ISO 27001 specifies requirements for establishing and maintaining an information security management system, covering risk assessment, control selection, leadership accountability, and continual improvement. Annex A lists reference controls.
Unlike SOC 2, it results in a certificate issued by an accredited body rather than an attestation report.
Alternative Names:
ISO/IEC 27001, Information Security Management Standard
Why it Matters?
ISO 27001 and SOC 2 overlap substantially, and many vendors hold both because buyers in different regions expect different things: SOC 2 dominates in North America and ISO 27001 internationally. For a legal buyer either is a reasonable baseline, and holding both signals investment rather than materially more security. The related ISO/IEC 42001 covers AI management and is the more differentiating credential for AI vendors.
Frequently Confused with
Related terms
Frequently asked questions
How does ISO 27001 differ from SOC 2?
Should a vendor have both?





