home / frameworks / soc-2 / soc-2-vs-iso-27001

// SOC 2 hub

SOC 2 vs ISO 27001

How a SOC 2 attestation differs from ISO/IEC 27001 certification, and when Canadian organizations pursue one or both.

2 different kinds of assurance

SOC 2 is an attestation. A CPA firm gives an opinion on a specific system's controls, and a Type 2 report shows the tests and their results. ISO/IEC 27001 is a certification. An accredited certification body audits an information security management system and, if it conforms, issues a certificate. The certificate states the scope, but it does not list tests or exceptions.

Readers therefore get different things. A SOC 2 Type 2 lets a customer see how individual controls performed. An ISO 27001 certificate tells a customer that a management system for security is in place, is audited every year, and covers a stated scope.

Structure and scope

SOC 2 is built on the Trust Services Criteria, with 33 common criteria for security and optional categories. The company writes its own controls. ISO/IEC 27001:2022 sets management system requirements in clauses 4 to 10, such as risk assessment, internal audit, and management review, and lists 93 reference controls in Annex A. The organization selects controls through its risk treatment and documents its choices in a statement of applicability.

Both expect risk assessment, access control, change management, incident response, vendor management, and monitoring. The overlap is large enough that the AICPA publishes a mapping from the Trust Services Criteria to ISO 27001.

Who does the work

A SOC 2 report must come from a licensed CPA firm. ISO 27001 certification comes from a certification body accredited to ISO/IEC 17021-1 and ISO/IEC 27006 by a national accreditation body. In Canada that body is the Standards Council of Canada, and certificates from bodies accredited by other members of the International Accreditation Forum are also widely accepted. Some firms offer both.

Cycles

SOC 2 Type 2 reports are usually renewed every year with back-to-back periods. ISO 27001 runs on a 3-year cycle. A certification audit is followed by surveillance audits in years 2 and 3, then a recertification audit before the certificate expires at the end of year 3.

Which customers ask for which

US buyers lean toward SOC 2. European and many Asian buyers lean toward ISO 27001. Canadian buyers ask for both, often depending on where their own security team trained. For Government of Canada cloud work, the Canadian Centre for Cyber Security lists AICPA SOC 2 Type II reports, ISO/IEC 27001 reports, ISO/IEC 27017 reports, and FedRAMP system security plans as the attestations it has compared with ITSG-33 controls.

Cloud providers that want a single listing covering both can look at CSA STAR Level 2, which builds on either a SOC 2 or an ISO 27001 engagement and adds the Cloud Controls Matrix.

Doing both

Many Canadian vendors hold both. The cheapest path is one control set mapped to both frameworks, one evidence repository, and audits timed close together so the same evidence can serve both. ISO 27001 adds management system work that SOC 2 doesn't require, such as a formal internal audit program and management reviews. SOC 2 adds detailed testing of how each control operated across the period. Expect each to need its own fieldwork, even with heavy reuse.

Resources

All SOC 2 resources

References

  1. Mapping: 2017 Trust Services Criteria to ISO 27001, AICPA and CIMA
  2. Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Security
  3. STAR Attestation, Cloud Security Alliance