SOC 2 or ISO/IEC 27001 for an EU vendor?

Updated 8 min read soc2pentest

This is the most expensive decision in the whole program, and it is usually made on instinct after one customer email. It should be made on the basis of who your next twenty customers will be.

Ask who is asking

SOC 2 and ISO/IEC 27001 are not competing quality levels. They are different products for different audiences, and the audience is the only variable that matters. A US enterprise buyer's vendor review has a field for SOC 2. A German public authority's tender has a field for ISO 27001. Neither will accept the other cheerfully, and neither is impressed by an argument about equivalence.

So before comparing anything, write down who has already asked, who you expect to ask in the next year, and what document each of them named. If the list is American, this guide has a short answer: SOC 2. If it is European public sector or European regulated entities, the answer is equally short and points the other way.

A report and a certificate are different objects

A SOC 2 is an attestation report: an examination performed by a CPA firm under the AICPA's attestation standards, ending in an opinion about controls, restricted to specified parties who understand the system. There is no certificate, and "compliance" is not a term the examination uses at all.

ISO/IEC 27001 certification is the opposite shape. An accredited certification body assesses a management system against a published standard and issues a certificate with a number on it, valid for three years with surveillance in between. The certificate can be shown to anyone, verified against the certification body, and pinned to a tender response.

That difference explains most of the behavior around them. A procurement officer who must document why a supplier was accepted wants a certificate they can attach. A security reviewer at a technology company wants the detail inside a report. Both are being rational.

What European buyers actually write down

This is measurable, so we measured it. Tenders Electronic Daily is the EU's official journal of above-threshold public procurement, and its search API supports full-text queries. Across the 2,301,748 notices published from 1 January 2024 to 13 September 2026:

Full-text mentions in EU public tender notices, 1 January 2024 to 13 September 2026
TermNoticesShare of the ISO 27001 count
ISO 27001 or ISO/IEC 270017,540100%
SOC 21492.0%
ISAE 3402771.0%
SOC 1720.95%
penetration test240.32%
ISAE 3000170.23%
Own measurement against the TED notices search API, expert queries of the form (FT="ISO 27001" OR FT="ISO/IEC 27001") AND (publication-date>=20240101) AND (publication-date<=20260913), reading totalNoticeCount. Download all queries and the count snapshot.

In these searches, the ISO terms appear roughly fifty times more often than SOC 2, and ISAE 3402 appears more often than ISAE 3000. The phrase "penetration test" matches 24 notices across the same date window. These observations describe the chosen search terms; they do not show whether a mention was a requirement, how many buyers it represents, or whether testing was requested using other wording.

Why EU law points at the ISO standard

The pattern in the tender data has a legislative echo. Commission Implementing Regulation (EU) 2024/2690, which sets the technical and methodological requirements for cybersecurity risk-management measures under NIS2 for digital infrastructure and digital providers, states in recital (3) that those requirements "are based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401, and technical specifications, such as CEN/TS 18026:2024".

No SOC report appears anywhere in that instrument. If your customers are European entities inside the NIS2 perimeter, the document that maps cleanly onto their own obligations is the ISO certificate. The same regulation, at Annex point 5.1.4, tells them to write "the right to audit or right to receive audit reports" into your contract – so a report of some kind is still coming, but the certificate is what gets your name past the first filter.

Where SOC 2 wins, decisively

None of the above means SOC 2 is the weaker product. In the market it was built for it is close to unavoidable.

  • US enterprise procurement asks for SOC 2 by name, and a vendor review that lists it will not be satisfied by an ISO certificate without an argument you will not win before quarter end.
  • A SOC 2 type 2 says something an ISO certificate does not: that controls operated effectively over a period, tested by sampling. A certificate says the management system conforms; the operating detail is not in the reader's hands.
  • The report contains the detail a technical reviewer wants – the system description, the control list, the tests performed and their results. That is why it closes reviews that a one-page certificate cannot.
  • ISO/IEC 27001 certification carries a management-system overhead that a twelve-person company genuinely feels: scope statement, risk methodology, statement of applicability, internal audit, management review. SOC 2 has less ceremony around the edges.

Cost and calendar shape

The two have different rhythms, and the rhythm matters more than the headline price.

A SOC 2 type 2 runs on an annual cycle: an observation window, an examination, a report dated at the end of it, then the next window opens. The report ages visibly. A customer looking at a report dated fourteen months ago will ask about the gap, so the cycle is effectively continuous once you start.

ISO/IEC 27001 runs on a three-year certification cycle with annual surveillance audits and a recertification at the end. The certificate does not age in the same visible way, but the surveillance visits are real, and losing certification between cycles is more damaging than a late report.

ISO/IEC 27001 has also become very common, which cuts both ways: it is well understood, and it no longer differentiates. The ISO Survey of certifications recorded 96,709 valid ISO/IEC 27001 certificates across 179,877 sites for 2024, up from 47,291 certificates and 89,541 sites the year before – growth of over 100% in a single year.

What carries over

Whichever you start with, a large part of the work is the same work, which is why sequencing matters more than choosing.

  • Access control, logging, change management, vendor management and incident response are evidenced almost identically for both.
  • A risk assessment is required by both, though ISO/IEC 27001 is far more prescriptive about how it is documented.
  • Security awareness training, and the record that it happened, is common ground.
  • One penetration test, scoped to the production platform, serves both: as evidence for the SOC 2 criteria and as evidence for the ISO control set covering technical vulnerabilities and security testing.
  • What does not carry over is the paperwork layer: the ISO statement of applicability and management review on one side, the SOC 2 system description and management assertion on the other.

A realistic rule of thumb: the second framework costs perhaps half of the first, and the shared half is the technical half.

Neither of them is a GDPR answer

This needs saying because customers conflate the three constantly. Data protection certification under the GDPR comes from a certification body accredited by the supervisory authority or the national accreditation body under Article 43(1), and even then, under Article 42(4), a certification "does not reduce the responsibility of the controller or the processor for compliance with this Regulation". A SOC 2 report is not a GDPR certification and neither is an ISO/IEC 27001 certificate.

What both can do is help you discharge two specific obligations. Article 32(1)(d) requires "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing" – and it binds the processor as well as the controller. Article 28(3)(h) requires the processor to "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller". A report or a certificate is usually how a supplier makes that second obligation survivable at scale, because the alternative is hosting inspections.

The order that usually works

For a European vendor with a mixed pipeline, the sequence that wastes least is:

  1. Fix the technical baseline first, because it is common to both and because everything else is documentation about it: multi-factor authentication on privileged access, centralized logging, access reviews with a record, change control, and an independent penetration test with retest evidence.
  2. Take whichever document your named, dated pipeline actually demands. A blocked deal beats a strategic preference every time.
  3. Add the second framework in the following cycle, reusing the technical evidence and writing only the new paperwork layer.

Note that the first item is not "pick a framework". It is the part you would do anyway, it produces evidence usable by both, and it is the only part that actually reduces risk rather than describing it.

When the honest answer is "neither, yet"

If nobody has asked, do not start. A SOC 2 program run speculatively costs six to nine months of engineering attention and produces a document with a date on it that will be stale before the first customer asks to see it. The same is true of certification.

What is worth doing before anyone asks is the technical baseline and one penetration test, because those hold their value regardless of which document you eventually buy, and because they are what the first serious customer questionnaire will actually probe. The readiness gap finder lists the evidence each choice implies, and does SOC 2 require a penetration test? covers where the testing expectation comes from in the first place.

Sources

  1. TED notices search API Publications Office of the European Union · 2026 Search API documentation. The table links to the exact queries and count snapshot for 1 January 2024 to 13 September 2026.
  2. Commission Implementing Regulation (EU) 2024/2690 EUR-Lex · 2024 Recital (3) on ISO/IEC 27001 and ISO/IEC 27002 as the basis of the requirements; Annex point 5.1.4 on supplier contract terms.
  3. Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex · 2016 Article 32(1)(d), Article 28(3)(h), Article 42(4) and Article 43(1) on accredited certification bodies.
  4. ISO Survey of certifications 2024 ISO · 2025 ISO/IEC 27001:2013 and 2022: 96,709 valid certificates and 179,877 sites in 2024, against 47,291 and 89,541 in 2023. Read from the published survey PDF; iso.org blocks automated access.
  5. ISO/IEC 27001 – Information security management systems ISO The standard's catalog entry. Certification is issued by an accredited certification body, not by a consultant.
  6. Promises of 'fast and easy' threaten SOC credibility Journal of Accountancy · 2026 SOC reports as CPA examinations, restricted use, and "compliance" as a term never used in SOC 2 examinations.

Questions

Related questions

Can we map an ISO/IEC 27001 certificate onto SOC 2 and skip the examination?

No. The control coverage overlaps substantially, so a certified organization is usually much closer to ready, but a SOC 2 report only exists once a CPA firm has performed the examination. A crosswalk shortens the work; it does not replace the opinion.

Which one do European investors and acquirers ask for?

It follows the buyer's own market rather than geography. A European fund whose portfolio sells into the United States will ask about SOC 2; one selling into European public sector will ask about ISO/IEC 27001. Ask them, rather than guessing.

Is ISO/IEC 27001 cheaper?

Not obviously, and the comparison is unstable because the cost is dominated by how far your controls already are from either target. The clearer difference is shape: certification is a three-year cycle with annual surveillance, a SOC 2 type 2 is an annual report that visibly ages.

Do we need both?

Only if your pipeline genuinely spans both markets. Where it does, the second one costs materially less than the first because the technical evidence is shared. Where it does not, the second document is a document nobody asked for.