ISO 27001 is a certifiable international standard, governed by ISO and audited by an accredited certification body (CB), and it produces a certificate. SOC 2 is a US attestation engagement, governed by the AICPA and performed by a licensed CPA firm, and it produces a detailed report. Both prove you take security seriously, but they come from different worlds, follow different rules, and land differently depending on who is asking for them.
We have audited organisations that hold both, organisations that picked one and regretted it, and organisations that picked one and were perfectly fine. The right choice depends on your market, not on which framework is "better".
At a glance
| Dimension | ISO/IEC 27001:2022 | SOC 2 (Type I or Type II) |
|---|---|---|
| Governing body | ISO/IEC (standard); IAF/national accreditation bodies like UKAS (oversight) | AICPA (criteria and guidance) |
| Standard or criteria | ISO/IEC 27001:2022 clauses 4-10 plus Annex A (93 controls) [1] | Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, Privacy [2] |
| Scope | Your defined ISMS scope, which can be the whole organisation or a subset | Specific system(s) or service(s) you define |
| Geography | International, recognised in 170+ countries; strongest pull in UK, EU, APAC, Middle East | Primarily US; growing recognition elsewhere, but not the default ask outside North America |
| Who audits | Accredited certification body (e.g. UKAS-accredited in the UK) | Licensed CPA firm (or firm supervised by a CPA) |
| Audit output | A certificate (one page) plus a Stage 1 and Stage 2 audit report | A SOC 2 report (typically 60-150 pages) with the auditor's opinion and detailed control descriptions |
| Type I vs Type II | No equivalent split; the Stage 2 audit always tests operating effectiveness | Type I: controls designed and in place at a point in time. Type II: controls operating effectively over a period (usually 3-12 months) |
| Validity | 3-year certificate cycle with annual surveillance audits [3] | Report covers a defined period; most customers expect a new Type II annually |
| Public availability | The certificate itself is often shared freely; the audit report is confidential to the CB and client | The report is confidential, shared under NDA with customers and prospects on request |
| Typical UK cost (first year) | £8,000-£40,000 all-in for a small to mid tech company [4] | £15,000-£50,000 for a Type II engagement from a UK-based CPA firm, though US firms may price differently |
| Time to achieve | 3-9 months for a small company from standing start to certificate [4] | 3-6 months to get controls in place, then 3-12 months observation window for Type II |
| Renewal | Surveillance audits in years 1 and 2, recertification in year 3 | New engagement each period; no formal "recertification" |
ISO 27001 requirements
ISO 27001 is a management system standard. It requires you to build an information security management system (ISMS): define a scope, identify interested parties, run a risk assessment, treat the risks, implement controls, monitor performance, run internal audits, hold management reviews, and improve. The 93 controls in Annex A are a reference set; you select which apply through your Statement of Applicability (SoA) [1].
The certification audit runs in two stages: Stage 1 checks your documentation and readiness, and Stage 2, usually a few weeks later, tests whether the system works in practice. An accredited CB like Calibre issues the certificate if you pass, then returns for surveillance audits each year and a full recertification at the three-year mark [3].
The standard is prescriptive about what you must do (run a risk assessment, have a policy, conduct internal audits) but flexible about how. We have seen a perfectly adequate ISMS run out of a Notion workspace and a Google Sheet, and we have also seen one collapse under the weight of a 200-page policy suite that nobody reads.
For a deeper look at what goes into the standard, see the requirements overview and the Annex A control breakdown.
SOC 2 requirements
SOC 2 is an attestation engagement under AT-C Section 205 and AT-C Section 320, using the AICPA's Trust Services Criteria (TSC) [2]. The Security criterion (sometimes called the Common Criteria) is mandatory. The other four (Availability, Processing Integrity, Confidentiality, Privacy) are optional, and you choose which are relevant to your service.
There is no fixed control list: the TSC describes criteria (outcomes), and you define your own controls to meet them. A CPA firm then tests those controls, either at a single point in time for a Type I report or over a review period of typically six to twelve months for a Type II.
The output is a detailed report rather than a certificate, covering a description of your system, the controls you implemented, the tests the auditor performed, and the results. Customers read it under NDA, and there is no central registry, no accreditation body oversight in the ISO sense, and no public certificate to wave around.
One practical difference we notice: because you define your own controls, two SOC 2 reports can look very different even if both companies are roughly the same size doing roughly the same thing. ISO 27001 certificates, by contrast, all trace back to the same 93-control reference list, which makes comparison easier for the buyer.
Geographic weight
This is the question that actually matters for most founders. Not "which is better?" but "which one will my customers accept?"
ISO 27001 is the default ask in the UK, the EU, the Middle East, much of Asia-Pacific, and increasingly in regulated sectors globally. If your customers are UK or European enterprises, government bodies, or financial services firms, ISO 27001 is what they put in procurement questionnaires. The UK had 4,455 valid certificates at end-2024, making it the fourth-largest national market [5]. The NHS Data Security and Protection Toolkit, for instance, maps heavily to ISO 27001 controls.
SOC 2 is the default ask in the US, particularly among SaaS companies selling to other SaaS companies. If you are a UK company selling into the US market, American procurement teams will ask for your SOC 2 Type II. Some will accept ISO 27001 instead, especially in regulated industries that understand international standards, but many mid-market US buyers have SOC 2 baked into their vendor assessment template and do not know what to do with an ISO certificate.
If you sell into both markets, you will probably need both eventually. The good news is that the overlap is substantial (we would estimate 60-70% of the control evidence), so the second one is cheaper and faster than the first.
Control overlap
Both frameworks care about the same security fundamentals: access control, encryption, incident response, change management, vendor management, business continuity, HR security, physical security. The language differs, the structure differs, but the actual controls you implement are largely the same.
Where they diverge:
- ISO 27001 requires a formal risk assessment methodology (clause 6.1.2) and a documented risk treatment plan. SOC 2 expects risk management but is less prescriptive about the method.
- ISO 27001 mandates internal audits (clause 9.2) and management reviews (clause 9.3). SOC 2 has no equivalent requirement, though most organisations doing SOC 2 run internal reviews anyway.
- SOC 2's Availability and Processing Integrity criteria go deeper into uptime, recovery, and data processing accuracy than Annex A typically demands. If your customers care about SLA commitments, this matters.
- ISO 27001 requires documented information (policies, procedures, records) in a way that SOC 2 does not mandate, though the CPA firm will want evidence of your controls, which amounts to much the same thing in practice.
A company that has already achieved ISO 27001 will find a SOC 2 engagement relatively straightforward, because the ISMS documentation, risk register, and control evidence translate directly. Going the other direction is slightly harder, because SOC 2 does not force you to build the management system scaffolding (scope, interested parties, risk methodology, internal audit programme) that ISO 27001 demands.
Which to get first
Our advice, which we give to most UK-based tech companies:
If your primary market is UK or European enterprises: Start with ISO 27001. It is the more widely recognised credential on this side of the Atlantic, it produces a certificate you can show publicly, and it builds the management system that makes a subsequent SOC 2 engagement easier. At Calibre, we work with a lot of SaaS companies that need to answer UK enterprise procurement questions first and worry about the US market later.
If your primary market is US SaaS: Start with SOC 2 Type II. US buyers expect it, the Type I gives you something to show within a few months, and you can layer ISO 27001 on top when the European deals start coming in.
If you sell equally into both: ISO 27001 first, then SOC 2. The ISMS gives you the systematic foundation, the documentation is reusable, and the certification is perpetual (renewed, not re-earned from scratch each year). SOC 2 then becomes a reporting exercise on top of controls you already run.
If a specific deal is driving the decision: Get whichever one the customer is asking for. Compliance is a commercial tool. Use it commercially.
Cost comparison
For a small UK tech company (10-50 staff), expect roughly:
| Cost element | ISO 27001 | SOC 2 Type II |
|---|---|---|
| Certification/audit fees | £4,000-£12,000 [4] | £15,000-£35,000 (CPA firm fees) |
| Consultant or platform | £5,000-£20,000 | £5,000-£15,000 |
| Internal time | 100-300 hours | 80-200 hours |
| Annual maintenance | £3,000-£8,000 (surveillance) | £12,000-£30,000 (new engagement) |
SOC 2 tends to be more expensive year-on-year because each annual report is a fresh engagement, not a surveillance audit. ISO 27001's three-year cycle with lighter surveillance audits in years one and two is generally cheaper to maintain.
For more detail on the ISO 27001 cost side, see how much ISO 27001 costs in the UK.
FAQ
Sometimes. Some US companies accept ISO 27001 as equivalent, particularly in financial services and healthcare. But many mid-market US SaaS buyers have SOC 2 hardcoded into their vendor review. Ask the customer. If they say "we need SOC 2", they mean SOC 2.
Not formally. They have different governing bodies, different scopes, and different outputs. The security controls overlap significantly, but neither is a subset of the other. Holding one does not exempt you from the other. For a closer look, see is ISO 27001 equivalent to SOC 2.
It is understood by UK companies that sell to US customers or work with US partners, but it is not the standard UK procurement teams ask for. UK enterprises, government, and the NHS default to ISO 27001. If a UK customer asks for SOC 2 specifically, they probably have a US parent company. See is SOC 2 recognised in the UK.
Yes, and many companies do. The evidence collection overlaps substantially. Some consultancies offer combined readiness programmes. The audit engagements themselves are separate (different auditors, different standards), but you can schedule them close together and reuse most of the documentation.
Neither is inherently harder: ISO 27001 has more documentation requirements, while SOC 2 Type II requires a longer observation period before you get the report. In our experience, the difficulty depends more on how mature your security practices already are than on which framework you choose.
Sources
- 1.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
- 2.AICPA. (2017). "Trust Services Criteria (With Revised Points of Focus - 2022)". https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/trustservicescriteria
- 3.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
- 4.High Table. (2026). "ISO 27001 Certification Cost Guide 2026". https://hightable.io/iso-27001-cost/
- 5.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
- 6.AICPA. (2024). "AT-C Section 205: Examination Engagements". https://us.aicpa.org/research/standards/auditattest/ssae
- 7.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026

