SOC 2 gives you a report from a CPA firm. ISO 27001 gives you a certificate

A customer’s security questionnaire comes back with one line on it: provide your SOC 2. Or a European prospect asks for your ISO/IEC 27001 scope statement. Whoever asked has a specific artifact in mind, and the two artifacts are produced by different kinds of organization, under different rules, and say different things. Buying the wrong one is an expensive way to find that out.

The short version

  • SOC 2 produces a report. It is written and signed by a CPA firm, it covers a scope and a period you and that firm define, and it is delivered to you to share under a non-disclosure agreement with the customers who asked for it.
  • ISO/IEC 27001 produces a certificate. It names your organization, the scope of your information security management system, and the body that issued it, and it can be shown publicly.
  • There is no SOC 2 certificate. SOC 2 produces a report written and signed by a CPA firm about a defined period, and the artifact your customer receives is that report, not a wall plaque. The phrase in circulation is wrong, and the error matters because the two artifacts are not interchangeable in a procurement file.

Both are evidence. Neither is a security control. What makes either one worth having is the programme underneath it, which is also the part that takes the time.

Why is the wrong phrase everywhere?

Because the search demand is there, and copy follows search demand. People type the phrase, so pages are written to match it — including pages belonging to firms that sell the preparation work and should know better. Some firms selling this work use the wrong phrase, and once a phrase is in a procurement template it propagates on its own: a buyer copies it into a questionnaire, a vendor copies it into an answer, and a year later it is in everybody’s contract.

We use the searched phrase nowhere on this site except to name it as the common error, because the whole value of the distinction is knowing which artifact a counterparty will accept.

SOC 2: what it is and who performs it

System and Organization Controls is, in the words of the body that promulgates the professional standards for it, “a suite of service offerings CPAs may provide” in connection with system-level controls of a service organization. The key word is CPAs. The engagement is performed by a licensed CPA firm, subject to peer review and professional standards. A security consultancy cannot perform one, and a software platform cannot produce one on its own.

What lands on your desk at the end is a report, usually a substantial one. It contains a description of the system in scope, written by you; the criteria the engagement was conducted against, drawn from the trust services criteria for security and, where you select them, availability, processing integrity, confidentiality and privacy; the practitioner’s opinion; and a section listing the tests performed and their results — including any exceptions found. A report with exceptions in it is normal. A customer’s security reviewer reads that section first.

A Type 1 report describes the controls as designed at a single point in time. A Type 2 report covers a period — commonly three to twelve months — and reports on whether the controls operated as described throughout it. A Type 1 report is quicker to obtain and weaker as evidence, because designing a control and running it for a year are different achievements. Most enterprise buyers who know what they are asking for want the Type 2.

ISO/IEC 27001: who issues the certificate, and what accreditation means

ISO/IEC 27001 is the international standard for an information security management system, published by ISO and IEC. The standard itself is a document you buy from the ISO catalogue; what a customer asks for is the certificate.

Certificates are issued by an accredited certification body — an independent organization that has itself been assessed, by a national accreditation body, as competent to run conformity assessments against the standard. That chain is the whole point. Anybody can print a document with a logo on it; the accreditation chain is what tells a reader that the body which issued it was examined by someone else against a published set of requirements. When you evaluate a quote, ask which accreditation the body holds and confirm it with the national accreditation body directly.

No. A consultancy that helps you prepare cannot also be the body that issues your certificate, because the body that issues it has to be independent of the work it is examining. This is not a technicality. Independence is what the artifact is for, and the firms that observe it are the ones whose certificates keep their value.

The certificate names a scope. A scope statement reading “the hosted platform and its supporting infrastructure” and one reading “the corporate IT function at the head office” are both valid certificates and are not remotely the same claim. Read the scope on any certificate a supplier sends you, including your own.

Side by side

QuestionSOC 2ISO/IEC 27001
What you receiveA report on a defined periodA certificate with a named scope
Who produces itA licensed CPA firmAn independent body holding accreditation
What it is measured againstTrust services criteria you selectThe requirements of the published standard
Can you publish itNormally shared under a non-disclosure agreementThe certificate is normally public
How it recursA new report each periodSurveillance visits, then a recertifying cycle
Where it is usually asked forNorth American enterprise procurementEuropean, Asian and global procurement

The row that decides most engagements is the last one. Which artifact your buyers ask for is a fact about your market, not a judgement about which standard is better.

What does a customer actually accept?

In practice a reviewer is trying to answer three questions. Does the scope of this artifact cover the thing being bought? Is the issuer independent and competent? Is it current? An artifact that fails any of those is treated as no artifact at all, whichever of the two it is.

That is also why either will often do. A reviewer who has a SOC 2 report in front of them covering the platform they are buying, for a period ending three months ago, is satisfied — and a reviewer holding a current certificate whose scope covers that platform is satisfied too. The reviewers who insist on one specific artifact are usually working from a procurement template rather than from a risk question, which is worth establishing early, because a template can sometimes be answered with a well-built evidence pack and a roadmap while the longer work proceeds.

How the preparation work differs

More is shared than either path’s marketing suggests. Both require you to know what is in scope, who has access to it, how changes reach production, how you detect and handle incidents, how you manage suppliers, and how you demonstrate that all of the above happened rather than merely existing on paper. That common core is most of the work, and it is the part that makes an organization measurably harder to attack.

Where they part company:

  • The management system. ISO/IEC 27001 expects an information security management system as a thing in its own right — a defined scope, a risk method applied consistently, objectives, internal review, and a management review that produces decisions. SOC 2 does not require that machinery by name, though organizations that have it find the report easier.
  • Evidence over a period. A Type 2 report turns on evidence that a control operated on every occasion it should have, throughout the period. That is a logging and retention problem as much as a policy problem, and it is the single most common reason a first attempt slips.
  • The description of the system. SOC 2 asks you to write a description that the report then attaches to. Writing it accurately is real work and is usually underestimated.

Our own work is on that shared core: readiness — closing the gaps, building the evidence so it is produced by the system rather than assembled by hand the week before, and rehearsing the questions. The examination and the conformity assessment are performed by others, which is the correct arrangement.

Which should you do first?

Choose the one your pipeline is asking for. If nobody has asked yet, the management-system route tends to build the more durable internal machinery, because it forces an explicit scope, a risk method and a review cycle that outlive any single engagement.

Two practical constraints usually settle it. The first is the deal calendar: if a signature is waiting on an artifact, that decides which artifact. The second is your own evidence maturity. If your logs do not retain long enough to demonstrate a full period, a Type 2 report is further away than it looks, and the months in between are better spent fixing the retention than waiting.

If artificial intelligence is part of what you sell, the same question is arriving in a third form, and the ground there is less settled — we compare the two dominant references in ISO 42001 and the NIST AI Risk Management Framework.

What a consultancy can and cannot do

Can

Set the scope with you. Run a gap assessment against the criteria or the requirements. Write and fix the controls, the policies and the system description. Build the evidence pipeline. Rehearse the interviews. Sit with you through the fieldwork and manage the remediation list.

Cannot

Perform the examination. Issue the report. Issue the certificate. Grade its own work. Promise an outcome — the independence that gives either artifact its value is exactly the thing that makes an outcome unpromisable.

A firm that blurs that line is telling you something useful about how it treats the rest of its obligations. The wider picture of where these sit among Canadian privacy obligations is in compliance and privacy.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Can a consultancy issue our ISO 27001 certificate?

No. A consultancy that helps you prepare cannot also be the body that issues your certificate, because the body that issues it has to be independent of the work it is examining.

Is there such a thing as a SOC 2 certificate?

There is no SOC 2 certificate. SOC 2 produces a report written and signed by a CPA firm about a defined period, and the artifact your customer receives is that report, not a wall plaque.

Do we need both SOC 2 and ISO 27001?

Most organizations need one. You need both when you sell into two markets that ask for different artifacts — North American enterprise procurement that asks for a SOC 2 report, and European or Asian procurement that asks for an ISO/IEC 27001 certificate.

What is the difference between a Type 1 and a Type 2 report?

A Type 1 report describes the controls as designed at a single point in time. A Type 2 report covers a period — commonly three to twelve months — and reports on whether the controls operated as described throughout it.

Which one should we do first?

Choose the one your pipeline is asking for. If nobody has asked yet, the management-system route tends to build the more durable internal machinery, because it forces an explicit scope, a risk method and a review cycle that outlive any single engagement.

Working out which one you need

Tell us which artifact your buyers are asking for and what you already have in place; the reply says what the gap looks like and which order the work goes in. More on how we write about this is in the writing index.

Discuss a scope