• ISO 27001
  • SOC 2
  • Compliance

ISO 27001 or SOC 2 for an SME: deliverables, recognition and how to choose

ISO 27001 produces a certificate issued by an accredited body, valid three years with annual surveillance. SOC 2 produces an attestation report issued by a CPA firm, renewed every year. What each framework requires and produces, what it costs under the published rules, and the criteria that determine the choice for an SME.

Komplyo5 min read

A client asks for a "certification", a prospect's security team requires an audit report: the ISO 27001 or SOC 2 question usually arrives through the sales channel. The two frameworks cover largely common security measures, but they produce different deliverables, address different markets and follow different audit cycles. This article describes what each framework requires and produces, based on the published texts, then the criteria that determine the choice.

What each framework produces

SOC 2 (System and Organization Controls 2) is an attestation framework defined by the AICPA (American Institute of Certified Public Accountants). It evaluates a service organisation's controls against five Trust Services Criteria (TSC): Security, which is mandatory, then Availability, Processing Integrity, Confidentiality and Privacy, optional and selected according to the activity. The audit is conducted by a licensed CPA (Certified Public Accountant) firm, which issues an attestation report, not a certificate. A Type I report describes the design of the controls at a given date; a Type II report covers their effective operation over an observation period, generally six to twelve months, and is the one enterprise clients ask for. The report is a detailed document, shared with clients under a non-disclosure agreement: it cannot be displayed publicly.

ISO/IEC 27001 is an international standard published by ISO (the International Organization for Standardization) and the IEC (International Electrotechnical Commission). It specifies the requirements of an ISMS (information security management system): a formal risk assessment, a Statement of Applicability covering the 93 controls of Annex A (2022 version), an internal audit, a management review and continual improvement. Certification is issued by an accredited certification body after a two-stage audit; the certificate, a short and publishable document, is valid for three years, conditional on annual surveillance audits and then a recertification. The cycle and the audit time calculation are governed by published rules, detailed in the costs section below.

Direct comparison

Criterion SOC 2 ISO 27001
Origin AICPA (United States) ISO/IEC (international)
Deliverable Detailed attestation report Publishable certificate
Scope Selected systems and services ISMS defined by the organisation
Controls Designed by the organisation, evaluated against the TSC Annex A (93 controls) via the Statement of Applicability
Auditor Licensed CPA firm Accredited certification body
Cycle Report renewed every year (Type II over an observation period) 3-year certificate, annual surveillance, recertification
Recognition Mainly North America International, including European public procurement
Distribution Under non-disclosure agreement Certificate can be displayed

Costs: what is governed by rules and what is not

Neither framework has a regulated price, and this article quotes no amount: audit fees and consulting services are market prices. The cost structure, however, can be described. For ISO 27001, the audit duration rests on shared accreditation rules (ISO/IEC 27006-1 for the audit time calculation, ISO/IEC 17021-1 for the three-year cycle), which makes quotes comparable in auditor days, provided you ask each body for the number of days per stage and the daily rate. For SOC 2, the CPA firm's engagement follows the AICPA attestation standards but its duration is not standardised; Type II adds the internal cost of the observation period, during which evidence of the controls' operation is collected continuously.

In both cases, the largest item is often the internal work: documentation, control implementation, evidence collection, and for ISO 27001 the internal audit and management review. That time counts in working days for the teams, to be included in the security budget like any other action.

The choice criteria

The first criterion is client demand. A contractual requirement or a procurement questionnaire that names one of the two frameworks settles the choice; compliance sits inside the sales process, not in the abstract. Absent an explicit requirement, market geography decides in most cases: ISO 27001 is the reference for European and international buyers and for public procurement in Europe, SOC 2 for North American buyers, particularly for SaaS platforms.

Two elements complete the analysis. The deliverable: an ISO 27001 certificate can be shown in tender responses, a SOC 2 report is passed client by client under a non-disclosure agreement, which corresponds to different commercial uses. The regulatory context: for a company in scope of NIS2, the Article 21 measures overlap substantially with the scope of an ISO 27001 ISMS, which pools part of the compliance work.

Doing both

The two frameworks rest on a common base: risk assessment, access control, incident response, supplier security, encryption and backups, awareness training, change management. An organisation that has built that base for a first framework covers most of the second; the additional work concentrates on each framework's own requirements (the Statement of Applicability, internal audit and management review on the ISO 27001 side, the observation period and the report on the SOC 2 side). The usual sequence starts from the framework the main market demands, then adds the second when an opportunity justifies it.

The overlap in Komplyo

Komplyo uses NIST CSF 2.0 as the assessment framework and treats ISO 27001 and SOC 2 as projections of the same answers, computed through the mappings between frameworks: a question is asked once, and readiness reads for both frameworks. Each framework's own requirements are covered by complementary questions in the dedicated workspaces, and ISO 27001 coverage exports in the format of a Statement of Applicability. The free diagnostic (23 questions, around 5 minutes) gives a first picture of the common base.

Sources

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.