Independent reference.Not affiliated with the AICPA or any audit firm.See methodology.
Pillar / Budget sanity check (multi-standard)

SOC 2 vs ISO 27001: which to do first, and what bundling actually saves.

They are not interchangeable. SOC 2 is an attestation, ISO 27001 is a certification, and they are issued by different kinds of organisation under different rules. They overlap heavily in the controls they look at, which is why running both as one programme costs less than running them twice. This page sets out the difference in cost shape, the order that suits each market, and why the confident bundle-saving percentages are not to be trusted.
Section 01

They are not interchangeable

SOC 2 is a CPA-issued attestation under AICPA standards. ISO 27001 is a certification issued by an accredited certification body against an ISO standard. The audiences differ: SOC 2 is the dominant signal in US enterprise sales, ISO 27001 in EU, UK and international B2B. The procedures differ: SOC 2 has Type 1 and Type 2 with an observation window, ISO 27001 has Stage 1 and Stage 2 with a recurring three-year certification cycle.

The control sets overlap substantially. The SOC 2 Common Criteria and ISO 27001 Annex A cover much of the same ground: access control, change management, vendor management, incident response. That is why concurrent programmes are cheaper than sequential ones. How much they overlap is a question without a single answer: published mappings between the two produce very different figures depending on the mapping method and on which direction you map in. So this page describes the overlap and does not quantify it. Any page offering you one confident percentage has chosen it rather than measured it.

Section 02

The difference that actually matters: cost shape

Most comparisons ask which standard is cheaper. The better question is what each one does to your cash over three years, because the two behave completely differently and neither publishes a fee.

How each standard's cost behaves over a three-year horizon
SOC 2ISO 27001
Year 1 weightReadiness, remediation, then the audit. Lighter scaffolding requirement to get started.Heavier. The ISMS itself has to exist before Stage 1: risk treatment plan, Statement of Applicability, internal audit, management review.
Year 2 and 3Full re-audit, every year, against a fresh observation window. There is no surveillance model.Surveillance audits, which are lighter engagements than the initial certification.
The recurring cycleAnnual. Customers expect a report covering the most recent 12 months, and a lapsed report is usually rejected.Three-year certification cycle, with recertification at the end of it.
What this means for budgetingFlatter and recurring. Easier to forecast, harder to ever stop paying.Front-loaded, then lighter. The year-1 number is the shock; the later years are the relief.

Neither column carries fees, and that is deliberate. SOC 2 audit fees are published by no CPA firm, and ISO 27001 certification-body fees are quoted per engagement in the same way. A table of pound figures here would be invention on both sides of it. What is real is the shape, and the shape is often what decides the question: a company on a short runway cares about the year-1 number, and a company planning a three-year compliance budget cares about the curve.

Section 03

For startups specifically

At startup scale the choice is rarely both at once. Runway and founder attention make one framework first the usual call, and the deciding factor is usually time rather than money. A SOC 2 Type 1 can be in a customer's hands in a quarter. ISO 27001 cannot move that fast from a standing start, because the ISMS scaffolding has to exist before the Stage 1 audit can begin, and building it is most of the year-1 work.

So for a US-leaning startup answering a single deal-blocking customer, SOC 2 first is almost always the faster route, and speed is what is being bought. ISO 27001's main advantage, the lighter surveillance years, matters least to exactly the companies whose plans do not extend three audit cycles ahead. The cost-efficient pattern is SOC 2 first, often Type 1 then Type 2, with ISO 27001 added in year 2 or 3 once international customers turn it into a revenue question. The SOC-2-only startup picture is on the startup cost page.

Section 04

Where the bundled saving comes from

Running the two together is cheaper than running them twice. The mechanism is real and worth understanding, precisely because the headline percentage attached to it usually is not.

Shared evidence base. Access reviews, change tickets, vendor reviews and incident response logs are collected once and tested against both frameworks. This is the largest part of the saving, and it is the part that evaporates first if the two programmes are run by different teams to different calendars.

Shared readiness. One readiness workstream covers both control sets. The gap log identifies the framework-specific items, but the core work is common.

Dual-purpose policies. Information security, access management, change management, incident response and vendor management policies are written once and apply to both. This is also the most commonly wasted saving, because teams split the policy set by framework and then maintain two of everything.

Single provider relationship. The two reports come from different regimes: a SOC 2 report is issued by a CPA firm licensed by a state board of accountancy and subject to AICPA peer review, and an ISO 27001 certificate is issued by a certification body accredited by a body such as UKAS. Where one provider genuinely covers both, you get one engagement letter, one project manager, one evidence portal. Where the providers differ, the saving is harder to capture.

Section 05

Which first

Customer baseRecommended sequenceWhy
US-leaning enterprise SaaSSOC 2 first, ISO 27001 in year 2 or 3SOC 2 is the dominant signal in US procurement. ISO 27001 follows once international expansion is real.
EU/UK-leaning B2BISO 27001 first, SOC 2 in year 2ISO 27001 is the structured ISMS expectation. SOC 2 follows for US customer expansion.
Both within 12 monthsConcurrentMaximum saving from shared engagement. Requires a unified readiness workstream and, ideally, one provider able to cover both.
Regulated industry (fintech, healthtech)Often both, sequencing customer-ledCustomer contracts force the order. Plan the multi-year programme up front.

Cross-reference

For the timeline shape on the SOC 2 side, see the timeline page. For why no audit-firm fee table appears anywhere on this site, see the audit firm fees page. For the GRC platform decision in a multi-framework programme, where real published prices do exist and the marginal cost of the second framework is visible, see the GRC platforms page.

Section 06

FAQ

Should I get SOC 2 or ISO 27001 first?+
US-leaning customer base, fast first report needed: SOC 2 first. EU, UK or international customer base, or a structured ISMS culture: ISO 27001 first. Both within 12 months: run them concurrently as a single programme. The choice is mostly market-driven rather than framework-driven, because the question being answered is which signal your buyers are actually asking for.
How much do you save running SOC 2 and ISO 27001 together?+
Less than the round numbers in circulation suggest, and nobody publishes the real figure. The mechanism is genuine: the control sets overlap heavily, so evidence collected once can be tested against both, one readiness workstream covers both, and policies are written once. The saving is real to the extent that the overlap is actually exploited, which requires one programme, one readiness effort, and ideally one provider. Two engagements merely running at the same time save nothing.
Is ISO 27001 cheaper than SOC 2?+
The interesting difference is shape, not total. ISO 27001 runs a three-year certification cycle with lighter surveillance audits in the intervening years. SOC 2 has no surveillance audit at all: every year is a full re-audit of a fresh observation window. So ISO 27001 front-loads more of its cost into year 1 building the ISMS scaffolding, and SOC 2 spreads a flatter, recurring cost. Which is cheaper for you depends on your scope and how many years you are budgeting for, and neither standard's fees are published.
Can the same firm do both?+
The two reports sit under different regimes, so check before you assume it. A SOC 2 report must be issued by a CPA firm, licensed by a state board of accountancy and subject to AICPA peer review. An ISO 27001 certificate must be issued by a certification body accredited by a national accreditation body such as UKAS, and under ISO/IEC 17021-1 a certification body cannot also consult on the management system it certifies. Ask any firm claiming both to name the CPA licence and the accredited certification body behind each engagement. Where a single provider genuinely covers both, the shared-evidence saving is easier to capture.
Which should a startup do first?+
For a US-leaning startup answering a deal-blocking customer, SOC 2 first is the usual call, and the reason is timing as much as money: a Type 1 can be in hand in a quarter, where ISO 27001 needs the ISMS scaffolding (risk treatment plan, Statement of Applicability, internal audit, management review) to exist before the Stage 1 audit can even start. ISO 27001's cheaper surveillance years are a real advantage that matters little to a company whose plans do not extend three audit cycles ahead.

Updated 2026-07-15