Skip to main content
RoseleapBlog · Compliance

ISO 27001 vs SOC 2: which one does your buyer want?

A side-by-side of the two certifications enterprise buyers ask for, what each actually proves, real costs and timelines, and how to run both without doubling the work.

·14 min read

The question arrives the same way every time. A deal is progressing, the buyer's security team sends a questionnaire, and somewhere in it is a line asking for your SOC 2 report or your ISO 27001 certificate. Suddenly a sales cycle depends on a document you do not have.

The short answer: ISO 27001 if your buyers are in Europe, the UK, India, the Middle East or Asia; SOC 2 if your buyers are American. If you sell to both, start with the one blocking revenue right now, and build so the second one costs you a fraction of the first.

The longer answer is worth reading, because these two things are less alike than the “vs” framing suggests. They are not competing standards. They are different kinds of object.

What each one actually is

ISO 27001 is a certification of a management system

ISO/IEC 27001 is an international standard for an Information Security Management System (ISMS). An accredited certification body audits you and, if you pass, issues a certificate valid for three years, with surveillance audits in years one and two and a full recertification in year three.

The emphasis is on the system: that you have identified your risks, chosen controls to address them, assigned ownership, and built a management cycle that reviews and improves all of it. The current version is ISO/IEC 27001:2022, whose Annex A lists 93 controls across four themes (organisational, people, physical, technological).

Critically, you do not have to implement all 93. You justify which apply through a document called the Statement of Applicability, and you justify any exclusions. Two certified companies can have quite different control sets.

SOC 2 is an attestation report about your controls

SOC 2 is not a certification and there is no such thing as being “SOC 2 certified”, whatever the badge on a competitor's website says. It is an attestation performed by a licensed CPA firm under AICPA standards. The output is a report, typically 40 to 100 pages, containing the auditor's opinion, your description of your system, the controls you defined, and the tests performed against each one.

Controls are organised under five Trust Services Criteria: Security (mandatory), Availability, Processing Integrity, Confidentiality and Privacy. You pick which additional criteria are in scope based on what you promise customers.

There are two types, and the difference matters commercially:

  • Type I: are the controls suitably designed as at a single date? Achievable quickly. Buyers increasingly treat it as a placeholder rather than an answer.
  • Type II: did the controls operate effectively across an observation window, usually three to twelve months? This is what enterprise buyers actually want.

Our SOC 2 readiness guide goes deeper on the Type I to Type II path.

Side by side

  • Output. ISO 27001: a one-page certificate you can publish. SOC 2: a long confidential report you share under NDA. The certificate is a better marketing asset; the report is a better answer to a security team.
  • Who performs it. ISO 27001: an accredited certification body. SOC 2: a licensed CPA firm.
  • Geography. ISO 27001 is the global default outside North America. SOC 2 dominates in the United States, particularly in SaaS.
  • Prescriptiveness. ISO 27001 gives you a control catalogue; SOC 2 expects you to define your own controls against criteria. SOC 2 is more flexible and, for that reason, harder for a first-timer to scope.
  • Duration. ISO 27001 certificates run three years with annual surveillance. SOC 2 reports cover a fixed window and go stale, so buyers expect a fresh one annually.
  • Failure mode. ISO 27001 has major and minor nonconformities you must close. SOC 2 has exceptions, which appear in the report and are visible to every buyer who reads it.
A SOC 2 report with a handful of documented exceptions is normal and defensible. A report with an adverse opinion is worse than having no report at all, because you cannot un-ring that bell with the buyers you already sent it to.

Real costs and timelines

For a company of roughly 20 to 80 people running a cloud product, in USD:

ISO 27001

  • Gap assessment and readiness work: $8,000 to $30,000 one-time.
  • Certification body, Stage 1 and Stage 2 audit: $12,000 to $35,000.
  • Surveillance audits: $5,000 to $12,000 per year in years one and two.
  • Recertification in year three: comparable to the initial audit.
  • Internal effort: 200 to 500 hours across the first cycle, concentrated in documentation and risk assessment.
  • Elapsed time: four to nine months from a standing start.

SOC 2

  • Readiness and remediation: $10,000 to $40,000 one-time.
  • Type I audit: $10,000 to $25,000.
  • Type II audit: $18,000 to $60,000 depending on scope and criteria.
  • Compliance automation platform, if used: $6,000 to $25,000 per year.
  • Elapsed time: three to four months to Type I, then the observation window (commonly three to six months for a first report) before Type II.

Indian firms will generally land at the lower end of these ranges for the readiness work and near the middle for the audit itself, since audit fees are set largely by the firm you engage rather than by your location.

The overlap, which is larger than people expect

Roughly 70 to 80 percent of the underlying work is shared. Both frameworks want:

  • Access control, provisioning and deprovisioning, with evidence.
  • A change management process with review and approval trails.
  • Vulnerability management and patching on a defined cadence.
  • Incident response, documented and tested.
  • Vendor and third-party risk management.
  • Business continuity and tested backups.
  • Security awareness training and background checks.
  • Logging and monitoring, with retention.
  • Encryption in transit and at rest.
  • Formal risk assessment and treatment.

The differences sit at the edges. ISO 27001 wants management review meetings, internal audits, a Statement of Applicability, and documented continual improvement. SOC 2 wants a detailed system description and evidence sampled across a period rather than at a point.

The practical implication: if you build your control set once and map it to both frameworks from the start, the second certification costs roughly 30 to 40 percent of the first. Doing them separately, two years apart, with different consultants and different evidence conventions, costs close to double.

How to choose

Choose ISO 27001 if

  • Your buyers are European, British, Indian, Gulf or East Asian.
  • You sell into regulated sectors that reference international standards in procurement.
  • You bid for government or public sector tenders, which frequently name ISO explicitly.
  • You want a public credential you can put on a website and a proposal, without an NDA dance.
  • You expect to add other ISO standards later, since the management system structure is shared.

Choose SOC 2 if

  • Your buyers are US companies, especially mid-market and enterprise SaaS purchasers.
  • Deals are stalling in security review right now and someone has named SOC 2 specifically.
  • You want evidence of controls operating over time rather than a conformity statement.
  • Your investors or board expect the framework their portfolio companies use.

Do both if

Your revenue genuinely splits across North America and elsewhere. Sequence it: get the one unblocking near-term revenue, run the observation or surveillance period, then add the second while the evidence machinery is already running. Do not attempt both from zero simultaneously with a small team; the documentation load lands at the same time and something gives.

The most expensive mistake we see is treating certification as a project rather than an operating change. Companies sprint to a certificate, disband the effort, and then rediscover a year later that nobody has been collecting evidence, running access reviews or holding management reviews. The surveillance audit finds this immediately.

What actually consumes the time

Not the controls. Most competent engineering teams already do the technical half: encryption, access control, backups, logging. What eats the calendar is:

  • Evidence. Proving a control ran, on a date, with an approver. Retrofitting a year of evidence is impossible, which is why the observation window cannot be compressed.
  • Policy documentation. Twenty to thirty documents that must reflect what you genuinely do, not a template with your logo dropped on top. Auditors interview staff, and templates unravel fast in interviews.
  • Vendor inventory. Listing every subprocessor, obtaining their reports, and assessing them.
  • Asset and data inventory. Knowing what data you hold, where it lives, and who can reach it. Almost nobody has this written down before they start.
  • Getting people to do things consistently. Offboarding checklists, ticket approvals, review sign-offs. This is culture work, and it is the part consultants cannot do for you.

Where this sits alongside privacy law

Neither framework makes you compliant with data protection law, and this trips people up constantly. ISO 27001 and SOC 2 are about how you protect information. GDPR and the DPDP Act are about whether you were allowed to collect and use it, and what rights the person it describes retains.

There is real synergy: an ISMS gives you most of the security-measures evidence that GDPR Article 32 and the DPDP Act's reasonable safeguards obligation expect. But a certificate is not a defence to a consent or purpose-limitation failure, and no regulator has ever accepted it as one.

Getting started without wasting a quarter

  • Ask your buyers, precisely. Not “do you need security certification” but “which document unblocks this deal, and by when”. The answer is often narrower than you feared, and sometimes a completed questionnaire plus a penetration test report is enough for now.
  • Scope tightly. One product, one environment, the teams that touch it. Scope creep is the main driver of cost in both frameworks and it is entirely self-inflicted.
  • Run a gap assessment before engaging an auditor. Two to three weeks, and it converts an open-ended anxiety into a task list with owners.
  • Build the evidence habit early, even before you formally start. Every month of clean evidence is a month you do not add to the observation window later.
  • Choose the auditor after readiness, not before. Auditors cannot advise you and audit you, so engaging one first just costs you time.

How RoseLeap can help

We run SOC 2 readiness as a fixed-scope engagement: gap assessment, control design, policy set, evidence pipeline, and auditor liaison through to the report. We are not an audit firm, which is precisely why we can do the readiness work.

For ISO 27001 we do the same on the ISMS side, and where you need both we design the control set once and map it to both frameworks so the second one is an increment rather than a repeat. Tell us who your buyers are and what they have asked for on the contact page, and we will come back with a recommendation and a fixed fee within one business day.

RoseLeap.

Rooted in Data · Built to Bloom

Need help with your own?

Tell us about your project. We come back with a clear, honest plan.

Start a Project