SOC 2 vs ISO 27001: which one to get first

One is a report with an opinion, the other is a certificate. Here is how to tell which one the buyer in front of you is asking for.

SOC 2 vs ISO 27001, in one line: SOC 2 is a report carrying a CPA firm’s opinion, and ISO 27001 is a certificate from an accredited certification body. The report is issued under the AICPA attestation standards.2 The certificate is never issued by ISO:

  • ISO states that it does not perform certification or issue certificates, and that certification is performed by external certification bodies. Source, read 2026-09-28.
  • ISO states that companies implementing ISO/IEC 27001 can decide whether they want to go through a certification process, and that a certificate from an accredited body may add confidence because an accreditation body has independently confirmed the certification body’s competence. Source, read 2026-09-28.

Everything else follows from that difference. Who you hire, what gets tested, how long it covers, and how a buyer checks it.

Most of the controls underneath are the same. Access reviews, onboarding and offboarding, encryption, logging, incident response, supplier checks. What differs is the frame around them and the document that comes out the other end.

Side by side

QuestionSOC 2ISO 27001
What you receiveA report with an opinionA certificate
Who issues itA licensed U.S. CPA firmAn accredited certification body
Measured againstThe AICPA Trust Services Criteria, plus the commitments you made to customersClauses 4 to 10 of the standard, plus the Annex A controls your risk assessment selects
What it covers in timeOne date for a Type 1, a period for a Type 2The management system at the time of each audit, across a three year cycle
RenewalA new report each yearSurveillance audits in years two and three, then recertification
How a buyer checks itReads the report under NDA and verifies the firm with its state boardLooks the certificate up in a public register

What each one actually tests

A SOC 2 examination tests controls against the Trust Services Criteria. Security is always in scope, and availability, confidentiality, processing integrity and privacy are added when you choose them.3 The criteria are measured against the promises you made to customers in contracts and service level agreements.

ISO 27001 tests a management system. The requirements in clauses 4 to 10 cover scope, leadership, risk, operation, internal audit, management review and improvement. Annex A is a reference list of 93 controls, and your risk assessment decides which apply. Annex A for a small team walks through the four themes.

So the two ask different questions. SOC 2 asks whether your controls met your commitments. ISO asks whether you run a system that finds and treats your own risks, and keeps doing it.

How much evidence carries over

A large share of the work is common to both. One firm that performs both has put a number on it:

  • A-LIGN states that SOC 2 and ISO 27001 overlap at 43%, meaning that a company that has already completed a SOC 2 assessment has already met 43% of the evidence required for ISO 27001. Source, read 2026-09-28.

The shared part is the controls and their records. The unshared part is the paperwork each framework invents for itself. SOC 2 needs a system description and a management assertion. ISO needs a Statement of Applicability, an internal audit and a management review.

If you already hold the certificate, ISO 27001 to SOC 2 prints the Annex A to Trust Services Criteria crosswalk in full. It marks each area as reused, re-tested, carved out or net new.

Which one your buyer is asking for

Read the request, not the market. A security questionnaire, a vendor onboarding form or a contract clause names what it wants. The words usually settle it.

“SOC 2 report” or “Type 2”
SOC 2. A certificate does not satisfy a request for a report.
“ISO 27001 certificate” or “certified”
ISO 27001. A buyer asking for a certificate number wants something they can look up.
“SOC 2 or ISO 27001”
Either. Pick on calendar and cost, then plan the second one.

A certificate is also a public fact. ISO publishes how many exist, and anyone can look one up:

  • ISO states that, as per the ISO Survey 2022, over 70 000 ISO/IEC 27001 certificates were reported in 150 countries. Source, read 2026-09-28.
  • IAF CertSearch describes itself as the official global database for accredited certificates, searchable by company name or certificate details, and states that it cross-checks data from the IAF, accreditation bodies and certification bodies. Source, read 2026-09-28.

How the calendars compare

A SOC 2 Type 1 speaks to a single date, so it is the fastest document either framework produces. A first Type 2 needs an observation window of at least three months before the examination can test it.

ISO has no fixed window. It does need records that the system has run, including an internal audit and a management review, before Stage 1. Then Stage 1 and Stage 2 run on the certification body’s schedule. How long ISO 27001 takes gives each phase, and the SOC 2 timeline does the same for the report.

What each costs through Polara Labs

We sell both, as separate products. Here they are side by side, and they are not bundled.

What you are buyingPriceWhat it covers
SOC 2 onboarding$2,000 one timeGap analysis, policies, evidence collection and the package. No Type 1 at this price
SOC 2 Type 1 examination$2,000 added later, or $4,000 with onboardingThe Type 1 examination and report, with the auditor engagement fee inside it
SOC 2 Type 2$600 per monthA 12-month term. Continuous evidence collection, and your first SOC 2 Type 2 audit is included in the term
ISO 27001 readiness$5,000 one timeRisk assessment, Statement of Applicability, policies, evidence, internal audit and management review
ISO 27001 certification auditQuoted by the bodyStage 1 and Stage 2, performed and billed by an accredited certification body

A full SOC 2 first year on the onboarding entry is $9,200: $2,000 plus $7,200 of Type 2 on the monthly schedule, with the first Type 2 audit inside the term. The ISO side is the readiness price, and the certification body’s fee sits on its own invoice.

What SOC 2 actually costs and what ISO 27001 certification costs put published market figures beside ours, and the pricing page has every price in one place.

Who signs each one

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.

If you need both

Do the one the current deal needs, then add the other. The controls and their records carry across, so the second framework is mostly the paperwork unique to it.

Keep one evidence trail rather than two. An access review run once, stored once and mapped to both frameworks is cheaper than the same review done twice. It also cannot drift out of sync.

Questions

What is the difference between SOC 2 and ISO 27001?
SOC 2 is a report. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues an opinion. ISO 27001 is a certificate. An accredited certification body audits your information security management system against the standard and certifies it. ISO itself does not certify anyone.
Should a startup get SOC 2 or ISO 27001 first?
The one the blocked deal names. If the security questionnaire or the contract asks for a SOC 2 report, get SOC 2. If it asks for an ISO 27001 certificate, get ISO. If a buyer will accept either, compare the calendars and the costs on this page and pick the one that closes the deal soonest.
Can one set of evidence serve both?
A large share of it. Policies, the risk assessment, access reviews, onboarding and offboarding records and incident records serve both. A-LIGN, which performs both, puts the overlap at 43 percent of the ISO evidence for a company that already has SOC 2. The system description and management assertion are SOC 2 only; the Statement of Applicability, internal audit and management review are ISO requirements.
How is each one renewed?
A SOC 2 report covers a date or a period, and buyers ask for a new one each year. An ISO 27001 certificate runs three years, with a surveillance audit by the certification body in each of the two years between and a recertification audit before expiry.
What do the two cost through Polara Labs?
SOC 2 onboarding is $2,000 one time, or $4,000 one time with the Type 1 examination included, and Type 2 is $600 per month on a 12-month term; your first SOC 2 Type 2 audit is included in the term. ISO 27001 readiness is $5,000 one time, and the certification body quotes and bills its own audit separately.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.