SOC 2 now, ISO 27001 next: planning your second framework
Much of the control work for SOC 2 carries over to ISO 27001, but ISO 27001 adds a formal information security management system and a certification audit by an accredited certification body. If a second framework is likely within a year, choose a tool that cross-maps controls and plan the SOC 2 scope with that in mind.
Startups that sell to international customers, or into regulated sectors, often find that SOC 2 is the first framework but not the last. Planning for the second one early is cheaper than retrofitting.
How is ISO 27001 different from SOC 2?
SOC 2 is an attestation report by a CPA firm on your controls against the Trust Services Criteria. ISO/IEC 27001 is an international standard for information security management systems; companies are certified against it by certification bodies. The current edition, ISO/IEC 27001:2022, is Edition 3, published in October 2022, and iso.org lists the standard at CHF 155. ISO 27001 asks for a management system around the controls: a defined scope, risk assessment and treatment, a Statement of Applicability, internal audit and management review.
What carries over from SOC 2?
Access control, change management, logging, incident response, vendor management, backups, training and many policies. If your SOC 2 policies are written well, many can be extended rather than rewritten. Evidence collected by your compliance tool can count toward both, if the tool maps one control to both frameworks.
Which tools state cross-mapping or large framework libraries?
Scytale states 80+ security, privacy and AI frameworks with control cross-mapping, and lists ISO 27001, ISO 27701, ISO 42001 and others. Vanta states 35+ frameworks including ISO 27001, ISO 42001, NIS2 and DORA. Secureframe lists ISO 27001:2022 among a broad framework set. Thoropass lists ISO 27001 and HITRUST. Comp AI quotes ISO 27001, ISO 42001 and ISO 9001 among twelve frameworks. On our room-to-grow criterion, Scytale leads at 4.6.
When should the second framework start?
After the first SOC 2 report, or at least after readiness is complete. Running both for the first time in parallel doubles the learning curve. A common pattern is SOC 2 in year one and ISO 27001 in year two, using the first year's controls as the base.
What about HIPAA, GDPR and ISO 42001?
HIPAA applies when you handle protected health information for US healthcare customers; GDPR applies to personal data of people in the EU; ISO/IEC 42001 is a management system standard for AI. All five tools in this guide list at least some of these. Check the tool's framework page by name before buying.
How should the first SOC 2 scope anticipate ISO 27001?
Write the SOC 2 scope so it can grow. If ISO 27001 will cover the whole company later, avoid a SOC 2 scope so narrow that half the controls must be rebuilt. Keep a risk register from the start, even though SOC 2 asks only for a risk assessment, because ISO 27001 builds on one. Record management reviews of security in writing. None of this adds much work in year one, and it shortens year two.
Sources
- ISO/IEC 27001:2022 at iso.orgSource: iso.org · Read 2026-09-29
- Scytale frameworksSource: scytale.ai · Read 2026-09-29
- Vanta frameworksSource: vanta.com · Read 2026-09-29
- Secureframe frameworksSource: secureframe.com · Read 2026-09-29
- Thoropass homepageSource: thoropass.com · Read 2026-09-29
- Comp AI pricingSource: trycomp.ai · Read 2026-09-29
- AICPA SOC suite of servicesSource: aicpa-cima.com · Read 2026-09-29
Questions founders ask
Should a startup do SOC 2 or ISO 27001 first?
Ask your customers. Buyers of business software often ask for SOC 2; international buyers often ask for ISO 27001.
How much does the ISO 27001 standard cost?
The standard document itself is listed at CHF 155 on iso.org. Certification audit fees are separate and set by the certification body.