# Who needs SOC 2? And what about ISO 27001?

> SOC 2, ISO 27001 or Cyber Essentials? Who needs each, how they differ, and which suits a UK business, in one comparison table.

Canonical: https://cybersecuritylondon.com/who-needs-soc2-compliance


By Cyber Security London, published 8 October 2026.

**In short:** SOC 2 is a US attestation report, most often requested by American customers of software and service companies. ISO 27001 is the international certifiable standard and is more widely recognised in the UK and Europe. Cyber Essentials is the UK government-backed baseline. Most UK businesses start with Cyber Essentials, then choose ISO 27001 or SOC 2 depending on their customers.

## How do SOC 2, ISO 27001 and Cyber Essentials compare?

|  | Cyber Essentials | ISO 27001 | SOC 2 |
| --- | --- | --- | --- |
| What it is | UK government-backed certification of five technical controls | International standard for an information security management system | US attestation report against the AICPA Trust Services Criteria |
| Outcome | Certificate | Certificate | Auditor's report (Type 1 or Type 2) |
| Who assesses | Licensed certification body | Accredited certification body | Licensed CPA firm |
| Scope | Technical baseline | People, process and technology, risk-based | Controls relevant to the services you provide |
| Typically asked for by | UK public sector and supply chains | UK, European and international clients | US customers, especially of SaaS and tech services |
| Effort | Low | High | High |

## Who actually needs SOC 2?

SOC 2 matters most if you sell software or technology services to US companies, because their procurement teams often expect a SOC 2 report. For a UK business selling mainly in the UK and Europe, ISO 27001 is usually the more recognised choice.

## What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses the design of your controls at a single point in time. A Type 2 report tests whether those controls operated effectively over a period, usually several months. Customers generally prefer Type 2.

## Where should a UK business start?

1. **Cyber Essentials** to get the technical basics right and certified.
2. **ISO 27001** if UK or European clients ask for a recognised management standard.
3. **SOC 2** if US customers specifically require it.

The work overlaps a great deal, so controls built for ISO 27001 support a later SOC 2 report.

## Frequently asked questions

### Is SOC 2 a certification?

No. SOC 2 is an attestation report written by an independent CPA firm. ISO 27001 and Cyber Essentials are certifications.

### Is ISO 27001 recognised in the US?

Yes, ISO 27001 is recognised internationally, though some US customers still ask for SOC 2 specifically.

### Can I do ISO 27001 and SOC 2 together?

Yes. Many controls overlap, so building one system that serves both reduces the total effort.

## Sources

- [ISO/IEC 27001:2022, International Organization for Standardization](https://www.iso.org/standard/27001)
- [SOC 2, AICPA & CIMA](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2)
- [Cyber Essentials, National Cyber Security Centre](https://www.ncsc.gov.uk/cyberessentials/overview)

## How we can help

- [ISO 27001](https://cybersecuritylondon.com/iso-27001)
- [Cyber Essentials](https://cybersecuritylondon.com/cyber-essentials)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
