SOC 2 vs ISO 27001: which to do first, and what bundling actually saves.
They are not interchangeable
SOC 2 is a CPA-issued attestation under AICPA standards. ISO 27001 is a certification issued by an accredited certification body against an ISO standard. The audiences differ: SOC 2 is the dominant signal in US enterprise sales, ISO 27001 in EU, UK and international B2B. The procedures differ: SOC 2 has Type 1 and Type 2 with an observation window, ISO 27001 has Stage 1 and Stage 2 with a recurring three-year certification cycle.
The control sets overlap substantially. The SOC 2 Common Criteria and ISO 27001 Annex A cover much of the same ground: access control, change management, vendor management, incident response. That is why concurrent programmes are cheaper than sequential ones. How much they overlap is a question without a single answer: published mappings between the two produce very different figures depending on the mapping method and on which direction you map in. So this page describes the overlap and does not quantify it. Any page offering you one confident percentage has chosen it rather than measured it.
The difference that actually matters: cost shape
Most comparisons ask which standard is cheaper. The better question is what each one does to your cash over three years, because the two behave completely differently and neither publishes a fee.
| SOC 2 | ISO 27001 | |
|---|---|---|
| Year 1 weight | Readiness, remediation, then the audit. Lighter scaffolding requirement to get started. | Heavier. The ISMS itself has to exist before Stage 1: risk treatment plan, Statement of Applicability, internal audit, management review. |
| Year 2 and 3 | Full re-audit, every year, against a fresh observation window. There is no surveillance model. | Surveillance audits, which are lighter engagements than the initial certification. |
| The recurring cycle | Annual. Customers expect a report covering the most recent 12 months, and a lapsed report is usually rejected. | Three-year certification cycle, with recertification at the end of it. |
| What this means for budgeting | Flatter and recurring. Easier to forecast, harder to ever stop paying. | Front-loaded, then lighter. The year-1 number is the shock; the later years are the relief. |
Neither column carries fees, and that is deliberate. SOC 2 audit fees are published by no CPA firm, and ISO 27001 certification-body fees are quoted per engagement in the same way. A table of pound figures here would be invention on both sides of it. What is real is the shape, and the shape is often what decides the question: a company on a short runway cares about the year-1 number, and a company planning a three-year compliance budget cares about the curve.
For startups specifically
At startup scale the choice is rarely both at once. Runway and founder attention make one framework first the usual call, and the deciding factor is usually time rather than money. A SOC 2 Type 1 can be in a customer's hands in a quarter. ISO 27001 cannot move that fast from a standing start, because the ISMS scaffolding has to exist before the Stage 1 audit can begin, and building it is most of the year-1 work.
So for a US-leaning startup answering a single deal-blocking customer, SOC 2 first is almost always the faster route, and speed is what is being bought. ISO 27001's main advantage, the lighter surveillance years, matters least to exactly the companies whose plans do not extend three audit cycles ahead. The cost-efficient pattern is SOC 2 first, often Type 1 then Type 2, with ISO 27001 added in year 2 or 3 once international customers turn it into a revenue question. The SOC-2-only startup picture is on the startup cost page.
Where the bundled saving comes from
Running the two together is cheaper than running them twice. The mechanism is real and worth understanding, precisely because the headline percentage attached to it usually is not.
Shared evidence base. Access reviews, change tickets, vendor reviews and incident response logs are collected once and tested against both frameworks. This is the largest part of the saving, and it is the part that evaporates first if the two programmes are run by different teams to different calendars.
Shared readiness. One readiness workstream covers both control sets. The gap log identifies the framework-specific items, but the core work is common.
Dual-purpose policies. Information security, access management, change management, incident response and vendor management policies are written once and apply to both. This is also the most commonly wasted saving, because teams split the policy set by framework and then maintain two of everything.
Single provider relationship. The two reports come from different regimes: a SOC 2 report is issued by a CPA firm licensed by a state board of accountancy and subject to AICPA peer review, and an ISO 27001 certificate is issued by a certification body accredited by a body such as UKAS. Where one provider genuinely covers both, you get one engagement letter, one project manager, one evidence portal. Where the providers differ, the saving is harder to capture.
Which first
| Customer base | Recommended sequence | Why |
|---|---|---|
| US-leaning enterprise SaaS | SOC 2 first, ISO 27001 in year 2 or 3 | SOC 2 is the dominant signal in US procurement. ISO 27001 follows once international expansion is real. |
| EU/UK-leaning B2B | ISO 27001 first, SOC 2 in year 2 | ISO 27001 is the structured ISMS expectation. SOC 2 follows for US customer expansion. |
| Both within 12 months | Concurrent | Maximum saving from shared engagement. Requires a unified readiness workstream and, ideally, one provider able to cover both. |
| Regulated industry (fintech, healthtech) | Often both, sequencing customer-led | Customer contracts force the order. Plan the multi-year programme up front. |
Cross-reference
For the timeline shape on the SOC 2 side, see the timeline page. For why no audit-firm fee table appears anywhere on this site, see the audit firm fees page. For the GRC platform decision in a multi-framework programme, where real published prices do exist and the marginal cost of the second framework is visible, see the GRC platforms page.