SOC 2 vs ISO 27001: which one to get first
One is a report with an opinion, the other is a certificate. Here is how to tell which one the buyer in front of you is asking for.
SOC 2 vs ISO 27001, in one line: SOC 2 is a report carrying a CPA firm’s opinion, and ISO 27001 is a certificate from an accredited certification body. The report is issued under the AICPA attestation standards.2 The certificate is never issued by ISO:
- ISO states that it does not perform certification or issue certificates, and that certification is performed by external certification bodies. Source, read 2026-09-28.
- ISO states that companies implementing ISO/IEC 27001 can decide whether they want to go through a certification process, and that a certificate from an accredited body may add confidence because an accreditation body has independently confirmed the certification body’s competence. Source, read 2026-09-28.
Everything else follows from that difference. Who you hire, what gets tested, how long it covers, and how a buyer checks it.
Most of the controls underneath are the same. Access reviews, onboarding and offboarding, encryption, logging, incident response, supplier checks. What differs is the frame around them and the document that comes out the other end.
Side by side
| Question | SOC 2 | ISO 27001 |
|---|---|---|
| What you receive | A report with an opinion | A certificate |
| Who issues it | A licensed U.S. CPA firm | An accredited certification body |
| Measured against | The AICPA Trust Services Criteria, plus the commitments you made to customers | Clauses 4 to 10 of the standard, plus the Annex A controls your risk assessment selects |
| What it covers in time | One date for a Type 1, a period for a Type 2 | The management system at the time of each audit, across a three year cycle |
| Renewal | A new report each year | Surveillance audits in years two and three, then recertification |
| How a buyer checks it | Reads the report under NDA and verifies the firm with its state board | Looks the certificate up in a public register |
What each one actually tests
A SOC 2 examination tests controls against the Trust Services Criteria. Security is always in scope, and availability, confidentiality, processing integrity and privacy are added when you choose them.3 The criteria are measured against the promises you made to customers in contracts and service level agreements.
ISO 27001 tests a management system. The requirements in clauses 4 to 10 cover scope, leadership, risk, operation, internal audit, management review and improvement. Annex A is a reference list of 93 controls, and your risk assessment decides which apply. Annex A for a small team walks through the four themes.
So the two ask different questions. SOC 2 asks whether your controls met your commitments. ISO asks whether you run a system that finds and treats your own risks, and keeps doing it.
How much evidence carries over
A large share of the work is common to both. One firm that performs both has put a number on it:
- A-LIGN states that SOC 2 and ISO 27001 overlap at 43%, meaning that a company that has already completed a SOC 2 assessment has already met 43% of the evidence required for ISO 27001. Source, read 2026-09-28.
The shared part is the controls and their records. The unshared part is the paperwork each framework invents for itself. SOC 2 needs a system description and a management assertion. ISO needs a Statement of Applicability, an internal audit and a management review.
If you already hold the certificate, ISO 27001 to SOC 2 prints the Annex A to Trust Services Criteria crosswalk in full. It marks each area as reused, re-tested, carved out or net new.
Which one your buyer is asking for
Read the request, not the market. A security questionnaire, a vendor onboarding form or a contract clause names what it wants. The words usually settle it.
- “SOC 2 report” or “Type 2”
- SOC 2. A certificate does not satisfy a request for a report.
- “ISO 27001 certificate” or “certified”
- ISO 27001. A buyer asking for a certificate number wants something they can look up.
- “SOC 2 or ISO 27001”
- Either. Pick on calendar and cost, then plan the second one.
A certificate is also a public fact. ISO publishes how many exist, and anyone can look one up:
- ISO states that, as per the ISO Survey 2022, over 70 000 ISO/IEC 27001 certificates were reported in 150 countries. Source, read 2026-09-28.
- IAF CertSearch describes itself as the official global database for accredited certificates, searchable by company name or certificate details, and states that it cross-checks data from the IAF, accreditation bodies and certification bodies. Source, read 2026-09-28.
How the calendars compare
A SOC 2 Type 1 speaks to a single date, so it is the fastest document either framework produces. A first Type 2 needs an observation window of at least three months before the examination can test it.
ISO has no fixed window. It does need records that the system has run, including an internal audit and a management review, before Stage 1. Then Stage 1 and Stage 2 run on the certification body’s schedule. How long ISO 27001 takes gives each phase, and the SOC 2 timeline does the same for the report.
What each costs through Polara Labs
We sell both, as separate products. Here they are side by side, and they are not bundled.
| What you are buying | Price | What it covers |
|---|---|---|
| SOC 2 onboarding | $2,000 one time | Gap analysis, policies, evidence collection and the package. No Type 1 at this price |
| SOC 2 Type 1 examination | $2,000 added later, or $4,000 with onboarding | The Type 1 examination and report, with the auditor engagement fee inside it |
| SOC 2 Type 2 | $600 per month | A 12-month term. Continuous evidence collection, and your first SOC 2 Type 2 audit is included in the term |
| ISO 27001 readiness | $5,000 one time | Risk assessment, Statement of Applicability, policies, evidence, internal audit and management review |
| ISO 27001 certification audit | Quoted by the body | Stage 1 and Stage 2, performed and billed by an accredited certification body |
A full SOC 2 first year on the onboarding entry is $9,200: $2,000 plus $7,200 of Type 2 on the monthly schedule, with the first Type 2 audit inside the term. The ISO side is the readiness price, and the certification body’s fee sits on its own invoice.
What SOC 2 actually costs and what ISO 27001 certification costs put published market figures beside ours, and the pricing page has every price in one place.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.
If you need both
Do the one the current deal needs, then add the other. The controls and their records carry across, so the second framework is mostly the paperwork unique to it.
Keep one evidence trail rather than two. An access review run once, stored once and mapped to both frameworks is cheaper than the same review done twice. It also cannot drift out of sync.
Questions
What is the difference between SOC 2 and ISO 27001?
Should a startup get SOC 2 or ISO 27001 first?
Can one set of evidence serve both?
How is each one renewed?
What do the two cost through Polara Labs?
Sources
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.