ISO 27001 vs SOC 2: which one does your buyer actually want?
A certificate or an attestation report - they answer different customers. When you need ISO 27001, when you need SOC 2, when you need both, and how to avoid paying twice for the same evidence.
By Kellwick Team · July 25, 2026 · 3 min read
The short answer: ISO 27001 is a certificate; SOC 2 is a report. International and EU buyers, tenders and regulators ask for ISO 27001. US enterprise buyers - especially SaaS procurement - ask for SOC 2. Many growing companies eventually need both, and the good news is that the control overlap is large enough that most of the evidence carries from one to the other.
If you are trying to decide which to do first, decide it the way your customers do: do the one your next big deal is asking for.
The core difference
| ISO 27001 | SOC 2 | |
|---|---|---|
| What it is | An international certification of an information security management system | A US attestation report on your controls |
| Who issues it | An accredited certification body (Stage 1 + Stage 2 audit) | A licensed CPA firm (an examination) |
| What you get | A certificate you can publish | A report you share under NDA |
| Who asks for it | International / EU buyers, tenders, regulators | US enterprise buyers, SaaS procurement |
| Cadence | 3-year cycle with annual surveillance | Type II typically renewed every 12 months |
The single most common misconception is calling SOC 2 a "certification". It is not. There is no SOC 2 certificate and no accreditation body. A CPA firm examines your controls against the AICPA Trust Services Criteria and writes a report, which you then hand to customers - usually behind an NDA - to answer their security due diligence.
SOC 2 in one paragraph
SOC 2 covers up to five Trust Services Criteria. Security (the Common Criteria) is always in scope. Availability, Confidentiality, Processing Integrity and Privacy are added only where your customers ask for them - and scoping them in when nobody is asking is the most common way teams overspend. A Type I report covers whether your controls are suitably designed at a point in time; a Type II covers whether they operated effectively over a period, commonly three to twelve months. Most enterprise buyers eventually want Type II.
When you need which
- You sell mostly to US companies: start with SOC 2. It is what their procurement teams recognise, and a Type I gives you something to show while the Type II observation window runs.
- You sell to EU, UK or international buyers, or bid for tenders: start with ISO 27001. It is the credential those buyers and frameworks name, and DORA/NIS2-adjacent conversations lean on it.
- You sell to both: you will likely need both. Do not treat that as two separate programmes.
The part that saves you money: the overlap
ISO 27001 Annex A and the SOC 2 Trust Services Criteria are describing much of the same security reality - access control, change management, logging and monitoring, incident response, vendor risk, backup and recovery. If you already run an ISO 27001 ISMS, a large share of your evidence maps straight onto the Common Criteria. The reverse is also true.
The mistake is building two parallel evidence bases with two different vocabularies. The right move is one control-and-evidence base, mapped to whichever framework a given buyer is asking about. That is exactly how we approach a second framework: build it on top of the first, not beside it.
What it costs
Both are two bills, not one. For ISO 27001 you pay a readiness/advisory partner to get audit-ready, then the certification body for the Stage 1 and Stage 2 audit. For SOC 2 you pay a readiness partner, then a CPA firm for the examination. The readiness side is where a good partner earns its fee - and where the evidence reuse between the two frameworks pays off. See our pricing page for the readiness ranges; the certification body and CPA fees are quoted separately by them.
Where Kellwick fits
Kellwick is an independent advisory practice - not a certification body and not a CPA firm. We get you audit-ready for either or both: scope the controls, build and map the evidence, close the gaps, and walk you into the certification-body audit or the CPA examination prepared. If you already hold one, we build the second on your existing evidence. See SOC 2 readiness or ISO 27001 readiness for SaaS, or start with a Mini Gap Review to find out where you stand.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.