Cloud Security Stack
Compliance and governance

Compliance

ISO 27001 or SOC 2: which one your customers actually want

They overlap heavily and they are not interchangeable. Which one to pursue depends almost entirely on where your customers are.

11 min read · Reviewed 22 August 2026 · Written against ISO/IEC 27001:2022 and the AICPA Trust Services Criteria.

The short answer is geography

If your customers are predominantly North American, they will ask for SOC 2. If they are European, British or in most of the rest of the world, they will ask for ISO 27001. Selling into both means you will eventually be asked for both.

This is not about which framework is more rigorous. It is about which one procurement departments recognise, and that is regional habit rather than a judgement of quality.

The practical differences
ISO 27001SOC 2
What it certifiesA management systemControls over a period
OutputA certificateAn auditor's report
Can be shared publicly
Typical first-time duration6 to 12 months3 to 12 months
RecurringSurveillance auditsAnnual report
Recognised in Europe
Recognised in North America

A SOC 2 report is a confidential document shared under NDA, which is a practical difference that catches people out in marketing.

Type 1 and Type 2 are not two options

A SOC 2 Type 1 says the controls were designed appropriately on one day. A Type 2 says they operated effectively over a period, usually three to twelve months. Customers asking for SOC 2 almost always mean Type 2.

Type 1 is useful as a milestone when you need to show progress to a customer who is waiting, and it is not a substitute. Budget for Type 2 from the start, because the observation window is the long pole.

Doing both, if you must

The control overlap is substantial, and the evidence collected for one covers a large share of the other. Organisations that need both should scope them together rather than sequentially, because running two separate projects duplicates the evidence work that dominates the effort.

The genuinely separate parts are the ISO management system documentation and the SOC 2 report narrative. Everything technical is largely shared.

The verdict

Our pick

Follow your customers, not the framework

Both are credible. The one that closes deals is the one your buyers recognise, and pursuing the other first delays revenue for no security benefit.

Who should skip

Do not start either without a customer asking. Both are expensive, both are ongoing, and neither improves security much beyond what the underlying controls already do.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.