Skip to content
Back to the guide

Compliance

ISO 27001 or SOC 2: which to choose

Both are about managing security systematically. The difference is who you prove it to.

4 min read

ISO 27001 and SOC 2 are what customers and partners most often ask for before signing a contract. They are not technical checks but confirmation that the company has a security management system: policies, roles, risks, controls.

ISO 27001

  • An international standard; the certificate is issued by an accredited body for three years with annual surveillance audits.
  • About the management system (ISMS): context, risks, a set of controls from Annex A.
  • Recognised everywhere: Europe, Asia, the public sector, tenders.

SOC 2

  • An American report format under AICPA criteria, produced by a CPA audit firm.
  • Type I: controls are described as of a date. Type II: controls operated over a period, usually 6 to 12 months.
  • Requested by US customers and SaaS partners.

How to choose

Customers in Europe and tenders: ISO 27001. Customers in the US and SaaS: SOC 2. Both markets: ISO 27001 first, then SOC 2 on the same base, because the controls overlap by 70 to 80 percent.

Articles