Explainer · evidence towards customers
ISO 27001 or SOC 2 – what do your customers want?
Both evidence information security, but they are not the same document. One certifies a management system, the other reports on individual controls over a period.
ISO/IEC 27001 is issued by an accredited certification body. What is examined is whether a management system exists and works. The result is a certificate of a few pages stating scope and a three-year validity, accompanied by annual surveillance audits.
SOC 2 comes from the American assurance world. An audit firm assesses a provider’s controls against the Trust Services Criteria and writes a report about it. That report is rarely under thirty pages, contains the system description, the tests performed and any exceptions found – and is usually released only under a confidentiality agreement.
For you as a customer the practical difference is this: a certificate takes two minutes to check for scope and validity. A SOC 2 report has to be read.
The differences
| Aspect | ISO/IEC 27001 | SOC 2 |
|---|---|---|
| Form of evidence | Certificate | Audit report with an opinion |
| Who examines | Accredited certification body | Audit firm |
| Subject | Management system and its effectiveness | The provider’s described controls |
| Time reference | Three years, with annual surveillance audits | Point in time (type I) or a period of usually 6 to 12 months (type II) |
| Scope | Stated on the certificate | System description and chosen criteria |
| What you receive | Certificate and, on request, the statement of applicability | Full report, usually under confidentiality |
| Statement on exceptions | None on the certificate | Listed individually, with impact |
| Prevalence | Europe, Switzerland, international | North America, increasingly among SaaS vendors |
What each can and cannot do
- The certificate is quick to verify
- Issuer, scope, validity – all checkable in the certification body’s register. For adding a supplier to a register that is often enough.
- The report says more
- It names concrete controls, the tests performed and the exceptions found. Anyone wanting to know whether the provider’s access management works finds it here – not on a certificate.
- The certificate says nothing about exceptions
- Certificates are issued with open minor nonconformities where a corrective plan exists. That does not appear on the document.
- The report has gaps you must know about
- Sub-service organisations can be carved out. A type I report says nothing about effectiveness over time. Both appear in the report, but not on page one.
What you should do as a customer
- Request rather than tick offHave the document handed over, not merely confirmed to exist.For SOC 2 a confidentiality agreement is usually needed – that is normal, not evasion.
- Check the scopeDoes the evidence cover the service you buy and the site delivering it?The most common finding: the certificate covers the parent company while delivery comes from a subsidiary.
- Check the periodIs the evidence current, and for SOC 2: type I or type II?For a critical service a type I report is a weak basis.
- Assess the gapsJudge carved-out sub-service organisations and open exceptions separately.That judgement is your actual evidence – not the provider’s document.
- Set a recall dateBoth forms of evidence expire.The next one is requested before the current lapses, not when the auditor asks.
What gets accepted in your audit is never the provider’s document but your assessment of it. A filed certificate without a review note is a file, not evidence.
When you are the one being asked
- Customers in Europe and Switzerland almost always ask for ISO 27001. A SOC 2 report is frequently not understood there.
- Customers in North America ask for SOC 2, sometimes plus ISO 27001 for international group entities.
- Holding both saves time in sales – the second examination costs considerably less because the controls are the same.
- For small vendors ISO 27001 is usually the cheaper entry, because the scope can be drawn narrowly.
Evidence is only as good as its administration
In SCRM, certificates and reports carry type, period, scope and review note as fields. What expires speaks up – and the assessment stays on the supplier, where the auditor looks.