SOC 2 vs ISO 27001: which one do you actually need?
A prospect asks for your SOC 2 report. Another asks whether you are ISO 27001 certified. They sound like the same question and they are not. Here is the difference, in the terms that matter when you have to pick one.
The short answer
If your buyers are mostly American technology companies, SOC 2 is usually what they will ask for. If your buyers are European, or enterprise procurement teams anywhere outside the US, ISO 27001 is usually the expectation. If both describe you, start with the one your current pipeline is blocked on and add the second later — the underlying work overlaps heavily.
That is the whole decision for most companies. The rest of this article explains why, so you can defend the choice internally.
They are different kinds of thing
This is the distinction people miss. ISO 27001 is a certification against an international standard. An accredited certification body audits your management system and, if it conforms, issues a certificate. It is a pass/fail outcome against published requirements that are identical for everyone.
SOC 2 is an attestation report, not a certificate. A licensed CPA firm examines the controls you described and issues an opinion on whether those controls are suitably designed and — in a Type II — operating effectively. The output is a long report someone has to read, not a certificate you can put on a website. Two SOC 2 reports from two companies can cover quite different controls and both be perfectly valid.
So: ISO 27001 answers "does this company meet the standard?" SOC 2 answers "are this company's own stated controls real and working?"
What each one covers
ISO 27001 requires a full information security management system: scope, leadership commitment, risk assessment, a Statement of Applicability covering all 93 Annex A controls, internal audit, management review and continual improvement. The emphasis is on the system that produces security, not only the controls themselves.
SOC 2 is built on the AICPA Trust Services Criteria. Security is mandatory; availability, processing integrity, confidentiality and privacy are optional categories you include based on what you promise customers. You choose your scope, then get examined against it.
Type I, Type II, and the timing trap
SOC 2 comes in two flavours, and the difference matters for planning:
- Type I assesses whether controls are suitably designed at a single point in time. Faster to obtain, but sophisticated buyers increasingly treat it as a placeholder.
- Type II assesses whether controls actually operated effectively across an observation window — commonly three to twelve months. This is what most buyers mean when they say "send us your SOC 2".
The trap: a Type II requires elapsed time with your controls genuinely running and generating evidence. You cannot compress it. If a deal closes in eight weeks and you have nothing in place, no amount of budget produces a Type II in time. ISO 27001 has a comparable constraint — auditors expect to see the system operating, including at least one internal audit and management review — so neither route is instant.
Both frameworks are really asking the same thing: can you show, with records, that what you claim about your security has been true for a while? Neither rewards a last-minute sprint.
How they compare in practice
- Geography. SOC 2 dominates in the United States. ISO 27001 is the global default and is what European, UK, Middle East and APAC procurement teams typically request.
- Who audits you. SOC 2: a CPA firm. ISO 27001: an accredited certification body.
- What you hand a customer. SOC 2: a confidential report, usually under NDA. ISO 27001: a public certificate plus, on request, your scope statement.
- Renewal rhythm. SOC 2 reports cover a defined window, so most companies repeat annually to avoid a coverage gap. ISO 27001 certificates run on a three-year cycle with surveillance audits in between.
- Flexibility. SOC 2 lets you define the control set. ISO 27001 fixes the requirements but lets you justify which Annex A controls apply to you.
Doing both without doing everything twice
The overlap is large. Access control, change management, vendor management, incident response, logging, HR security, encryption — the underlying practices satisfy both. What differs is the packaging: ISO 27001 wants the management-system wrapper, SOC 2 wants a control narrative and evidence samples for the examiner.
The efficient sequence for most companies is to build the ISO 27001 management system first and then map it onto the Trust Services Criteria, because the ISO structure is the stricter container and the mapping direction is easier. If a US deal is the immediate blocker, invert it — but design your controls from the start knowing ISO will follow, so you are not rebuilding governance a year later.
And if AI is part of your product
Neither framework was designed for AI-specific risk. If you build or deploy AI systems, buyers are starting to ask a third question — how you govern models, training data and automated decisions — which is what ISO 42001 addresses. It shares the same management-system structure as ISO 27001, so it slots in alongside rather than starting from zero. Our ISO 42001 guide covers what that involves.
Choosing, concretely
Ask three questions. Where are the customers who are currently blocked? What exactly did they ask for in writing — a certificate, or a report? And which one will still be right in two years given where you are selling next? Pick on that basis, not on which one looks cheaper. The wrong framework delivered perfectly still does not unblock the deal.
Not sure which one your buyers want?
Moonlight helps companies, entrepreneurs and teams of every size choose the right framework and get there — fully async, no unnecessary calls.
Start with a Gap Analysis