Guides

ISO 27001 + SOC 2 combined programs

One control set, one evidence effort, two credentials — how companies that need both sequence the work without paying twice.

Why combine

The frameworks overlap heavily: access control, logging and monitoring, incident response, vendor management, change management, and risk assessment all produce evidence that serves both. A combined program builds the control set once and runs two audits against it — typically 30–50% cheaper than two separate programs (planning logic, not a measured average).

Sequencing

  1. Build one control set mapped to both ISO 27001 Annex A and the SOC 2 Trust Services Criteria. A control matrix is the core artifact.
  2. Collect evidence once with both frameworks' sampling in mind — SOC 2 Type 2 needs evidence across its observation period; ISO 27001 Stage 2 needs evidence the ISMS operates.
  3. Run ISO 27001 Stage 1 early — its documentation review validates your control design before the SOC 2 observation period locks in.
  4. Schedule the audits adjacently so one evidence-collection effort feeds both, with different firms: an accredited CB for ISO 27001, a licensed CPA firm for SOC 2.

Who does what

WorkstreamWho
Control design & implementationYou, a consultant, or a platform
ISO 27001 Stage 1 + Stage 2Accredited certification body
SOC 2 Type 2Licensed CPA firm

A few firms hold both credentials — verify each one separately (accreditation for ISO 27001, CPA license for SOC 2) before assuming one engagement covers both. CBs in our directory with SOC 2 overlap include BARR Advisory, Schellman, A-LIGN, and Prescient.

Plan a combined program

Get scoped quotes for ISO 27001 — and ask shortlisted CBs about combined-program experience. Free, 2 minutes.

Get a free quote