AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

ISO 27001 vs SOC 2: Which One Your Customers Are Actually Asking For

ISO 27001 vs SOC 2 for a small software company: what each one proves, who asks for which, what the certificate costs you in time, and how to do the work once.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

Two customers, two acronyms, one CTO

The founder of a 25-person logistics software company in Chicago has two deals in the pipeline in the same month. The first is a hospital group in Texas that wants to route pharmacy deliveries through the platform. Their vendor security form asks for a SOC 2 Type 2 report. The second is a freight forwarder in Dubai bidding on a government contract. Their tender requires every technology supplier to hold an ISO 27001 certificate.

The head of sales says the obvious thing: get both. The finance lead points out that the company has exactly one person who understands the systems well enough to do either, and she is the CTO, and she is also shipping the product.

The CTO reads both standards over a weekend. On Monday she surprises the founder. About four-fifths of what the two audits will ask for is the same work: who has access to what, whether there are logs, what happens when something breaks, which vendors touch customer data. The difference is who examines it and what document comes out the other end.

She proposes one plan. Build the controls once, keep one evidence folder, and let two different examiners read it. The founder asks how long. She says the Texas hospital's Type 2 needs six months of the controls running, so the earliest report is spring, and the Dubai certificate can be audited from the same evidence a month later.

Sales asks if there is a faster way. There is not.

What the heck does this mean

ISO 27001 is an international standard for an information security management system, an ISMS. Certification means an accredited body audited your system, your risk assessment, and the controls you chose from its list, and issued a certificate valid for three years with annual check-ups.

SOC 2 is an attestation report, not a certificate. A licensed CPA firm tests your controls against the AICPA's Trust Services Criteria and writes an opinion. Type 1 covers a date; Type 2 covers a period.

The practical difference is the audience. ISO 27001 is what international buyers, European partners and government tenders, including those in the UAE, ask for. SOC 2 is what US enterprise procurement, hospitals, banks and insurers ask for, because their vendor policies were written around it.

The management system is the part ISO adds that SOC 2 does not require by name: a documented process for assessing risk, choosing controls, reviewing them with leadership and improving them. SOC 2 assumes you have one; ISO makes you show it.

The overlap is the point. Access control, logging, incident response, vendor management, change management and backup are tested by both. Do them once. Do them properly. Then decide which examiner goes first based on which customer is waiting.

The numbers that matter

There were 96,709 valid ISO 27001 certificates worldwide covering 179,877 sites in the ISO Survey 2024. That is the population your Dubai customer is comparing you against, and it grows every year.

ISO 27001 is a stated prequalification criterion in many UAE government technology tenders, according to UAE procurement practice in 2026. For the freight forwarder's bid, the certificate is not a preference; it is the entry ticket.

Detection and escalation costs plus lost business make up nearly two-thirds of the cost of a breach, according to the IBM 2026 Cost of a Data Breach Report. Both frameworks exist to shrink those two numbers, which is why a customer who has been burned asks for one of them before signing.

What to do this week

  1. Put everyone behind a single identity provider with MFA, and write the offboarding rule: access removed the day someone leaves, with a record. Both examiners will sample your last five departures. (CIS 5 Account Management)
  2. Turn on audit logging in the cloud console, the identity provider, the code repository and the production database, with retention of at least a year. Type 2 needs the logs for the whole window; ISO needs them to exist and be reviewed. Start today. (CIS 8 Audit Log Management)
  3. Write the incident response plan on one page with names, run a thirty-minute tabletop, and open an incident log even if the first entry is "tabletop, no real incidents to date". Both frameworks ask for the plan, the test and the log. (CIS 17 Incident Response Management)
  4. Write the risk register: the ten things most likely to hurt the company, how likely, how bad, and what you decided. ISO requires it by name; SOC 2 auditors ask for it under a different heading. (CIS 17 Incident Response Management)
  5. List every vendor that touches customer data, collect each one's SOC 2 or ISO certificate, and note who reviewed it and when. (CIS 15 Service Provider Management)
  6. Decide the order from the customer calendar. If the hospital's contract is spring, the Type 2 window opens now and the ISO audit follows from the same folder. If the tender closes first, flip it. Tell both customers the date in writing. (CIS 8 Audit Log Management)

Where AccuSights fits

We build the one evidence folder that both examiners read. Our assessment maps your controls to the SOC 2 criteria and the ISO 27001 control list at the same time, so the gap list is one list. Our team implements the controls at a reasonable rate, from identity and logging to data loss prevention, scanning and protection of the systems in scope, and we keep the evidence flowing so the CTO can go back to shipping. Take the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer who has prepared companies for both audits.

Questions people ask

Can you get SOC 2 and ISO 27001 at the same time? Yes, and for a small company it is the sensible way to do it. Most of the controls are the same: access management, logging, incident response, vendor oversight, change control. Build them once, collect evidence once, and let the CPA firm and the certification body each examine the same folder from their own angle. The two audits can run in the same season, and some firms offer both under one engagement.

Is ISO 27001 recognized in the US? Recognized, yes. Preferred, usually not. US buyers, particularly in healthcare and financial services, are conditioned to ask for a SOC 2 report because their vendor policies were written around it. Most will accept an ISO 27001 certificate as evidence of a program, but the procurement form still has a box that says SOC 2, and the person filling it out rarely has the authority to redraw the form.

How long is an ISO 27001 certificate valid? Three years, with a surveillance audit by the certification body each year in between. Miss a surveillance audit and the certificate can be suspended. At the end of the three years you go through a recertification audit, which is closer in scope to the original. The practical effect is that ISO 27001 is an annual commitment with a three-year rhythm, much like a SOC 2 Type 2 is an annual report with a rolling window.

Two customers asked two questions. The right answer to both was the same folder. Build the folder.

Controls this post maps to

CIS 5 Account ManagementCIS 8 Audit Log ManagementCIS 17 Incident Response Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.