From ISO 27001 to SOC 2
Already ISO 27001 Certified? Get the SOC 2 Report Your US Buyers Ask For
Your ISMS passed an accredited certification audit, and a US customer still wants a SOC 2 report before it signs. Auditsuisse, a licensed US CPA firm enrolled in the AICPA Peer Review program, issues that Type I or Type II report and reuses your ISO 27001 evidence wherever it addresses a Trust Services Criterion.
Why a US Buyer Asks for SOC 2 When You Already Hold ISO 27001
US enterprise buyers ask for SOC 2 by name, and contract addenda often specify a Type II. ISO 27001 is what European and multinational enterprises ask for in the same way, so US-first companies usually do SOC 2 first and add ISO 27001 later for European deals; companies based outside the United States often arrive in the opposite order.
An ISO 27001 certificate does not substitute for a SOC 2 report in that review: the buyer wants a different document — an independent auditor's opinion on your controls against the AICPA's Trust Services Criteria, with a system description and test results. The certificate does give you a head start, because much of what the auditor needs already exists.
Certification vs Attestation: What Actually Changes
A certification such as ISO 27001 is issued by an accredited certification body that audits your ISMS against the standard and declares that you meet it. The outcome is pass or fail; the deliverable is a certificate, typically valid for three years with annual surveillance audits, that buyers can verify in a public registry.
A SOC 2 report is an attestation that only a licensed CPA firm can issue, under the AICPA's attestation standards (SSAE 18). It contains the auditor's opinion, management's assertion, a description of your system, the controls in scope and the result of every test. The opinion is unqualified, qualified or adverse; the report is confidential, shared under NDA and renewed annually. "SOC 2 certified" is therefore a misnomer: your customer receives a SOC 2 Type I or Type II report.
What Carries Over From Your ISO 27001 Program
A certified ISMS has already produced much of what a SOC 2 auditor asks for. Documentation and evidence you maintain for ISO 27001 can be reused wherever it addresses a Trust Services Criterion — the objectives listed in full in our SOC 2 controls list. Four groups carry over most often:
- Policies and governance records — policy set, roles and responsibilities, management review minutes and training records (CC1, CC2, CC5).
- Risk assessments — methodology, risk register and treatment plan (CC3); supplier reviews for vendor risk (CC9).
- Access reviews — provisioning approvals, periodic access reviews and deprovisioning records (CC6).
- Change management records — change tickets, approvals, test evidence and release records (CC8).
We map the overlap at scoping, walking through your Statement of Applicability and evidence against the Security Trust Services Criteria to agree what we can accept as it stands, what needs a SOC 2-specific form (for example, evidence dated inside a Type II observation period) and what SOC 2 requires that ISO 27001 does not, starting with the system description. We do not quote a percentage of reuse in advance.
Beyond the Certificate
What the SOC 2 Report Adds
The Auditor's Opinion
An independent opinion from a licensed US CPA firm on whether your controls meet the Security Trust Services Criteria — the Common Criteria (CC1–CC9) in every SOC 2 report — with every test and result, including exceptions. Availability, Confidentiality, Processing Integrity and Privacy can be added and are quoted at scoping.
Type I or Type II
A Type I covers control design as of a single date. A Type II covers design and operating effectiveness over a 3–12 month observation period, tested against dated evidence from that window. Most enterprise buyers ultimately require a Type II; see our Type I vs Type II guide.
The System Description
Management's description of the system in scope — infrastructure, software, people, processes, data, system boundary and subservice organizations such as your cloud provider — written to the AICPA's Description Criteria. Your ISO 27001 scope statement and Statement of Applicability are inputs; the description itself is a SOC 2 deliverable.
Price and Timeline
We publish our standard fees. Scoped to the Security Trust Services Category, a SOC 2 Type I costs $3,000 to $10,000, a Type II $5,000 to $15,000 and a combined Type I + Type II engagement $7,000 to $20,000, by headcount from 1 to 999 employees; larger organizations receive a custom quote. The full schedule is on our SOC 2 pricing page. The fee is the same on any GRC platform or none, and holding ISO 27001 neither raises nor lowers it.
These are base prices for standard engagements: fees may be higher for complex products or system descriptions, multi-cloud environments or on-premise infrastructure, each engagement may be priced higher or lower at scoping, and your fee is confirmed in the engagement letter.
A SOC 2 Type I takes about 4–8 weeks of fieldwork and reporting, roughly 3–6 months in total including readiness. A Type II takes roughly 6–15 months in total, including a 3–12 month observation period during which your controls must operate and produce dated evidence. An existing ISO 27001 program changes the readiness and remediation stretch, not the observation period: Type II evidence cannot be created retroactively. See our SOC 2 timeline guide for each phase.
How to Start
Book a 30-minute scoping call. We confirm scope, headcount tier and whether you need a Type I, a Type II or both, and take a first look at your ISO 27001 documentation. Every engagement requires individual approval and confirmation of auditor independence before an engagement letter is issued. The engagement then runs in four phases:
- Discovery — we map your systems and in-scope services and define the Trust Services Categories for your report.
- Readiness — gap analysis against every applicable criterion, with the ISO 27001 evidence mapping agreed before fieldwork.
- Fieldwork — remote or on-site evidence collection, walkthroughs and control testing with a senior auditor from day one.
- Delivery — the final SOC 2 report and management letter.
Engagements run in English, German, French or Italian for European teams and in English, Spanish or Portuguese in Latin America; see also our page on SOC 2 audits for international companies.
ISO 27001 to SOC 2 FAQ
Does ISO 27001 replace SOC 2 for US customers?
Usually not. US buyers ask for SOC 2 by name because their vendor security review is built around the SOC 2 report: a licensed CPA firm's opinion on your controls against the AICPA Trust Services Criteria, with a system description and test results. An ISO 27001 certificate is a different deliverable and, if the request names SOC 2, will not satisfy it.
Can we reuse our ISO 27001 evidence for SOC 2?
Yes, where it addresses a Trust Services Criterion. Policies, risk assessments, access reviews and change management records maintained for ISO 27001 are the evidence a SOC 2 auditor requests; we map them to the Security Trust Services Criteria at scoping. Some evidence needs a SOC 2-specific form, such as dated evidence from a Type II observation period, and the system description has no ISO 27001 equivalent. We do not promise a percentage of reuse in advance.
How much does SOC 2 cost if we already have ISO 27001?
The published schedule applies: $3,000 to $10,000 for a Type I, $5,000 to $15,000 for a Type II and $7,000 to $20,000 for a combined engagement, by headcount from 1 to 999 employees for the Security Trust Services Category; larger companies receive a custom quote. These are base prices for standard engagements, confirmed at scoping and in the engagement letter. Holding ISO 27001 does not change the fee; where it helps is the readiness work on your side.
How long does SOC 2 take if we already hold ISO 27001?
A SOC 2 Type I takes about 4 to 8 weeks of fieldwork and reporting, roughly 3 to 6 months in total including readiness. A Type II takes roughly 6 to 15 months in total, including a 3 to 12 month observation period during which your controls must operate and produce dated evidence. ISO 27001 can reduce readiness and remediation but does not shorten the observation period.
Should we get a Type I or a Type II first?
Read your customer's security addendum first. If it requires a Type II, a Type I will not close the deal; start the observation period as soon as your controls are operating. Otherwise the combined engagement delivers a Type I report first and the Type II observation period starts immediately afterwards. Because the controls in a certified ISMS are already operating, that period can often start without a long remediation phase.
Can one firm handle both ISO 27001 and SOC 2?
Not in the sense of one firm issuing both documents. An ISO 27001 certificate is issued by an accredited certification body; a SOC 2 report can only be issued by a licensed CPA firm. Auditsuisse issues SOC 1 and SOC 2 reports, with ISAE 3402 dual reporting available, and does not issue ISO 27001 certificates. We work alongside your certification body, mapping your ISMS evidence to the Trust Services Criteria.
Get Started
Get the SOC 2 Report Your Buyer Asked For
A 30-minute scoping call confirms scope, timeline and fee and starts mapping your ISO 27001 evidence to the Trust Services Criteria.