SOC 2 to ISO 27001 reuse estimator
SOC 2 and ISO 27001 share most of their control work and almost none of their management system work. This estimates the split for your situation instead of leaving you with the usual answer, which is that there is a lot of overlap.
Every comparison page says the two frameworks overlap and none of them says by how much. The honest answer has two halves. Your SOC 2 control evidence carries a long way into Annex A, often most of the way. Clauses 4 through 10 of ISO 27001, which are the 25 requirements that make it a management system, are barely touched by a SOC 2 engagement, and that is where a second-framework project actually spends its money.
The estimate appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
Where the numbers come from
The estimate is built on one structural fact rather than on a control-level mapping, because control-level mappings between the two frameworks are approximate and every vendor publishes a different one. The fact is that ISO 27001 has two halves and SOC 2 only overlaps with one of them.
| ISO 27001 requirement | Covered by a SOC 2 Type 2 | Why |
|---|---|---|
| Annex A technological controls | Most of it | Access, logging, vulnerability management, change and backup are tested by SOC 2 fieldwork in almost the same terms. |
| Annex A people controls | Most of it | Screening, training, agreements and offboarding are common criteria evidence already. |
| Annex A organizational controls | Roughly half | Supplier and incident work carries over. Asset inventory, classification and the compliance group usually do not. |
| Annex A physical controls | Some | Where an office is in scope, SOC 2 covers less of this than people assume. |
| Clauses 4 to 10, the 25 requirements | Little | Scope statement, risk method, objectives, internal audit, management review and corrective action are ISO constructs. SOC 2 asks for none of them by name. |
| Overall readiness effort saved on a first ISO 27001 | 25% to 55% | Against starting from nothing, for a company holding a current Type 2 |
The saving is real and it is not the audit fee
The certification body prices from audit days, and audit days come from headcount, scope and complexity. Holding a SOC 2 report does not reduce them. What it reduces is the readiness work, which is the larger number: the gap assessment finds less, the control implementation is mostly done, and the evidence exists. Expect the certification body quote on the cost page to be unchanged and the consultant quote to fall.
Common questions
Can we reuse SOC 2 evidence in an ISO 27001 audit?
The underlying evidence, yes. Access reviews, onboarding records, change tickets, vulnerability scans and supplier reviews are the same artefacts and an ISO auditor will sample them happily. The SOC 2 report itself is not evidence of an ISO control, because it was written against different criteria and by a firm with no standing in the ISO scheme.
Does an ISO 27001 certificate replace our SOC 2 report?
Not with a buyer who asked for SOC 2. North American procurement teams frequently have the framework written into a policy, and a certificate is not a substitute for an attestation in that conversation. Companies selling on both sides of the Atlantic usually end up holding both, which is why the order you get them in matters. See the comparison.
How long does the second framework take?
Six to nine months for a company with a current Type 2, against nine to fifteen from a standing start. The constraint moves from building controls to the management system requirements, and specifically to running an internal audit and a management review, both of which need the system to have been operating first. That floor does not go away because you already hold a report.
Does a compliance platform make this automatic?
It makes the evidence mapping fast and it does none of the management system work. A platform will tick a large share of Annex A from your existing SOC 2 evidence within a day. It will not write your scope statement, run your risk assessment, hold your management review or conduct your internal audit, and those are the items that set the timeline.
Get the second framework quoted properly
Tell us what your SOC 2 covers and we will match you with Canadian firms that price ISO 27001 against existing evidence rather than from scratch.
Get matched