ISO 27001 specifies requirements for establishing and maintaining an information security management system, covering risk assessment, control selection, leadership accountability, and continual improvement. Annex A lists reference controls.

Unlike SOC 2, it results in a certificate issued by an accredited body rather than an attestation report.

Alternative Names:

ISO/IEC 27001, Information Security Management Standard

Why it Matters?

ISO 27001 and SOC 2 overlap substantially, and many vendors hold both because buyers in different regions expect different things: SOC 2 dominates in North America and ISO 27001 internationally. For a legal buyer either is a reasonable baseline, and holding both signals investment rather than materially more security. The related ISO/IEC 42001 covers AI management and is the more differentiating credential for AI vendors.

Frequently Confused with

Related terms

Frequently asked questions

How does ISO 27001 differ from SOC 2?

How does ISO 27001 differ from SOC 2?

ISO 27001 certifies a management system through an accredited body. SOC 2 produces an auditor's attestation report on described controls. The control coverage overlaps heavily.

Should a vendor have both?

Should a vendor have both?

Not necessarily. Either is a reasonable baseline, though vendors serving both North American and international buyers commonly hold both.