SOC 2 and ISO/IEC 27001 are the two attestations vendors most often hand over during a due diligence assessment. They are frequently treated as interchangeable. They are not. They prove different things, in different ways, with different outputs — and a strong vendor assessment uses each one for what it is actually good at.
The short version
- ISO 27001 certifies that the vendor runs an Information Security Management System (ISMS) — a continuous, governed process for managing security risk.
- SOC 2 attests that specific controls operated effectively against the Trust Services Criteria during a defined period.
- ISO 27001 says: "we run a competent security programme". SOC 2 says: "these specific controls actually worked for the last 12 months".
Audit model
ISO 27001 is a certification issued by an accredited certification body against a published international standard. The output is a certificate plus a Statement of Applicability (SoA) listing the Annex A controls in scope.
SOC 2 is an attestation performed by a CPA firm against the AICPA Trust Services Criteria. The output is a long report — typically tens to hundreds of pages — describing the system, the controls and the auditor's testing.
Scope
ISO 27001 scope is the ISMS — usually expressed in terms of organisational units, services and locations. SOC 2 scope is the system — usually a specific product or platform. A vendor can be ISO 27001 certified for the whole company but only have one product covered by SOC 2 (or vice versa).
Always verify the scope describes the service you are buying. A certificate that covers the corporate office but not the product is not helpful.
Output
ISO 27001 gives you a short certificate and a SoA. You learn that the vendor has an ISMS, which controls they have selected and which they have excluded with justification.
SOC 2 gives you a long, detailed report including the auditor's opinion, the control descriptions, the test procedures and any exceptions found. You learn how individual controls actually performed. See How to Review a SOC 2 Report for the mechanics.
What each one is good at
- Use ISO 27001 to assess maturity. A current certificate from a reputable body indicates the vendor runs a managed, audited security programme. The SoA tells you what they consider in scope.
- Use SOC 2 to assess effectiveness. The control descriptions and exceptions tell you how the controls actually operate — and where they fail.
When to ask for both
For any vendor that processes regulated personal data, sits in the critical path of your service, or holds material confidential data, the two together are stronger than either alone:
- ISO 27001 confirms the vendor has a governed ISMS and that security is managed continuously.
- SOC 2 Type II confirms specific controls — encryption, access management, change management, incident response — operated effectively over a defined period.
For lower-tier vendors, one of the two is usually proportionate. The decision should be documented in your risk-tiering policy, not negotiated per vendor.
What neither one proves
- That the vendor's current security posture matches the audit period — both are point-in-time evidence.
- That the vendor complies with GDPR, NIS2, DORA or sector-specific regulation — those need their own evidence (DPA, transfer mechanisms, resilience documentation).
- That a specific incident will not happen. Attestations describe controls, not outcomes.
Putting them inside a due diligence assessment
Treat both as inputs into the requirements-to-evidence map. Each one supplies evidence for a subset of your requirements; together they cover most security and governance topics. The remainder — data protection, residency, sub-processors, resilience — comes from the DPA, the security white paper and the architecture documentation. See What is Vendor Due Diligence? for the wider context.