Buyer's guide

ISO 27001 vs SOC 2: Which Should You Get First?

Both show customers you take security seriously, but they're not the same thing and they don't answer the same question. Here's what each one actually covers, and a practical way to decide where to start.

What ISO 27001 actually certifies

ISO/IEC 27001 certifies that you operate an information security management system, an ISMS, that meets the standard's clauses 4 through 10, and that you've assessed and addressed the 93 Annex A controls relevant to your organisation in a Statement of Applicability. It's a management-system standard before it's a control checklist: an auditor is checking that you have a running process for identifying risk, deciding what to do about it and reviewing whether it's working, not just that individual technical controls exist in isolation.

Certification is issued by an accredited certification body after a two-stage audit: a Stage 1 review of your ISMS documentation and scope, followed by a Stage 2 audit that tests whether the controls are actually operating. The certificate is typically valid for three years, with surveillance audits in between.

What SOC 2 actually attests

SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the AICPA's Trust Services Criteria, security is always in scope, with availability, processing integrity, confidentiality and privacy as optional additional criteria, and writes a report describing what they found. There's no "SOC 2 certificate" to hang on a wall; what you get is a detailed report you share directly with customers, usually under NDA.

There are two report types. A Type I report describes your controls as designed at a single point in time. A Type II report goes further, describing how those controls actually operated over an observation window, commonly three to twelve months, which is why Type II carries more weight with enterprise buyers and takes longer to obtain the first time.

Side by side

ISO 27001 SOC 2
Output Certificate from an accredited certification body Attestation report from a licensed CPA firm
What's evaluated An ISMS: clauses 4–10 plus 93 Annex A controls Controls against the Trust Services Criteria
Point-in-time or period? Certified at audit, valid ~3 years with surveillance Type I: a point in time. Type II: an observation period
Typically requested by International customers, government tenders US enterprise and SaaS buyers
First-time timeline Months of prep, then a two-stage audit Type I can be fast; Type II needs the observation window first

How to decide which to pursue first

The honest answer is usually: whichever one your actual customers, regulators or tenders are asking for. If you don't have a specific ask yet, a few patterns hold reasonably well:

  • Selling mainly to US enterprise or SaaS buyers? SOC 2, usually Type II, is the more commonly expected report in procurement and security review processes.
  • Selling internationally, into government, or in a market where certification carries more procurement weight than a report? ISO 27001 tends to be the one that's asked for by name.
  • Need something fast while a bigger deal is in progress? A SOC 2 Type I can be achieved sooner than ISO certification or a SOC 2 Type II, though it carries less weight than either.
  • Not sure yet, but know you'll eventually need both? Start wherever your current pipeline is pointing, and build the evidence base so the second framework is mostly a mapping exercise rather than starting over.

Why you don't have to choose forever

ISO 27001 and SOC 2 overlap substantially in the actual controls underneath them: access control, change management, vendor risk, incident response and logging all show up in both. Most organisations that hold both frameworks aren't running two separate compliance programmes; they're mapping one evidence base to two sets of requirements. Done well, the second framework costs a fraction of the effort the first one did, because the risk assessment, the policies and the control evidence already exist, and the work is mostly showing how they satisfy the second framework's specific language.

This is the approach Touchpoint's Attest is built around: assessments against ISO 27001, SOC 2 and other frameworks share one risk register and one evidence base, so holding more than one certification or report doesn't mean running more than one programme. Read more on the Attest page, or go straight to the individual framework pages for ISO 27001 and SOC 2.

Frequently asked questions

Can I get ISO 27001 and SOC 2 at the same time?+

Yes. The two frameworks share a large amount of control overlap, particularly around access control, change management and incident response, so a single evidence collection effort can often support both, pursued in parallel or in close succession, rather than from scratch twice.

Is SOC 2 a certification like ISO 27001?+

No. ISO 27001 results in a certificate issued by an accredited certification body that is valid for a set period. SOC 2 results in an attestation report written by a licensed CPA firm describing your controls and, for Type II, how they operated over an observation window. There is no SOC 2 "certificate" to display.

Which one do most US customers ask for?+

SOC 2 is more commonly requested by US-based enterprise customers and SaaS buyers, particularly Type II. ISO 27001 is more often requested by international customers, government tenders and organisations outside North America, though both appear regularly in vendor security reviews on either side of the Atlantic.

How long does each one take to achieve?+

ISO 27001 certification typically takes a few months of preparation followed by a two-stage audit. SOC 2 Type I can be issued quickly once controls are in place, but Type II requires an observation period, commonly three to twelve months, before the auditor can report on how controls actually operated.

Not sure which framework your customers actually need?

Tell us what's being asked of you and we'll help you figure out where to start.

Ask us