← All articles
ISO 27001 · SOC 2

SOC 2 vs ISO 27001: which one do you actually need?

Moonlight GRC · 8 min read

A prospect asks for your SOC 2 report. Another asks whether you are ISO 27001 certified. They sound like the same question and they are not. Here is the difference, in the terms that matter when you have to pick one.

The short answer

If your buyers are mostly American technology companies, SOC 2 is usually what they will ask for. If your buyers are European, or enterprise procurement teams anywhere outside the US, ISO 27001 is usually the expectation. If both describe you, start with the one your current pipeline is blocked on and add the second later — the underlying work overlaps heavily.

That is the whole decision for most companies. The rest of this article explains why, so you can defend the choice internally.

They are different kinds of thing

This is the distinction people miss. ISO 27001 is a certification against an international standard. An accredited certification body audits your management system and, if it conforms, issues a certificate. It is a pass/fail outcome against published requirements that are identical for everyone.

SOC 2 is an attestation report, not a certificate. A licensed CPA firm examines the controls you described and issues an opinion on whether those controls are suitably designed and — in a Type II — operating effectively. The output is a long report someone has to read, not a certificate you can put on a website. Two SOC 2 reports from two companies can cover quite different controls and both be perfectly valid.

So: ISO 27001 answers "does this company meet the standard?" SOC 2 answers "are this company's own stated controls real and working?"

What each one covers

ISO 27001 requires a full information security management system: scope, leadership commitment, risk assessment, a Statement of Applicability covering all 93 Annex A controls, internal audit, management review and continual improvement. The emphasis is on the system that produces security, not only the controls themselves.

SOC 2 is built on the AICPA Trust Services Criteria. Security is mandatory; availability, processing integrity, confidentiality and privacy are optional categories you include based on what you promise customers. You choose your scope, then get examined against it.

Type I, Type II, and the timing trap

SOC 2 comes in two flavours, and the difference matters for planning:

The trap: a Type II requires elapsed time with your controls genuinely running and generating evidence. You cannot compress it. If a deal closes in eight weeks and you have nothing in place, no amount of budget produces a Type II in time. ISO 27001 has a comparable constraint — auditors expect to see the system operating, including at least one internal audit and management review — so neither route is instant.

Both frameworks are really asking the same thing: can you show, with records, that what you claim about your security has been true for a while? Neither rewards a last-minute sprint.

How they compare in practice

Doing both without doing everything twice

The overlap is large. Access control, change management, vendor management, incident response, logging, HR security, encryption — the underlying practices satisfy both. What differs is the packaging: ISO 27001 wants the management-system wrapper, SOC 2 wants a control narrative and evidence samples for the examiner.

The efficient sequence for most companies is to build the ISO 27001 management system first and then map it onto the Trust Services Criteria, because the ISO structure is the stricter container and the mapping direction is easier. If a US deal is the immediate blocker, invert it — but design your controls from the start knowing ISO will follow, so you are not rebuilding governance a year later.

And if AI is part of your product

Neither framework was designed for AI-specific risk. If you build or deploy AI systems, buyers are starting to ask a third question — how you govern models, training data and automated decisions — which is what ISO 42001 addresses. It shares the same management-system structure as ISO 27001, so it slots in alongside rather than starting from zero. Our ISO 42001 guide covers what that involves.

Choosing, concretely

Ask three questions. Where are the customers who are currently blocked? What exactly did they ask for in writing — a certificate, or a report? And which one will still be right in two years given where you are selling next? Pick on that basis, not on which one looks cheaper. The wrong framework delivered perfectly still does not unblock the deal.

Not sure which one your buyers want?

Moonlight helps companies, entrepreneurs and teams of every size choose the right framework and get there — fully async, no unnecessary calls.

Start with a Gap Analysis