Guide · Standards compared

SOC 2 vs ISO 27001: what's the difference?

They cover a lot of the same security ground, which is why they're often confused — but they're different kinds of thing. SOC 2 is a report, produced by an accountant. ISO 27001 is a certificate, issued against an international standard. Which you need usually comes down to a simpler question than the acronyms suggest: who's asking, and where are they?

SOC 2, in one line

SOC 2 is a US attestation: a licensed CPA (accountancy) firm examines your controls against the AICPA's Trust Services Criteria — security, and optionally availability, processing integrity, confidentiality and privacy — and issues a report with their opinion. There's no certificate; you share the report itself with customers, often under NDA. It comes in two flavours (Type 1 and Type 2 — see below), and it's the credential US enterprise buyers most often ask for.

ISO 27001, in one line

ISO/IEC 27001 is an international certification: an accredited certification body assesses your information security management system (ISMS) — risk assessment, a documented set of controls, internal audit, management review and continual improvement — and, if you pass, issues a certificate anyone can verify. It's the recognised security credential in the UK, Europe and much of the world, and it requires a managed system behind it, not just a snapshot of controls.

The key differences

Type 1 vs Type 2, quickly. A SOC 2 Type 1 report says your controls are suitably designed at a point in time. A Type 2 report says they actually operated effectively over a period — commonly three to twelve months. Enterprise customers almost always want Type 2, because it evidences the controls working, not just existing.

Do they overlap? Yes — but neither is a pass for the other

Both are built on a set of information-security controls, and there's heavy overlap between them, so the work you do for one genuinely accelerates the other. But they're not interchangeable, and holding one does not grant the other. ISO 27001 adds the entire management-system layer — governance, risk assessment, continual improvement — that SOC 2 doesn't require. SOC 2 adds a CPA-attested report, structured differently from an ISO certificate. Maintain strong controls once and you serve both; but don't expect a SOC 2 report to stand in for an ISO certificate, or the reverse.

Which do you need?

Plenty of companies end up doing both because they sell into both markets — and because the security work underneath is largely shared, the second credential is far less than double the effort. For UK buyers the first security question is often Cyber Essentials vs ISO 27001 rather than SOC 2 — worth knowing which conversation you're actually in.

Where Kavorly fits

Kavorly runs the ISO 27001 management system — context, risk, Statement of Applicability, audits, management review and the controls beneath them — and keeps the security controls and their evidence current as you work. That same maintained control set and evidence is the groundwork a SOC 2 examination draws on, so the discipline that earns your ISO certificate also supports the report a US customer asks for. Kavorly is the management system; the SOC 2 examination itself is carried out by a CPA firm.

How ISO 27001 evidence works → · GRC tools vs an IMS →


This guide is a general introduction, not certification, attestation or professional advice. SOC 2 examinations are performed by licensed CPA firms under AICPA standards, and ISO/IEC 27001 certification by accredited certification bodies; refer to those for authoritative requirements.

Questions

Before you book the wrong exam.

A US customer asked for SOC 2. We're UK — do we still need ISO 27001?

Maybe both. That customer wants a report they recognise; UK, European and public-sector buyers usually want ISO 27001. If you only sell to that one US account, SOC 2 Type 2 may be enough. If you also bid here, you'll likely need the certificate too. The security work underneath overlaps, so the second is not a second project from scratch.

Can we send them our ISO 27001 certificate instead of a SOC 2 report?

Usually not. A certificate is not a CPA report, and many US enterprise buyers will still ask for the report. Holding ISO 27001 helps the SOC 2 exam because the controls are already maintained; it doesn't replace it.

Who issues each one — and can software do it?

SOC 2 comes from a licensed CPA firm. ISO 27001 comes from an accredited certification body (UKAS in the UK). Software can run the management system and keep evidence current. It cannot issue either credential.

If we do ISO 27001 first, what's left for SOC 2?

The observation period and the CPA report. Type 2 needs controls operating over a period — commonly three to twelve months — and a firm to examine them. If your ISO 27001 system is already live, that period is largely time you were going to spend anyway, not a new control-building project.

Next step

Working out which credential your customers want?

Check your ISO 27001 readiness in three minutes — free, no sign-up — or see how far your standards already overlap.