The email arrives from the procurement team. Attached is a security questionnaire. Question 3 asks: “Do you hold ISO 27001 or SOC 2 certification?”
You have neither. You have six months to close the deal. Which one do you pursue?
At Metaluxo we run gap assessments for companies that need one, the other, or both. The answer is almost never “both.” It is whichever your buyer accepts as evidence.
What the frameworks actually are
ISO 27001 is an international standard published by the International Organization for Standardization. It certifies that you have an Information Security Management System (ISMS) that meets a defined set of requirements. The certification is issued by an accredited certification body and is valid for three years with annual surveillance audits.
SOC 2 is an attestation report governed by the American Institute of Certified Public Accountants (AICPA). It evaluates your controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 Type 2 report covers a period of time — typically six to twelve months — and is issued by a licensed CPA firm.
The critical difference is not technical. It is geographic and cultural. European enterprise buyers grew up with ISO standards. North American buyers grew up with SOC reports.
The overlap: why you do not need two parallel programmes
ISO 27001 Annex A contains 93 controls. SOC 2’s common criteria contain 33 points of focus. When we map them, approximately 80% overlap directly:
- Access control → CC6.1
- Encryption → CC6.7
- Incident response → CC7.3, CC7.4
- Risk assessment → CC3.2
- Vendor management → CC9.2
- Monitoring and logging → CC7.2
The practical implication is that a single risk assessment, a single policy set, and a single evidence collection exercise can satisfy both frameworks. The only duplication is in the audit itself: you pay an ISO certification body for one report and a CPA firm for the other.
Which one to choose
Choose ISO 27001 if:
- Your buyers are in the UK, EU, or Middle East
- You are bidding for government or health-system contracts
- You need a certificate to hang on the wall (SOC 2 is a report, not a certificate)
- Your competitors all have ISO 27001
Choose SOC 2 if:
- Your buyers are in North America
- You are selling to SaaS companies or venture capital-backed startups
- Your buyers ask for a Type 2 report specifically
- You already use a US-based compliance automation tool
Choose both if:
- You have buyers on both continents and the revenue justifies the second audit cost
- You are preparing for an exit and want the broadest possible compliance posture
- You have the internal bandwidth to manage two audit cycles simultaneously
For a company under 50 people, both is usually overkill. One framework, implemented well, is more valuable than two frameworks, implemented poorly.
Timeline and cost reality
| Phase | ISO 27001 | SOC 2 Type 2 |
|---|---|---|
| Gap assessment | 4 weeks | 4 weeks |
| Remediation | 3–6 months | 3–6 months |
| Audit / observation period | Stage 1 + Stage 2 (1–2 weeks total) | 6–12 months observation |
| Report / certificate | 2–4 weeks after Stage 2 | 4–6 weeks after period ends |
| Total to completion | 4–9 months | 7–14 months |
| Typical audit cost (SME) | £4K–£8K | £8K–£20K |
The SOC 2 Type 2 timeline is longer because the auditor must observe controls operating over time. ISO 27001 is a point-in-time certification — pass Stage 2 and you are certified.
How to run one programme for both
If you decide to pursue both, run ISO 27001 first. The ISMS structure — scope, risk assessment, policies, internal audit, management review — is the foundation. SOC 2 then becomes a mapping exercise: show how each ISO control satisfies the relevant Trust Services Criteria.
At Metaluxo we run combined readiness programmes that deliver an ISO 27001 gap assessment and a SOC 2 readiness review in a single four-week engagement. If your buyers are asking for both, book a free 30-minute consultation and we will map exactly what evidence you need.
The wrong answer is to chase certification for its own sake. The right answer is to ask your buyers what they accept — then give them that.
Common questions
Can one audit satisfy both ISO 27001 and SOC 2?
Yes. A single gap assessment against ISO 27001 Annex A typically covers most SOC 2 Trust Services Criteria. You evidence once and map to both frameworks.
Which is more expensive, ISO 27001 or SOC 2?
ISO 27001 usually costs more because it requires a certification body audit. SOC 2 Type 2 requires an AICPA-licensed firm. For a small company, the consultancy cost is similar; the auditor cost differs.
Do startups need both ISO 27001 and SOC 2?
Rarely. Startups should ask their top three buyers which framework they require. Most SMEs need only one.