Last reviewed 2026-07-01 · ~7 min read

SOC 2 or ISO 27001 — which one does your customer actually want?

You have accepted that some formal security credential is in your future — a customer said so, or three did. Now you are looking at two acronyms that every vendor forum discusses as if they were interchangeable, priced like a car, each demanding months of work. Getting this choice wrong does not just waste money; it wastes a year of calendar, because these credentials cannot be bought quickly when the deal that needed the other one arrives.

The good news: for most companies the right first choice is determined by two facts you already know — where your buyers are, and what their vendor-review process actually says. Here is the comparison in plain terms, and a way to decide that does not involve a forum argument.

Two different kinds of artefact

The deepest difference is not scope or rigour — it is what you end up holding.

System and Organization Controls (SOC) 2 produces a report. A licensed accounting firm examines your controls against the Trust Services Criteria of the American Institute of Certified Public Accountants (AICPA) and writes a long, confidential document: your system described, your controls listed, the auditor's tests and findings. Customers read it under a non-disclosure agreement and judge for themselves. There is no certificate and no logo, only the report.

The International Organization for Standardization's ISO/IEC 27001 produces a certificate. An accredited certification body audits your Information Security Management System (ISMS) — the standing system by which you assess risk, choose controls, and improve — against the standard. Pass, and you hold a public, referenceable certificate valid for three years, with surveillance audits between. Customers see one page and a scope statement.

This difference explains most buyer behaviour. American security teams are staffed to read reports: they want the detail, the exceptions, the auditor's notes. European and international procurement processes are built to check certificates: a register lookup satisfies the checkbox. Neither is more virtuous; they are different bureaucratic traditions asking for different paper.

The geography rule, and when it lies

The default heuristic is honest and works: selling mostly to United States companies, do SOC 2 first; selling mostly to Europe, the United Kingdom, or internationally, do ISO 27001 first.

But the rule has exceptions, and they are exactly where expensive mistakes happen. US enterprises with global parents sometimes require ISO 27001. European subsidiaries of American firms often ask for SOC 2. Some industries lean on their own frameworks entirely. And a large customer's vendor portal may accept either — or demand both above a certain deal size. Which is why the real rule is:

Read the actual words in the actual contracts. Pull the security schedules and questionnaires from your last five enterprise deals and your top three prospects. Count what is literally required: "SOC 2 Type II report" and "ISO/IEC 27001 certificate" are different sentences. If the evidence is mixed, ask the prospect that matters most a direct question: "Which artefact clears your vendor review — a SOC 2 Type II report or an ISO 27001 certificate?" Procurement teams answer this question happily. It is their checklist; they know what is on it.

The work overlaps more than the paperwork does

Here is the fact that lowers the stakes: underneath the differing paperwork, the two frameworks largely examine the same things. Access control and Multi-Factor Authentication (MFA). Onboarding and offboarding. Risk assessment. Incident response. Vendor management. Backups, logging, change control. A commonly cited figure is that the control work overlaps by well over half, and practitioner experience supports it.

Two practical consequences follow. First, the underlying work is never wasted — build the controls once and they serve whichever credential you pursue, this year and next. Second, doing the second one later is much cheaper than the first, because the control set and the evidence habits already exist; the second effort is mostly mapping and the new audit's mechanics.

The differences that remain are real but manageable: ISO 27001 asks you to run a management system — a standing cycle of risk assessment, internal audit, and management review — which is a heavier ongoing rhythm; SOC 2 Type II asks you to evidence your controls operating over a window, commonly three to twelve months, which is a heavier evidence-collection burden. Small teams tend to find ISO 27001 more bureaucratic and SOC 2 more evidentiary. Neither is light.

The decision, stated plainly

Putting it together, in order of force:

1. If a specific, valuable deal names one — do that one. Blocked revenue outranks strategy.

2. If the pattern in your contracts leans one way — follow the pattern. Count the sentences; do not vote from vibes.

3. If genuinely mixed — follow next year's market. The credential takes months to obtain; buy it for where your pipeline is heading, not where it was.

4. Do not start both at once as your first effort. The combined audit calendar, evidence load, and cost routinely overwhelm small teams, and the overlap means sequencing loses you little. Do one, absorb it into normal operations, add the second when the pipeline pays for it.

And if you are still one step earlier — unsure whether you need either credential yet — that decision has its own test, which we walk through in Do you actually need SOC 2 yet?.

Whichever you choose, readiness comes first

Both paths begin the same way: map your current controls against the framework, find the gaps, fix them, and collect evidence for a while before any auditor arrives. Walking into either audit cold is how you buy a report full of exceptions or a failed certification attempt — both of which end up in front of customers. The readiness phase is unglamorous, and it is where the outcome is actually decided.


When you want this ready to use

Sylvan Assurance's SOC 2 Audit-Readiness Assessment toolkit runs the readiness phase: the assessment against the Trust Services Criteria, gap-analysis worksheets, evidence checklists, and scoping guidance — in editions for a founder, a team, or a consultant running client readiness, from $49. And because the control work overlaps, the companion Sylvan Press books, SOC 2 in Plain English, keep ISO 27001 alongside throughout — volume two covers the audit and continuous operations with the ISO path in view, so the second credential is a planned step rather than a restart.

The free SOC 2 readiness check at sylvanassurance.com/free/soc2 scores you against the core criteria in about five minutes. It runs entirely in your browser. Your answers are never transmitted.

Prefer the long form? The companion Sylvan Press title, SOC 2 in Plain English, covers the same ground in depth.

See where you stand

Whichever artefact your buyers want, the gap list starts in the same place. The free check shows how far from audit-ready you are today. It runs entirely in your browser — your answers never leave your device.

Take the free SOC 2 readiness check