ISO 27001 or SOC 2: decision tool
These are not alternatives so much as answers to different buyers. This works out which buyer you have, which one to get first, and whether you will eventually need both.
Both are voluntary, both are driven by a customer, and neither is law. The choice is decided almost entirely by who is asking and where they are, which is why this takes six questions rather than twenty. The answer appears on this page.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
The difference in one paragraph
ISO 27001 is a certification. An accredited body audits your information security management system against a published standard and issues a certificate, valid three years with surveillance audits in between. SOC 2 is an attestation. A CPA firm examines your controls against criteria set by the AICPA and writes a report giving an opinion, with no certificate and no certifying body. That is why a questionnaire asking you to attach a certificate cannot be answered with a SOC 2 report: there is nothing to attach.
| ISO 27001 | SOC 2 Type 2 | |
|---|---|---|
| What you get | A certificate | A report with an auditor's opinion |
| Who issues it | An accredited certification body | A CPA firm |
| Usually asked for by | European, UK and global buyers, and tenders | North American enterprise procurement |
| Typical first year | $40,000 to $110,000 | $40,000 to $75,000 |
| Typical elapsed time | 9 to 15 months | 6 to 12 months |
| Renewal shape | Surveillance in years 2 and 3, recertification at year 3 | A fresh audit every year |
The longer comparison, including what carries over from one to the other, is on ISO 27001 compared with SOC 2. Cost detail for each is on the ISO cost page and on what SOC 2 costs in Canada.
Common questions
Can we do both at once?
They share a lot of underlying control work, so running them together costs meaningfully less than running them a year apart. Doing both from a standing start inside three months is not realistic. The workable version is to get the one your buyer named, then add the second on the same control evidence within the following year.
Will a European customer accept a SOC 2 report?
Sometimes, and it is not the way to bet. European and UK procurement policies are frequently written against ISO 27001 by name, and the reviewer may have no authority to accept a substitute even if they personally think it is equivalent. If the contract names ISO 27001, ask whether a SOC 2 report would satisfy it before assuming either answer.
Is one of them harder?
ISO 27001 is usually more work in year one, because you are building a management system with a risk assessment, a Statement of Applicability, an internal audit and a management review, and SOC 2 does not require that apparatus. Over three years the gap narrows, since SOC 2 is audited every year while ISO surveillance audits are shorter than the initial one.
Does either of them cover our privacy obligations?
No. PIPEDA, or the provincial statute that displaces it in Quebec, British Columbia and Alberta, applies to your handling of personal information whether or not you hold anything. Both frameworks cover the safeguards side well and cover consent, purpose, retention and access rights not at all. Budget the privacy work alongside, not inside.