Back to Blog

SOC 2 vs ISO 27001: Which One First, Which One Second

Don't hedge. Five questions determine which framework wins. Then the recommendation matrix and the cross-framework efficiency play if you eventually need both.

Quick Answer

Don't hedge. Five questions determine which framework wins. Then the recommendation matrix and the cross-framework efficiency play if you eventually need both.

The "should we do SOC 2 or ISO 27001" question doesn't have a generic answer. It has a specific answer for your specific company, and the specific answer is determined by three inputs: where your customers buy, what they require in procurement, and how mature your sales motion is. Most blog posts on this topic give a hedged "both are good, depends on your needs" non-answer. That's not useful when there's a procurement deadline on the calendar and a budget that won't fund both certifications.

This is the decision framework. Five questions, in order. Each one collapses the option space. By the end you have a defensible answer for which framework to pursue first, which (if any) to pursue second, and on what timeline.

77%
of enterprise buyers require ISO 27001, SOC 2, or NIST compliance from vendors (ISC2 Supply Chain Risk Survey, 2025)
46%
of software buyers cite security certifications as the top reason for selecting a vendor (Gartner Digital Markets, 2024)
11
stakeholders in the median enterprise buying committee for deals above $100K ACV (Gartner Future of Sales)

The decision in five questions

Run through these in order. Each answer narrows the recommendation.

  • Where are your top 10 target customers headquartered?: US-only or US-dominant pipeline → SOC 2 first. Europe-heavy or Asia-heavy pipeline → ISO 27001 first. Mixed pipeline with no clear majority → check procurement requirements specifically (next question). Geographic origin is the single biggest predictor of which framework procurement teams default to requesting.
  • What does the customer procurement template actually require?: Read the security addendum from your three most-recent enterprise procurement processes. The template either says "SOC 2 Type II required," "ISO 27001 required," "either acceptable," or "information security certification required (vendor to specify)." The template language overrides the geographic default — if your US prospects' procurement templates explicitly accept ISO 27001, the geographic default doesn't apply.
  • What's the cost of not having the cert that's being asked for?: If the deal pipeline has $500K+ ARR riding on a cert the customer demanded by a specific date, that cert wins regardless of the geographic or theoretical "right" answer. Most companies do the cert the deal demands, on the deal's timeline. The strategic optimization happens once survival isn't on the line.
  • What's your sales motion in 18 months?: If you're shifting from US-only to international expansion in the next 12–18 months, plan for ISO 27001 as the second framework (or do it first if the timeline pulls forward). If you're scaling US enterprise and Fortune 500 is the target, plan for SOC 2 Type II with an annual cadence. The 18-month sales motion shapes whether you eventually need both or whether one will hold.
  • How much team capacity do you have for compliance work?: Running both frameworks simultaneously is materially more than 2× the work of running either alone — the overlap reduces audit fees but doesn't reduce internal time proportionally. If the security/ops capacity is one person spending 20% time on compliance, you can't run both at once. If you have a dedicated GRC person or a mature platform supporting both, the dual-framework model is feasible.

The recommendation matrix

The five questions collapse into a small number of recommended paths:

Profile
First Framework
Second Framework (if any)
Timing
US-dominant pipeline, mid-market SaaS, no immediate international
SOC 2 Type II
None unless international expansion accelerates
9–14 months to first Type II
US-dominant pipeline with named EU prospects in next 12 months
SOC 2 Type II
ISO 27001 (12 months after SOC 2 Type II)
First framework first, second when capacity returns
Europe-dominant or Asia-dominant pipeline
ISO 27001
SOC 2 Type II if US enterprise becomes meaningful
ISO 27001 in 12–18 months, SOC 2 added later
Mixed global pipeline with deals on both sides hitting in the next 6 months
Whichever the largest 1–2 deals require
The other within 12 months
Dual-framework cadence; budget for $90K+ incremental
Pre-sales, building toward first enterprise deals
SOC 2 Type I (then Type II)
ISO 27001 if/when international demand materializes
Type I in 4–6 months, Type II 6–12 months later

Where the two frameworks materially diverge

The control sets overlap heavily — roughly 70–80% of SOC 2's Trust Services Criteria map directly to ISO 27001 Annex A controls, which is why a platform that runs both frameworks concurrently is the default answer for teams committed to running dual-framework programs. The meaningful differences sit in three areas:

Area
SOC 2 Approach
ISO 27001 Approach
Scope flexibility
Service-specific: scoped to a defined system. Trust services criteria are pick-and-choose (Security mandatory, others optional)
Organization-wide: scoped to the ISMS, which can be defined narrowly or broadly. Full Annex A applicability statement required
Risk management formality
Implicit; controls are designed around risk but the risk register is not a primary artifact
Explicit; a documented risk assessment + treatment plan is a central artifact, reviewed by the auditor
Improvement / management system
Annual re-attestation; no formal continuous improvement requirement
Continuous improvement is core: management reviews, internal audits, corrective action workflow are required artifacts
Output
Attestation report (Type I or Type II) — a narrative + control test results document
Certificate (3-year cycle with annual surveillance audits) + the underlying audit report
Geographic recognition
Strong in US, accepted but secondary in EU/Asia
Strong globally, accepted but secondary in US (procurement template default)
The Risk Register Difference Most Underestimate

ISO 27001's risk management requirement is the line item that catches most SOC-2-experienced teams off-guard. SOC 2 lets you implement controls without formally documenting a risk register that justifies each one. ISO 27001 requires a documented risk assessment that drives the Statement of Applicability — meaning you have to justify in writing why each Annex A control is or isn't applicable to your scope, and tie controls to identified risks. The work is real, even when the underlying controls are largely the same. Risk registers are automatically built and maintained in vCISO Lite — see how.

When running both is worth the cost

Running both frameworks simultaneously is the right answer when three conditions are jointly true:

  • Deal pipeline crosses both geographic defaults: US enterprise deals demanding SOC 2 + EU/global enterprise deals demanding ISO 27001, both active in the next 12 months. Single-framework constrains the pipeline; dual-framework unlocks both.
  • Sales cycle compresses with the dual signal: Customers who see both certs published treat the vendor as more mature — particularly for enterprise procurement in regulated industries. The shortened cycle on enterprise deals can recover the incremental compliance cost in the first 1–2 deals.
  • Compliance capacity exists to maintain both without burning the team: Either a dedicated GRC headcount, a mature compliance platform with audit-ready evidence for both frameworks, or both. Trying to maintain both with neither produces audit findings on both fronts.

Outside those three conditions, single-framework first + the other as a follow-on is the better economic and operational call. The doubled-up audit cycles, two sets of evidence requests, two auditor relationships, and two report-generation events compound the operational load in ways that pure cost-comparison misses.

The cross-framework efficiency play

If you do end up running both, structure the second framework to maximize overlap. The mechanics:

What overlaps cleanly

Access control, change management, vulnerability management, encryption controls, incident response, vendor management, business continuity, physical security (if applicable), HR security. The control implementations are substantively the same; only the documentation framing differs. A single control matrix can map to both frameworks' criteria.

What doesn't overlap

Risk assessment formality (ISO requires explicit; SOC 2 doesn't). Statement of Applicability (ISO requires; SOC 2 doesn't). Management review cadence (ISO requires; SOC 2 doesn't). Continuous improvement workflow (ISO requires; SOC 2 doesn't). These are net-new artifacts that ISO 27001 requires beyond the SOC 2 baseline.

Neither AICPA nor ISO publishes benchmark pricing, and the Big-4 firms that audit at the top of the market don’t publish rate cards. What’s directionally clear: adding a second framework to an existing program is materially cheaper than running both from scratch, because the 65–75% control overlap means the readiness work is already done. What varies is how much internal-time load the second framework’s framework-specific artifacts (Statement of Applicability, formal risk assessment, management review cadence for ISO; SOC 2’s narrative description of the system) actually add on top.

The 2026 updates: both frameworks got refreshed

The choice looks different in 2026 than it did in 2022 because both standards moved.

ISO/IEC 27001:2022 — transition deadline has passed

The three-year transition from ISO/IEC 27001:2013 to :2022 ended on October 31, 2025. Certificates that didn’t transition by that date are now invalid. Organizations that lapsed can’t use the shortcut transition audit — they have to run a full Stage 1 + Stage 2 audit from scratch. If a target customer’s procurement template asks for “ISO 27001,” verify the vendor’s certificate is against the 2022 revision, not the retired 2013 version.

Annex A restructured materially: 114 controls in 14 domains (2013) → 93 controls in 4 themes (2022) — Organizational (37), People (8), Physical (14), Technological (34). Eleven new controls were added, including Threat intelligence (A.5.7), Information security for cloud services (A.5.23), ICT readiness for business continuity (A.5.30), Configuration management (A.8.9), Data masking (A.8.11), Data leakage prevention (A.8.12), and Secure coding (A.8.28). Existing ISMSes that transitioned in 2023–2025 already absorbed these; anyone starting fresh in 2026 is starting on the 2022 baseline.

SOC 2 — Trust Services Criteria stable, Points of Focus and attestation standard updated

The 2017 Trust Services Criteria themselves have not changed. What changed underneath: AICPA released revised Points of Focus in 2022 — implementation guidance under each criterion covering cloud configuration, third-party risk and vendor concentration, ransomware, and remote workforce. The attestation standard also moved: SSAE No. 21 (Direct Examination Engagements) is effective for SOC reports issued on or after June 15, 2022, adding AT-C section 206 and reshaping AT-C 105 and 205. Any SOC 2 auditor working from pre-SSAE-21 language is behind.

The NIS2 factor: what’s actually driving ISO 27001 demand in Europe right now

The single biggest 2025–2026 story for the SOC-2-vs-ISO-27001 choice, if any deal touches Europe, is NIS2. The EU’s NIS2 Directive (Directive (EU) 2022/2555) transposition deadline was October 17, 2024, and 23 EU member states missed it — the Commission opened infringement procedures. Enforcement is landing through 2025 and 2026, and it is pulling procurement toward ISO 27001 in a concrete way.

ENISA published its Technical Implementation Guidance on Cybersecurity Risk Management Measures in June 2025 — the operational document that European in-scope entities work from. It maps every one of NIS2’s ten mandatory measures to ISO/IEC 27001:2022 and ISO/IEC 27002:2022 controls. For an EU-facing seller, this is decisive: aligning to ISO 27001:2022 gives you a defensible control mapping to the NIS2 measures your buyer is being audited against. SOC 2 does not have this crosswalk.

What this means for the decision framework

If any of the top-10 target customers are in-scope for NIS2 (which is broad — energy, transport, banking, health, digital infrastructure, public administration, and their supply chains), ISO 27001 moves from “nice to have for the EU pipeline” to “the framework their vendor-risk template will actually recognize.” The five-question decision framework above stands, but the third question — “what does the customer procurement template actually require” — should specifically check whether the template references NIS2 or ENISA guidance.

The AI overlay: ISO 42001 changes the calculus for AI vendors

ISO/IEC 42001:2023, the AI management system standard, is now certifiable. The structural point that matters for the framework choice: ISO 42001 shares clauses 4 through 10 with ISO 27001 — both are Annex SL management-system standards, so their organizational context, leadership, planning, support, operations, performance evaluation, and improvement clauses are structurally identical. An organization running an ISO 27001 ISMS extends into an AIMS by adding an Annex, not by building a second management system.

The early certification wave signals where enterprise procurement is heading: AWS certified in November 2024, KPMG became the first Big-4 to certify in December 2025, IBM Granite is the first major open-source AI model developer to earn it, and BCG announced among the first 100 organizations globally certified in January 2026. The pattern rhymes with SOC 2’s 2015–2018 arrival cycle: once critical mass of vendors certify, buyer expectation resets.

SOC 2 does not have this structural alignment with ISO 42001. AICPA has begun scoping assurance-over-AI as a CPA service area — the Journal of Accountancy covered it in November 2025 — but has not shipped a finalized “SOC for AI” framework yet. That gap is temporary but real: for AI-vendor sellers in 2026, the ISO 27001 + ISO 42001 stack is the certified path that maps to how the market is moving.

For the EU AI Act specifically, ISO 42001 maps to seven of the operational governance articles — Article 9 (risk management), Article 10 (data governance), Article 11 (technical documentation), Article 12 (record-keeping), Article 13 (transparency), Article 14 (human oversight), and Article 17 (quality management systems). Core obligations for high-risk AI systems take effect August 2, 2026; the deployer obligations put direct compliance responsibility on the buyer, which means buyers will screen vendors on this framework alignment specifically. vCISO Lite runs SOC 2, ISO 27001, and ISO 42001 off a single control library so the evidence collected once satisfies every audit — see how vCISO Lite can help you prove compliance with any framework.

Cyber insurance: neither framework buys you a discount

Both carriers and brokers get asked the SOC 2 vs. ISO 27001 question by vendors hoping one certification cuts premium. In 2024–2025, the answer from Aon, Marsh, and Beazley’s own published materials is the same either way. Underwriters price on documented technical controls — MFA (100% coverage on email and remote access is baseline), EDR deployed and updated, immutable backups, a written IR plan, patch cadence, and increasingly, external attack-surface scans the carrier runs during underwriting.

Aon’s proprietary CyQu assessment platform (3,226 clients in the 2024 sample, 10,000-client database) maps to ISO and NIST, not to SOC 2 — but the underwriting decision is still control-based, not framework-based. Marsh’s “12 Key Cyber Resilience Controls” framing is the same. Beazley’s Q1 2025 threat reporting emphasizes credential compromise and remote-access hardening, not certification credentials. The honest read: a framework certification helps you evidence the controls carriers care about; it doesn’t substitute for having them, and it doesn’t win a premium discount by itself.

The bottom line

SOC 2 first if your customer geography and procurement template say so; ISO 27001 first if they say the opposite; both if your pipeline crosses both geographic defaults and you have the capacity. The decision is concrete enough to make with the five questions and the recommendation matrix — there's no need to hedge. The doubled-cost trap catches companies who try to do both prematurely; the single-framework trap catches companies whose pipeline expands geographically faster than the certification cadence. Pick the framework that unlocks the deals on the calendar, then add the second when the pipeline justifies it.

Run both frameworks without doubling the operational lift

vCISO Lite maps SOC 2 trust services criteria and ISO 27001 Annex A controls to a single underlying control matrix, so the evidence collected once satisfies both audits and the policy library serves both frameworks. The overlap that's theoretical in the standards becomes operational — the same control implementation produces evidence consumable by either auditor, with the framework-specific artifacts (Statement of Applicability, risk assessment, management review) layered on top where ISO requires them. Built for the 33 million US small and mid-sized businesses that don't have a CISO yet, but need to decide between (or run both of) the two dominant frameworks.

If you're scoping a first framework or considering adding a second, visit vcisolite.com to learn more and get started.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.