ISMS must meet: establishing, implementing, maintaining and continually improving it. The standard is built around a risk management process, and your certificate names the scope the management system covers, which can be a whole organization or a defined part of it.
Annex A lists reference controls. With the 2022 edition, the set moved to 93 controls in four clauses, down from 114 controls in 14 clauses in the previous edition. The Statement of Applicability records which Annex A controls you include, whether they're implemented and why, tying your controls to your risk treatment decisions.
SOC 2 scope is a system: the infrastructure, software, people, procedures and data used to provide a service, plus the Trust Services Criteria categories you choose. The common criteria, CC1 to CC9, apply in every SOC 2 report, and availability, processing integrity, confidentiality and privacy each add their own criteria. The criteria describe outcomes; you decide which controls meet them.
A SOC 2 report also spells out its boundaries with vendors and customers. The description can use the carve-out method for a subservice organization, excluding its controls from the examination while describing the controls assumed to run there, and it lists the complementary user entity controls customers must operate. When you read either outcome from a vendor, read its scope and boundaries as closely as its conclusion.
Upkeep over time
ISO/IEC 27001 certification follows the audit program in ISO/IEC 17021-1, the requirements standard for certification bodies. The initial audit has two stages. Surveillance audits follow in the first and second years after the certification decision, and a recertification audit takes place in the third year, before the certificate expires. The first surveillance audit must fall no more than 12 months after the certification decision.
European Accreditation's guidance on that clause puts it simply: in each calendar year there must be at least one audit, whether surveillance or recertification. Between audits, the management system has to keep operating: the standard asks for an ISMS that is maintained and continually improved, not built once.
SOC 2 has no certificate to maintain. Each report covers either a single date (Type 1) or a review period (Type 2), and the AICPA criteria read for this guide set no expiry. Customers decide how recent a report must be, so if they expect continuing coverage, plan consecutive review periods without long gaps.
How to decide what comes first
Start with evidence of demand, not with a view on which framework is better. For a SaaS company or any other service provider, the deciding question is what your current and target customers ask for, in writing: security questionnaires, vendor requirements, requests for proposals and contract clauses.
If requests name one outcome, pursue that one first. If they name both, compare deadlines and the business each outcome unlocks, then plan the second so it reuses the first one's controls and evidence. These questions help you get clear answers:
- Which outcome do your questionnaires or contracts name: a SOC 2 report, an ISO/IEC 27001 certificate, or either?
- If SOC 2, do you need Type 1, Type 2 or both, and which categories?
- If ISO/IEC 27001, which parts of our business must the certificate cover?
- Is there a renewal, tender or contract date that one of them must meet?
- Would you accept one outcome now and the other later?
Doing both: one control set, separate issuers
The controls behind the two outcomes overlap in many areas, such as access control, change management, supplier oversight and incident management. Build one control set, map each control to the Annex A controls and the Trust Services Criteria it supports, and keep one evidence library. A second outcome then adds mapping and audit time rather than a second program.
Watch for the differences. ISO/IEC 27001 asks for management system elements, such as a documented ISMS scope and a Statement of Applicability, that a SOC 2 examination doesn't. SOC 2 asks for a system description written to the AICPA description criteria, which ISO/IEC 27001 doesn't. Plan those documents separately.
Keep the issuers independent of the people who build your controls. ISO/IEC 17021-1 bars a certification body, and any entity under its organizational control, from offering or providing management system consultancy, and its activities must not be marketed as linked with a consultancy. For SOC 2, the AICPA Code of Professional Conduct treats accepting responsibility for designing, implementing or maintaining internal control as a management responsibility, and a CPA firm that takes it on impairs its independence.
That leaves three separate roles: the team or advisor that helps you prepare, the certification body that audits the ISMS, and the CPA firm that examines the system. Coordinate their schedules so evidence requests don't collide, but keep the roles apart.
What a shared control set looks like
A shared control set is a single list of controls, each written once and linked to every requirement it helps meet. It keeps owners, frequencies and evidence in one place, so a change to a control is made once and shows up in both programs.
- One control statement, owner and frequency per control
- A mapping column for ISO/IEC 27001 (clauses and Annex A) and one for the Trust Services Criteria
- One evidence location per control, organized by period
- A single risk register that feeds ISO/IEC 27001 risk treatment and the SOC 2 risk assessment
- A calendar that shows ISO/IEC 27001 audit dates next to the SOC 2 review period