Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Do you need both SOC 2 and ISO 27001?

Last verified

You need both only when different buyers actually require a SOC 2 report and an ISO/IEC 27001 certificate. That is a business decision, not a requirement of either text. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Decision guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. SOC 2 is an attestation report, not a certificate. Overlap lives in controls and evidence; the artefacts stay different. Clauses 4–10 and the Annex A SoA still apply on the ISO side.

What this page is, and what it is not

Audience: a compliance lead facing mixed US and international asks.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.

“Both” is not a badge you owe the internet. It is extra cost for extra artefacts.

Buyer situations, justification, and overlap

Overlap means reusable evidence, not a single opinion that satisfies both issuers. Last verified 10 September 2026. Not legal advice.

When both artefacts may be justified (business decision, not a requirement; not legal advice; last verified 10 September 2026)
Buyer situationWhy both may be justifiedWhat overlapsKind of text
US enterprise wants SOC 2 Type II; EU group wants an ISO 27001 certificateEach artefact unblocks a different contract. Neither substitutes.Access, change, logging, vendor, and risk records can feed both.Market / contractual demand.
One strategic customer names both in the same security scheduleThe schedule is the driver. Confirm they will accept sequencing.Same operating evidence; two reporting wrappers.Contractual requirement if signed.
Investor or board wants “every logo”May be justified for fundraising optics — still a business choice, not a clause.Little extra security value if no buyer will read the second artefact.Internal preference — not a standard.
You already have SOC 2 and an international tender appearsIncremental cost is the ISMS documented information, SoA, internal audit, management review, and CB fees — not a second copy of every control.TSC-mapped evidence often maps into Annex A technological and organisational themes.Illustrative incremental-cost framing — not a quote.
You already have ISO 27001 and a US buyer asks for SOC 2Incremental cost is the CPA examination and TSC mapping, plus the Type II period.ISMS records help; they do not become a SOC 2 report.Attestation vs certification distinction.
No mixed buyers, only curiosityBoth is usually not justified yet.Nothing required to overlap.ShipReady Metrics recommendation: wait for a named ask.

Sequencing and incremental cost

There is no universally cheaper first step — and this page will not name one. Incremental cost of the second artefact is usually: extra documented information the first programme did not need, a second issuer’s fees, and calendar time (Type II period or Stage 1/2 plus IAF MD 5 days). Internal evidence collection is the overlapping saving. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for a both/and decision. Last verified 10 September 2026. Not legal advice.

  • Can we name a buyer for the SOC 2 report and a buyer for the ISO certificate?
  • Have we told the board this is a business decision, not a dual mandate from the standards?
  • Is overlap described as evidence reuse, not as “one audit equals both”?
  • Have we budgeted the second issuer (CPA or accredited CB) separately?
  • Is the SOC 2 reading list the live /guides/frameworks/soc-2 page?
  • Have we refused unpublished /docs/soc-2 links?

What to do now

These steps do not file.

  • Fill the situation table with your actual accounts.
  • Read the vs page if you still need the artefact definitions.
  • Read the cost and auditor-evidence pages before you staff a second programme.
  • If only one artefact is named, do not start the second.
  • Re-verify sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance crosswalks both frameworks to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass. The obligation map can mark both in-scope. Evidence collection and evidence review serve one evidence set to two programmes.

Human judgment, a CPA, and an accredited certification body remain required for the two artefacts.

Primary sources (last verified 10 September 2026)

AICPA SOC 2; ISO/IEC 27001:2022; ISO/IEC 27002:2022 as guidance for control implementation. Not legal advice.

Frequently asked questions