A client asks for a "certification", a prospect's security team requires an audit report: the ISO 27001 or SOC 2 question usually arrives through the sales channel. The two frameworks cover largely common security measures, but they produce different deliverables, address different markets and follow different audit cycles. This article describes what each framework requires and produces, based on the published texts, then the criteria that determine the choice.
What each framework produces
SOC 2 (System and Organization Controls 2) is an attestation framework defined by the AICPA (American Institute of Certified Public Accountants). It evaluates a service organisation's controls against five Trust Services Criteria (TSC): Security, which is mandatory, then Availability, Processing Integrity, Confidentiality and Privacy, optional and selected according to the activity. The audit is conducted by a licensed CPA (Certified Public Accountant) firm, which issues an attestation report, not a certificate. A Type I report describes the design of the controls at a given date; a Type II report covers their effective operation over an observation period, generally six to twelve months, and is the one enterprise clients ask for. The report is a detailed document, shared with clients under a non-disclosure agreement: it cannot be displayed publicly.
ISO/IEC 27001 is an international standard published by ISO (the International Organization for Standardization) and the IEC (International Electrotechnical Commission). It specifies the requirements of an ISMS (information security management system): a formal risk assessment, a Statement of Applicability covering the 93 controls of Annex A (2022 version), an internal audit, a management review and continual improvement. Certification is issued by an accredited certification body after a two-stage audit; the certificate, a short and publishable document, is valid for three years, conditional on annual surveillance audits and then a recertification. The cycle and the audit time calculation are governed by published rules, detailed in the costs section below.
Direct comparison
| Criterion | SOC 2 | ISO 27001 |
|---|---|---|
| Origin | AICPA (United States) | ISO/IEC (international) |
| Deliverable | Detailed attestation report | Publishable certificate |
| Scope | Selected systems and services | ISMS defined by the organisation |
| Controls | Designed by the organisation, evaluated against the TSC | Annex A (93 controls) via the Statement of Applicability |
| Auditor | Licensed CPA firm | Accredited certification body |
| Cycle | Report renewed every year (Type II over an observation period) | 3-year certificate, annual surveillance, recertification |
| Recognition | Mainly North America | International, including European public procurement |
| Distribution | Under non-disclosure agreement | Certificate can be displayed |
Costs: what is governed by rules and what is not
Neither framework has a regulated price, and this article quotes no amount: audit fees and consulting services are market prices. The cost structure, however, can be described. For ISO 27001, the audit duration rests on shared accreditation rules (ISO/IEC 27006-1 for the audit time calculation, ISO/IEC 17021-1 for the three-year cycle), which makes quotes comparable in auditor days, provided you ask each body for the number of days per stage and the daily rate. For SOC 2, the CPA firm's engagement follows the AICPA attestation standards but its duration is not standardised; Type II adds the internal cost of the observation period, during which evidence of the controls' operation is collected continuously.
In both cases, the largest item is often the internal work: documentation, control implementation, evidence collection, and for ISO 27001 the internal audit and management review. That time counts in working days for the teams, to be included in the security budget like any other action.
The choice criteria
The first criterion is client demand. A contractual requirement or a procurement questionnaire that names one of the two frameworks settles the choice; compliance sits inside the sales process, not in the abstract. Absent an explicit requirement, market geography decides in most cases: ISO 27001 is the reference for European and international buyers and for public procurement in Europe, SOC 2 for North American buyers, particularly for SaaS platforms.
Two elements complete the analysis. The deliverable: an ISO 27001 certificate can be shown in tender responses, a SOC 2 report is passed client by client under a non-disclosure agreement, which corresponds to different commercial uses. The regulatory context: for a company in scope of NIS2, the Article 21 measures overlap substantially with the scope of an ISO 27001 ISMS, which pools part of the compliance work.
Doing both
The two frameworks rest on a common base: risk assessment, access control, incident response, supplier security, encryption and backups, awareness training, change management. An organisation that has built that base for a first framework covers most of the second; the additional work concentrates on each framework's own requirements (the Statement of Applicability, internal audit and management review on the ISO 27001 side, the observation period and the report on the SOC 2 side). The usual sequence starts from the framework the main market demands, then adds the second when an opportunity justifies it.
The overlap in Komplyo
Komplyo uses NIST CSF 2.0 as the assessment framework and treats ISO 27001 and SOC 2 as projections of the same answers, computed through the mappings between frameworks: a question is asked once, and readiness reads for both frameworks. Each framework's own requirements are covered by complementary questions in the dedicated workspaces, and ISO 27001 coverage exports in the format of a Statement of Applicability. The free diagnostic (23 questions, around 5 minutes) gives a first picture of the common base.