Skip to main content

Explainers

SOC 2 vs ISO 27001: what to ask vendors for

A report is not a certificate. Here is what SOC 2 and ISO 27001 actually prove, who issues each one, and which to require for which data.

Solomon AmosPublished 18 Sep 20269 min read

A padlock resting on a computer keyboard
Photo by FLY:D on Unsplash

When a buyer asks a vendor for security evidence, the answer usually arrives as one of two documents: a SOC 2 report or an ISO 27001 certificate. Procurement teams tend to treat them as interchangeable proof that a vendor takes security seriously, but they are structurally different artefacts, produced by different kinds of firm, read by different audiences, and renewed on different cycles. A SOC 2 report is a narrative audit opinion written by a CPA firm. An ISO 27001 certificate is a one-page attestation issued by an accredited certification body confirming that a management system met a published standard. Knowing which one you actually need, and for which category of data, saves a renewal cycle spent chasing the wrong document.

What a SOC 2 report actually contains

SOC 2 is a reporting framework defined by the American Institute of CPAs. A licensed CPA firm audits a vendor against one or more of five trust services criteria: security, availability, processing integrity, confidentiality and privacy. Security is mandatory; the other four are chosen by the vendor depending on what they want covered. The output is a long-form report, often 40 to 120 pages, containing the auditor's opinion, a description of the system, and a detailed list of controls tested with results for each one. A Type I report is a snapshot of controls at a single point in time. A Type II report, which is what most buyers should insist on, tests those controls operating over a window, usually three to twelve months. Distribution is restricted: SOC 2 reports are meant to be shared under NDA with the vendor's customers and prospects, not published on a public register. That restriction is itself a clue buyers can use, covered further down.

What an ISO 27001 certificate actually contains

ISO/IEC 27001 is an international standard for an information security management system, or ISMS: the policies, risk assessments and controls a vendor runs to manage information security on an ongoing basis. A vendor does not audit itself against the standard. An accredited certification body performs a two-stage audit, checks the vendor's Statement of Applicability against Annex A controls, and if the vendor passes, issues a certificate valid for three years, with surveillance audits in the intervening years. The certificate itself is short: scope, certificate number, issuing body, accreditation mark, issue and expiry dates. It says nothing about which controls were tested or how. Buyers who want that detail have to request the Statement of Applicability separately. One dating detail matters here: certificates that still cite the 2013 edition of the standard lapsed on 31 October 2025 under IAF MD 26, so any certificate a vendor shows you today should reference the 2022 edition.

Report versus certificate: the structural difference

SOC 2 reportISO 27001 certificate
Issued byA licensed CPA firmAn accredited certification body
What it provesSpecific controls were tested and how they performedA management system meets the standard's requirements
Typical length40 to 120 pages1 page, plus an optional Statement of Applicability
DistributionRestricted, shared under NDAOften published on the certification body's public register
ValidityCovers a fixed audit window, reissued annuallyValid for 3 years, with annual surveillance audits
Geography of adoptionDominant in North AmericaDominant in Europe, Asia and government procurement

The two documents answer different questions, which is why buyers sometimes need both.

A padlock resting on a computer keyboard
A certificate confirms a system exists. A report shows how it performed. · Photo by FLY:D on Unsplash

Which one to ask for, by data type

  • Customer PII in a SaaS product: a SOC 2 Type II covering security and confidentiality is the closer fit, because it shows how access controls and monitoring performed over time, not just that a policy existed.
  • Cardholder data: neither document substitutes for PCI DSS. A vendor handling card data still needs a PCI attestation of compliance from a Qualified Security Assessor; SOC 2 or ISO 27001 evidence is supporting context, not a replacement.
  • Health data under a US BAA: HIPAA has no certification scheme at all, so a vendor claiming to be "HIPAA certified" is misdescribing itself. What exists is a signed Business Associate Agreement and, ideally, a SOC 2 report scoped to include HIPAA-mapped controls.
  • Multi-country enterprise deals, especially with EU or UK buyers: procurement teams there frequently ask for ISO 27001 by default, because it is the standard their own auditors recognise and because the certificate sits on a public register they can check themselves.
  • Infrastructure and hosting providers: look for both. A hosting vendor that only has one of the two is more common than you would expect, and the gap is worth asking about directly rather than assuming coverage.

How to verify either document without asking the vendor

  1. 1

    Check the certification body's public register first

    Most ISO 27001 certification bodies, such as BSI, DNV or SGS, publish a searchable register of active certificates. If a vendor's certificate does not appear there under the name and scope claimed, treat the claim as unverified rather than assuming an admin error.

  2. 2

    Confirm the audit firm is licensed to issue SOC 2 opinions

    SOC 2 reports name the CPA firm on the cover page. That firm should be a real, licensed practice; a quick search of the state board of accountancy or the firm's own site confirms it exists and issues attestation work.

  3. 3

    Read the scope before the headline, not after

    A report or certificate can be narrowly scoped to one product line or one data centre. Check which systems and locations are actually covered before assuming the whole vendor relationship is protected.

  4. 4

    Ask for a bridge letter if the report is aging

    A SOC 2 Type II report more than nine months old is stale. A bridge letter from the same audit firm, covering the gap to the current date, is the standard way vendors fill that window without a full re-audit.

  5. 5

    Cross-check the CertReports evidence date

    Where a vendor's evidence has been indexed, check the dated snapshot rather than a vendor's marketing page. A framework badge with no attached evidence date is not verifiable and should be flagged as no public evidence, not assumed to be current.

Do buyers need both

For a mid-market SaaS vendor selling mainly into North America, a strong SOC 2 Type II is usually sufficient on its own, and asking for ISO 27001 as well adds cost without adding much buyer confidence. For a vendor selling into Europe, into government-adjacent supply chains, or into any buyer whose own compliance team runs an ISO-aligned vendor risk programme, ISO 27001 tends to be the document that clears procurement gates even when a SOC 2 report also exists. Vendors operating in both markets increasingly hold both, and larger buyers are starting to ask for both by default rather than accepting either as a substitute for the other. The overlap in underlying controls is real, since both frameworks converge on access control, change management, incident response and vendor risk management, but the audits, the auditors, and the resulting documents remain separate exercises with separate costs.

A desk covered in printed reports and documents
Coverage in the index compares dated evidence, not vendor claims. · Photo by Helloquence on Unsplash

What the index shows across both frameworks

In the CertReports index on 2026-09-18, 1,842 vendor profiles show a dated SOC 2 Type II report as their most recent security evidence, against 1,206 vendor profiles showing an active ISO 27001 certificate referencing the 2022 edition. Of those, 611 vendors show both a current SOC 2 report and a current ISO 27001 certificate on file. The remainder show one framework only, and a further set show a framework badge on the vendor's own marketing page with no dated evidence attached, which the index records as no public evidence rather than treating the badge as confirmed.

1,842
Vendors with a dated SOC 2 Type II report
CertReports index, 2026-09-18
1,206
Vendors with an active ISO 27001 certificate
2022 edition, CertReports index, 2026-09-18
611
Vendors holding both, current
CertReports index, 2026-09-18
ISO/IEC 27001 is the world's best-known standard for information security management systems. It provides requirements for an organisation to establish, implement, maintain and continually improve an information security management system.

A note on how vendors describe this evidence

Marketing copy sometimes says a vendor is "SOC 2 certified", but that phrase is not accurate: SOC 2 produces a report and an auditor's opinion, not a certification, so there is no such thing as being "SOC 2 certified" in the way there is for ISO 27001. The distinction is not pedantic. A certificate can be checked against a public register in minutes. A report cannot be verified the same way, because it is distributed under NDA, which is exactly why buyers should ask to see the report itself, or its evidence date, rather than accepting a badge on a trust page as proof of anything.

Use /compare before you sign

Where a vendor shows evidence for both frameworks, or for neither, the fastest way to see the full picture side by side is the /compare tool, which lines up dated evidence rather than marketing claims.

People also ask

Is ISO 27001 better than SOC 2?

Neither is objectively better; they measure different things. ISO 27001 certifies that a management system meets a standard, checked by an accredited body and often listed on a public register. SOC 2 is an auditor's tested opinion on specific controls over a period, distributed under NDA. Which one matters more depends on your buyer's market: European and government-adjacent buyers lean towards ISO 27001, while North American SaaS buyers lean towards SOC 2 Type II.

Do I need both SOC 2 and ISO 27001?

Not always. A vendor selling mainly in one region can often get by with the framework that region's buyers expect. Vendors selling across North America, Europe and government-adjacent supply chains increasingly hold both, since a growing share of large buyers now ask for both rather than accepting either as a substitute. In the CertReports index on 2026-09-18, 611 vendors currently hold both, current.

Which is more common in the US versus Europe?

SOC 2 dominates in the United States, largely because it is a CPA-firm product built around AICPA trust services criteria that US procurement teams already recognise. ISO 27001 dominates in Europe and much of Asia, where accredited certification against an international standard is the default expectation in vendor risk programmes and public sector procurement. Vendors selling into both markets typically need to carry evidence for both.

Which is easier to verify without asking the vendor?

ISO 27001, in most cases. Certification bodies such as BSI, DNV and SGS publish searchable public registers, so a buyer can confirm a certificate's status, scope and expiry directly. SOC 2 reports are restricted under NDA and are not published anywhere public, so verification usually depends on the vendor sharing the report, or on a third-party index recording the report's existence and evidence date.

SOC 2ISO 27001framework comparisonvendor security reviewcompliance evidence
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like