In this article:

ISO 27001 vs SOC 2: Which Do You Need?

Compliance
/
July 17, 2026
ISO 27001 vs SOC 2: Which Do You Need?

Sell to US enterprises and the answer is SOC 2. Sell into European or global procurement and the answer is ISO 27001. The decision belongs to your customers more than to you: the framework worth buying is the one your buyers ask for by name, and they ask along geographic lines. US enterprise security reviews are built around the SOC 2 report. EU, UK, and much of APAC procurement, along with government-adjacent buyers worldwide, file an ISO 27001 certificate instead. If your pipeline contains both kinds of logo, you will probably end up with both frameworks, and the overlap between them is large enough that the second one typically costs 40 to 60 percent less than the first.

One is a report, the other is a certificate

SOC 2 is an attestation. A licensed CPA firm examines your controls and issues a report, often 60 to 120 pages, containing the auditor's opinion, your description of the system, and control-by-control test results. The buyer's security team reads it, or at least the exceptions section. ISO 27001 is a certification. An accredited certification body audits your information security management system, or ISMS, against the standard and issues a certificate that fits on one page. Nobody reads an ISO certificate; they verify it against the registrar's directory and file it. That difference explains most of what follows: SOC 2 answers a security reviewer's detailed questions, while ISO 27001 answers a procurement checkbox at global scale.

How SOC 2 is structured

SOC 2 is organized around the trust services criteria. Security is mandatory and, for most first-time reports, the whole audit; Availability, Confidentiality, Processing Integrity, and Privacy are optional additions that should track what customers actually request, since each one raises audit effort and fee. There is no fixed control list. You define the controls that meet the criteria for your environment, and the auditor tests them. A Type 1 report tests whether controls are designed properly at a point in time. A Type 2 report tests whether they operated over a window of three to twelve months, which is the version enterprise buyers want. The report renews annually, because a Type 2 covering last year says nothing about this one.

How ISO 27001 is structured

ISO 27001 certifies a management system, not a control snapshot. Clauses 4 through 10 are mandatory and cover context, leadership, planning, support, operation, performance evaluation, and improvement. From a risk assessment you build a Statement of Applicability across the 93 controls in Annex A, then prove the system actually runs: internal audits under Clause 9.2, management reviews, corrective actions, and an evidence trail behind all of it. The certification body audits in two stages, a documentation review and then a full operating audit, and issues a certificate valid for three years with surveillance audits in years two and three. The standard cares as much about whether the system improves itself as about any individual control.

Audit cadence, and what it costs in attention

SOC 2 is an annual treadmill. Every year there is a new observation window, new fieldwork, and a new report, and the evidence work never really stops. ISO 27001 runs on a three-year cycle: the heavy lift is initial certification, surveillance audits in years two and three run a third to half the initial auditor-days, and recertification lands in year three near the original fee. The internal machinery, internal audit and management review, runs annually either way. Neither cadence is optional once customers rely on the artifact: a lapsed SOC 2 window leaves months that no report will ever cover, and a missed surveillance audit suspends an ISO certificate, which surfaces in procurement checks at the worst possible moment. Teams holding both consistently report that SOC 2 consumes more recurring attention, while ISO 27001 front-loads its pain into the build.

What each one costs

The totals land in the same neighborhood; the shape differs. For SOC 2, plan on $30,000 to $90,000 all-in for year one: $7,000 to $25,000 for a Type 1 audit or $12,000 to $45,000 for a Type 2 at typical startup and mid-market scope, plus readiness work, tooling, and a penetration test if customers expect one, with steady state at $25,000 to $75,000 a year. The full breakdown is in our SOC 2 cost guide. For ISO 27001, a 20 to 200 person company should plan $35,000 to $120,000 through the first three-year cycle: $6,000 to $30,000 for the Stage 1 and Stage 2 audits, $15,000 to $60,000 for consultant-supported implementation, $5,000 to $15,000 for an outsourced internal audit, and $4,000 to $12,000 per surveillance year, itemized in our ISO 27001 cost breakdown. SOC 2 spends flat and annual; ISO spends front-loaded with lighter years two and three.

How long each takes

From a reasonable security baseline, SOC 2 moves faster to a first artifact: readiness in six to twelve weeks, a Type 1 report around month three, and a first Type 2 report at month six to nine after a three-month window. ISO 27001 is slower to first proof because the management system has to exist and demonstrably run before Stage 2: six to twelve months of implementation, then six to ten weeks through the two audit stages. Call it eight to fourteen months to a certificate from a standing start, and meaningfully less if a SOC 2 program already exists. Pursuing both at once from zero is workable when the control build is shared; the audits themselves remain separate events with separate calendars.

Read your pipeline, not the frameworks

The frameworks do not decide this; your deals do. Pull the last twenty security questionnaires and count what was requested by name. US SaaS and mid-market enterprise buyers default to SOC 2. European enterprises, global manufacturers, telecoms, and public-sector-adjacent buyers default to ISO 27001, and many will not accept a SOC 2 report as a substitute because their procurement system literally has a field for a certificate number. Regulated US industries generally accept either but ask for SOC 2 first. A concrete example: if one $400,000 European deal wants ISO 27001 and the rest of the pipeline asks for SOC 2, run SOC 2 now, offer the certificate on a dated roadmap, and let the deal's economics decide whether the ISO program starts this quarter or next year. Sequence by revenue at risk, not by which standard reads better.

When you need both

Companies that sell on both sides of the Atlantic usually end up holding both, and the economics are better than they look because the control overlap is large. One control set, designed once, can feed both audits. The domains that carry most of the evidence weight are shared:

  • Risk assessment and treatment
  • Access control and periodic access reviews
  • Change management
  • Vendor and supplier review
  • Incident response
  • Logging, monitoring, and alerting
  • Business continuity and backup testing

Run one ISMS as the system of record, map controls to both frameworks in your compliance platform, and let each audit sample from the same evidence. Done this way, the second framework typically costs 40 to 60 percent less in fees and effort than the first did, and auditors on both sides quote lower against an organized program. Sequencing follows markets: US-first companies usually run SOC 2 first and add ISO 27001 when international pipeline materializes, while ISO-first companies bolt on SOC 2 when US enterprise deals appear.

Two independence lines worth knowing

SOC 2 opinions can only be issued by licensed CPA firms, and the firm that signs the opinion cannot also design and build the controls it audits. BD Emerson performs SOC 2 examinations through its attest arm, BD Emerson CPA, and keeps implementation and attest work on opposite sides of that line. ISO 27001 certificates can only be issued by accredited certification bodies, the kind listed in the ANAB and UKAS directories, and those bodies are barred from consulting for the clients they certify. BD Emerson is not a certification body: we implement, we prepare, and we perform Clause 9.2 internal audits, and an accredited registrar issues the certificate. Any vendor offering to build your program and hand you the credential in a single contract is describing something that will not survive a customer's due diligence.

Where BD Emerson fits

We run both programs from the consulting side, and SOC 2 examinations through the attest side, never both for the same client at the same time. Our SOC 2 practice covers readiness through report, and our ISO 27001 consulting practice takes an ISMS from scoping to a certificate held with an accredited registrar. If you are staring at a questionnaire asking for the one you do not have, start with the pipeline conversation, because that is where this decision actually lives.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director