Compliance · SOC 2 · ISO 27001SOC 2 vs ISO 27001: which should you get first?

CISA · AWS Solutions Architect Professional · 27 Jul 2026
Both prove you take security seriously, but they're built for different audiences. SOC 2 is a US-market attestation; ISO 27001 is an international certification. Which you need depends on who's asking.
The short answer
SOC 2 is a US-centric attestation report an auditor writes about your controls; ISO 27001 is an internationally recognised certification of your information security management system (ISMS). If your buyers are US SaaS companies, they'll ask for SOC 2. If they're European, Middle Eastern or global enterprises, they'll ask for ISO 27001.
Side by side
| Dimension | SOC 2 | ISO 27001 |
|---|
| What it is | Attestation report (Type 1 or Type 2) | Certification against a standard |
| Geography | US market default | International default |
| Who asks | US SaaS & enterprise buyers | EU, UK, UAE, global enterprises |
| Output | A report shared under NDA | A public certificate |
| Basis | Trust Services Criteria | ISMS + Annex A controls |
| Cycle | Type 2 covers a 3–12 month window | 3-year cycle, annual surveillance |
Who asks for which
It's almost always market-driven, not preference-driven:
- Selling to US SaaS or fintech → SOC 2 Type 2.
- Selling to EU/UK/UAE enterprises or on public tenders → ISO 27001.
- Selling to both → you'll eventually need both.
Cost & timeline
SOC 2 Type 1 is usually the fastest and cheapest to start — a point-in-time attestation you can often reach in weeks, which unblocks a stalled deal. SOC 2 Type 2 then adds an observation window. ISO 27001 takes longer up front because you must stand up and run an ISMS before the Stage 1 and Stage 2 audits, but its controls overlap heavily with SOC 2.
How to sequence them
- Deal blocked now by a US buyer? Start with SOC 2 Type 1, then Type 2.
- Going after EU/global from the start? Build the ISO 27001 ISMS — it also covers most of SOC 2.
- Need both? Implement one AWS control set and map it to both frameworks; don't run two programmes.
My take after 16 years
Neither is 'better'. The mistake is treating either as a paperwork exercise. Build the controls for real in AWS — IAM, KMS, CloudTrail, Config — and both a SOC 2 auditor and an ISO 27001 assessor can trace evidence in minutes. One control set, two outcomes.
## What each one actually certifies
Much of the confusion between these two dissolves once you notice they are different kinds of thing, not two brands of the same thing.
SOC 2 is an attestation report. A licensed CPA firm examines controls you defined and issues an opinion on them. You choose the scope and the applicable Trust Services Criteria, and the report describes those controls and whether they were suitably designed — and for Type 2, whether they operated across a period. There is no pass mark and no certificate; there is a report, and a sophisticated buyer reads it rather than filing it.
ISO 27001 is a certification against a standard. An accredited certification body assesses whether you operate an information security management system meeting the standard's requirements. The output is a certificate with a scope statement, valid for three years with surveillance audits in between. The emphasis is on the management system — risk assessment, objectives, internal audit, management review — rather than on a control list.
The practical consequence: SOC 2 asks "did you run the controls you said you would?", ISO 27001 asks "do you have a functioning system for deciding which controls you need and keeping them working?" That is why ISO tends to feel heavier on process and SOC 2 heavier on evidence.
## The overlap is larger than the difference
Because both ultimately concern the same security fundamentals, the implementation work is largely shared. Access control, encryption, logging and monitoring, change management, incident response, vendor management, business continuity and secure development appear in both.
What genuinely differs is the wrapper. ISO 27001 additionally requires a documented risk assessment methodology applied consistently, a Statement of Applicability justifying every Annex A control you include or exclude, internal audits, and management review with recorded outputs. Those are real work and they are also, in my experience, the parts organisations benefit from most — a Statement of Applicability forces decisions that otherwise stay vague.
SOC 2's distinctive demand is evidence density over a period. Every control needs a durable, dated artefact for each occurrence across the observation window. ISO's surveillance model samples rather than requiring continuous proof, which feels lighter month to month.
If you build the technical controls once and instrument evidence properly, the incremental cost of the second framework is mostly documentation and mapping — commonly a third or less of the first, though that depends heavily on how well the first was done.
## Misconceptions worth clearing up
Five that come up in nearly every conversation.
"ISO 27001 is the international one, SOC 2 is American." Broadly true as a demand pattern, misleading as a rule. Plenty of US enterprises accept ISO; plenty of European buyers ask for SOC 2 because their own vendors do. Ask your actual pipeline rather than reasoning from geography.
"SOC 2 is easier." Not inherently — it is differently shaped. A Type 2 with several criteria and a twelve-month window is not a light exercise, and the observation period means calendar time you cannot compress.
"We can reuse the SOC 2 report for ISO." The controls and evidence transfer substantially; the report does not. Certification requires the management system, and no amount of SOC 2 evidence substitutes for a risk methodology, a Statement of Applicability and internal audit.
"Certification means we are secure." Both attest to a defined scope. A narrow scope produces a clean result over a small surface. This is why sophisticated buyers read the scope statement first — and why you should read your vendors'.
"We need both to sell." Rarely true at the start. Most companies need whichever one their current buyers ask for, and adding the second when demand appears rather than in anticipation.
## Doing both without doing everything twice
If you know both are coming, the sequencing that wastes least is straightforward.
Build the technical controls once, on the assumption they must satisfy the stricter reading of either framework. Instrument evidence collection from the start so artefacts accumulate automatically rather than being assembled per audit. Write the risk assessment and Statement of Applicability early even if ISO is the later goal — the discipline improves SOC 2 scoping as a side effect, because it forces you to articulate what is in scope and why.
Then choose which to certify first based on which unblocks revenue soonest, and treat the second as a mapping and documentation exercise rather than a fresh programme. Running them as two independent projects — separate consultants, separate control sets, separate evidence — is the expensive path and it is depressingly common.
Related: AWS compliance controls mapping for the control-level detail, how to pass SOC 2 Type 2, and ISO 27001 implementation.
Common questions
Is SOC 2 or ISO 27001 better?
Neither - it depends on your market. US SaaS buyers ask for SOC 2; EU, UK, UAE and global enterprises ask for ISO 27001. Many companies eventually need both.
Can I do both SOC 2 and ISO 27001?
Yes. The control sets overlap by roughly 80 percent, so you implement one set of AWS controls and map it to both frameworks rather than running two separate programmes.
Which is cheaper to start?
SOC 2 Type 1 is usually the fastest and cheapest to reach because it is a point-in-time attestation; ISO 27001 takes longer up front because you must stand up and operate an ISMS first.
Which do enterprise buyers ask for more often?
In North American software sales, SOC 2 Type 2 dominates. In Europe, the Middle East and much of Asia, ISO 27001 is more frequently named, and in regulated sectors it is sometimes the only one recognised. The reliable method is to look at the last ten security questionnaires you received rather than at general advice.
How much does the second one cost after the first?
Substantially less if the first was built properly — commonly a third or less, concentrated in documentation and mapping rather than engineering. Substantially more if the first was achieved through manual evidence gathering, because none of that effort compounds.
Can the same firm do both?
Not usually. SOC 2 requires a licensed CPA firm; ISO 27001 certification requires an accredited certification body. Some organisations hold both accreditations, but they are distinct qualifications — verify rather than assume, and be sceptical of any provider offering to both prepare you and certify you.
Is there a point in doing neither?
Yes, if nobody is asking. Both are responses to buyer or regulator demand. If neither exists yet, the useful work is building controls in the right shape — SSO, least privilege, centralised immutable logging, code review, tested backups — which is good engineering regardless and turns a future audit from a project into a formality.