ISO 27001 to SOC 2: one control set, two reports
One control set can serve both, but a certificate and an attestation report differ in object, criteria, examiner, output and period.
Compliance5 Sept 202613 min read
On this page
What this is
An organisation holds one of the two products and a buyer asks for the other. A certificate holder meets North American buyers who file attestation reports; a SOC 2 organisation meets European buyers who want the certificate. One control set can serve both, and the products are still not interchangeable.
They differ in five ways that decide the work: what is examined, against which criteria, by whom, what comes out, and over what period. This page sets out those differences, then crosswalks the criteria to the clauses and controls a management system already carries. The crosswalk is GRCIDE's. No mapping published by the criteria's author is claimed or implied here. Choosing a GRC framework defines the attestation report assumed here.
Three disciplines meet in that crosswalk, as one loop rather than three teams. Governance decides what the organisation promises: service commitments and system requirements on the report side, the management system scope and objectives on the certificate side. Risk decides which controls exist and why: the risk assessment at clause 6.1.2 and the treatment decision at clause 6.1.3 1. On the report side, one criteria series asks for objectives clear enough that their risks can be identified 2. Compliance produces the two reports from the same evidence.
The two products side by side
A row means the two products answer the same question differently, not that either satisfies the other.
| ISO/IEC 27001:2022 certification | SOC 2 examination | |
|---|---|---|
| Object | The management system, audited against a requirements standard 3 | Controls at a service organisation, read against security, availability, processing integrity, confidentiality or privacy 4 |
| Criteria | Clauses 4 to 10, plus the controls chosen at 6.1.3 and recorded against the Annex A reference set 5 | Criteria common to all five categories, plus additional specific criteria for availability, processing integrity, confidentiality and privacy 6 |
| Categories | One scope statement, no modules | Any category alone or combined. Security is addressed in most engagements, and the common criteria alone suit it 7 |
| Examiner | A certification body, deciding on objective evidence rather than other interests 8 and undertaking conformity assessment impartially 9 | A CPA firm; the criteria document calls the examiner the practitioner 10 |
| Output | A certificate with a defined scope 3, plus a written report for each audit 11 | A type 2 report carries management's assertion, the description of the system, the practitioner's report, and tests of controls with results 12 |
| Period | A programme for the full cycle: two-stage initial audit, surveillance in the first and second years after the decision, recertification in the third 13. Surveillance runs at least once a calendar year outside recertification years 14 | A type 1 is fixed to one as-of date 15. A type 2 opines on operating effectiveness throughout a period and describes its tests and results 16 |
Points of focus are not a checklist
Each criterion is followed by points of focus: important characteristics of the criterion, drawn from the COSO framework. They can help management and the practitioner judge whether a control was built right and worked 17. The criteria can be applied without evaluating every point of focus one by one 18.
The 2022 edition revised the points of focus. The revisions did not alter the criteria, which remain suitable for a trust services engagement 19. An organisation mapped against the 2017 text is mapped against the same criteria today.
The crosswalk
A row asserts that a criteria series and the clauses beside it address the same objective, not that meeting one meets the other. The gap column holds the difference.
The criteria are aligned to the 17 COSO principles, with supplemental criteria added under COSO principle 12. Those supplemental criteria are grouped as logical and physical access controls, system operations, change management and risk mitigation 20. Every identifier in the first column is as printed in the criteria table; each theme beside it is paraphrased 21. The third column's clause numbers come from the ISO/IEC 27001:2022 contents 22.
| Criteria series | Theme, paraphrased | ISO/IEC 27001:2022 | ISO/IEC 27002:2022 | Gap for the other product |
|---|---|---|---|---|
| CC1.1 to CC1.5 | Control environment: integrity, board oversight, structures, competence, accountability | 5.1, 5.2, 5.3, 7.2, 7.3 | 5.1 Policies for information security; 5.2 Information security roles and responsibilities; 6.3 Information security awareness, education and training 23 | Oversight evidence in report form |
| CC2.1 to CC2.3 | Information and communication: quality information, internal and external communication | 7 (communication), 7.5 | 5.5 Contact with authorities; 5.37 Documented operating procedures; 6.8 Information security event reporting 24 | Communicating commitments to customers |
| CC3.1 to CC3.4 | Risk assessment: specify objectives, analyse risk, consider fraud, assess change | 6.1.2, 6.1.3, 6.2, 8.2, 8.3 | 5.7 Threat intelligence; 5.8 Information security in project management; 5.9 Inventory of information and other associated assets 25 | Fraud as a named risk factor |
| CC4.1 and CC4.2 | Monitoring: ongoing and separate evaluations, timely communication of deficiencies | 9.1, 9.2, 9.2.2, 9.3 | 5.35 Independent review of information security; 5.36 Compliance with policies, rules and standards for information security 26 | Deficiencies dated inside the period |
| CC5.1 to CC5.3 | Control activities: select and develop them, add general technology controls, deploy through policy | 6.1.3, 8.1, Annex A | 8.9 Configuration management; 5.37 Documented operating procedures 27 | A link from each control to a commitment |
| CC6.1 to CC6.8 | Access: architecture, registration and removal, least privilege, physical entry, disposal, boundary, transfer, malware | 8.1, Annex A | 5.15 Access control; 5.16 Identity management; 5.18 Access rights; 7.2 Physical entry 28 | Dated samples: joiner, leaver, access review |
| CC7.1 to CC7.5 | System operations: detect configuration change and vulnerabilities, monitor anomalies, evaluate events, respond, recover | 8.1, Annex A | 8.8 Management of technical vulnerabilities; 8.16 Monitoring activities; 5.26 Response to information security incidents 29 | Proof the cycle ran at its stated frequency |
| CC8.1 | Change management: authorise, design, configure, document, test, approve, implement changes | 8.1, Annex A | 8.32 Change management; 8.31 Separation of development, test and production environments 30 | A sampled change trail, not a policy |
| CC9.1 and CC9.2 | Risk mitigation: business disruption, and risks from vendors and business partners | 6.1.3, 8.1, Annex A | 5.19 Information security in supplier relationships; 5.21 Managing information security in the ICT supply chain; 5.29 Information security during disruption 31 | A vendor inventory with an assurance date |
| A1.1 to A1.3 | Availability: capacity, environmental protections, backup and recovery infrastructure, recovery testing | 8.1, Annex A | 8.6 Capacity management; 8.13 Information backup; 5.30 ICT readiness for business continuity 32 | Optional category; add it when a contract asks |
| PI1.1 to PI1.5 | Processing integrity: processing objectives, then controls over inputs, processing, output, storage | None direct; operations sit under 8.1 | 8.26 Application security requirements; 8.29 Security testing in development and acceptance 33 | Weakest reuse; specifications are new work |
| C1.1 and C1.2 | Confidentiality: identify and maintain information designated confidential, then dispose of it | 8.1, Annex A | 5.12 Classification of information; 8.10 Information deletion; 6.6 Confidentiality or non-disclosure agreements 34 | What contracts call confidential, not a scheme |
| P1.1 to P8.1 | Privacy: notice, choice and consent, collection, use, retention, disposal, access, disclosure, quality, enforcement | Annex A only | 5.34 Privacy and protection of PII 35 | A privacy management system; the nearest certifiable standard is ISO/IEC 27701:2025 |
Privacy is the one place where the certificate offers no counterpart. Personal information is protected inside the management system, but no ISO 27001 clause states the privacy groupings above; Annex A reaches one PII control.
What a 27001 holder adds for SOC 2
The system description. The certificate's scope statement names an organisation and its locations. The report describes a system, and that description is its own deliverable.
Service commitments and system requirements. In a SOC 2 engagement the objectives are the commitments made to customers and the system requirements. Commitments are what management tells customers a system will do, set out in contracts, service levels or a public statement. System requirements are how the system must function to meet those commitments, applicable law and other business objectives 36. They anchor control design. That wording, to meet the entity's objectives, recurs. In SOC 2 it reads as the service organisation's commitments and system requirements 37.
A period, with evidence at every stated frequency. A type 2 opinion covers operating effectiveness throughout the period, so a quarterly control needs four instances inside it. An annual rhythm rarely produces that density unasked.
The categories decision. Security alone is the working scope for a first report. Each added category brings its own criteria and evidence.
Outcome-shaped controls. The criteria set out the outcomes controls should ordinarily meet, rather than mandating a control set. Each entity sets its own objectives and implements controls to meet them 38. A catalogue built from operations maps onto that shape. A catalogue copied from Annex A does not. The method is in Control ownership and the control catalogue.
What a SOC 2 organisation adds for 27001
The reverse direction builds a management system around controls that already run. Clauses 4 to 10 are the work.
- Context and scope. Clause 4.3 determines the scope of the information security management system 39.
- Leadership. Clause 5.3 assigns organisational roles, responsibilities and authorities 40.
- Risk treatment and the Statement of Applicability. Clause 6.1.2 is the risk assessment, 6.1.3 the treatment, compared against the Annex A reference set 41. The sequence that produces a defensible Statement of Applicability is in Building an ISMS people actually use.
- Competence and documented information. Clause 7.2 covers competence and clause 7.5 documented information 42.
- Internal audit, management review and correction. Clause 9.2 requires a planned internal audit programme with auditors selected so objectivity and impartiality are preserved. Clause 9.3 is the management review and clause 10.2 nonconformity and corrective action 43.
- The certification cycle. The initial audit runs in two stages 44. Stage 2 evaluates the implementation of the management system, effectiveness included, at the organisation's own sites 45. Hosting it is covered in Running the external audit.
Controls that pass an examination do not, on their own, make a management system. The loop above them is what is missing: scope, risk decisions, audit, review, correction.
Sequencing
Three routes. The buyer decides, not the framework.
| Route | When it fits | What it still costs |
|---|---|---|
| Certificate first | Buyers are mostly European, and one artefact has to travel across markets | The description of the system and the period evidence are still ahead |
| Report first | One enterprise deal turns on a questionnaire; the sequence is in The 90-day SOC 2 Type 1 plan | Clauses 4 to 10 are still ahead, and a type 1 report establishes none of them |
| Both in one evidence cycle | Both buyer groups are already in the pipeline and the control set is stable | Two examiners in one year, and one team answering both |
The route that fails is the third, attempted before the controls exist. Choosing a GRC framework sets out which instrument each driver names.
Evidence reuse
One catalogue row, two framework lines: each control carries the reference control numbers it serves and the criteria it answers, and the catalogue stays one list. Reference controls carry attributes that filter, sort or present them in different views, and an organisation may add its own 46. One test, two examiners: the access review performed once is read by the certification body against the clauses and by the practitioner against the criteria. Both methods are in Control ownership and the control catalogue and Running the external audit.
The loop holds here too. Governance sets the commitments and the scope, risk decides which controls exist through clauses 6.1.2 and 6.1.3, and compliance presents that evidence twice. Where an obligation rather than a control is the starting point, From regulation to controls produces the register both products read from.
Reuse breaks in three places.
- Period against cycle. The report covers a fixed window; the certification cycle runs on surveillance and recertification. An access review that satisfies the surveillance audit may fall outside the report period.
- Sampling. The certification body obtains information by appropriate sampling and verifies it as audit evidence 47. A type 2 report describes its tests of controls and their results, which sets a different expectation of density.
- The description. Nothing in the management system produces it, and nothing in the report produces the Statement of Applicability. These two documents are the irreducible extra work in each direction.
Change log
| Date | Change |
|---|---|
| 2026-09-05 | First publication. Every identifier, clause and control read from the sources below. |
References
Primary sources only. Identifiers, paragraph and clause numbers and control titles are cited as printed; every requirement is paraphrased.
- AICPA. 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus – 2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 21
- AICPA & CIMA. SOC 2® — SOC for Service Organizations: Trust Services Criteria. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/ 4
- AICPA & CIMA. Illustrative SOC 2® Report with Illustrative System Description. https://www.aicpa-cima.com/resources/download/illustrative-soc-2-r-report-with-description-and-assertion 12
- AICPA & CIMA. Illustrative Management Representation Letter: SOC 2® Type 1, 31 August 2022. https://www.aicpa-cima.com/resources/download/illustrative-management-representation-letter-soc-2-r-type-1 15
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 22
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. Catalogue entry at https://www.iso.org/standard/75652.html; control numbers, titles and attributes read from a licensed single-user copy 48
- ISO/IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. Catalogue entry at https://www.iso.org/standard/61651.html; clauses read from a licensed single-user copy 49
- ISO/IEC. Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance. ISO/IEC 27701:2025. https://www.iso.org/standard/85819.html 50
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, AICPA or any other standards body.
Sources
- 1ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3, iso.org/obp · verified 2026-09-03
- 2AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), CC3.1 · verified 2026-09-05
- 3iso.org, ISO/IEC 27001:2022 catalogue entry · verified 2026-09-03
- 4AICPA & CIMA, SOC 2 topic page · verified 2026-09-03
- 5ISO/IEC 27001:2022 clause 6.1.3 and Annex A, iso.org/obp · verified 2026-09-03
- 6AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .09 · verified 2026-09-05
- 7AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), paras. .11 and .14 · verified 2026-09-05
- 8ISO/IEC 17021-1:2015 clause 4.2, licensed copy · verified 2026-09-05
- 9ISO/IEC 17021-1:2015 clause 5.2, licensed copy · verified 2026-09-05
- 10AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .25 · verified 2026-09-05
- 11ISO/IEC 17021-1:2015 clause 9.4.8, licensed copy · verified 2026-09-05
- 12AICPA & CIMA, illustrative SOC 2 report · verified 2026-09-03
- 13ISO/IEC 17021-1:2015 clauses 9.1.3.1 and 9.1.3.2, licensed copy · verified 2026-09-05
- 14ISO/IEC 17021-1:2015 clause 9.1.3.3, licensed copy · verified 2026-09-05
- 15AICPA & CIMA, illustrative type 1 representation letter · verified 2026-09-04
- 16AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .16 · verified 2026-09-05
- 17AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .04 · verified 2026-09-05
- 18AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .07 · verified 2026-09-05
- 19AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), Revisions in This Version · verified 2026-09-05
- 20AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .08 · verified 2026-09-05
- 21AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .29 · verified 2026-09-05
- 22ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
- 23ISO/IEC 27002:2022 controls 5.1, 5.2 and 6.3, licensed copy · verified 2026-09-05
- 24ISO/IEC 27002:2022 controls 5.5, 5.37 and 6.8, licensed copy · verified 2026-09-05
- 25ISO/IEC 27002:2022 controls 5.7, 5.8 and 5.9, licensed copy · verified 2026-09-05
- 26ISO/IEC 27002:2022 controls 5.35 and 5.36, licensed copy · verified 2026-09-05
- 27ISO/IEC 27002:2022 controls 8.9 and 5.37, licensed copy · verified 2026-09-05
- 28ISO/IEC 27002:2022 controls 5.15, 5.16, 5.18 and 7.2, licensed copy · verified 2026-09-05
- 29ISO/IEC 27002:2022 controls 8.8, 8.16 and 5.26, licensed copy · verified 2026-09-05
- 30ISO/IEC 27002:2022 controls 8.32 and 8.31, licensed copy · verified 2026-09-05
- 31ISO/IEC 27002:2022 controls 5.19, 5.21 and 5.29, licensed copy · verified 2026-09-05
- 32ISO/IEC 27002:2022 controls 8.6, 8.13 and 5.30, licensed copy · verified 2026-09-05
- 33ISO/IEC 27002:2022 controls 8.26 and 8.29, licensed copy · verified 2026-09-05
- 34ISO/IEC 27002:2022 controls 5.12, 8.10 and 6.6, licensed copy · verified 2026-09-05
- 35ISO/IEC 27002:2022 control 5.34, licensed copy · verified 2026-09-05
- 36AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .19 · verified 2026-09-05
- 37AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), paras. .18 and .21 · verified 2026-09-05
- 38AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .03 · verified 2026-09-05
- 39ISO/IEC 27001:2022 clause 4.3, iso.org/obp · verified 2026-09-03
- 40ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
- 41ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3 and Annex A, iso.org/obp · verified 2026-09-03
- 42ISO/IEC 27001:2022 clauses 7.2 and 7.5, iso.org/obp · verified 2026-09-03
- 43ISO/IEC 27001:2022 clauses 9.2, 9.3 and 10.2, iso.org/obp · verified 2026-09-03
- 44ISO/IEC 17021-1:2015 clause 9.3.1.1, licensed copy · verified 2026-09-05
- 45ISO/IEC 17021-1:2015 clause 9.3.1.3, licensed copy · verified 2026-09-05
- 46ISO/IEC 27002:2022 clause 4.2, licensed copy · verified 2026-09-05
- 47ISO/IEC 17021-1:2015 clause 9.4.4, licensed copy · verified 2026-09-05
- 48ISO/IEC 27002:2022 contents, licensed copy · verified 2026-09-05
- 49ISO/IEC 17021-1:2015 contents, licensed copy · verified 2026-09-05
- 50iso.org, ISO/IEC 27701:2025 catalogue entry · verified 2026-09-03
Related
- The 90-day SOC 2 Type 1 plan
Briefing
- AI use-case triage form
Template
- China–EU regulatory bridge
Reference