Skip to content
SecuriFii

Choosing

Running ISO 27001 and SOC 2 concurrently, in practice

That the controls overlap is the easy part and widely known. The saving is realised or lost in how you sequence the work, and in resisting the urge to merge two things that genuinely are different.

Facts checked2026-09-11

How do you run ISO 27001 and SOC 2 at once?

Start the SOC 2 observation window first. It is the only element of either programme that elapsed time alone can satisfy, so the window should be running while you build the ISO management system rather than after it. Teams that finish the ISMS first and then start the clock add months for no reason.

Design each control once, with one evidence trail, and map it to both sets of requirements — access control, change management, logging, supplier management, incident response, HR security, encryption. One access review producing one dated record satisfies an Annex A control and a common criterion simultaneously. Two parallel processes producing two records is the failure this is meant to avoid, and it happens whenever the two programmes have different owners who do not meet.

Keep the assessment artefacts separate, because they are genuinely different documents doing different jobs. The Statement of Applicability justifies control selection against risk; the SOC 2 system description describes the service and its boundaries to a reader. Neither substitutes for the other, and attempting to write one document that serves both produces something that satisfies neither auditor.

The bottom line

One control set and one evidence store, two assessment tracks, and the observation window started early. The saving is real and it is lost the moment the two programmes are run by people who are not talking to each other.

Related insights