Illustration contrasting an ISO certificate carrying a seal with a SOC report carrying an opinion, beside a recurring audit cycle

ISO and SOC Certifications

Updated: September 29, 2026

Sooner or later a customer's procurement form asks whether you are ISO 27001 certified, or whether you have a SOC 2 report. This section explains what each of those actually is, which ones apply to which kind of business, and what getting one involves — in time, in work, and in what has to change about how you operate.

The short version, before the detail: ISO gives you a certificate, SOC gives you a report, and they answer different questions. Neither of them is a statement that you are secure.

The Difference That Confuses Everyone

Table comparing ISO certification with SOC attestation across what you receive, who issues it, what it states, who may read it, whether failures are listed, how scope is set, and where each is recognised

An ISO certificate is a binary outcome from an accredited certification body: you conform to the standard across a stated scope, or you do not. It is a public document you can put on a website, and it says nothing about what went wrong during the audit.

A SOC report is an audit opinion from a licensed audit firm. It runs to dozens of pages, describes the controls you chose to put forward, lists every test the auditor performed, and prints the results — including the failures, which are called exceptions. It is shared under NDA. There is no such thing as being “SOC 2 certified”, and a supplier who says they are has told you something about how carefully they read it.

The other structural difference is time:

Two timelines: an ISO cycle of stage one, stage two, two surveillance audits and recertification, against one SOC report a year each covering the twelve months behind it

The Information Security Family

These are the ones asked about most, and the ones most relevant to anyone running infrastructure.

ISO/IEC 27001

The information security management system. The single most requested certificate, and the foundation the others in this family extend.

SOC 2

The report North American buyers ask for. Security plus whichever of availability, confidentiality, processing integrity and privacy you include.

ISO/IEC 27017

Cloud-specific security guidance, for providers and for the organisations using them. Adds to 27001 rather than replacing it.

ISO/IEC 27018

Protecting personal data in a public cloud when you process it on someone else's behalf.

ISO/IEC 27701

Privacy information management, with an explicit mapping to data protection law. The nearest thing to a certifiable privacy standard.

SOC 1

For services that affect your customers' financial reporting — payroll, payments, anything their auditors need to rely on.

SOC 3

The publishable summary of a SOC 2. A marketing document with an auditor's name on it, and useful as exactly that.

The Wider Management System Family

These are not security standards, but they are built the same way — the same clause structure, the same audit cycle — so once you have run one, the next costs far less.

ISO 9001

Quality management. The oldest and most widely held certificate in the world, and frequently a hard requirement in public tenders.

ISO 22301

Business continuity. Overlaps directly with disaster recovery planning, and demands that the plan be tested.

ISO/IEC 20000-1

IT service management. The certifiable standard that sits next to ITIL, which is a framework and cannot be certified.

ISO 14001

Environmental management. Increasingly requested in supply-chain and reporting questionnaires rather than only by manufacturers.

How to Choose

The honest answer is that in most cases the market chooses for you, and it is worth being clear about that rather than building a compliance programme on principle.

Three Things to Check on Anyone Else's Certificate

This works in both directions: it is how you evaluate a supplier, and it is what a customer should be doing to you.

  1. The scope. A certificate covers a defined scope, and the scope is chosen by the organisation being certified. One product line, one office, or one legal entity out of six is entirely legitimate and entirely different from what the logo implies. Read the scope statement on the certificate, not the badge on the website.
  2. The accreditation. An ISO certificate is worth what the certification body behind it is worth, and the body should itself be accredited by a national accreditation body — in Bulgaria that is the Bulgarian Accreditation Service, elsewhere the equivalent national body — operating under the international mutual recognition arrangement. Certificates from unaccredited bodies exist and are cheaper.
  3. The date, and for SOC the period. An ISO certificate has an expiry. A SOC report covers a period that has already ended, sometimes many months ago; ask what has happened since, and whether there is a bridge letter covering the gap.

What It Actually Costs

Not in money, which depends entirely on size and on your certification body, but in the things people underestimate:

Scope of this section. These pages explain what the standards require and how the process works, from the perspective of people who build and run the infrastructure being audited. We are not a certification body, an accredited auditor or a legal adviser, and nothing here is legal advice. Which standards apply to your business is a question for your legal counsel or a compliance specialist; standards are also revised on a cycle, so confirm the current edition before you commit to anything.