Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

SOC 2 vs ISO 27001: which do you need?

Last verified

Need SOC 2 when buyers want a CPA attestation report against the AICPA Trust Services Criteria. Need ISO/IEC 27001 when they want an accredited ISMS certificate. They are different artefacts. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Comparison, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. SOC 2 is not a certificate. No “better than.” Clauses 4–10 vs Annex A still apply only on the ISO side. The live SOC 2 help page on this site is the What Is SOC 2 companion.

What this page is, and what it is not

Audience: a founder choosing a first assurance artefact.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.

It does not say one framework is better. It maps dimensions so you can match the artefact to the buyer.

Side-by-side dimensions

Read each row as a difference in kind, not a score. Last verified 10 September 2026. Not legal advice.

SOC 2 compared with ISO/IEC 27001 (not a ranking; not legal advice; last verified 10 September 2026)
DimensionSOC 2ISO/IEC 27001Kind of text
What you receiveA CPA attestation report (opinion) against the AICPA Trust Services Criteria.An accredited certificate against the ISMS standard (Clauses 4–10, Annex A via SoA).Attestation criteria vs certification standard.
Who issues itA licensed CPA / firm performing the examination.An IAF-MLA accredited certification body (ISO/IEC 17021-1, ISO/IEC 27006).Professional attestation vs accredited certification.
Typical buyer geographyOften US enterprise SaaS questionnaires and vendor reviews.Often EU and other international tenders and group security reviews.Market convention — not a law.
Legal characterNot a statute. Demand is usually contractual.Voluntary standard, not a law. Demand is usually contractual or market.Neither is a legal mandate from this page.
Time and cost (illustrative)Type I vs Type II period drives elapsed time; fees plus internal effort.Stage 1/2 plus a typical three-year cycle; IAF MD 5 influences audit days.Illustrative commercial comparison — not quotes, not “cheaper.”
Which first (decision, not a rule)If every named buyer asked for SOC 2 and none asked for ISO 27001.If a named tender or international buyer asked for the certificate.ShipReady Metrics recommendation is to follow the written ask.

Decision tree

1. List the last written security asks. 2. If they name SOC 2 only, start with SOC 2. 3. If they name ISO 27001 only, start with the ISMS and an accredited body. 4. If they name both, read the both page — that is a business decision, not a requirement of either text. 5. If they say “certification” loosely, ask which artefact they will accept. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for the choice. Last verified 10 September 2026. Not legal advice.

  • Have we written down the exact artefact each buyer named?
  • Are we describing SOC 2 as a report and ISO 27001 as a certificate?
  • Have we avoided “better than” language in the board slide?
  • Is the SOC 2 explainer we share the live /guides/frameworks/soc-2 page?
  • If ISO is in play, is the body IAF-MLA accredited?
  • Have we accepted that this page does not determine YOUR obligations?

What to do now

These steps do not file and do not start a clock.

  • Export the last five security questionnaires and highlight the artefact named.
  • Read the both page if the list is mixed.
  • Read what ISO 27001 is if the ISMS concept is still fuzzy.
  • Read the live SOC 2 framework guide for the attestation side.
  • Re-verify AICPA and ISO sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance holds both frameworks in the 24-framework library, crosswalked to shared canonical controls (Annex A to about 72) with a crosswalk-density honesty layer — coverage, not a pass. Evidence can be reused; the artefacts remain different.

A CPA still issues the SOC 2 report. An accredited certification body still issues the ISO certificate.

Primary sources (last verified 10 September 2026)

AICPA SOC 2 topic page; ISO/IEC 27001:2022; ISO/IEC 17021-1; IAF. Not legal advice. Not a ranking.

Frequently asked questions