TL;DR

ISO 27001 certifies a management system. SOC 2 reports on controls you designed yourself. They are not the same kind of object, and that is what makes the choice.

  • ISO 27001 gives you a certificate from a body accredited to ISO/IEC 17021-1. SOC 2 gives you a report from a licensed CPA firm. No one is “SOC 2 certified”.
  • SOC 2 lets you set your own controls, categories and window, so two SOC 2 reports are not comparable. Two ISO 27001 certificates are.
  • The overlap runs one way. ISO 27001 first makes SOC 2 cheap. SOC 2 first does not make ISO 27001 cheap, because Clauses 4 to 10 have no SOC 2 equivalent.
  • ISO 27001 runs a three-year cycle with annual surveillance. SOC 2 needs a fresh report every year, plus a bridge letter to cover the gap.
  • Neither answers the Canadian residency question. SOC 2 has no data residency criterion at all.
  • Let your pipeline choose. US software buyers ask for SOC 2. European, UK and Canadian public sector buyers ask for a certificate number.
93Annex A controls in ISO/IEC 27001:2022, in four themes
5Trust services categories. Only security is in every report
3 yrsHow long an accredited ISO 27001 certificate runs
0Data residency criteria anywhere in SOC 2

Sources: ISO/IEC 27001:2022 · AICPA Trust Services Criteria · Standards Council of Canada

One is a certificate. The other is a report.

Start with the object each process produces. It settles most of the confusion in one step.

ISO/IEC 27001 is a published standard. You build an information security management system that meets it. An independent certification body audits you and issues a certificate. In Canada the Standards Council of Canada accredits those bodies. SCC is direct about the entry requirement. Its ISMS accreditation page states that “as a pre-requisite, certification bodies must also be accredited to ISO/IEC 17021-1.” The certificate names the standard, the scope and the expiry date. A buyer can check it in a minute.

SOC 2 produces something else. A licensed CPA firm examines your controls and writes a report. That report holds the auditor’s opinion, your own description of your system, the tests the firm performed, and the results. It runs to dozens of pages. There is no certificate, no logo you earn and no public registry.

So “SOC 2 certified” is wrong. It still appears on hundreds of vendor sites. Say “SOC 2 report” or “SOC 2 examination” and you sound like someone who has read one.

Certificate

ISO/IEC 27001

A management system audited against a published standard.

Who signs itA certification body, accredited in Canada by SCC.
What a buyer seesA certificate number, a scope statement and an expiry date.
ComparableYes. The requirement clauses are the same for everyone.
Report

SOC 2

An opinion on controls you wrote, tested against criteria.

Who signs itA licensed CPA firm, which can be a Canadian one.
What a buyer seesA document to read, under an NDA, before they trust it.
ComparableNo. Scope, categories and window all change per company.

The difference in kind, before the difference in cost.

In SOC 2 you write your own controls

This is the difference that changes the work, and most comparisons skip it.

SOC 2 rests on the AICPA Trust Services Criteria. The current set is the 2017 criteria, with revised points of focus issued in 2022. Note the word criteria. They are not controls. Criterion CC6.1 asks you to restrict logical access. It does not name single sign-on, or set a password length, or tell you to review access every quarter. You decide all of that. You write it into your system description. Your auditor then tests two things. Does your control design hold up. In a Type 2, did it run for the whole period.

Five categories exist: security, availability, processing integrity, confidentiality and privacy. Security appears in every SOC 2 report. The other four are yours to add, and each one you add costs time.

ISO 27001 runs the other way round. Clauses 4 to 10 are requirements. You meet them or you do not certify. Annex A then gives you 93 controls across four themes. Your Statement of Applicability records which ones you applied. It also records why you left the rest out. Your scope is yours. The requirements are not.

What trips people up

“We have SOC 2” tells a buyer close to nothing on its own. Ask four things. Which categories does the report cover. How long did the observation window run. Which systems sit inside the scope. What sits in the exceptions section. A clean Type 2 over twelve months across all five categories is a different document from a Type 1 covering security alone. Both get called “SOC 2”.

The overlap is real, and it runs one way

Every comparison quotes an overlap figure. Treat those numbers with care. The AICPA does publish mappings. It says they “identify the relationship” between the 2017 Trust Services Criteria and “the requirements in a specified framework.” A mapping shows where things line up. It does not tell you how much work you save.

Here is what an overlap figure hides. The overlap sits in the controls. Access control, change management, encryption, vendor management, incident response, logging and monitoring. Build those once and they count twice.

The gap sits in ISO 27001 Clauses 4 to 10, and SOC 2 asks for none of it. No risk assessment. No risk treatment plan. No Statement of Applicability. No internal audit programme. No management review. No nonconformity and corrective action process. That is the machinery of a management system, and it is the part that takes months.

So the sequencing advice is not symmetric:

  1. ISO 27001 first, then SOC 2. Your controls run, your evidence flows and you hold a documented risk assessment. The SOC 2 examination comes down to scoping, a system description and a window.
  2. SOC 2 first, then ISO 27001. Your controls transfer. The management system does not exist yet, and you start it from zero in year two.
 ISO 27001SOC 2
What you getA certificateA report with an auditor’s opinion
Who issues itAn accredited certification bodyA licensed CPA firm
Named control setAnnex A, 93 controlsNone. You design your own
Risk assessment and treatmentRequired, Clause 6.1Not required
Statement of ApplicabilityRequiredNot required
Internal audit and management reviewRequired, Clauses 9.2 and 9.3Not required
You set the scopeYesYes
How long it lastsThree years, with annual surveillanceNo expiry. Buyers treat it as current for about twelve months
Comparable across two vendorsYesNo

What each one costs you in year two

The first year is the one everybody budgets for. The shape of year two is what catches teams out, and the two frameworks have opposite shapes.

ISO 27001 has a light year

ISO 27001 runs on a three-year cycle. The initial audit comes in two parts. Stage 1 reviews your documents and your readiness. Stage 2 tests the system in operation. You get the certificate, then a surveillance audit each year, then a recertification audit in year three. The weight sits in year one. Years two and three are lighter, and the calendar is predictable.

One date still catches people. The transition window for the 2013 edition closed on 31 October 2025. A certificate naming ISO/IEC 27001:2013 is no longer current. Check which edition yours names before you send it to a buyer, and check the same on any supplier certificate you accept.

SOC 2 has no light year

Each SOC 2 report covers a stated period. When the period ends, the report starts ageing. Buyers treat one as current for about twelve months past the period end date, though nothing in the criteria says so. Ask for a report in month fourteen and you get asked for a bridge letter instead. That is a management-signed statement covering the gap, and enterprise buyers cap it at around three months.

So the shapes differ. ISO 27001 gives you a lumpy cost on a fixed calendar. SOC 2 gives you a level cost that never pauses. Neither is cheaper in every case. For real figures see what a SOC 2 Type 2 report costs and how long a SOC 2 Type 2 takes.

Choosing between them in Canada

Here is the part that is different in Canada, and it is not the law.

Most companies never face this choice. A US software startup sells to US buyers and gets asked for SOC 2. A German manufacturer gets asked for ISO 27001. Canadian firms sit between two conventions. Your pipeline holds US enterprise buyers who send a SOC 2 request. It also holds European, UK and Canadian public sector buyers who want a certificate number on a form. That is why the question is live in Toronto and settled in San Francisco.

Both routes work from here.

An ISO 27001 certificate issued in Canada travels. SCC accredits Canadian certification bodies for the standard and signs the International Accreditation Forum Multilateral Recognition Arrangement for that programme.

“Certification to ISO/IEC 27001 by SCC-accredited certification bodies is widely accepted internationally.”

Standards Council of CanadaInformation Security Management Systems accreditation

A SOC 2 report issued in Canada travels too. SOC 2 is an AICPA framework and the practitioner must be a licensed CPA firm, but that firm can be Canadian. CPA Canada publishes its own SOC 2 guide. It calls the guide “a non-authoritative resource which we have adapted from the AICPA version to meet Canadian standards”. The guide covers “reporting in accordance with both Canadian and international, or Canadian and U.S. standards”. A Canadian-issued report carries the same weight with a US buyer.

What neither one proves

This matters more than the accreditation detail, and almost nobody says it.

Neither framework tells a buyer where your data sits. SOC 2 has no data residency criterion. Nothing in the Trust Services Criteria asks the question, so a clean report says nothing about whether Canadian records stayed in Canada. ISO 27001 does not mandate residency either. It gives you controls for information transfer and for cloud services, and your Statement of Applicability shows a reader what you chose. A buyer can read that document. A buyer cannot read residency off a certificate.

Neither one proves compliance with Canadian privacy law. Look at PIPEDA, PHIPA in Ontario, Law 25 in Quebec, and OSFI B-13 for banks and insurers. Each carries duties that no security framework satisfies on its own. Both frameworks help. Neither substitutes.

If Canadian data residency is your differentiator, put it in the contract and in the system description that ships with your report. Do not expect the framework to carry it for you.

How to choose, in four questions

  1. What is your pipeline asking for? Read the last ten security questionnaires you received. The answer is in them more often than not. Build for the buyer you have, not the market you plan to enter.
  2. Is a deal blocked right now? Ask that buyer what they accept as an interim step. A Type 1 report or a signed readiness statement often unblocks a deal while the Type 2 window runs.
  3. Do you sell outside North America? Then ISO 27001 does more per dollar. A certificate number is a field on a European procurement form. A SOC 2 report is not.
  4. Are you doing both in the end? Then start with ISO 27001. The management system is the long pole, and once it stands the SOC 2 examination is scoping and description.

What good looks like

A team that answers “which one do you have” with three facts. A scope, a period, and the name of the body or firm that signed it. That answer closes a questionnaire. “We are SOC 2 certified” opens three more.

Frequently asked questions

Is SOC 2 a certification?

No. SOC 2 is an attestation engagement. A licensed CPA firm examines your controls and issues a report with an opinion. There is no certificate and no registry. ISO 27001 is a certification, issued by a body accredited for that purpose.

Which is harder, ISO 27001 or SOC 2?

ISO 27001 asks for more. On top of the controls it requires a risk assessment, a Statement of Applicability, an internal audit programme and a management review. SOC 2 requires none of those. SOC 2 is harder in one respect. A Type 2 report needs your controls to run for the whole observation window. You cannot fix things the week before.

Can one audit cover both ISO 27001 and SOC 2?

Not one audit. They are different engagements under different rules, and a certification body cannot issue a SOC 2 opinion. You can run one control set and one evidence pipeline for both, which is where the saving lives. Expect two audit events and two invoices.

If I have ISO 27001, how much of SOC 2 is done?

Most of the control work. Your access control, change management, encryption, vendor and incident controls map across to the common criteria. What remains is scoping the system, choosing your categories, writing the system description and running the observation window.

Does ISO 27001 or SOC 2 satisfy PIPEDA or PHIPA?

Neither one does. Both improve your security posture and both give you documents a regulator will read with interest. Canadian privacy law carries its own duties on consent, access, retention and breach reporting. Treat the frameworks as support, not as proof.

Which is better recognised in Canada?

Buyers accept both, and the answer turns on your buyer rather than your postcode. SCC accredits Canadian ISO 27001 certification bodies and signs the IAF arrangement, so a certificate issued here travels. A SOC 2 report from a Canadian CPA firm carries the same weight with a US buyer as one from a US firm.

Do I need both?

Only if your buyers do. Two frameworks means two audit cycles and two sets of fees for one control set. Check your pipeline first. If every request in the last year said SOC 2, a certificate buys you nothing this year.

Key takeaways

  • ISO 27001 produces a certificate from an accredited body. SOC 2 produces a report from a CPA firm.
  • “SOC 2 certified” is not a thing. The correct words are report and examination.
  • SOC 2 criteria are not controls. You design the controls, so no two reports compare.
  • The overlap sits in the controls. The gap sits in ISO 27001 Clauses 4 to 10, which SOC 2 never asks for.
  • Doing ISO 27001 first makes SOC 2 cheap. The reverse does not hold.
  • ISO 27001 gives you a light year two. SOC 2 does not, and the gap needs a bridge letter.
  • Neither framework answers the Canadian residency question. Put that in the contract.
  • Your pipeline decides. Read the last ten questionnaires before you read another comparison.
HZ

Hunter Zhu Founder of Nank.ai, a Toronto firm that takes Canadian companies to SOC 2, ISO 27001, and ISO 42001. Connect on LinkedIn

Not sure which one your buyers want?

Nank.ai runs SOC 2 and ISO 27001 programmes for Canadian companies from Toronto, with your evidence and your data held in Canada. We will read your questionnaires with you and tell you which framework earns its cost first.

.

Table of Contents

Scroll to Top