Certify guides
SOC 2, ISO 27001, and audit-ready certification workflows.
What is ISO/IEC 27001?
ISO/IEC 27001:2022 is a voluntary international standard for an information security management system. Clauses 4–10 set certifiable ISMS requirements; Annex A lists 93 selectable controls. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Who needs ISO 27001?
You need ISO/IEC 27001 when a buyer or tender asks for an accredited certificate — not because it is a law. Clauses 4–10 apply only if you certify. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
How do you get ISO 27001 certified?
Build an ISMS under Clauses 4–10, write a SoA for Annex A, run internal audit and management review, then pass Stage 1 and Stage 2 with an accredited body. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What is the ISO 27001 certification process?
The ISO/IEC 27001 process is Stage 1 (documentation and readiness), Stage 2 (implementation and effectiveness), then a typical three-year certificate with surveillance and later recertification. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What is an ISO 27001 readiness assessment?
A readiness or gap assessment compares your ISMS to Clauses 4–10 and Annex A so you can decide go/no-go for Stage 1. It is best practice, not a mandatory clause. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What are the ISO 27001 Annex A controls?
Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: Organizational 37, People 8, Physical 14, Technological 34. You select them in the Statement of Applicability. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What evidence does an ISO 27001 auditor request?
An ISO/IEC 27001 auditor samples mandatory documented information required by Clauses 4–10, then supporting operating records for Annex A controls you marked implemented. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
How long does ISO 27001 certification take?
Elapsed time to an accredited ISO/IEC 27001 certificate is typically months, not weeks — often half a year to well over a year. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
How much does ISO 27001 cost?
ISO/IEC 27001 cost is certification-body fees plus internal effort, optional consultants, tooling, and remediation. Figures here are typical and illustrative, not quotes. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What is an ISO 27001 surveillance audit?
A surveillance audit is the usual year-1 and year-2 sample that keeps an ISO/IEC 27001 certificate valid inside a typical three-year cycle. It is partial, not a full recertification. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What is ISO 27001 recertification?
Recertification is the full reassessment of your ISMS before the typical three-year ISO/IEC 27001 certificate expires. It is broader than surveillance. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
How do you choose an ISO certification body?
Choose a certification body that is accredited for ISO/IEC 27001 by an IAF-MLA accreditation body, then verify the listing in IAF CertSearch. This page ranks no body. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
SOC 2 vs ISO 27001: which do you need?
Need SOC 2 when buyers want a CPA attestation report against the AICPA Trust Services Criteria. Need ISO/IEC 27001 when they want an accredited ISMS certificate. They are different artefacts. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Do you need both SOC 2 and ISO 27001?
You need both only when different buyers actually require a SOC 2 report and an ISO/IEC 27001 certificate. That is a business decision, not a requirement of either text. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
How does ShipReady Metrics support ISO 27001 evidence?
ShipReady Metrics records ISO/IEC 27001-mapped evidence, shows Annex A crosswalk density, and holds policies and risks you already own. It does not certify you. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
What is SOC 2, and what does the report prove?
SOC 2 is an attestation examination in which a licensed CPA firm reports an opinion on a service organisation's controls against the AICPA Trust Services Criteria. The deliverable is a report, not a certificate. Security (the common criteria) is always in scope; the other four categories are optional.
SOC 2 Type I or Type II — which report do you need?
Type I reports whether controls are suitably designed at a point in time. Type II reports whether they also operated effectively across a review period, commonly three to twelve months. Most enterprise buyers ask for Type II; Type I is an interim artefact, not lighter assurance.
Who needs SOC 2, and is it ever legally required?
Nobody is required by law to have a SOC 2 report. The trigger is commercial: enterprise procurement, vendor-risk review, and contract clauses. It typically matters for business-to-business software that stores or processes customer data. Regulatory regimes such as HIPAA and PCI DSS are a different question entirely.
How do you get a SOC 2 report, step by step?
Seven phases: choose the criteria and system boundary, run a gap assessment, remediate, engage a licensed CPA firm, run the observation period if you want a Type II, support fieldwork, then receive the report. You do the first three; only the CPA firm performs the examination and issues the opinion.
What belongs on a SOC 2 readiness checklist?
Group readiness work by the common criteria series: governance, communication, risk assessment, monitoring, control activities, access, operations, change management, and vendor risk. For each, know the control, the owner, and the dated evidence it produces. Readiness is your own assessment, never an attestation opinion.
What happens during a SOC 2 audit?
The CPA firm plans the engagement, walks through each control, requests complete populations of events, selects samples, tests design and — for a Type II — operating effectiveness, discusses deviations, then drafts the report and issues an opinion. The procedures are the practitioner's judgement, not your preference.
Who can perform a SOC 2 examination and issue the report?
Only an independent licensed CPA firm can perform a SOC 2 examination and issue the report containing the opinion. Compliance-automation platforms, readiness advisers, security consultancies, and penetration-testing providers cannot, whatever their marketing implies. Verify the licence with the relevant state board of accountancy.
What evidence will a SOC 2 auditor request?
Expect complete populations plus sampled artefacts per control area: access provisioning and removal records, periodic access reviews, change approvals, deployment records, vulnerability findings with remediation dates, incident tickets, vendor reviews, training completions, and policy acknowledgements — all dated inside the period.
How long does SOC 2 take from start to report?
There is no single number. Four stages run in sequence: readiness and remediation, the observation period for a Type II (commonly three to twelve months), fieldwork, then report drafting. A Type I skips the observation period. Those durations are market observations, not rules, and not a promise about your engagement.
How much does SOC 2 cost, and what drives the price?
Cost has four parts: the CPA firm's examination fee, readiness and tooling, technical testing such as a penetration test, and internal time. Scope, the number of criteria categories, organisation size, and evidence maturity move each one. Only a firm's proposal is a price; nothing here is a quote.
What happens if you have SOC 2 audit exceptions?
An exception is a deviation the auditor found when testing a control: a sampled item without the expected evidence, or a control that did not operate as described. Exceptions appear in the report with your management response. They do not automatically produce a qualified or adverse opinion.
What happens if you fail SOC 2?
You cannot fail SOC 2, because there is no pass or fail. The examination produces an opinion: unmodified, qualified, adverse, or a disclaimer. A qualified opinion names specific criteria that were not met; an adverse one is broader. All are recoverable through remediation and a new examination period.
How do you choose a SOC 2 auditor?
Start with the non-negotiables: a licensed CPA firm, verified with the state board, with current peer review and no independence conflict. Then compare relevant recent experience, report readability, engagement-team continuity, fieldwork lead time, and fee against identical written scope. Nobody should be ranking firms for you.
How do you prepare engineering teams for SOC 2?
Translate the criteria into habits your team already half has: every production change independently approved, access granted and removed through a tracked path, secrets out of repositories, logs and alerts someone triages, backups tested, incidents ticketed with a review. The evidence is a by-product of doing it properly.
How do you collect SOC 2 evidence continuously?
Capture evidence as controls run rather than assembling it before fieldwork: pull requests and approvals as they merge, provisioning and removal records as they happen, scan findings and their remediation dates, review records at each cadence. A Type II opinion covers a period, so evidence has to cover it too.
How does ShipReady Metrics support SOC 2 evidence?
It collects evidence continuously, records a human met verdict per control, crosswalks SOC 2 to canonical controls by criteria series reference, holds policies, ingests connector findings, and shares a scoped reviewer view. It prepares evidence; it does not issue the report — only a licensed CPA firm does.
What are the best SOC 2 audit firms?
What are the best SOC 2 audit firms? This page lists major CPA firms by stated criteria, not a ranking. Inclusion is not endorsement. Verify AICPA peer review and CPA licensure. Not legal advice.
What are the best ISO 27001 certification bodies?
What are the best ISO 27001 certification bodies? This is an inclusion-criteria checklist, not a ranking. Verify accreditation on IAF and national AB registers. Inclusion is not endorsement. Not legal advice.
How do you choose a security auditor?
How do you choose a security auditor? Walk the decision tree: outcome, provider type, required accreditation, then shortlist. Not legal advice. Not procurement advice. Does not determine which standard applies to YOU.
What is the difference between an auditor, a consultant, and a certification body?
What is the difference between an auditor, a consultant, and a certification body? Each role issues different outputs under different rules. This page compares roles. Not legal advice. Not procurement advice.
What does accreditation mean for security assurance?
What does accreditation mean for security assurance? It is the AB→CB chain for ISO schemes and CPA peer review for SOC 2. Verify on public registers. Not legal advice.
What questions should you ask before hiring an auditor?
What questions should you ask before hiring an auditor? This question bank groups accreditation, independence, scope, and price themes. Not legal advice. Not procurement advice.
Can the same firm prepare you and audit you?
Can the same firm prepare you and audit you? Usually no — self-review threats apply under AICPA and ISO/IEC 17021-1. Not legal advice. Not procurement advice.
What are security audit independence requirements?
What are security audit independence requirements? Threats include self-review and familiarity; safeguards vary by scheme. Not legal advice. Does not determine YOUR engagement structure.
How do major security assurance providers compare?
How do major assurance providers compare? This matrix compares authorizations by scheme — not a ranking. Verify each cell before you buy. Inclusion is not endorsement. Not legal advice.
SOC 2 compliance: what it requires and what auditors sample
SOC 2 is an AICPA attestation in which a licensed CPA firm examines a service organization's security controls against the Trust Services Criteria and issues a report with the auditor's opinion. Preparing for one means collecting evidence that controls operate, mapping it to the criteria, and assembling the package the auditor samples in a Type I or Type II examination.
ISO 27001: the ISMS, Annex A, and the certification cycle
ISO/IEC 27001 is the international standard for an information security management system (ISMS). To certify, an organization maintains a risk assessment, a Statement of Applicability, and evidence that its Annex A controls operate — then an accredited body audits that system on a recurring cycle rather than a single point in time.