AI COMPLIANCE COMPARE

Field guide · Track 1: Foundations · Lesson 2 of 10

SOC 2 and ISO 27001: an attestation and a certification

By the Signal Desk, AI Compliance Compare · Reviewed 2026-09-29

Short answer

SOC 2 is an attestation report issued by a licensed CPA firm under AICPA standards; ISO/IEC 27001 is a certifiable standard for an information security management system, with certificates issued by certification bodies. Most platforms here support both, and many teams need both once they sell into several markets.

What is SOC 2?

The AICPA describes System and Organization Controls (SOC) as a suite of service offerings CPAs may provide. SOC 2 reports on controls at a service organization relevant to five categories named in the AICPA guide's title: security, availability, processing integrity, confidentiality and privacy. A SOC 2 report is written by a CPA firm after it examines your controls. A Type I report looks at whether controls are designed properly at a point in time; a Type II report covers whether they operated effectively over an observation period, commonly several months.

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for information security management systems (ISMS). The current version is ISO/IEC 27001:2022, Edition 3, published in October 2022 by ISO/IEC JTC 1/SC 27. Instead of a report, a certification body audits your ISMS and issues a certificate if it conforms. The ISMS is a management system: risk assessment, a Statement of Applicability listing which controls apply, internal audits and management review.

Which one do you need?

Buyers in one market often ask for a SOC 2 report; buyers in others expect an ISO 27001 certificate. The two overlap heavily in the controls they cover, which is why cross-mapping matters: evidence gathered for one can support much of the other. Every platform on this site names both SOC 2 and ISO 27001 on its pages except Sprinto, whose pages state framework counts without listing names.

What should you check with a platform?

Ask whether the platform's entry plan covers one of these or both, whether controls are mapped once for both, and who arranges each audit. For SOC 2 the auditor must be a licensed CPA firm; for ISO 27001, a certification body. A platform can help you prepare, but it does not issue the report or the certificate.

How long does each one take?

Vendors publish speed claims, but the honest answer depends on you. A SOC 2 Type I can follow as soon as controls are designed and the auditor is scheduled. A Type II needs the observation period to run first, so the calendar is set by that period plus the auditor's fieldwork and reporting. ISO 27001 certification runs in audit stages set by the certification body. Plan the calendar with the auditor, not with a marketing page, and treat any 'in days' claim as the vendor's description of readiness rather than of the report date.

Next lesson · Lesson 3Control cross-mapping and common control frameworksHow one control can satisfy several frameworks, and which vendors describe it.

Keep reading