ISO 27001 or SOC 2: which one, and when you need both
Two of the most requested assurances in security procurement, built for different audiences. How to choose, and why “get both” is sometimes the cheapest answer.
What each one actually is
ISO/IEC 27001 is an internationally recognised standard for an information security management system (ISMS), certified by a UKAS or ANAB-accredited body. The certificate says you run a governed, audited system.
SOC 2 is an AICPA attestation against the Trust Services Criteria — security, plus optionally availability, confidentiality, processing integrity and privacy. A CPA firm issues a report: Type I tests design at a point in time, Type II tests operating effectiveness over a period.
So one is a certificate you hold up; the other is a report a buyer (or their auditor) reads in full.
Which your buyers will ask for
Geography and sector decide it more than anything technical. Regulated sectors and buyers in the UK, EU and Asia tend to require ISO 27001. US technology buyers more often ask for SOC 2, increasingly Type II.
If you sell across both worlds, you will eventually be asked for both. The order should follow your pipeline: certify to what your next ten deals demand.
Why doing one makes the other cheap
Both frameworks resolve to the same control families: access, change, monitoring, vendor management, incident response. Run one control set well, evidenced by operating, and it satisfies both.
The marginal cost of the second assurance is then mostly mapping and an audit, not new work. Firms that treat each as a separate project pay twice; firms that treat security as the source of evidence pay once.
Questions, answered
Is SOC 2 a certification?
Type I or Type II?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.