← All insights

SOC 2 · ISO 27001

SOC 2 vs ISO 27001: which one a UK SaaS should actually pursue.

The answer depends less on the standards themselves and more on where the next twenty enterprise deals are likely to come from.

The buyer signal each one sends

SOC 2 and ISO 27001 are both legitimate, well-respected security assurance artefacts. They are not interchangeable in the eyes of buyers. A SOC 2 Type 2 report tells a US enterprise procurement team that an AICPA-licensed CPA firm has observed your controls in operation over a defined window. An ISO 27001 certificate tells a UK, EU or international buyer that a UKAS-accredited body has certified your management system against a globally recognised standard.

The mistake UK SaaS founders make most often is choosing on cost or speed alone. The right question is which artefact your top twenty target accounts actually ask for in their security questionnaire — because that is the one that unblocks revenue.

Side-by-side comparison

What it is
SOC 2

An AICPA attestation report issued by a US CPA firm. Type 1 covers design; Type 2 covers operating effectiveness over a defined window.

ISO 27001

A management-system certification issued by a UKAS-accredited body against an international standard.

Who recognises it
SOC 2

US enterprise buyers, particularly mid-market tech. Patchy recognition in EU, UK public sector, and regulated industries.

ISO 27001

Globally recognised. The default in UK, EU, Middle East and APAC procurement. Increasingly accepted in the US.

Cost (year one)
SOC 2

Roughly £25,000 to £60,000 including audit, depending on Trust Services Criteria scope.

ISO 27001

Roughly £15,000 to £45,000 including audit fees, for a small-to-mid organisation.

Cost (ongoing)
SOC 2

Fresh audit every year — audit fees recur in full annually.

ISO 27001

Annual surveillance audits (smaller and cheaper) for years two and three, full recertification in year three.

Time to a usable artefact
SOC 2

SOC 2 Type 1 in two to three months. Type 2 requires an additional three- to twelve-month observation window.

ISO 27001

Three to six months to a Stage 2 certificate that holds for three years.

Scope flexibility
SOC 2

Auditee chooses which Trust Services Criteria apply — Security is mandatory, the rest are optional.

ISO 27001

Scope is defined by the organisation but the standard's clauses and Annex A controls all apply.

UK and EU procurement reality

In the UK and EU, ISO 27001 is the default. Public-sector tenders ask for it by name. Regulated buyers in finance, health and energy expect it as table stakes. GDPR-driven due diligence increasingly looks for ISO 27001 with the 27701 privacy extension. A SOC 2 report alone in these markets is not rejected, but it almost always triggers a follow-up question.

That asymmetry matters for sequencing. For a UK SaaS selling primarily into UK and European enterprises, ISO 27001 is the certificate that opens doors first. SOC 2 becomes a useful addition once US enterprise revenue starts to dominate the pipeline.

US procurement reality

US enterprise buyers split. Large regulated US enterprises — banks, insurers, healthcare systems — usually accept ISO 27001 as equivalent or preferable. US mid-market tech buyers, particularly those who themselves hold SOC 2, often still default to asking for a SOC 2 report by name. They will accept ISO 27001 with explanation, but the path of least resistance is the SOC 2 artefact they recognise.

For a UK SaaS with meaningful US ambition, the realistic answer is both — ISO 27001 first for global reach, SOC 2 Type 2 added once the cost is justified by deal flow. Done in that order, the second certificate reuses roughly 80 percent of the control work from the first.

Decision matrix by buyer mix

  1. Mostly UK and EU revenue

    ISO 27001 is the clear default. SOC 2 adds cost and audit overhead without meaningfully changing buyer behaviour.

  2. Mostly US mid-market tech revenue

    SOC 2 Type 2 is the artefact buyers actually ask for. ISO 27001 is the cleaner foundation if you can afford the timeline.

  3. Mixed UK / EU / US enterprise revenue

    ISO 27001 first, SOC 2 Type 2 added in year two. The second certificate is roughly 50 percent of the cost of the first because the controls overlap.

  4. Regulated industries (finance, health, public sector)

    ISO 27001 — and increasingly 27701 alongside it — is the answer regardless of geography. SOC 2 rarely satisfies the regulatory test on its own.

What carries over if you add the other

Roughly 80 percent of the underlying control work overlaps. Access management, change control, vendor management, incident response, encryption, logging and monitoring all evidence both. The genuinely incremental work when adding SOC 2 to an existing ISMS is the Trust Services Criteria mapping, the observation-period evidence collection, and the CPA firm's document requests — significant but far short of a second full programme.

Going the other way — adding ISO 27001 to an existing SOC 2 — the new work is mostly clause-level management-system requirements: leadership engagement, formal risk assessment methodology, internal audit and management review rhythms, and the Statement of Applicability. Most SOC 2-mature organisations get to Stage 2 in three to four months.

Next step

Map it to your pipeline

A short scoping call will tell you which certificate unblocks the most revenue first, and the realistic cost and timeline to add the other if and when it earns its keep.