ISO27K

SOC 2 to ISO 27001 reuse estimator

SOC 2 and ISO 27001 share most of their control work and almost none of their management system work. This estimates the split for your situation instead of leaving you with the usual answer, which is that there is a lot of overlap.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

Every comparison page says the two frameworks overlap and none of them says by how much. The honest answer has two halves. Your SOC 2 control evidence carries a long way into Annex A, often most of the way. Clauses 4 through 10 of ISO 27001, which are the 25 requirements that make it a management system, are barely touched by a SOC 2 engagement, and that is where a second-framework project actually spends its money.

The estimate appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

What do you hold today?

Which trust services criteria are in the report?

Security is mandatory in every SOC 2. The others are chosen, and each one you added covers more of Annex A.

Do you have a documented risk assessment?

Clause 6.1.2 wants a repeatable method producing risks with named owners and assessed levels. A risk matrix produced once for the SOC 2 auditor is not that.

Which of these already happen?

These are clause 9 and clause 10 requirements. SOC 2 asks for none of them by name, so most companies tick nothing here and that is the normal starting point.

How is evidence collected today?

How many people work there?

Where the numbers come from

The estimate is built on one structural fact rather than on a control-level mapping, because control-level mappings between the two frameworks are approximate and every vendor publishes a different one. The fact is that ISO 27001 has two halves and SOC 2 only overlaps with one of them.

What an existing SOC 2 typically covers of an ISO 27001 project
ISO 27001 requirementCovered by a SOC 2 Type 2Why
Annex A technological controlsMost of itAccess, logging, vulnerability management, change and backup are tested by SOC 2 fieldwork in almost the same terms.
Annex A people controlsMost of itScreening, training, agreements and offboarding are common criteria evidence already.
Annex A organizational controlsRoughly halfSupplier and incident work carries over. Asset inventory, classification and the compliance group usually do not.
Annex A physical controlsSomeWhere an office is in scope, SOC 2 covers less of this than people assume.
Clauses 4 to 10, the 25 requirementsLittleScope statement, risk method, objectives, internal audit, management review and corrective action are ISO constructs. SOC 2 asks for none of them by name.
Overall readiness effort saved on a first ISO 2700125% to 55%Against starting from nothing, for a company holding a current Type 2

The saving is real and it is not the audit fee

The certification body prices from audit days, and audit days come from headcount, scope and complexity. Holding a SOC 2 report does not reduce them. What it reduces is the readiness work, which is the larger number: the gap assessment finds less, the control implementation is mostly done, and the evidence exists. Expect the certification body quote on the cost page to be unchanged and the consultant quote to fall.

Common questions

Can we reuse SOC 2 evidence in an ISO 27001 audit?

The underlying evidence, yes. Access reviews, onboarding records, change tickets, vulnerability scans and supplier reviews are the same artefacts and an ISO auditor will sample them happily. The SOC 2 report itself is not evidence of an ISO control, because it was written against different criteria and by a firm with no standing in the ISO scheme.

Does an ISO 27001 certificate replace our SOC 2 report?

Not with a buyer who asked for SOC 2. North American procurement teams frequently have the framework written into a policy, and a certificate is not a substitute for an attestation in that conversation. Companies selling on both sides of the Atlantic usually end up holding both, which is why the order you get them in matters. See the comparison.

How long does the second framework take?

Six to nine months for a company with a current Type 2, against nine to fifteen from a standing start. The constraint moves from building controls to the management system requirements, and specifically to running an internal audit and a management review, both of which need the system to have been operating first. That floor does not go away because you already hold a report.

Does a compliance platform make this automatic?

It makes the evidence mapping fast and it does none of the management system work. A platform will tick a large share of Annex A from your existing SOC 2 evidence within a day. It will not write your scope statement, run your risk assessment, hold your management review or conduct your internal audit, and those are the items that set the timeline.

Get the second framework quoted properly

Tell us what your SOC 2 covers and we will match you with Canadian firms that price ISO 27001 against existing evidence rather than from scratch.

Get matched