Compliance frameworks
SOC 2 vs ISO 27001: Which Does Your Business Need?
A prospect has asked for your SOC 2, or a procurement team wants to know whether you are ISO 27001 certified. Both requests tend to arrive with a deal attached, which is why they get answered quickly rather than carefully.
Before starting a compliance programme because those words appeared in a procurement request, it is worth understanding what the customer actually requires. SOC 2 and ISO 27001 can both give customers assurance about how you manage security, but they are different mechanisms and they produce different outputs. This article covers what each one is, how they differ, what to clarify when a customer names one, and how to work out which is relevant to your organisation.
SOC 2 vs ISO 27001: the short answer
SOC 2 is an AICPA attestation and reporting framework used to report on controls at a service organisation against the applicable Trust Services Criteria. ISO/IEC 27001 is an international standard specifying requirements for an information security management system, and an organisation can be certified against it. Neither automatically replaces the other. Which one is relevant depends on your circumstances and the requirements you need to meet.
What is SOC 2?
SOC 2 sits within the AICPA System and Organization Controls suite and concerns controls at service organisations. The examination is carried out against the applicable AICPA Trust Services Criteria, which cover security, availability, processing integrity, confidentiality and privacy, with the relevant categories determined by the engagement.
The output is a SOC 2 report. It is an attestation and reporting engagement rather than a certification, which is why "SOC 2 certified" is inaccurate even though it is commonly said. What the report describes, including the difference between the available report types and how the examination itself runs, is covered on our SOC 2 preparation page.
What is ISO 27001?
The formal designation is ISO/IEC 27001, and the current standard is ISO/IEC 27001:2022. It specifies requirements for an information security management system, or ISMS: the set of policies, processes, responsibilities and controls through which an organisation establishes, implements, maintains and continually improves the way it manages information security.
Organisations can be certified to the standard. ISO itself does not certify organisations; certification is performed by certification bodies that assess the ISMS against the requirements of the standard. What implementation and certification preparation involve in practice is covered on our ISO 27001 page.
What is the difference between SOC 2 and ISO 27001?
The clearest difference is in what each one produces and who produces it. SOC 2 results in a report on controls, prepared through an examination by an independent audit firm. ISO/IEC 27001 results in certification of a management system, granted by a certification body after assessment. They are different mechanisms of assurance, not two versions of the same thing.
| SOC 2 | ISO 27001 | |
|---|---|---|
| What it is | An examination and reporting framework for controls at service organisations using the applicable AICPA Trust Services Criteria. | An international standard specifying requirements for an information security management system. |
| Primary output | A SOC 2 attestation report. | Certification to ISO/IEC 27001 following assessment by a certification body. |
| Who performs the independent assessment | An appropriately qualified independent CPA or audit firm under the applicable AICPA attestation requirements. | A certification body. Accreditation may provide additional independent assurance of that certification body's competence. |
| Underlying approach | Examination of controls relevant to the applicable Trust Services Criteria. | Assessment of whether the organisation's ISMS meets the requirements of ISO/IEC 27001. |
| Scope | Defined around the service organisation and system being examined, and the applicable criteria. | The organisation defines the scope of its ISMS. The two scopes are not automatically equivalent. |
| Can an organisation have both? | Yes. | Yes. |
| Does one automatically satisfy the other? | No. | No. |
Scroll the table horizontally to see both columns.
Which one do customers usually ask for?
It varies, and it varies more than most summaries admit. What a customer asks for depends on that customer, its procurement process, the industry it operates in, the contract being negotiated, the nature of the service you provide and the data involved. Two prospects in the same sector can have entirely different supplier assurance requirements.
SOC 2 is commonly encountered in North American enterprise contexts, and ISO 27001 has broad international recognition. Those are tendencies rather than rules, and treating them as a geographic split will occasionally point you in the wrong direction. Plenty of organisations encounter both requirements from customers in the same region.
The practical position is that the customer's actual requirement matters more than a generic rule about who asks for what. If the requirement first appeared in a supplier security review, our guide to completing a customer security questionnaire covers how to work through that process. Being asked about a framework in a questionnaire does not by itself create a certification requirement.
What if a customer has specifically asked for one?
Clarify what they actually require before committing time and budget. A named framework in an email is often shorthand for a broader assurance need, and the specifics change what you should do next.
If a customer asks for SOC 2
- Do they specifically require a SOC 2 report, or assurance in a broader sense?
- Are they asking for a particular type of report?
- Is the requirement contractual, or part of a procurement questionnaire?
- Is there a deadline connected to the deal?
- Are they looking for evidence of particular controls rather than the report itself?
Which report type applies, and what the examination involves, is covered on our SOC 2 preparation page.
If a customer asks for ISO 27001
- Do they specifically require certification to ISO/IEC 27001?
- Is certification a contractual or procurement requirement?
- What scope do they expect the certification to cover?
- Is there a deadline associated with the requirement?
- Are they asking for certification, or simply evidence of an information security management programme?
What certification preparation involves is covered on our ISO 27001 page.
A customer's request is important evidence for the decision, but it is not the only factor. One deal can justify a programme that then serves the next twenty, or it can pull you into a commitment that does not fit where the business is going. Both are worth knowing before you start.
Do you need SOC 2, ISO 27001, or both?
Some organisations pursue one and never need the other. Some ultimately pursue both because their customer base pulls them in both directions. Neither route automatically produces the other's output, so holding one does not remove the work involved in the other, even where the underlying security work overlaps.
The factors that usually decide it are explicit customer requirements, contractual commitments, any regulatory context that applies, the markets you are targeting, the maturity of your organisation and its security function, the nature of the service, the data you handle, and your longer-term commercial strategy. Pursuing both is not inherently better; it is only better if both are genuinely relevant.
Which should you do first?
There is no universal order. A sensible sequence depends on which requirement is strongest right now, what security and governance work you have already completed, what you have committed to customers, and what your longer-term needs look like. If one route is tied to a signed commitment and the other is speculative, that usually answers the question on its own. Where neither is committed, the decision is a strategic one rather than a technical one.
What if different customers ask for different frameworks?
When requests start diverging, it is usually a signal to stop responding deal by deal and look at your assurance strategy as a whole. Answering each request in isolation tends to produce duplicated effort and a programme shaped by whichever customer shouted most recently.
- Identify which requirements recur across deals rather than treating each as a one-off
- Separate mandatory contractual requirements from stated preferences
- Look at the security and control work you have already done, and where it applies to both routes
- Avoid duplicating effort where the same underlying controls support more than one requirement
- Consider which framework aligns with the customers you intend to sell to next, not only current ones
There is real overlap between the security and control work relevant to SOC 2 and to ISO 27001, so effort spent on access control, risk management, incident response or supplier assurance rarely serves only one of them. That overlap is not equivalence. Completing one does not mean the organisation automatically satisfies the other, and each still requires its own independent assessment.
What should you consider before deciding?
A short set of questions, answered honestly before any budget is committed, tends to produce a better decision than the pressure of a single deal.
- What are customers actually asking for, in their own words and in writing?
- Is the requirement contractual, or a preference expressed during a review?
- Which markets and customers are strategically important over the next few years?
- What security and compliance work already exists that either route could build on?
- What scope would the report or certification be intended to cover?
- Are there regulatory requirements that bear on the decision?
- Who will own the programme internally, and do they have the time for it?
- Is this a one-off customer requirement or a recurring commercial pattern?
- Could both eventually be relevant, and does that change the sequence you choose?
Getting help with SOC 2 or ISO 27001
It helps to separate two different kinds of help. Preparation support means understanding the requirement, scoping it, closing gaps in controls and documentation, and getting the organisation ready. Independent assessment means the SOC 2 examination itself, carried out by an appropriately qualified audit firm, or the ISO/IEC 27001 certification assessment, carried out by a certification body. These are distinct roles and they cannot be collapsed into one.
Providers found through Heelr may help with the preparation side, depending on their expertise and the services they offer. Not every provider works across both frameworks, and no provider on Heelr issues a SOC 2 report or an ISO/IEC 27001 certificate. Heelr does not perform either function. The formal independent assessment must be carried out by the appropriate qualified auditor or certification body.
Not sure which route fits your requirements?
If a customer requirement has raised SOC 2 or ISO 27001 and you are not yet sure which is relevant, Heelr can help you find cybersecurity providers with compliance expertise who can help you understand the requirement and prepare for the appropriate route. Heelr is the marketplace: the preparation work is carried out by independent professionals and providers, the relevant independent assessment is carried out by an auditor or certification body, and you agree scope and price before anything begins.
Common questions
Is SOC 2 a certification?
No. SOC 2 is an attestation and reporting engagement that results in a SOC 2 report on controls at a service organisation. Describing an organisation as "SOC 2 certified" is a common informal shorthand, but it is not accurate. The correct terms are a SOC 2 examination, a SOC 2 attestation and a SOC 2 report.
Does ISO 27001 automatically satisfy a SOC 2 request?
No. The two involve overlapping security and control work, so effort spent on one is rarely wasted on the other. Certification to ISO/IEC 27001 does not produce a SOC 2 report, and a customer that specifically requires a SOC 2 report is asking for a different output.
Does a SOC 2 report satisfy a customer asking for ISO 27001 certification?
Not automatically. If the customer specifically requires certification to ISO/IEC 27001, a SOC 2 report is a different form of assurance produced through a different process. The customer decides what evidence it will accept, so it is worth clarifying the actual procurement or contractual requirement before assuming either will do.
Can the same provider help with both SOC 2 and ISO 27001 preparation?
Potentially, where the provider has appropriate expertise in both. Preparation support is separate from the independent attestation or certification itself, which must be carried out by the appropriate qualified auditor or certification body.
