ISO 27001 to SOC 2: what carries over

The four questions a certificate holder actually has, answered in order, with the crosswalk printed in full on the page.

The certificate is not the evidence. That is the entire ISO 27001 to SOC 2 gap in one line. Annex A of ISO/IEC 27001:2022 holds 93 controls in four clauses, and the artifacts behind them answer a large share of the Trust Services Criteria already.1 Your certificate is not one of those artifacts. It records a conclusion a certification body reached, and an examination performed under the AICPA attestation standards needs the records that conclusion was based on.2

Four questions follow from that. Which Annex A themes answer which criteria. Which evidence gets read as it is. Which gets re-tested. And what SOC 2 asks for that your Information Security Management System never produced.

The counts first, because everything below sits on them. ISO published the 2022 edition on 25 October 2022. Annex A went from 114 controls in fourteen clauses to 93 in four, of which 11 are new, 24 are merged and 58 are updated. The International Accreditation Forum states those figures in IAF MD 26, issue 2, and set 31 October 2025 as the last date an accredited 2013 certificate could be transitioned. Checked 1 August 2026. So if your certificate is current, it is a 2022 certificate, and the crosswalk below assumes that.

Themes map, controls do not

Annex A sorts its controls into organizational, people, physical and technological measures. The Trust Services Criteria sort differently: nine common criteria series that every SOC 2 report covers, plus category criteria for availability, confidentiality, processing integrity and privacy when you scope them.1 One structure is built around a management system. The other is built around commitments made to customers.

So a control-by-control mapping is the wrong shape. It produces a column of maybes and a false sense of coverage. Group by theme instead. Then decide, per area, what your auditor does with the evidence you already keep. That last decision is the column worth reading.

As is
The artifact you already maintain satisfies the criterion in the form it is in. Your auditor reads it and moves on.
Re-tested
The same artifact type carries over, but a Type 2 tests it across the whole observation period instead of at one audit visit. You keep the process. The population changes.
Carved out
The control belongs to a subservice organization, usually your cloud provider, and is excluded from your description with its own criteria named.
Net new
Nothing in your ISMS produces this. You write it.

The Annex A to Trust Services Criteria crosswalk

Clause references are given so you can line each row up against your own Statement of Applicability. The control areas are described rather than quoted, because Annex A text is copyrighted and ISO does not publish it freely. The criteria come from the AICPA document, which is public.1

Annex A areaTrust Services CriteriaWhat the auditor does
A.5 Organizational, 37 controls
Policies for information security (A.5.1)CC1.5, CC2.2, CC5.3As is
Roles, segregation of duties, management responsibilities (A.5.2 to A.5.4)CC1.3, CC1.4As is
Threat intelligence, contact with authorities and special interest groups (A.5.5 to A.5.7)CC7.1As is
Asset inventory, ownership, acceptable use, return of assets (A.5.9 to A.5.11)CC6.1, CC6.5Re-tested
Classification, labeling and transfer of information (A.5.12 to A.5.14)CC6.7, C1.1As is
Access control, identity, authentication information, access rights (A.5.15 to A.5.18)CC6.1, CC6.2, CC6.3Re-tested
Supplier relationships and information and communications technology supply chain (A.5.19 to A.5.23)CC9.2As is
Incident planning, assessment, response and evidence collection (A.5.24 to A.5.28)CC7.3, CC7.4, CC7.5Re-tested
Continuity of information security and readiness for continuity (A.5.29, A.5.30)A1.2, A1.3Re-tested
Legal, contractual and privacy requirements, independent review, documented procedures (A.5.31 to A.5.37)CC2.3, CC4.1, CC5.3As is
A.6 People, 8 controls
Screening (A.6.1)CC1.4Re-tested
Terms and conditions of employment, disciplinary process (A.6.2, A.6.4)CC1.1, CC1.5As is
Awareness, education and training (A.6.3)CC1.4, CC2.2Re-tested
Responsibilities after termination or change of employment (A.6.5)CC6.2, CC6.3Re-tested
Confidentiality agreements, remote working, event reporting (A.6.6 to A.6.8)CC2.3, CC6.7, CC7.3As is
A.7 Physical, 14 controls
Perimeters, entry controls, securing offices, physical monitoring (A.7.1 to A.7.4)CC6.4Carved out
Equipment siting, utilities, cabling, maintenance, off-site assets (A.7.5, A.7.8 to A.7.13)CC6.4, A1.2Carved out
Clear desk, clear screen, unattended equipment (A.7.7)CC6.7As is
Secure disposal and reuse of equipment and storage media (A.7.10, A.7.14)CC6.5Re-tested
A.8 Technological, 34 controls
User endpoints, privileged access rights, information access restriction (A.8.1 to A.8.3)CC6.1, CC6.3Re-tested
Access to source code, secure authentication (A.8.4, A.8.5)CC6.1, CC8.1Re-tested
Capacity management (A.8.6)A1.1Re-tested
Protection against malware, technical vulnerability management (A.8.7, A.8.8)CC6.8, CC7.1Re-tested
Configuration management (A.8.9)CC7.1, CC8.1Re-tested
Information deletion, data masking, data leakage prevention (A.8.10 to A.8.12)CC6.5, C1.2As is
Backup and redundancy of processing facilities (A.8.13, A.8.14)A1.2Re-tested
Logging, monitoring activities, clock synchronization (A.8.15 to A.8.17)CC7.2Re-tested
Network security, segregation, filtering, use of cryptography (A.8.20 to A.8.24)CC6.6, CC6.7As is
Secure development, testing, environment separation, change management (A.8.25 to A.8.34)CC8.1Re-tested
No Annex A counterpart
A description of the system, its boundary, its components and its subservice organizationsSection 3 of the reportNet new
A written assertion signed by management about that description and the controlsSection 2 of the reportNet new
Service commitments and system requirements drawn from customer contracts and published documentationCC2.3, CC3.1Net new
Carve-out or inclusive treatment of each subservice organizationCC9.2Net new
Complementary user entity controls, written as obligations on your customersCC9.2Net new
Category criteria for availability, confidentiality or processing integrity, where scopedA1, C1, PI1Net new

Privacy is left out of the last group on purpose. It carries more criteria than availability, confidentiality and processing integrity put together,1 and a first report rarely needs it. The scoping tool works out which categories your buyer is actually asking for.

What an auditor reads as it is

The reusable set is documentary, and you already own all of it. Your policy suite. The risk assessment and risk treatment plan. The Statement of Applicability. The asset register, the supplier register, signed confidentiality agreements, job descriptions with security responsibilities in them.

Two of your ISO artifacts are worth more than the rest. The first is the internal audit report, because CC4.1 asks for periodic evaluations of whether controls are present and working, and an ISO internal audit is exactly that.1 The second is management review, which lands on the same criterion from the governance side. Both are accepted in the form your ISMS already produces them.

The Statement of Applicability is the third, and it does a different job. It is not evidence of anything. It is the best starting index you will find for the mapping work, because it already records which controls apply to you and why the excluded ones do not. That is half of a scoping memo written before anyone asked for one.

What gets re-tested, and why that is not duplication

A certification body audits conformity of the management system and samples at the audit visit. A SOC 2 Type 2 opinion covers a stated period, so the service auditor selects instances from the population that occurred inside that period and tests each one.3 Same control. Different question.

ISO asks whether the process exists and operates. SOC 2 asks how many times it fired between two dates, and whether every selected instance was correct. That is why the access review your certification body looked at once becomes a population of every review inside the window, and why the joiner and leaver records for the whole period get pulled rather than a handful.

The practical consequence is about completeness rather than effort. You will be asked to prove that an export is the whole population and not a filtered view of it. A conformity audit does not have to ask that, because it samples at the visit rather than across a window. Retention settings decide whether you can answer. The evidence checklist lists what each artifact has to carry to be testable.

How much overlap, in someone else’s numbers

A-LIGN, which performs both SOC 2 examinations and ISO 27001 certification, puts the overlap at 43 percent, measured in the other direction: “if you’ve already completed a SOC 2 assessment, you’ve already met 43% of evidence required for ISO 27001.” Source, published 4 September 2025, read 1 August 2026. The denominators differ by direction, so treat it as a scale rather than a promise.

What SOC 2 adds that ISO never asked for

This is the part of the delta nobody writes down, and it is not controls. It is documents, and none of them exist inside an ISMS.

  1. The system description. Section 3 of the report. What the service does, where its boundary sits, which components are inside it, and which subservice organizations it depends on. ISO has no equivalent document.
  2. Management’s written assertion. Your own signed statement about the description and the controls, which is the thing the CPA firm then examines. The Statement of Applicability is not this and cannot stand in for it.
  3. Service commitments and system requirements. The largest conceptual gap. ISO measures your controls against your own risk assessment. SOC 2 measures them against the promises you made to customers in contracts, service level agreements and published documentation.1 Those promises have to be written down as the basis for the controls.
  4. Subservice organization treatment. Carve-out or inclusive, decided per provider, and stated in the description. Annex A asks you to manage suppliers. It does not ask you to declare which parts of your own report you are excluding.
  5. Complementary user entity controls. The things your customers have to do for your controls to work, written as obligations on them. Wording them is the part with consequences, because a vague one transfers nothing.

Four of those five are writing tasks. The fifth, service commitments, is a decision about scope that then drives everything else, so do it first.

Who signs, and who cannot

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

One vocabulary note that matters here more than elsewhere. You hold a certificate. SOC 2 does not produce one. It produces a report carrying an opinion, which is why there is no SOC 2 certificate to hang next to the one you already have.4

How many weeks the delta actually takes

Split the answer by report type, because the calendars are unrelated.

A Type 1 has no observation period. It speaks to a single date, so the work is the mapping, the three net-new documents, and whatever your Statement of Applicability excluded that a criterion still requires. For a company with a live ISMS that is document work rather than engineering, and it is the fastest route out of a blocked deal.

A first Type 2 is set by elapsed time. Three months is the accepted minimum window, and no certificate shortens it. Controls have to operate across a period before anyone can test whether they operated effectively. Why three months is the floor works through the arithmetic, and the phase by phase timeline gives every other duration.

Holding ISO 27001 moves one phase and only one. Gap remediation is shorter, because the controls exist and the policies are written. Everything downstream of that runs on the same clock as it would for anyone else.

What it costs on top

Through Polara Labs a Type 1 is $4,000 one time, and that number includes the first examination and the engagement fee for the independent partner auditor. Type 2 monitoring is $600 per month on a 12-month term, and each examination is $5,000, so a full Type 2 year with one examination comes to $12,200.

Your certificate does not move those figures. The examination fee pays for testing, and the testing happens whether or not you arrived organized. What an ISMS buys you is the part before the examination, which is the part that usually takes the longest.

Where to start on Monday

  1. Open the Statement of Applicability and mark every excluded control against the crosswalk above. Exclusions that touch a common criterion are your real gap list.
  2. Write the service commitments down. Pull them from your contracts, your service level agreements and your public documentation, then check that a control exists for each one.
  3. Decide carve-out or inclusive for each subservice organization before you draft the description, because the choice changes what the description has to say.
  4. Check your retention windows against the observation period you intend to claim. Logs that roll off at 90 days cannot evidence a six month window.
  5. Pick the report type from the deal, not from the framework. A buyer holding your ISO certificate and still asking for SOC 2 usually wants the Type 2, and usually accepts a Type 1 while the window runs.

Questions

Can I reuse ISO 27001 evidence for SOC 2?
Most of the documentary set, yes. Policies, the risk assessment, the Statement of Applicability, the asset and supplier registers, internal audit reports, management review minutes and corrective action records are read as they are. What does not carry over unchanged is operational evidence in a Type 2, because the examination tests a population of instances across a period rather than a sample taken at one audit visit. The certificate itself is never evidence. It records a conclusion, and a service auditor needs the records behind it.
Which Annex A controls map to the Trust Services Criteria?
Themes map cleanly, individual controls do not. Annex A of ISO/IEC 27001:2022 holds 93 controls in four clauses covering organizational, people, physical and technological measures. The Trust Services Criteria are organized as nine common criteria series plus category criteria. The crosswalk on this page pairs each Annex A area with the criteria it feeds and marks whether the evidence is reused as is, re-tested, carved out or net new.
Does an ISO 27001 certificate shorten the SOC 2 observation period?
No. Three months is the accepted minimum for a first Type 2, and it is elapsed time rather than work. The controls have to operate across the period so the auditor has instances to select from. A certificate says nothing about the period a SOC 2 report will cover. A Type 1 has no observation period at all, which is why an ISO holder in a hurry usually starts there.
What does SOC 2 require that ISO 27001 does not?
Five things with no Annex A counterpart. A description of the system and its boundary, a written assertion signed by management, a statement of the service commitments and system requirements the controls exist to meet, a carve-out or inclusive decision for every subservice organization, and complementary user entity controls written as obligations on your customers. Category criteria for availability, confidentiality or processing integrity are added only if you scope them.
How much does adding SOC 2 to ISO 27001 cost?
Through Polara Labs a Type 1 is $4,000 one time, covering the first examination and the engagement fee for the independent partner auditor. Type 2 monitoring is $600 per month on a 12-month term and each examination is $5,000. Holding ISO 27001 does not change those numbers, because the examination fee reflects the work of testing rather than the state you arrived in. What it changes is how long you spend getting ready.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.
  4. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty