Skip to content

Resources/Comparisons/6 min read

Is ISO 27001 equivalent to SOC 2?

The short answer

ISO 27001 and SOC 2 are not equivalent. They overlap on roughly 80% of security controls, but ISO 27001 is an international certification standard governed by ISO and audited by accredited certification bodies, while SOC 2 is a US attestation framework governed by the AICPA and performed by licensed CPA firms. Most UK and European buyers ask for ISO 27001; most US enterprise buyers ask for SOC 2.

  • Steve ThomasCTO & Co-Founder

Last updated

No. They are cousins, not twins. ISO 27001 is an international certification standard for an information security management system (ISMS), governed by ISO and audited by accredited certification bodies. SOC 2 is a US attestation framework, governed by the AICPA, performed by licensed CPA firms, and built around five Trust Services Criteria. They overlap on perhaps 80% of security controls, but they differ in scope, geography, legal standing, output, and what your customers actually do with the result.

Both standards in brief

ISO/IEC 27001:2022 is a requirements standard. It tells you to build an ISMS covering risk assessment, policies, controls, internal audit, and management review (Clauses 4 through 10), then pick from 93 reference controls in Annex A [1]. A certification body (CB) accredited by a national body such as UKAS in the UK audits you in two stages, issues a three-year certificate, and returns annually for surveillance. At end-2024 there were 96,709 valid certificates worldwide, 4,455 of them in the UK [2].

SOC 2 is an attestation engagement defined by the AICPA's Trust Services Criteria (TSC) [3]. A CPA firm examines your controls against up to five categories: security (the only mandatory one), availability, processing integrity, confidentiality, and privacy. The output is a Type I report (point-in-time) or a Type II report (over a review period, usually 6 to 12 months). There is no central registry of SOC 2 reports and no single accreditation body; the CPA firm's licence and peer review process serve as the quality gate.

Side by side

DimensionISO 27001SOC 2
Governing bodyISO/IEC (international)AICPA (US)
Audit performed byAccredited certification bodyLicensed CPA firm
AccreditationUKAS (UK), ANAB (US), other IAF membersAICPA peer review programme
OutputCertificate (one page) + audit reportSOC 2 Type I or Type II report (80-200+ pages)
ScopeEntire ISMS, including management system clausesControls mapped to selected Trust Services Criteria
Control framework93 controls in Annex A (4 themes)Trust Services Criteria (5 categories, ~60+ points of focus)
Validity3-year cycle with annual surveillanceType II covers a stated review period; no fixed expiry, but buyers expect annual renewal
GeographyRecognised worldwide; dominant in UK, EU, Asia-PacificDominant in US; growing recognition in UK for US-facing SaaS
Cost (UK, small tech co)Roughly £8,000 to £20,000 all-in first year [4]Roughly £15,000 to £40,000 for a Type II, depending on scope and CPA firm [5]
Legal/regulatory weightReferenced in UK GDPR (Article 32), NIS2, DORA, many procurement frameworksNot directly referenced in UK or EU regulation

Overlap

The overlap is genuine. Both frameworks want you to run risk assessments, enforce access controls, manage incidents, handle vendor risk, and maintain audit trails. A 2017 mapping by the AICPA itself showed that an organisation meeting ISO 27001 Annex A controls would satisfy a large share of the SOC 2 security criterion [6]. If you already have one, the marginal cost of adding the other drops significantly because you are not building controls from scratch, just mapping them to a second framework and sitting a second audit.

I have audited companies that hold both, and in practice the risk register, the access reviews, the incident log, and the change management process are the same artefacts. What changes is the shape of the audit: an ISO 27001 auditor checks whether your ISMS meets the requirements in Clauses 4 to 10 and whether you have implemented the controls declared in your Statement of Applicability (SoA), while a SOC 2 auditor tests whether specific controls operated effectively over the review period and describes any exceptions in the report.

Differences

The differences matter more than the overlap if you are deciding which to pursue first.

Certification vs attestation. ISO 27001 gives you a certificate: a binary pass/fail. Either the CB issues it or it does not. SOC 2 gives you a report with an opinion, and that opinion can be qualified or unqualified. A qualified SOC 2 opinion means the auditor found exceptions, and your customer gets to read exactly what those exceptions were. An ISO 27001 certificate, by contrast, does not show your customer the audit findings; it just confirms you met the standard.

Management system vs controls testing. ISO 27001 requires you to run an ISMS, which means management review, internal audit, continual improvement, documented objectives, and leadership commitment (Clauses 5 through 10). SOC 2 does not require a formal management system. You can pass a SOC 2 audit with good controls and no management review, but you cannot pass an ISO 27001 audit without one.

Geography and buyer expectations. In the UK and Europe, ISO 27001 is the default ask. UK government procurement frameworks reference it. The ICO has cited it as evidence of appropriate technical and organisational measures under UK GDPR Article 32 [7]. SOC 2 is rarely requested by UK buyers unless they are subsidiaries of US companies. In the US, the reverse is true: enterprise buyers and their procurement teams ask for SOC 2, and ISO 27001 is a bonus rather than a requirement.

Regulatory recognition. ISO 27001 is explicitly mentioned in the EU's NIS2 Directive (Article 21) as a relevant standard for cybersecurity risk management [8]. It is also referenced in DORA for financial entities. SOC 2 has no equivalent regulatory standing outside the US.

Which one to get first

For a mostly UK or European customer base, start with ISO 27001; for a mostly US enterprise base, start with SOC 2. If your customers are split, ISO 27001 still makes the better foundation because the management system requirements force you to build the governance layer that SOC 2 does not demand, and mapping an existing ISMS to Trust Services Criteria is a well-trodden path.

At Calibre we handle the ISO 27001 side, and for SOC 2 you will need a CPA firm. The good news is that if you build your ISMS properly the first time, the SOC 2 readiness gap is usually a few weeks of control mapping and a review period, not a second full implementation. I have seen teams go from ISO 27001 certificate to SOC 2 Type II in under six months.

For a detailed look at how much ISO 27001 costs in the UK, the 93 Annex A controls, or whether SOC 2 is recognised in the UK, the linked articles go deeper.

FAQ

It depends on who is asking. A UK or European customer will almost always accept ISO 27001. A US enterprise procurement team usually wants SOC 2 specifically. Some will accept either, but you should ask rather than assume.

Only if your customer base spans both sides of the Atlantic and those customers specifically require each one. Many UK-based SaaS companies selling into the US hold both. If you are only selling domestically, ISO 27001 alone is usually sufficient.

Roughly 80% of the security controls map across. The remaining gap is mostly structural: ISO 27001's management system requirements (internal audit, management review, documented ISMS scope) have no direct SOC 2 equivalent, while SOC 2's availability and processing integrity criteria go into operational detail that ISO 27001 covers more broadly.

ISO 27001 has a higher governance bar because of the ISMS requirements. SOC 2 Type II has a longer evidence-gathering period because the auditor needs to see controls operating over time, usually 6 to 12 months. Neither is harder overall; they test different things.

Sources

  1. 1.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection. Information security management systems. Requirements". https://www.iso.org/standard/27001
  2. 2.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
  3. 3.AICPA. (2017). "Trust Services Criteria (SOC 2)". https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services
  4. 4.High Table. (2026). "ISO 27001 Cost Guide 2026". https://hightable.io
  5. 5.Vanta. (2025). "How Much Does SOC 2 Compliance Cost?". https://www.vanta.com/resources/how-much-does-soc-2-cost
  6. 6.AICPA. (2017). "Mapping of AICPA Trust Services Criteria to ISO 27001". https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services
  7. 7.Information Commissioner's Office. (2024). "Guide to the UK GDPR: Security". https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/
  8. 8.European Parliament and Council. (2022). "Directive (EU) 2022/2555 (NIS2), Article 21". https://eur-lex.europa.eu/eli/dir/2022/2555

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.