In short: SOC 2 gives you an attestation report from an independent CPA firm on your controls against the AICPA's Trust Services Criteria. ISO 27001 gives you a certificate from an accredited certification body that your information security management system conforms to ISO/IEC 27001:2022. Both are respected; which one you need usually depends on what your customers ask for.
Side by side
| SOC 2 | ISO 27001 | |
|---|---|---|
| What you get | An attestation report (not a certificate) | A certificate |
| Who issues it | An independent CPA firm | A certification body accredited by an accreditation body |
| Measured against | AICPA 2017 Trust Services Criteria (revised points of focus, 2022) | ISO/IEC 27001:2022 requirements, with 93 Annex A controls |
| Always in scope | Security (common criteria); other four categories optional | The ISMS you define, with controls chosen by risk assessment |
| Time dimension | Type 1: a point in time. Type 2: a period, typically 3–12 months per auditors | Three-year certificate, with annual surveillance audits |
| Published costs | See the Cost & Readiness Index for attributed figures for both | |
Where they overlap
Both expect the same security foundations: access control, change management, incident response, backups, vendor oversight, awareness training and evidence that these operate. Work done for one usually helps with the other; our readiness assessment covers those foundations whichever you choose.