SCRM Supplier Compliance & Risk Management

Explainer · evidence towards customers

ISO 27001 or SOC 2 – what do your customers want?

Both evidence information security, but they are not the same document. One certifies a management system, the other reports on individual controls over a period.

ISO/IEC 27001 is issued by an accredited certification body. What is examined is whether a management system exists and works. The result is a certificate of a few pages stating scope and a three-year validity, accompanied by annual surveillance audits.

SOC 2 comes from the American assurance world. An audit firm assesses a provider’s controls against the Trust Services Criteria and writes a report about it. That report is rarely under thirty pages, contains the system description, the tests performed and any exceptions found – and is usually released only under a confidentiality agreement.

For you as a customer the practical difference is this: a certificate takes two minutes to check for scope and validity. A SOC 2 report has to be read.

The differences

AspectISO/IEC 27001SOC 2
Form of evidenceCertificateAudit report with an opinion
Who examinesAccredited certification bodyAudit firm
SubjectManagement system and its effectivenessThe provider’s described controls
Time referenceThree years, with annual surveillance auditsPoint in time (type I) or a period of usually 6 to 12 months (type II)
ScopeStated on the certificateSystem description and chosen criteria
What you receiveCertificate and, on request, the statement of applicabilityFull report, usually under confidentiality
Statement on exceptionsNone on the certificateListed individually, with impact
PrevalenceEurope, Switzerland, internationalNorth America, increasingly among SaaS vendors

What each can and cannot do

The certificate is quick to verify
Issuer, scope, validity – all checkable in the certification body’s register. For adding a supplier to a register that is often enough.
The report says more
It names concrete controls, the tests performed and the exceptions found. Anyone wanting to know whether the provider’s access management works finds it here – not on a certificate.
The certificate says nothing about exceptions
Certificates are issued with open minor nonconformities where a corrective plan exists. That does not appear on the document.
The report has gaps you must know about
Sub-service organisations can be carved out. A type I report says nothing about effectiveness over time. Both appear in the report, but not on page one.

What you should do as a customer

  1. Request rather than tick offHave the document handed over, not merely confirmed to exist.For SOC 2 a confidentiality agreement is usually needed – that is normal, not evasion.
  2. Check the scopeDoes the evidence cover the service you buy and the site delivering it?The most common finding: the certificate covers the parent company while delivery comes from a subsidiary.
  3. Check the periodIs the evidence current, and for SOC 2: type I or type II?For a critical service a type I report is a weak basis.
  4. Assess the gapsJudge carved-out sub-service organisations and open exceptions separately.That judgement is your actual evidence – not the provider’s document.
  5. Set a recall dateBoth forms of evidence expire.The next one is requested before the current lapses, not when the auditor asks.

What gets accepted in your audit is never the provider’s document but your assessment of it. A filed certificate without a review note is a file, not evidence.

When you are the one being asked

  • Customers in Europe and Switzerland almost always ask for ISO 27001. A SOC 2 report is frequently not understood there.
  • Customers in North America ask for SOC 2, sometimes plus ISO 27001 for international group entities.
  • Holding both saves time in sales – the second examination costs considerably less because the controls are the same.
  • For small vendors ISO 27001 is usually the cheaper entry, because the scope can be drawn narrowly.

Evidence is only as good as its administration

In SCRM, certificates and reports carry type, period, scope and review note as fields. What expires speaks up – and the assessment stays on the supplier, where the auditor looks.

Request a consultation Go to SOC 2 Go to BSI C5