SOC 2 or ISO 27001 First? A Decision Guide for NZ and Australian Companies
SOC 2 or ISO 27001: which should a New Zealand or Australian company do first? The buyer signals that decide it, how the two differ in output, timeline and cost of upkeep, and how to build one control set that serves both.
By Krish Pasumarthi, Founder, CybrGenCRISC, CDPSE, ISO/IEC 42001 Lead Auditor
- weeks to SOC 2 Type I
- 12weeks to SOC 2 Type I
- months to ISO 27001
- 6months to ISO 27001
- control set for both
- 1control set for both
- buyer signals
- 7buyer signals
Let your buyers decide
Neither framework is better in general. The right first choice is whichever your pipeline asks for. Read down the signals and count which way they point.
| If this is true of your business | It points to |
|---|---|
| Most of your pipeline is US companies, or US-headquartered enterprises | SOC 2 first |
| Security questionnaires ask for a SOC 2 report by name | SOC 2 first |
| You need a credible answer within a quarter | SOC 2 Type I, in about 12 weeks with a tight scope |
| You bid for government work or tenders that score certification | ISO 27001 first |
| Your buyers are mainly in the UK, Europe or Asia | ISO 27001 first |
| You want a credential you can publish on your website and in proposals | ISO 27001, since the certificate is public |
| Your customers are APRA-regulated or similar | Either. They will assess you under CPS 234 and CPS 230 regardless, and accept both as evidence. |
Ask your top five prospects which they need. Their answer outweighs any general advice, including this page.
How SOC 2 and ISO 27001 differ
| Area | SOC 2 compared with ISO 27001 |
|---|---|
| What it is | SOC 2 is an attestation report against the AICPA Trust Services Criteria. ISO 27001 is a certifiable standard for an information security management system. |
| Who issues it | SOC 2: an independent licensed CPA firm. ISO 27001: an accredited certification body, typically accredited by JAS-ANZ in New Zealand and Australia. |
| What you receive | SOC 2: a detailed report, usually shared under NDA. ISO 27001: a public certificate, with the Statement of Applicability shared on request. |
| Focus | SOC 2 tests whether specific controls are designed and, for Type II, operate over a period. ISO 27001 tests the management system that selects and runs controls, plus a sample of the controls. |
| Time to first result | SOC 2 Type I: about 12 weeks with a tight scope. ISO 27001: about six months for a focused SME. |
| Ongoing cycle | SOC 2 Type II reports are typically renewed every year. ISO 27001 runs a three-year certificate cycle with annual surveillance audits. |
| Overlap | Most SOC 2 security controls land on ISO 27001 Annex A. ISO 27001 adds risk treatment, the Statement of Applicability, internal audit and management review. |
One control set, two reports
Most growing NZ and Australian SaaS companies end up needing both. The efficient order looks like this.
Step 1
Phase 1: Build one control set
- 1.Scope once, using the boundary both frameworks will share
- 2.Run one risk assessment that satisfies ISO 27001 clause 6 and SOC 2 CC3
- 3.Design each control once and map it to both frameworks
Exit criteria
One control model with owners and evidence sources, mapped to both.
Step 2
Phase 2: Deliver what buyers ask for first
- 1.SOC 2 Type I, or ISO 27001 Stage 1 and Stage 2
- 2.Collect evidence in one system of record
- 3.Start the operating rhythm: reviews, scans, training, monitoring
Exit criteria
The first report or certificate in hand, and controls already running.
Step 3
Phase 3: Extend to the second
- 1.ISO 27001: add the management system clauses, SoA, internal audit and management review
- 2.SOC 2: add the system description and engage a CPA firm
- 3.Align audit calendars so evidence serves both
Exit criteria
Both frameworks from one control set, with one annual calendar.
Mistakes when choosing
Choosing on reputation, not pipeline
The framework your competitors have matters less than the one your next five buyers ask for.
Running them as two projects
Separate control sets, separate evidence and separate owners double the effort and drift apart within a year.
Assuming one replaces the other
Some buyers accept either, many do not. Ask before you assume your ISO certificate will satisfy a US buyer, or the reverse.
Forgetting the upkeep
Both require operating evidence every year. Budget for the running cost, not just the first audit.
Questions we get asked
Is SOC 2 or ISO 27001 better?
Neither is better in general. SOC 2 is usually expected by US buyers; ISO 27001 is usually preferred in the UK, Europe, Asia and public sector tenders. Choose the one your pipeline asks for first, and design one control set that maps to both.
Which is faster, SOC 2 or ISO 27001?
A SOC 2 Type I report can be reached in about 12 weeks with a tight scope. ISO 27001 certification typically takes about six months for a focused SME because the management system must operate and be internally audited before certification.
Does ISO 27001 cover SOC 2?
Not on its own. Most SOC 2 security controls map to ISO 27001 Annex A, but a SOC 2 report must still be issued by a CPA firm after testing your controls against the Trust Services Criteria. An ISO 27001 ISMS makes that much faster.
Can we do SOC 2 and ISO 27001 at the same time?
Yes, and with one control set it is efficient. Many companies deliver whichever their buyers need first, then extend to the second within six to twelve months.
Which do New Zealand government agencies want?
Agencies assess suppliers against their own requirements, such as NZISM and the Protective Security Requirements. ISO 27001 certification is commonly recognised in tenders, and either framework supports, but does not replace, the agency's own assessment.
Not sure which your buyers need?
A 30-minute conversation is usually enough to decide. CybrGen designs one control set that serves SOC 2, ISO 27001 and the other frameworks your customers ask for, so the second report is an extension, not a new project.