Skip to content

Have SOC 2? You've covered most of the way to ISO 27001.

If you sell into the UK, EU or APAC, or to regulated and public-sector buyers anywhere, they ask for ISO 27001 by name, and a SOC 2 report will not satisfy them. The good news: this is not a second security project. Most of your controls are already running, and much of your SOC 2 work carries straight over.

Get Certified
Recognised in 170+ countries
Most of your SOC 2 work reuses
Certified in days, not months

SOC 2 opens doors in North America. ISO 27001 opens them everywhere else.

Recognised worldwide

ISO 27001 is the information-security standard in over 170 countries. SOC 2 is understood mainly in North America.

UK and EU buyers ask for it by name

Public-sector frameworks like G-Cloud, and NHS, MOD and enterprise procurement, commonly request an ISO 27001 certificate. A SOC 2 report does not close that gap.

A certificate, not a private report

SOC 2 is a restricted-use attestation you share under NDA. ISO 27001 is a certificate you can publish, valid for three years.

Regulatory alignment

ISO 27001 is an accepted way to evidence the appropriate technical and organisational measures UK GDPR expects, and it aligns with NIS2 and DORA.

You're already most of the way there

Much of your SOC 2 control set maps straight onto ISO 27001. The new work is the management system around it, not a second security programme.

SOC 2 vs ISO 27001, side by side

Same goal, proving you take security seriously. Different instruments.

SOC 2 (Type II) against ISO/IEC 27001:2022

Nature

SOC 2: Attestation, an auditor's opinion

ISO 27001: Certification, a certificate that stands on its own

Owned by

SOC 2: AICPA, the US accountancy body

ISO 27001: ISO/IEC, the international standards bodies

Audited by

SOC 2: A licensed CPA firm

ISO 27001: An accredited certification body

Output

SOC 2: A restricted-use report over a review period

ISO 27001: A public certificate, valid three years

Rhythm

SOC 2: Re-audit every year

ISO 27001: Audit and certification, then annual surveillance, recertification at year 3

Control Logic

SOC 2: Criteria-driven, meeting the Trust Services Criteria

ISO 27001: Risk-driven, clauses 4 to 10 plus Annex A controls chosen by risk

Best known to

SOC 2: North American buyers

ISO 27001: Global buyers, regulators and partners

You've done most of the work

A mature SOC 2 Type II programme gives you substantial reusable coverage, and the AICPA publishes an official SOC 2 to ISO 27001 mapping to prove it. The exact share is yours to confirm in a crosswalk, but the pattern is consistent.

Carries Over

What carries over from SOC 2

  • Governance and policies (CC1 to CC2)
  • Your risk assessment as a starting point (CC3)
  • Access and identity (CC6)
  • Operations and incident management (CC7)
  • Change management (CC8)
  • Vendor and continuity controls (CC9)

Your access reviews, change logs, incident post-mortems, vendor reviews and monitoring dashboards transfer too, as long as they sit within the ISO scope and period.

Still to Build

What ISO 27001 adds on top

  • A formal ISMS scope
  • A defined risk method and Statement of Applicability
  • Measurable security objectives
  • Controlled documents
  • And the two things SOC 2 never asks for: a full internal audit and a management review

From SOC 2 to ISO 27001 certified, answered

No. They overlap heavily on controls, but SOC 2 is a US attestation report and ISO 27001 is an international certificate. Holding one does not make you the other, and a buyer who asks for ISO 27001 will not accept a SOC 2 report in its place.

It is understood, but it is rarely what gets asked for. UK buyers and public-sector frameworks reference ISO 27001 by name, so handing over a SOC 2 report tends to start a security questionnaire rather than close the conversation.

Follow your buyers. If North America is a real part of your revenue, keep the SOC 2, because that's what those buyers' processes are built around. If your growth is UK, EU or regulated, ISO 27001 is the one being asked for. Most scaling companies end up holding both.

For most teams holding a SOC 2 Type II, roughly sixty to eighty percent of the groundwork. The operational controls carry over almost entirely. What's missing is the management system: risk assessment, Statement of Applicability, internal audit and management review.

It's different rather than harder. SOC 2 is heavier on detailed control testing and reporting. ISO 27001 is stricter about how you decide what to control and how you prove the system is managed. Teams with a mature SOC 2 usually find the second one calmer.

The audit itself takes days. The variable is how quickly you close the management-system gaps, which is typically a few weeks of focused work. You'll have the full timeline in writing after scoping, before you commit.

No. There is no law that requires it. In practice, though, many enterprise and public-sector contracts make it a condition of doing business, which is why it can feel mandatory once you sell upmarket.

Not for the certificate. SOC 2 attestations come from CPA firms and ISO 27001 certificates from accredited certification bodies, and keeping those apart is an impartiality requirement rather than a preference. Your SOC 2 auditor stays where they are, and we work alongside them.

The full playbook, free

We wrote the guide we wished existed: From SOC 2 to ISO 27001, a practical guide.

Inside: the clause-by-clause crosswalk from your SOC 2 controls to ISO 27001, the Annex A gaps that usually surface after SOC 2, the five phases to certification, the twelve documents an auditor will always expect, and the free tooling and templates to get there.

From SOC 2 to ISO/IEC 27001, a practical guide

About Calibre

Calibre is an AI-native ISO 27001 certification body, built by engineers and compliance leaders from Palantir and the traditional certification world. We set out to give modern software companies the most seamless audit experience in the industry, with certification measured in days of audit time, not months of admin.

You've done the hard part. Let's make it global.

You built a real security programme to earn SOC 2. ISO 27001 turns it into a certificate the whole world recognises, and we make the management-system part straightforward.