ISO and SOC Certifications
Updated: September 29, 2026
Sooner or later a customer's procurement form asks whether you are ISO 27001 certified, or whether you have a SOC 2 report. This section explains what each of those actually is, which ones apply to which kind of business, and what getting one involves — in time, in work, and in what has to change about how you operate.
The short version, before the detail: ISO gives you a certificate, SOC gives you a report, and they answer different questions. Neither of them is a statement that you are secure.
The Difference That Confuses Everyone
An ISO certificate is a binary outcome from an accredited certification body: you conform to the standard across a stated scope, or you do not. It is a public document you can put on a website, and it says nothing about what went wrong during the audit.
A SOC report is an audit opinion from a licensed audit firm. It runs to dozens of pages, describes the controls you chose to put forward, lists every test the auditor performed, and prints the results — including the failures, which are called exceptions. It is shared under NDA. There is no such thing as being “SOC 2 certified”, and a supplier who says they are has told you something about how carefully they read it.
The other structural difference is time:
The Information Security Family
These are the ones asked about most, and the ones most relevant to anyone running infrastructure.
ISO/IEC 27001
The information security management system. The single most requested certificate, and the foundation the others in this family extend.
SOC 2
The report North American buyers ask for. Security plus whichever of availability, confidentiality, processing integrity and privacy you include.
ISO/IEC 27017
Cloud-specific security guidance, for providers and for the organisations using them. Adds to 27001 rather than replacing it.
ISO/IEC 27018
Protecting personal data in a public cloud when you process it on someone else's behalf.
ISO/IEC 27701
Privacy information management, with an explicit mapping to data protection law. The nearest thing to a certifiable privacy standard.
SOC 1
For services that affect your customers' financial reporting — payroll, payments, anything their auditors need to rely on.
SOC 3
The publishable summary of a SOC 2. A marketing document with an auditor's name on it, and useful as exactly that.
The Wider Management System Family
These are not security standards, but they are built the same way — the same clause structure, the same audit cycle — so once you have run one, the next costs far less.
ISO 9001
Quality management. The oldest and most widely held certificate in the world, and frequently a hard requirement in public tenders.
ISO 22301
Business continuity. Overlaps directly with disaster recovery planning, and demands that the plan be tested.
ISO/IEC 20000-1
IT service management. The certifiable standard that sits next to ITIL, which is a framework and cannot be certified.
ISO 14001
Environmental management. Increasingly requested in supply-chain and reporting questionnaires rather than only by manufacturers.
How to Choose
The honest answer is that in most cases the market chooses for you, and it is worth being clear about that rather than building a compliance programme on principle.
- Selling to North American companies? They will ask for SOC 2. Start there.
- Selling to European or Asian enterprises, or bidding for public tenders? ISO 27001, and often ISO 9001 alongside it, because a tender scoring sheet asks for a certificate number rather than a report.
- Both markets? Do ISO 27001 first and SOC 2 second. The control work overlaps heavily, and 27001 gives you the management system that makes the SOC 2 evidence collection routine instead of a scramble.
- Nobody is asking yet? Then do the underlying work — the security controls, the documented processes, the tested backups — and certify when a deal depends on it. The controls are what protect you; the certificate is what sells.
Three Things to Check on Anyone Else's Certificate
This works in both directions: it is how you evaluate a supplier, and it is what a customer should be doing to you.
- The scope. A certificate covers a defined scope, and the scope is chosen by the organisation being certified. One product line, one office, or one legal entity out of six is entirely legitimate and entirely different from what the logo implies. Read the scope statement on the certificate, not the badge on the website.
- The accreditation. An ISO certificate is worth what the certification body behind it is worth, and the body should itself be accredited by a national accreditation body — in Bulgaria that is the Bulgarian Accreditation Service, elsewhere the equivalent national body — operating under the international mutual recognition arrangement. Certificates from unaccredited bodies exist and are cheaper.
- The date, and for SOC the period. An ISO certificate has an expiry. A SOC report covers a period that has already ended, sometimes many months ago; ask what has happened since, and whether there is a bridge letter covering the gap.
What It Actually Costs
Not in money, which depends entirely on size and on your certification body, but in the things people underestimate:
- Six to twelve months for a first ISO 27001, if you are starting from scratch and someone owns it properly. Less if your controls are already in good shape, more if they are not.
- A named owner with real time. Certification fails most often not on technical controls but on nobody having been given the job.
- Evidence, continuously. The audit does not ask whether you have a process; it asks you to show records that it ran. Reviews that happened without minutes did not happen as far as an auditor is concerned.
- It does not end. Surveillance audits, internal audits, management reviews, risk reassessments — every year, indefinitely. A certificate is an ongoing commitment, and treating it as a project with an end date is the most common way to lose it at the first surveillance audit.
Scope of this section. These pages explain what the standards require and how the process works, from the perspective of people who build and run the infrastructure being audited. We are not a certification body, an accredited auditor or a legal adviser, and nothing here is legal advice. Which standards apply to your business is a question for your legal counsel or a compliance specialist; standards are also revised on a cycle, so confirm the current edition before you commit to anything.