Skip to main content

SOC 2 vs ISO 27001: the honest comparison for Australian companies

Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026

ISO 27001 and SOC 2 answer the same question — can we trust you with our data? — for two different audiences, in two different formats. One is a certification, the other an attestation.

The short answer

ISO 27001 is a certification; SOC 2 is an attestation report. Ask your buyer which one they want before you spend a dollar on either. Australian government, PSPF-aligned and most European and APAC buyers ask for ISO 27001. United States buyers ask for SOC 2.

At the control level the two overlap heavily — commonly put at 60 to 80 percent. What does not overlap is the management system. ISO 27001 requires a documented ISMS with a risk assessment, a Statement of Applicability, an internal audit and a management review. SOC 2 requires none of that; it examines whether the controls you claim to have are designed properly and operating. If you need both, do ISO 27001 first in most cases — its ISMS gives you the governance layer SOC 2 assumes you already run.

Certification vs attestation — the difference that matters

ISO 27001 is certified. An accredited certification body — in Australia, one accredited by JAS-ANZ — audits your ISMS in two stages and issues a certificate valid for three years, with surveillance audits in years one and two. The certificate is short and publicly verifiable on the certification body register.

SOC 2 is attested. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report — often 40 to 100 pages, containing the auditor's opinion, your system description, every control tested, and any exceptions found. There is no certificate and no public register; the report is normally shared under NDA.

Side by side

ISO/IEC 27001:2022SOC 2
What it isCertifiable international standardAICPA attestation engagement
What you getA certificate, valid 3 yearsA report covering a stated period
Who issues itAccredited certification body (JAS-ANZ in Australia)Licensed CPA firm
Publicly verifiableYesNo — shared under NDA
Control set93 Annex A controls, 4 themes5 Trust Services Criteria; Security mandatory
Management system requiredYes — ISMS, risk assessment, SoA, internal audit, management reviewNo
CycleStage 1 + 2, surveillance yrs 1–2, re-cert yr 3Annual, to keep the report current
Primary marketAustralia, EU, APAC, government tendersUnited States, SaaS procurement

How much overlap is there really?

Enough that the second framework is far cheaper than the first. Access control, change management, logging and monitoring, incident response, vendor risk, backup and recovery, physical controls and security awareness all carry across. What does not carry across is the ISMS itself — scope, risk assessment method, Statement of Applicability and risk treatment plan — plus the Clause 9 internal audit and management review, both mandatory for ISO 27001 and absent from SOC 2. SOC 2 adds a detailed system description that ISO 27001 never asks for.

What each one costs in Australia

Indicative 2026 ranges for an Australian SMB of 10–50 staff. ISO 27001 readiness typically runs $25,000–$55,000 with a Stage 1 and Stage 2 audit of $8,000–$20,000 paid separately to the accredited body, then surveillance from $2,500 a year and re-certification of $8,000–$15,000 in year three. SOC 2 readiness is comparable, with the CPA examination fee on top and repeated annually because the report goes stale. Over three years ISO 27001 is frequently the lower total, because its audit cycle is less frequent. Full numbers are in the ISO 27001 certification guide for Australia.

Doing both, in the right order

Build the ISMS, certify to ISO 27001, map across to the Trust Services Criteria, then run the SOC 2 observation window and examination. Reverse the order only when a single US deal is gating revenue and the buyer will not wait — in that case a SOC 2 Type I gets a report into the conversation quickly, but budget for the ISMS work afterwards regardless.

The credentials behind each

Frameworks are certified at the organisation level; people are certified separately. PECB ISO 27001 Lead Implementer ($849 + GST) builds and runs the ISMS. PECB ISO 27001 Lead Auditor ($849 + GST) plans and leads ISMS audits under ISO 19011. PECB Lead SOC 2 Analyst ($849 + GST) prepares a service organisation for a SOC 2 examination. Every enrolment includes the official PECB examination voucher and one free resit within 12 months. Aegentra does not issue SOC 2 reports or ISO 27001 certificates — those come from a licensed CPA firm and an accredited certification body respectively. For organisation-level work see ISO 27001 readiness and SOC 2 readiness.