Choosing
Running ISO 27001 and SOC 2 concurrently, in practice
That the controls overlap is the easy part and widely known. The saving is realised or lost in how you sequence the work, and in resisting the urge to merge two things that genuinely are different.
Facts checked — 2026-09-11
How do you run ISO 27001 and SOC 2 at once?
Start the SOC 2 observation window first. It is the only element of either programme that elapsed time alone can satisfy, so the window should be running while you build the ISO management system rather than after it. Teams that finish the ISMS first and then start the clock add months for no reason.
Design each control once, with one evidence trail, and map it to both sets of requirements — access control, change management, logging, supplier management, incident response, HR security, encryption. One access review producing one dated record satisfies an Annex A control and a common criterion simultaneously. Two parallel processes producing two records is the failure this is meant to avoid, and it happens whenever the two programmes have different owners who do not meet.
Keep the assessment artefacts separate, because they are genuinely different documents doing different jobs. The Statement of Applicability justifies control selection against risk; the SOC 2 system description describes the service and its boundaries to a reader. Neither substitutes for the other, and attempting to write one document that serves both produces something that satisfies neither auditor.
The bottom line
One control set and one evidence store, two assessment tracks, and the observation window started early. The saving is real and it is lost the moment the two programmes are run by people who are not talking to each other.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.
Choosing
SOC 2 or ISO 27001 first? A commercial question wearing a technical costume
Your pipeline decides this, not the frameworks — and the two produce very different things to hand a customer.
Choosing
Accredited and unaccredited certification are not the same product
Both produce a certificate. Only one carries independent oversight of the auditor — and it is checkable.