Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

ISO 27001 or SOC 2: which one, and when you need both

Two of the most requested assurances in security procurement, built for different audiences. How to choose, and why “get both” is sometimes the cheapest answer.

Updated September 2026 · 7 min read

What each one actually is

ISO/IEC 27001 is an internationally recognised standard for an information security management system (ISMS), certified by a UKAS or ANAB-accredited body. The certificate says you run a governed, audited system.

SOC 2 is an AICPA attestation against the Trust Services Criteria — security, plus optionally availability, confidentiality, processing integrity and privacy. A CPA firm issues a report: Type I tests design at a point in time, Type II tests operating effectiveness over a period.

So one is a certificate you hold up; the other is a report a buyer (or their auditor) reads in full.

Which your buyers will ask for

Geography and sector decide it more than anything technical. Regulated sectors and buyers in the UK, EU and Asia tend to require ISO 27001. US technology buyers more often ask for SOC 2, increasingly Type II.

If you sell across both worlds, you will eventually be asked for both. The order should follow your pipeline: certify to what your next ten deals demand.

Why doing one makes the other cheap

Both frameworks resolve to the same control families: access, change, monitoring, vendor management, incident response. Run one control set well, evidenced by operating, and it satisfies both.

The marginal cost of the second assurance is then mostly mapping and an audit, not new work. Firms that treat each as a separate project pay twice; firms that treat security as the source of evidence pay once.

FAQ

Questions, answered

Is SOC 2 a certification?
No. SOC 2 is an independent auditor’s attestation report, not a pass/fail certificate. You share the report and buyers read it. ISO 27001 is a certification issued by an accredited body.
Type I or Type II?
Type I tests control design at a point in time; Type II tests operating effectiveness over a period, usually three to twelve months. Buyers increasingly want Type II because it shows the controls actually ran.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.