Skip to content
Xavi Creus

Security & compliance

SOC 2 and ISO 27001

SOC 2 and ISO 27001 are the two leading security certifications a software company obtains to prove to customers that its data controls are audited.

Definition

SOC 2 and ISO 27001 are the two most recognised frameworks for demonstrating that a company manages information security properly. SOC 2, created by the American Institute of Certified Public Accountants, results in an auditor's report on a company's controls over security, availability, confidentiality, processing integrity and privacy. ISO 27001 is an international standard for an information security management system, and results in a certificate after an accredited audit. Both are independent evidence that you do what you say.

In a company that sells software, SOC 2 and ISO 27001 are the answer to the security questionnaire that every enterprise buyer sends. Without one of them, procurement stalls or demands weeks of custom evidence. SOC 2 is the default expectation in the United States, ISO 27001 in Europe and Asia, and many SaaS companies hold both. Getting there means writing policies, implementing controls such as access reviews and encryption, collecting evidence over months and passing an external audit, then repeating annually.

The current version of the ISO standard is ISO/IEC 27001:2022, and certificates issued against the older 2013 edition became invalid after the transition deadline of 31 October 2025. The misconception is that certification equals security. It proves controls exist and are followed, not that the product is unhackable, and a company can be certified and still get breached. Compliance automation platforms have cut the cost and time significantly, making it realistic for companies with 20 employees to certify.

In practice

A SaaS company lost two enterprise deals in a year to the question "do you have SOC 2 or ISO 27001?". It certified over the following nine months with a compliance platform and a part-time consultant, and the next security questionnaire took an afternoon instead of a month.

Why it matters

SOC 2 and ISO 27001 are the price of admission to enterprise contracts if you sell software, and a reasonable filter when you buy it. Start the process before you need it; it takes six to twelve months, and a lost deal costs more than the audit.

Frequently asked questions

What is the difference between SOC 2 and ISO 27001?
SOC 2 is a US audit framework that produces a detailed report on your controls, most often requested by American customers. ISO 27001 is an international standard that certifies your security management system, more common in Europe and Asia. They overlap heavily, and many companies do both using shared evidence.
How long does it take to get SOC 2 or ISO 27001?
Typically 6 to 12 months for a first certification, depending on how mature your controls already are. A SOC 2 Type II report requires observing controls over a period of usually 3 to 12 months. Compliance automation platforms shorten evidence collection, but policies, access reviews and training still need to be genuinely in place.

Need this explained for your company?

One hour with me is usually enough to turn the vocabulary into a decision.

Book a session