Compliance
SOC 2 vs ISO 27001: which one do you actually need
Both frameworks cover similar ground but produce different documents for different audiences. Here's how to tell which one your customers are actually asking for.
SOC 2 and ISO 27001 get asked about almost interchangeably, but they’re structurally different, and the difference matters for deciding which one to pursue first — or whether to pursue both.
What each one actually is
SOC 2 is an attestation report, issued by a licensed CPA firm, that evaluates a company’s controls against the AICPA’s Trust Services Criteria (most commonly Security, sometimes also Availability, Confidentiality, Processing Integrity, or Privacy). The output is a report, not a certificate — it describes what was tested and what the auditor found.
ISO/IEC 27001 is a certifiable management system standard. A company builds an Information Security Management System (ISMS) — a defined, operating set of processes for managing information security risk — and an accredited certification body audits it against the standard’s Annex A controls. The output is a certificate with a defined validity period, renewed through ongoing surveillance audits.
Why customers ask for one over the other
In practice, SOC 2 is the default expectation in the US B2B SaaS market, particularly for companies selling to other American companies. ISO 27001 tends to be the expectation for companies selling into Europe or other international markets, or working with larger multinational enterprise customers whose own compliance programs are built around ISO standards.
If a security questionnaire or procurement process explicitly names one framework, that’s the clearest signal. If it’s ambiguous — “do you have a security certification” — the buyer’s geography and the size of the deals coming in are usually a good proxy.
The overlap is bigger than most people expect
Both frameworks cover largely the same operational ground: access control, change management, incident response, vendor risk management, logging and monitoring, and so on. A company that has done real work toward one is not starting from zero on the other. The practical approach for companies that need both is to map the overlapping controls and build evidence that satisfies both frameworks at once, rather than running two disconnected compliance programs in parallel.
A reasonable way to decide
Start with what’s actually blocking revenue today. If a specific enterprise deal or renewal is stalled on a named framework, that’s the one to pursue first. If nothing is blocked yet but growth plans point toward Europe or larger multinational customers, it’s worth building toward ISO 27001 earlier rather than reactively.
SOC 2 readiness and ISO 27001 readiness are worth scoping together if both are realistically on the horizon, specifically to avoid duplicating the underlying control work.
Related capabilities
Related articles
What actually drives the cost of SOC 2
SOC 2 cost doesn't have a single answer. Here's what actually moves the number: report type, scope, remediation work, and whether a compliance tool is doing the heavy lifting.
What auditors actually look for in SOC 2 readiness
Auditors don't grade policy documents on how well-written they are. They test whether controls actually operated the way the documentation says they do.
Have a question this didn't answer?
Every engagement starts with a conversation about your specific situation, not a generic package.