Skip to content
Decision guideVerified October 2026

SOC 2 or ISO 27001 First? A Decision Guide for NZ and Australian Companies

SOC 2 or ISO 27001: which should a New Zealand or Australian company do first? The buyer signals that decide it, how the two differ in output, timeline and cost of upkeep, and how to build one control set that serves both.

By Krish Pasumarthi, Founder, CybrGenCRISC, CDPSE, ISO/IEC 42001 Lead Auditor

weeks to SOC 2 Type I
12weeks to SOC 2 Type I
months to ISO 27001
6months to ISO 27001
control set for both
1control set for both
buyer signals
7buyer signals
Start here

Let your buyers decide

Neither framework is better in general. The right first choice is whichever your pipeline asks for. Read down the signals and count which way they point.

Buyer signals and which framework each points to
Most of your pipeline is US companies, or US-headquartered enterprisesSOC 2 first
Security questionnaires ask for a SOC 2 report by nameSOC 2 first
You need a credible answer within a quarterSOC 2 Type I, in about 12 weeks with a tight scope
You bid for government work or tenders that score certificationISO 27001 first
Your buyers are mainly in the UK, Europe or AsiaISO 27001 first
You want a credential you can publish on your website and in proposalsISO 27001, since the certificate is public
Your customers are APRA-regulated or similarEither. They will assess you under CPS 234 and CPS 230 regardless, and accept both as evidence.

Ask your top five prospects which they need. Their answer outweighs any general advice, including this page.

Side by side

How SOC 2 and ISO 27001 differ

Comparison of SOC 2 and ISO/IEC 27001
What it isSOC 2 is an attestation report against the AICPA Trust Services Criteria. ISO 27001 is a certifiable standard for an information security management system.
Who issues itSOC 2: an independent licensed CPA firm. ISO 27001: an accredited certification body, typically accredited by JAS-ANZ in New Zealand and Australia.
What you receiveSOC 2: a detailed report, usually shared under NDA. ISO 27001: a public certificate, with the Statement of Applicability shared on request.
FocusSOC 2 tests whether specific controls are designed and, for Type II, operate over a period. ISO 27001 tests the management system that selects and runs controls, plus a sample of the controls.
Time to first resultSOC 2 Type I: about 12 weeks with a tight scope. ISO 27001: about six months for a focused SME.
Ongoing cycleSOC 2 Type II reports are typically renewed every year. ISO 27001 runs a three-year certificate cycle with annual surveillance audits.
OverlapMost SOC 2 security controls land on ISO 27001 Annex A. ISO 27001 adds risk treatment, the Statement of Applicability, internal audit and management review.
Doing both

One control set, two reports

Most growing NZ and Australian SaaS companies end up needing both. The efficient order looks like this.

  1. Step 1

    Phase 1: Build one control set

    1. 1.Scope once, using the boundary both frameworks will share
    2. 2.Run one risk assessment that satisfies ISO 27001 clause 6 and SOC 2 CC3
    3. 3.Design each control once and map it to both frameworks

    Exit criteria

    One control model with owners and evidence sources, mapped to both.

  2. Step 2

    Phase 2: Deliver what buyers ask for first

    1. 1.SOC 2 Type I, or ISO 27001 Stage 1 and Stage 2
    2. 2.Collect evidence in one system of record
    3. 3.Start the operating rhythm: reviews, scans, training, monitoring

    Exit criteria

    The first report or certificate in hand, and controls already running.

  3. Step 3

    Phase 3: Extend to the second

    1. 1.ISO 27001: add the management system clauses, SoA, internal audit and management review
    2. 2.SOC 2: add the system description and engage a CPA firm
    3. 3.Align audit calendars so evidence serves both

    Exit criteria

    Both frameworks from one control set, with one annual calendar.

From the field

Mistakes when choosing

  • Choosing on reputation, not pipeline

    The framework your competitors have matters less than the one your next five buyers ask for.

  • Running them as two projects

    Separate control sets, separate evidence and separate owners double the effort and drift apart within a year.

  • Assuming one replaces the other

    Some buyers accept either, many do not. Ask before you assume your ISO certificate will satisfy a US buyer, or the reverse.

  • Forgetting the upkeep

    Both require operating evidence every year. Budget for the running cost, not just the first audit.

FAQ

Questions we get asked

Is SOC 2 or ISO 27001 better?

Neither is better in general. SOC 2 is usually expected by US buyers; ISO 27001 is usually preferred in the UK, Europe, Asia and public sector tenders. Choose the one your pipeline asks for first, and design one control set that maps to both.

Which is faster, SOC 2 or ISO 27001?

A SOC 2 Type I report can be reached in about 12 weeks with a tight scope. ISO 27001 certification typically takes about six months for a focused SME because the management system must operate and be internally audited before certification.

Does ISO 27001 cover SOC 2?

Not on its own. Most SOC 2 security controls map to ISO 27001 Annex A, but a SOC 2 report must still be issued by a CPA firm after testing your controls against the Trust Services Criteria. An ISO 27001 ISMS makes that much faster.

Can we do SOC 2 and ISO 27001 at the same time?

Yes, and with one control set it is efficient. Many companies deliver whichever their buyers need first, then extend to the second within six to twelve months.

Which do New Zealand government agencies want?

Agencies assess suppliers against their own requirements, such as NZISM and the Protective Security Requirements. ISO 27001 certification is commonly recognised in tenders, and either framework supports, but does not replace, the agency's own assessment.

Not sure which your buyers need?

A 30-minute conversation is usually enough to decide. CybrGen designs one control set that serves SOC 2, ISO 27001 and the other frameworks your customers ask for, so the second report is an extension, not a new project.