
Compliance
ISO 27001 or SOC 2: which to choose
Both are about managing security systematically. The difference is who you prove it to.
4 min read
ISO 27001 and SOC 2 are what customers and partners most often ask for before signing a contract. They are not technical checks but confirmation that the company has a security management system: policies, roles, risks, controls.
ISO 27001
- An international standard; the certificate is issued by an accredited body for three years with annual surveillance audits.
- About the management system (ISMS): context, risks, a set of controls from Annex A.
- Recognised everywhere: Europe, Asia, the public sector, tenders.
SOC 2
- An American report format under AICPA criteria, produced by a CPA audit firm.
- Type I: controls are described as of a date. Type II: controls operated over a period, usually 6 to 12 months.
- Requested by US customers and SaaS partners.
How to choose
Customers in Europe and tenders: ISO 27001. Customers in the US and SaaS: SOC 2. Both markets: ISO 27001 first, then SOC 2 on the same base, because the controls overlap by 70 to 80 percent.
Articles

NIS2 and DORA: who is affected and what to do
Two European frameworks that turn cybersecurity from a recommendation into an obligation with management liability.
4 min read
What a pentest is and how it differs from a vulnerability scanner
A scanner finds known holes from a list. A pentester thinks like an attacker and chains small things into a real breach.
4 min read