Book a Security Assessment letstalk@networklondon.co.uk · London Bridge
Compliance

Who needs SOC 2?
And what about ISO 27001?

By Cyber Security London · · 2 min read

In short

SOC 2 is a US attestation report, most often requested by American customers of software and service companies. ISO 27001 is the international certifiable standard and is more widely recognised in the UK and Europe. Cyber Essentials is the UK government-backed baseline. Most UK businesses start with Cyber Essentials, then choose ISO 27001 or SOC 2 depending on their customers.

How do SOC 2, ISO 27001 and Cyber Essentials compare?

Cyber EssentialsISO 27001SOC 2
What it isUK government-backed certification of five technical controlsInternational standard for an information security management systemUS attestation report against the AICPA Trust Services Criteria
OutcomeCertificateCertificateAuditor's report (Type 1 or Type 2)
Who assessesLicensed certification bodyAccredited certification bodyLicensed CPA firm
ScopeTechnical baselinePeople, process and technology, risk-basedControls relevant to the services you provide
Typically asked for byUK public sector and supply chainsUK, European and international clientsUS customers, especially of SaaS and tech services
EffortLowHighHigh

Who actually needs SOC 2?

SOC 2 matters most if you sell software or technology services to US companies, because their procurement teams often expect a SOC 2 report. For a UK business selling mainly in the UK and Europe, ISO 27001 is usually the more recognised choice.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses the design of your controls at a single point in time. A Type 2 report tests whether those controls operated effectively over a period, usually several months. Customers generally prefer Type 2.

Where should a UK business start?

  1. Cyber Essentials to get the technical basics right and certified.
  2. ISO 27001 if UK or European clients ask for a recognised management standard.
  3. SOC 2 if US customers specifically require it.

The work overlaps a great deal, so controls built for ISO 27001 support a later SOC 2 report.

Frequently asked questions

No. SOC 2 is an attestation report written by an independent CPA firm. ISO 27001 and Cyber Essentials are certifications.

Yes, ISO 27001 is recognised internationally, though some US customers still ask for SOC 2 specifically.

Yes. Many controls overlap, so building one system that serves both reduces the total effort.

Sources

  1. ISO/IEC 27001:2022, International Organization for Standardization
  2. SOC 2, AICPA & CIMA
  3. Cyber Essentials, National Cyber Security Centre
Contact

Start with
an assessment.

Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.

Studio

The Leather Market
London Bridge

Dealing with a live incident? Put “urgent” in your message or email letstalk@networklondon.co.uk. We use your details only to reply, see our privacy notice.