Yes, but it is not the first thing a UK buyer asks for. SOC 2 is an American attestation framework governed by the AICPA, and it carries real weight with US-headquartered customers, investors, and enterprise procurement teams. In UK procurement, ISO 27001 is the default expectation. If you are a UK company selling into both markets, you may end up holding both, and the overlap is larger than most people assume.
SOC 2 in brief
SOC 2 (Service Organisation Control 2) is an attestation report issued by a licensed CPA firm against the AICPA's Trust Services Criteria [1]. It comes in two flavours: a Type I report confirms your controls existed at a point in time, while a Type II report confirms they existed and operated effectively over a period, usually six to twelve months. Type II is the one buyers care about; a Type I is a stepping stone, not a destination.
The Trust Services Criteria cover five categories (security, which is mandatory, plus availability, processing integrity, confidentiality, and privacy), and you choose which apply to your service. Most SaaS companies include security plus one or two others.
Unlike an ISO 27001 certificate, a SOC 2 report is a 60-to-120-page document containing the auditor's opinion, a management assertion, a description of your system, and the test results, shared under NDA through a trust centre or a sales-team handoff rather than displayed publicly.
UK buyer expectations
In our experience auditing UK tech companies, roughly one in five already holds or is pursuing SOC 2, almost always because a US customer put it on a vendor questionnaire. UK-headquartered buyers rarely ask for it. What they ask for is ISO 27001, and increasingly Cyber Essentials Plus for government supply-chain work [2].
Public-sector procurement in the UK leans heavily on ISO 27001. The National Cyber Security Centre references it in its cloud security guidance [3], and the Crown Commercial Service's G-Cloud framework treats an ISO 27001 certificate as a recognised signal of information security maturity. SOC 2 is not mentioned in most UK government frameworks we have reviewed.
That said, UK fintech and healthtech companies selling to US banks or US hospital groups will hear "send us your SOC 2" in the first procurement call. The standard is deeply embedded in US enterprise buying. Ignoring it means losing deals or spending weeks filling in bespoke security questionnaires that a SOC 2 report would have answered in one PDF.
Overlap
The overlap between ISO 27001 and SOC 2 is significant: both require risk assessment, access controls, incident management, change management, vendor management, and monitoring. A 2022 mapping by the AICPA itself showed that roughly 80% of the Trust Services Criteria map to ISO 27001 Annex A controls or management-system clauses [4].
The practical difference is in how they work:
| ISO 27001 | SOC 2 Type II | |
|---|---|---|
| Issued by | Accredited certification body | Licensed CPA firm |
| Output | Certificate (public) | Attestation report (shared under NDA) |
| Governing body | ISO/IAF/UKAS | AICPA |
| Scope | Your ISMS, which you define | Your system and the TSC you select |
| Audit cycle | Stage 1 + Stage 2, then annual surveillance | Annual Type II report, typically 3-12 month observation window |
| UK recognition | Default in UK procurement | Recognised, not default |
| US recognition | Understood, not default | Default in US enterprise procurement |
| Validity | 3-year certificate with annual audits | Report covers a stated period; no ongoing "validity" |
If you already have ISO 27001, a good chunk of your evidence (policies, risk register, access reviews, incident logs) carries straight across to a SOC 2 engagement. The CPA firm will still test it independently, but you are not starting from scratch. We have seen companies add SOC 2 in eight to twelve weeks on top of an existing ISMS, versus six months from a standing start.
Carrying both
You probably need both if all three of these are true: you sell to US enterprise customers who require SOC 2, you sell to UK mid-market or public-sector buyers who expect ISO 27001, and losing either pipeline would materially hurt revenue. That describes a large number of UK SaaS companies in the £2m-£20m ARR range.
If you are pre-revenue or early stage and your customers are entirely UK-based, start with ISO 27001, which is the more portable credential internationally with 96,709 valid certificates across 179,877 sites worldwide at end-2024 [5]. SOC 2, by contrast, is almost exclusively a US and Canadian market signal.
If your entire customer base is US enterprise and you have no UK public-sector ambitions, SOC 2 alone may be sufficient for now, but know that it will not satisfy a UK regulator or an EU partner asking about NIS2 readiness.
Cost comparison
SOC 2 Type II engagements in the UK typically run £15,000 to £40,000 per year for the CPA firm's fees, depending on scope and company size [6]. That is on top of whatever you spend on ISO 27001 certification. The internal effort overlaps significantly if you run them from the same control set, but the audit fees do not, because you are paying two separate firms under two separate frameworks.
At Calibre, we handle the ISO 27001 side. We cannot issue a SOC 2 report (that requires a CPA firm), but we have seen plenty of clients run both programmes in parallel, and the companies that build their ISMS properly the first time find SOC 2 readiness comes almost as a side effect.
For a detailed breakdown of ISO 27001 costs, see our guide on how much ISO 27001 costs in the UK.
FAQ
In private-sector sales, sometimes. A sophisticated UK buyer may accept a SOC 2 Type II report as evidence of your security controls. In public-sector procurement or regulated industries, no. ISO 27001 is the expected standard, and a SOC 2 report is not a substitute for an accredited certificate.
Not formally. They cover similar ground, and roughly 80% of the Trust Services Criteria map to ISO 27001 controls [4], but they are governed by different bodies, audited by different types of firm, and produce different outputs. See our comparison of ISO 27001 vs SOC 2 for a detailed breakdown.
Yes. A SOC 2 Type II report covers a defined observation period. Once that period ends, the report goes stale. Most companies commission a new report annually. ISO 27001 works differently: you get a three-year certificate with annual surveillance audits.
If you are a UK company, start with ISO 27001. It is recognised globally, satisfies UK procurement requirements, and gives you a reusable evidence base for SOC 2 later. If your very first paying customer is a US bank that will not sign without SOC 2, pragmatism wins.
Sources
- 1.AICPA. (2017). "TSP Section 100: 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy". https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services
- 2.National Cyber Security Centre. (2025). "Cyber Essentials: Requirements for IT Infrastructure". https://www.ncsc.gov.uk/cyberessentials/overview
- 3.National Cyber Security Centre. (2024). "Cloud Security Guidance". https://www.ncsc.gov.uk/collection/cloud-security
- 4.AICPA. (2022). "SOC 2 Trust Services Criteria and ISO 27001 Mapping". https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services
- 5.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
- 6.High Table. (2026). "SOC 2 Cost Guide 2026". https://hightable.io

