ISO 27001 to SOC 2: what carries over
The four questions a certificate holder actually has, answered in order, with the crosswalk printed in full on the page.
The certificate is not the evidence. That is the entire ISO 27001 to SOC 2 gap in one line. Annex A of ISO/IEC 27001:2022 holds 93 controls in four clauses, and the artifacts behind them answer a large share of the Trust Services Criteria already.1 Your certificate is not one of those artifacts. It records a conclusion a certification body reached, and an examination performed under the AICPA attestation standards needs the records that conclusion was based on.2
Four questions follow from that. Which Annex A themes answer which criteria. Which evidence gets read as it is. Which gets re-tested. And what SOC 2 asks for that your Information Security Management System never produced.
The counts first, because everything below sits on them. ISO published the 2022 edition on 25 October 2022. Annex A went from 114 controls in fourteen clauses to 93 in four, of which 11 are new, 24 are merged and 58 are updated. The International Accreditation Forum states those figures in IAF MD 26, issue 2, and set 31 October 2025 as the last date an accredited 2013 certificate could be transitioned. Checked 1 August 2026. So if your certificate is current, it is a 2022 certificate, and the crosswalk below assumes that.
Themes map, controls do not
Annex A sorts its controls into organizational, people, physical and technological measures. The Trust Services Criteria sort differently: nine common criteria series that every SOC 2 report covers, plus category criteria for availability, confidentiality, processing integrity and privacy when you scope them.1 One structure is built around a management system. The other is built around commitments made to customers.
So a control-by-control mapping is the wrong shape. It produces a column of maybes and a false sense of coverage. Group by theme instead. Then decide, per area, what your auditor does with the evidence you already keep. That last decision is the column worth reading.
- As is
- The artifact you already maintain satisfies the criterion in the form it is in. Your auditor reads it and moves on.
- Re-tested
- The same artifact type carries over, but a Type 2 tests it across the whole observation period instead of at one audit visit. You keep the process. The population changes.
- Carved out
- The control belongs to a subservice organization, usually your cloud provider, and is excluded from your description with its own criteria named.
- Net new
- Nothing in your ISMS produces this. You write it.
The Annex A to Trust Services Criteria crosswalk
Clause references are given so you can line each row up against your own Statement of Applicability. The control areas are described rather than quoted, because Annex A text is copyrighted and ISO does not publish it freely. The criteria come from the AICPA document, which is public.1
| Annex A area | Trust Services Criteria | What the auditor does |
|---|---|---|
| A.5 Organizational, 37 controls | ||
| Policies for information security (A.5.1) | CC1.5, CC2.2, CC5.3 | As is |
| Roles, segregation of duties, management responsibilities (A.5.2 to A.5.4) | CC1.3, CC1.4 | As is |
| Threat intelligence, contact with authorities and special interest groups (A.5.5 to A.5.7) | CC7.1 | As is |
| Asset inventory, ownership, acceptable use, return of assets (A.5.9 to A.5.11) | CC6.1, CC6.5 | Re-tested |
| Classification, labeling and transfer of information (A.5.12 to A.5.14) | CC6.7, C1.1 | As is |
| Access control, identity, authentication information, access rights (A.5.15 to A.5.18) | CC6.1, CC6.2, CC6.3 | Re-tested |
| Supplier relationships and information and communications technology supply chain (A.5.19 to A.5.23) | CC9.2 | As is |
| Incident planning, assessment, response and evidence collection (A.5.24 to A.5.28) | CC7.3, CC7.4, CC7.5 | Re-tested |
| Continuity of information security and readiness for continuity (A.5.29, A.5.30) | A1.2, A1.3 | Re-tested |
| Legal, contractual and privacy requirements, independent review, documented procedures (A.5.31 to A.5.37) | CC2.3, CC4.1, CC5.3 | As is |
| A.6 People, 8 controls | ||
| Screening (A.6.1) | CC1.4 | Re-tested |
| Terms and conditions of employment, disciplinary process (A.6.2, A.6.4) | CC1.1, CC1.5 | As is |
| Awareness, education and training (A.6.3) | CC1.4, CC2.2 | Re-tested |
| Responsibilities after termination or change of employment (A.6.5) | CC6.2, CC6.3 | Re-tested |
| Confidentiality agreements, remote working, event reporting (A.6.6 to A.6.8) | CC2.3, CC6.7, CC7.3 | As is |
| A.7 Physical, 14 controls | ||
| Perimeters, entry controls, securing offices, physical monitoring (A.7.1 to A.7.4) | CC6.4 | Carved out |
| Equipment siting, utilities, cabling, maintenance, off-site assets (A.7.5, A.7.8 to A.7.13) | CC6.4, A1.2 | Carved out |
| Clear desk, clear screen, unattended equipment (A.7.7) | CC6.7 | As is |
| Secure disposal and reuse of equipment and storage media (A.7.10, A.7.14) | CC6.5 | Re-tested |
| A.8 Technological, 34 controls | ||
| User endpoints, privileged access rights, information access restriction (A.8.1 to A.8.3) | CC6.1, CC6.3 | Re-tested |
| Access to source code, secure authentication (A.8.4, A.8.5) | CC6.1, CC8.1 | Re-tested |
| Capacity management (A.8.6) | A1.1 | Re-tested |
| Protection against malware, technical vulnerability management (A.8.7, A.8.8) | CC6.8, CC7.1 | Re-tested |
| Configuration management (A.8.9) | CC7.1, CC8.1 | Re-tested |
| Information deletion, data masking, data leakage prevention (A.8.10 to A.8.12) | CC6.5, C1.2 | As is |
| Backup and redundancy of processing facilities (A.8.13, A.8.14) | A1.2 | Re-tested |
| Logging, monitoring activities, clock synchronization (A.8.15 to A.8.17) | CC7.2 | Re-tested |
| Network security, segregation, filtering, use of cryptography (A.8.20 to A.8.24) | CC6.6, CC6.7 | As is |
| Secure development, testing, environment separation, change management (A.8.25 to A.8.34) | CC8.1 | Re-tested |
| No Annex A counterpart | ||
| A description of the system, its boundary, its components and its subservice organizations | Section 3 of the report | Net new |
| A written assertion signed by management about that description and the controls | Section 2 of the report | Net new |
| Service commitments and system requirements drawn from customer contracts and published documentation | CC2.3, CC3.1 | Net new |
| Carve-out or inclusive treatment of each subservice organization | CC9.2 | Net new |
| Complementary user entity controls, written as obligations on your customers | CC9.2 | Net new |
| Category criteria for availability, confidentiality or processing integrity, where scoped | A1, C1, PI1 | Net new |
Privacy is left out of the last group on purpose. It carries more criteria than availability, confidentiality and processing integrity put together,1 and a first report rarely needs it. The scoping tool works out which categories your buyer is actually asking for.
What an auditor reads as it is
The reusable set is documentary, and you already own all of it. Your policy suite. The risk assessment and risk treatment plan. The Statement of Applicability. The asset register, the supplier register, signed confidentiality agreements, job descriptions with security responsibilities in them.
Two of your ISO artifacts are worth more than the rest. The first is the internal audit report, because CC4.1 asks for periodic evaluations of whether controls are present and working, and an ISO internal audit is exactly that.1 The second is management review, which lands on the same criterion from the governance side. Both are accepted in the form your ISMS already produces them.
The Statement of Applicability is the third, and it does a different job. It is not evidence of anything. It is the best starting index you will find for the mapping work, because it already records which controls apply to you and why the excluded ones do not. That is half of a scoping memo written before anyone asked for one.
What gets re-tested, and why that is not duplication
A certification body audits conformity of the management system and samples at the audit visit. A SOC 2 Type 2 opinion covers a stated period, so the service auditor selects instances from the population that occurred inside that period and tests each one.3 Same control. Different question.
ISO asks whether the process exists and operates. SOC 2 asks how many times it fired between two dates, and whether every selected instance was correct. That is why the access review your certification body looked at once becomes a population of every review inside the window, and why the joiner and leaver records for the whole period get pulled rather than a handful.
The practical consequence is about completeness rather than effort. You will be asked to prove that an export is the whole population and not a filtered view of it. A conformity audit does not have to ask that, because it samples at the visit rather than across a window. Retention settings decide whether you can answer. The evidence checklist lists what each artifact has to carry to be testable.
A-LIGN, which performs both SOC 2 examinations and ISO 27001 certification, puts the overlap at 43 percent, measured in the other direction: “if you’ve already completed a SOC 2 assessment, you’ve already met 43% of evidence required for ISO 27001.” Source, published 4 September 2025, read 1 August 2026. The denominators differ by direction, so treat it as a scale rather than a promise.
What SOC 2 adds that ISO never asked for
This is the part of the delta nobody writes down, and it is not controls. It is documents, and none of them exist inside an ISMS.
- The system description. Section 3 of the report. What the service does, where its boundary sits, which components are inside it, and which subservice organizations it depends on. ISO has no equivalent document.
- Management’s written assertion. Your own signed statement about the description and the controls, which is the thing the CPA firm then examines. The Statement of Applicability is not this and cannot stand in for it.
- Service commitments and system requirements. The largest conceptual gap. ISO measures your controls against your own risk assessment. SOC 2 measures them against the promises you made to customers in contracts, service level agreements and published documentation.1 Those promises have to be written down as the basis for the controls.
- Subservice organization treatment. Carve-out or inclusive, decided per provider, and stated in the description. Annex A asks you to manage suppliers. It does not ask you to declare which parts of your own report you are excluding.
- Complementary user entity controls. The things your customers have to do for your controls to work, written as obligations on them. Wording them is the part with consequences, because a vague one transfers nothing.
Four of those five are writing tasks. The fifth, service commitments, is a decision about scope that then drives everything else, so do it first.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
One vocabulary note that matters here more than elsewhere. You hold a certificate. SOC 2 does not produce one. It produces a report carrying an opinion, which is why there is no SOC 2 certificate to hang next to the one you already have.4
How many weeks the delta actually takes
Split the answer by report type, because the calendars are unrelated.
A Type 1 has no observation period. It speaks to a single date, so the work is the mapping, the three net-new documents, and whatever your Statement of Applicability excluded that a criterion still requires. For a company with a live ISMS that is document work rather than engineering, and it is the fastest route out of a blocked deal.
A first Type 2 is set by elapsed time. Three months is the accepted minimum window, and no certificate shortens it. Controls have to operate across a period before anyone can test whether they operated effectively. Why three months is the floor works through the arithmetic, and the phase by phase timeline gives every other duration.
Holding ISO 27001 moves one phase and only one. Gap remediation is shorter, because the controls exist and the policies are written. Everything downstream of that runs on the same clock as it would for anyone else.
What it costs on top
Through Polara Labs a Type 1 is $4,000 one time, and that number includes the first examination and the engagement fee for the independent partner auditor. Type 2 monitoring is $600 per month on a 12-month term, and each examination is $5,000, so a full Type 2 year with one examination comes to $12,200.
Your certificate does not move those figures. The examination fee pays for testing, and the testing happens whether or not you arrived organized. What an ISMS buys you is the part before the examination, which is the part that usually takes the longest.
Where to start on Monday
- Open the Statement of Applicability and mark every excluded control against the crosswalk above. Exclusions that touch a common criterion are your real gap list.
- Write the service commitments down. Pull them from your contracts, your service level agreements and your public documentation, then check that a control exists for each one.
- Decide carve-out or inclusive for each subservice organization before you draft the description, because the choice changes what the description has to say.
- Check your retention windows against the observation period you intend to claim. Logs that roll off at 90 days cannot evidence a six month window.
- Pick the report type from the deal, not from the framework. A buyer holding your ISO certificate and still asking for SOC 2 usually wants the Type 2, and usually accepts a Type 1 while the window runs.
Questions
Can I reuse ISO 27001 evidence for SOC 2?
Which Annex A controls map to the Trust Services Criteria?
Does an ISO 27001 certificate shorten the SOC 2 observation period?
What does SOC 2 require that ISO 27001 does not?
How much does adding SOC 2 to ISO 27001 cost?
Sources
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- Statements on Standards for Attestation Engagements
- SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy
- SOC 2 Report
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.