Back to insights
    Reference

    ISO 27001 to SOC 2: one control set, two reports

    One control set can serve both, but a certificate and an attestation report differ in object, criteria, examiner, output and period.

    Compliance5 Sept 202613 min read

    2017 Trust Services Criteria (With Revised Points of Focus – 2022)ISO/IEC 17021-1:2015ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 27701:2025
    On this page

    What this is

    An organisation holds one of the two products and a buyer asks for the other. A certificate holder meets North American buyers who file attestation reports; a SOC 2 organisation meets European buyers who want the certificate. One control set can serve both, and the products are still not interchangeable.

    They differ in five ways that decide the work: what is examined, against which criteria, by whom, what comes out, and over what period. This page sets out those differences, then crosswalks the criteria to the clauses and controls a management system already carries. The crosswalk is GRCIDE's. No mapping published by the criteria's author is claimed or implied here. Choosing a GRC framework defines the attestation report assumed here.

    Three disciplines meet in that crosswalk, as one loop rather than three teams. Governance decides what the organisation promises: service commitments and system requirements on the report side, the management system scope and objectives on the certificate side. Risk decides which controls exist and why: the risk assessment at clause 6.1.2 and the treatment decision at clause 6.1.3 1. On the report side, one criteria series asks for objectives clear enough that their risks can be identified 2. Compliance produces the two reports from the same evidence.

    The two products side by side

    A row means the two products answer the same question differently, not that either satisfies the other.

    ISO/IEC 27001:2022 certificationSOC 2 examination
    ObjectThe management system, audited against a requirements standard 3Controls at a service organisation, read against security, availability, processing integrity, confidentiality or privacy 4
    CriteriaClauses 4 to 10, plus the controls chosen at 6.1.3 and recorded against the Annex A reference set 5Criteria common to all five categories, plus additional specific criteria for availability, processing integrity, confidentiality and privacy 6
    CategoriesOne scope statement, no modulesAny category alone or combined. Security is addressed in most engagements, and the common criteria alone suit it 7
    ExaminerA certification body, deciding on objective evidence rather than other interests 8 and undertaking conformity assessment impartially 9A CPA firm; the criteria document calls the examiner the practitioner 10
    OutputA certificate with a defined scope 3, plus a written report for each audit 11A type 2 report carries management's assertion, the description of the system, the practitioner's report, and tests of controls with results 12
    PeriodA programme for the full cycle: two-stage initial audit, surveillance in the first and second years after the decision, recertification in the third 13. Surveillance runs at least once a calendar year outside recertification years 14A type 1 is fixed to one as-of date 15. A type 2 opines on operating effectiveness throughout a period and describes its tests and results 16

    Points of focus are not a checklist

    Each criterion is followed by points of focus: important characteristics of the criterion, drawn from the COSO framework. They can help management and the practitioner judge whether a control was built right and worked 17. The criteria can be applied without evaluating every point of focus one by one 18.

    The 2022 edition revised the points of focus. The revisions did not alter the criteria, which remain suitable for a trust services engagement 19. An organisation mapped against the 2017 text is mapped against the same criteria today.

    The crosswalk

    A row asserts that a criteria series and the clauses beside it address the same objective, not that meeting one meets the other. The gap column holds the difference.

    The criteria are aligned to the 17 COSO principles, with supplemental criteria added under COSO principle 12. Those supplemental criteria are grouped as logical and physical access controls, system operations, change management and risk mitigation 20. Every identifier in the first column is as printed in the criteria table; each theme beside it is paraphrased 21. The third column's clause numbers come from the ISO/IEC 27001:2022 contents 22.

    Criteria seriesTheme, paraphrasedISO/IEC 27001:2022ISO/IEC 27002:2022Gap for the other product
    CC1.1 to CC1.5Control environment: integrity, board oversight, structures, competence, accountability5.1, 5.2, 5.3, 7.2, 7.35.1 Policies for information security; 5.2 Information security roles and responsibilities; 6.3 Information security awareness, education and training 23Oversight evidence in report form
    CC2.1 to CC2.3Information and communication: quality information, internal and external communication7 (communication), 7.55.5 Contact with authorities; 5.37 Documented operating procedures; 6.8 Information security event reporting 24Communicating commitments to customers
    CC3.1 to CC3.4Risk assessment: specify objectives, analyse risk, consider fraud, assess change6.1.2, 6.1.3, 6.2, 8.2, 8.35.7 Threat intelligence; 5.8 Information security in project management; 5.9 Inventory of information and other associated assets 25Fraud as a named risk factor
    CC4.1 and CC4.2Monitoring: ongoing and separate evaluations, timely communication of deficiencies9.1, 9.2, 9.2.2, 9.35.35 Independent review of information security; 5.36 Compliance with policies, rules and standards for information security 26Deficiencies dated inside the period
    CC5.1 to CC5.3Control activities: select and develop them, add general technology controls, deploy through policy6.1.3, 8.1, Annex A8.9 Configuration management; 5.37 Documented operating procedures 27A link from each control to a commitment
    CC6.1 to CC6.8Access: architecture, registration and removal, least privilege, physical entry, disposal, boundary, transfer, malware8.1, Annex A5.15 Access control; 5.16 Identity management; 5.18 Access rights; 7.2 Physical entry 28Dated samples: joiner, leaver, access review
    CC7.1 to CC7.5System operations: detect configuration change and vulnerabilities, monitor anomalies, evaluate events, respond, recover8.1, Annex A8.8 Management of technical vulnerabilities; 8.16 Monitoring activities; 5.26 Response to information security incidents 29Proof the cycle ran at its stated frequency
    CC8.1Change management: authorise, design, configure, document, test, approve, implement changes8.1, Annex A8.32 Change management; 8.31 Separation of development, test and production environments 30A sampled change trail, not a policy
    CC9.1 and CC9.2Risk mitigation: business disruption, and risks from vendors and business partners6.1.3, 8.1, Annex A5.19 Information security in supplier relationships; 5.21 Managing information security in the ICT supply chain; 5.29 Information security during disruption 31A vendor inventory with an assurance date
    A1.1 to A1.3Availability: capacity, environmental protections, backup and recovery infrastructure, recovery testing8.1, Annex A8.6 Capacity management; 8.13 Information backup; 5.30 ICT readiness for business continuity 32Optional category; add it when a contract asks
    PI1.1 to PI1.5Processing integrity: processing objectives, then controls over inputs, processing, output, storageNone direct; operations sit under 8.18.26 Application security requirements; 8.29 Security testing in development and acceptance 33Weakest reuse; specifications are new work
    C1.1 and C1.2Confidentiality: identify and maintain information designated confidential, then dispose of it8.1, Annex A5.12 Classification of information; 8.10 Information deletion; 6.6 Confidentiality or non-disclosure agreements 34What contracts call confidential, not a scheme
    P1.1 to P8.1Privacy: notice, choice and consent, collection, use, retention, disposal, access, disclosure, quality, enforcementAnnex A only5.34 Privacy and protection of PII 35A privacy management system; the nearest certifiable standard is ISO/IEC 27701:2025

    Privacy is the one place where the certificate offers no counterpart. Personal information is protected inside the management system, but no ISO 27001 clause states the privacy groupings above; Annex A reaches one PII control.

    What a 27001 holder adds for SOC 2

    The system description. The certificate's scope statement names an organisation and its locations. The report describes a system, and that description is its own deliverable.

    Service commitments and system requirements. In a SOC 2 engagement the objectives are the commitments made to customers and the system requirements. Commitments are what management tells customers a system will do, set out in contracts, service levels or a public statement. System requirements are how the system must function to meet those commitments, applicable law and other business objectives 36. They anchor control design. That wording, to meet the entity's objectives, recurs. In SOC 2 it reads as the service organisation's commitments and system requirements 37.

    A period, with evidence at every stated frequency. A type 2 opinion covers operating effectiveness throughout the period, so a quarterly control needs four instances inside it. An annual rhythm rarely produces that density unasked.

    The categories decision. Security alone is the working scope for a first report. Each added category brings its own criteria and evidence.

    Outcome-shaped controls. The criteria set out the outcomes controls should ordinarily meet, rather than mandating a control set. Each entity sets its own objectives and implements controls to meet them 38. A catalogue built from operations maps onto that shape. A catalogue copied from Annex A does not. The method is in Control ownership and the control catalogue.

    What a SOC 2 organisation adds for 27001

    The reverse direction builds a management system around controls that already run. Clauses 4 to 10 are the work.

    • Context and scope. Clause 4.3 determines the scope of the information security management system 39.
    • Leadership. Clause 5.3 assigns organisational roles, responsibilities and authorities 40.
    • Risk treatment and the Statement of Applicability. Clause 6.1.2 is the risk assessment, 6.1.3 the treatment, compared against the Annex A reference set 41. The sequence that produces a defensible Statement of Applicability is in Building an ISMS people actually use.
    • Competence and documented information. Clause 7.2 covers competence and clause 7.5 documented information 42.
    • Internal audit, management review and correction. Clause 9.2 requires a planned internal audit programme with auditors selected so objectivity and impartiality are preserved. Clause 9.3 is the management review and clause 10.2 nonconformity and corrective action 43.
    • The certification cycle. The initial audit runs in two stages 44. Stage 2 evaluates the implementation of the management system, effectiveness included, at the organisation's own sites 45. Hosting it is covered in Running the external audit.

    Controls that pass an examination do not, on their own, make a management system. The loop above them is what is missing: scope, risk decisions, audit, review, correction.

    Sequencing

    Three routes. The buyer decides, not the framework.

    RouteWhen it fitsWhat it still costs
    Certificate firstBuyers are mostly European, and one artefact has to travel across marketsThe description of the system and the period evidence are still ahead
    Report firstOne enterprise deal turns on a questionnaire; the sequence is in The 90-day SOC 2 Type 1 planClauses 4 to 10 are still ahead, and a type 1 report establishes none of them
    Both in one evidence cycleBoth buyer groups are already in the pipeline and the control set is stableTwo examiners in one year, and one team answering both

    The route that fails is the third, attempted before the controls exist. Choosing a GRC framework sets out which instrument each driver names.

    Evidence reuse

    One catalogue row, two framework lines: each control carries the reference control numbers it serves and the criteria it answers, and the catalogue stays one list. Reference controls carry attributes that filter, sort or present them in different views, and an organisation may add its own 46. One test, two examiners: the access review performed once is read by the certification body against the clauses and by the practitioner against the criteria. Both methods are in Control ownership and the control catalogue and Running the external audit.

    The loop holds here too. Governance sets the commitments and the scope, risk decides which controls exist through clauses 6.1.2 and 6.1.3, and compliance presents that evidence twice. Where an obligation rather than a control is the starting point, From regulation to controls produces the register both products read from.

    Reuse breaks in three places.

    • Period against cycle. The report covers a fixed window; the certification cycle runs on surveillance and recertification. An access review that satisfies the surveillance audit may fall outside the report period.
    • Sampling. The certification body obtains information by appropriate sampling and verifies it as audit evidence 47. A type 2 report describes its tests of controls and their results, which sets a different expectation of density.
    • The description. Nothing in the management system produces it, and nothing in the report produces the Statement of Applicability. These two documents are the irreducible extra work in each direction.

    Change log

    DateChange
    2026-09-05First publication. Every identifier, clause and control read from the sources below.

    References

    Primary sources only. Identifiers, paragraph and clause numbers and control titles are cited as printed; every requirement is paraphrased.

    1. AICPA. 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus – 2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 21
    2. AICPA & CIMA. SOC 2® — SOC for Service Organizations: Trust Services Criteria. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/ 4
    3. AICPA & CIMA. Illustrative SOC 2® Report with Illustrative System Description. https://www.aicpa-cima.com/resources/download/illustrative-soc-2-r-report-with-description-and-assertion 12
    4. AICPA & CIMA. Illustrative Management Representation Letter: SOC 2® Type 1, 31 August 2022. https://www.aicpa-cima.com/resources/download/illustrative-management-representation-letter-soc-2-r-type-1 15
    5. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 22
    6. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. Catalogue entry at https://www.iso.org/standard/75652.html; control numbers, titles and attributes read from a licensed single-user copy 48
    7. ISO/IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. Catalogue entry at https://www.iso.org/standard/61651.html; clauses read from a licensed single-user copy 49
    8. ISO/IEC. Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance. ISO/IEC 27701:2025. https://www.iso.org/standard/85819.html 50

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, AICPA or any other standards body.

    Sources

    1. 1ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3, iso.org/obp · verified 2026-09-03
    2. 2AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), CC3.1 · verified 2026-09-05
    3. 3iso.org, ISO/IEC 27001:2022 catalogue entry · verified 2026-09-03
    4. 4AICPA & CIMA, SOC 2 topic page · verified 2026-09-03
    5. 5ISO/IEC 27001:2022 clause 6.1.3 and Annex A, iso.org/obp · verified 2026-09-03
    6. 6AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .09 · verified 2026-09-05
    7. 7AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), paras. .11 and .14 · verified 2026-09-05
    8. 8ISO/IEC 17021-1:2015 clause 4.2, licensed copy · verified 2026-09-05
    9. 9ISO/IEC 17021-1:2015 clause 5.2, licensed copy · verified 2026-09-05
    10. 10AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .25 · verified 2026-09-05
    11. 11ISO/IEC 17021-1:2015 clause 9.4.8, licensed copy · verified 2026-09-05
    12. 12AICPA & CIMA, illustrative SOC 2 report · verified 2026-09-03
    13. 13ISO/IEC 17021-1:2015 clauses 9.1.3.1 and 9.1.3.2, licensed copy · verified 2026-09-05
    14. 14ISO/IEC 17021-1:2015 clause 9.1.3.3, licensed copy · verified 2026-09-05
    15. 15AICPA & CIMA, illustrative type 1 representation letter · verified 2026-09-04
    16. 16AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .16 · verified 2026-09-05
    17. 17AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .04 · verified 2026-09-05
    18. 18AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .07 · verified 2026-09-05
    19. 19AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), Revisions in This Version · verified 2026-09-05
    20. 20AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .08 · verified 2026-09-05
    21. 21AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .29 · verified 2026-09-05
    22. 22ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
    23. 23ISO/IEC 27002:2022 controls 5.1, 5.2 and 6.3, licensed copy · verified 2026-09-05
    24. 24ISO/IEC 27002:2022 controls 5.5, 5.37 and 6.8, licensed copy · verified 2026-09-05
    25. 25ISO/IEC 27002:2022 controls 5.7, 5.8 and 5.9, licensed copy · verified 2026-09-05
    26. 26ISO/IEC 27002:2022 controls 5.35 and 5.36, licensed copy · verified 2026-09-05
    27. 27ISO/IEC 27002:2022 controls 8.9 and 5.37, licensed copy · verified 2026-09-05
    28. 28ISO/IEC 27002:2022 controls 5.15, 5.16, 5.18 and 7.2, licensed copy · verified 2026-09-05
    29. 29ISO/IEC 27002:2022 controls 8.8, 8.16 and 5.26, licensed copy · verified 2026-09-05
    30. 30ISO/IEC 27002:2022 controls 8.32 and 8.31, licensed copy · verified 2026-09-05
    31. 31ISO/IEC 27002:2022 controls 5.19, 5.21 and 5.29, licensed copy · verified 2026-09-05
    32. 32ISO/IEC 27002:2022 controls 8.6, 8.13 and 5.30, licensed copy · verified 2026-09-05
    33. 33ISO/IEC 27002:2022 controls 8.26 and 8.29, licensed copy · verified 2026-09-05
    34. 34ISO/IEC 27002:2022 controls 5.12, 8.10 and 6.6, licensed copy · verified 2026-09-05
    35. 35ISO/IEC 27002:2022 control 5.34, licensed copy · verified 2026-09-05
    36. 36AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .19 · verified 2026-09-05
    37. 37AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), paras. .18 and .21 · verified 2026-09-05
    38. 38AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), para. .03 · verified 2026-09-05
    39. 39ISO/IEC 27001:2022 clause 4.3, iso.org/obp · verified 2026-09-03
    40. 40ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    41. 41ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3 and Annex A, iso.org/obp · verified 2026-09-03
    42. 42ISO/IEC 27001:2022 clauses 7.2 and 7.5, iso.org/obp · verified 2026-09-03
    43. 43ISO/IEC 27001:2022 clauses 9.2, 9.3 and 10.2, iso.org/obp · verified 2026-09-03
    44. 44ISO/IEC 17021-1:2015 clause 9.3.1.1, licensed copy · verified 2026-09-05
    45. 45ISO/IEC 17021-1:2015 clause 9.3.1.3, licensed copy · verified 2026-09-05
    46. 46ISO/IEC 27002:2022 clause 4.2, licensed copy · verified 2026-09-05
    47. 47ISO/IEC 17021-1:2015 clause 9.4.4, licensed copy · verified 2026-09-05
    48. 48ISO/IEC 27002:2022 contents, licensed copy · verified 2026-09-05
    49. 49ISO/IEC 17021-1:2015 contents, licensed copy · verified 2026-09-05
    50. 50iso.org, ISO/IEC 27701:2025 catalogue entry · verified 2026-09-03