If you sell to customers in the EU, start from one fact: no EU law requires either one. NIS2 does not name ISO 27001 in its articles, DORA mentions neither ISO 27001 nor SOC 2, and neither appears on the GDPR's register of approved certification mechanisms. So the requirement comes from your customer's procurement team, not from a regulator. What the legal texts do show is the direction those teams look in. NIS2 tells Member States to encourage "European and international standards", a recital names the ISO/IEC 27000 series, and ISO/IEC 27001 has been adopted unchanged as a European Standard. No EU text names SOC 2. A SOC 2 is still accepted in plenty of EU deals, and in Germany the BSI's cloud catalogue, C5, is reported in the form of a SOC 2 report. Which one to get depends on who is asking and what their contract says, and the cheapest way to find out is to ask before you commit.
This guide compares the two from the primary texts: the AICPA criteria, ISO's own pages, the EU acts your EU customers are subject to, and the BSI's C5 FAQ. What a SOC 2 report contains is in SOC 2 Type 1 vs Type 2. How ISO 27001 is organised is in ISO 27001 Annex A explained.
| SOC 2 | ISO 27001 | |
|---|---|---|
| What it is | An attestation report on controls, against the AICPA's 2017 Trust Services Criteria (points of focus revised 2022) | An international standard for an information security management system, ISO/IEC 27001:2022, published October 2022 |
| Who signs it | A CPA, the service auditor, under AT-C sections 105 and 205; outside the US, a practitioner may report under ISAE 3000 (Revised) | A certification body; accreditation by a national accreditation body is optional but, in ISO's words, "may bring an additional layer of confidence" |
| What you receive | A report restricted to specified parties | A certificate you can show anyone |
| How long it lasts | Covers a date (Type 1) or a period (Type 2); the AICPA sets no expiry | A three year cycle with surveillance audits at least once a calendar year |
| European status | No EU act or European Standard names it | Adopted unchanged by CEN and CENELEC as EN ISO/IEC 27001:2023 |
What is the difference between SOC 2 and ISO 27001?
One is a report, the other a certificate, and they answer different questions. A SOC 2 examination, in the AICPA's words, "is performed in accordance with AT-C section 105 ... and AT-C section 205", and the CPA, "known as a service auditor", expresses an opinion on your description of the system and your controls against the Trust Services Criteria. A Type 1 covers the design of the controls as of a date; a Type 2 adds whether they operated effectively over a period. Every SOC 2 includes the common criteria, which are the security criteria, and you add availability, processing integrity, confidentiality or privacy where your commitments to customers need them.
ISO/IEC 27001:2022 sets requirements for a management system: scope, risk assessment, risk treatment, internal audit and management review. Its Annex A lists 93 controls in four themes, 37 organisational, 8 people, 14 physical and 34 technological. The standard itself calls Annex A "a list of possible information security controls" and requires a justification for any you exclude. A certification body audits the system and, if it conforms, issues a certificate.
Does EU law require SOC 2 or ISO 27001?
Neither, though the wording of the acts favours standards over reports.
NIS2. Article 21(1) of the NIS2 Directive asks for measures that take into account "the state-of-the-art and, where applicable, relevant European and international standards". Article 25(1) has Member States "encourage the use of European and international standards and technical specifications relevant to the security of network and information systems", and recital 79 points to "European and international standards, such as those included in the ISO/IEC 27000 series." For cloud, data centre, managed service and the other digital providers it covers, Commission Implementing Regulation (EU) 2024/2690 says in recital 3 that its requirements "are based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401". None of this makes certification compulsory. The details are in NIS2 vs ISO 27001.
Supply chain. NIS2 Article 21(2)(d) requires "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers". That is the provision that puts a security questionnaire in front of you. Point 5.1.4 of the Annex to Regulation 2024/2690 lists what the customer's contracts with suppliers should specify, including "the right to audit or right to receive audit reports". A SOC 2 report or an ISO audit report is how most suppliers satisfy the second half of that.
DORA. The text of Regulation (EU) 2022/2554 mentions neither ISO 27001 nor SOC 2. Article 28(5) says financial entities "may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards", and for critical or important functions they must "take due consideration of the use ... of the most up-to-date and highest quality information security standards". Either credential is evidence for that judgement; neither discharges the contract clauses in Article 30, which for critical or important functions include "unrestricted rights of access, inspection and audit". More in ISO 27001 vs DORA.
GDPR. Article 28(1) requires a controller to use "only processors providing sufficient guarantees", and Article 28(5) lets "an approved certification mechanism as referred to in Article 42" serve as evidence of them. Neither ISO 27001 nor SOC 2 is such a mechanism: the EDPB register lists schemes such as Europrivacy and EuroPriSe, and neither standard appears on it. A buyer can still weigh either as evidence under Article 32, but neither carries the Article 42 status.
Which one do EU customers ask for?
We know of no official statistic that answers this by country, and you should distrust any article that gives one without a source. ISO reports that, per the ISO Survey 2022, "over 70 000 certificates were reported in 150 countries" for ISO/IEC 27001, which tells you how widespread the standard is but not what any given buyer requires. The legal texts above make ISO 27001 the easier fit for a European procurement team that has to cite "European and international standards", and the certificate is simpler to hand around because it is public. A SOC 2 report is restricted: the AICPA's guidance has management and the service auditor agree on "the intended users of the report (referred to as specified parties)", so it usually goes out under a non-disclosure agreement.
Two cases tip the other way. If the customer is a US group buying for its EU subsidiaries, or already holds SOC 2 reports from its other vendors, its security team may ask for a SOC 2 by default. And in Germany, cloud providers are often asked for C5, the BSI's Cloud Computing Compliance Criteria Catalogue. The BSI's C5 FAQ says "The test report must be written in the form of a SOC 2 report" and that "there are no C5 certificates". It also says that, for the basic criteria, "the C5 requires a management system that is based on ISO / IEC 27001". A C5 buyer is asking for both disciplines at once.

What the other results get wrong
Page one for this query is mostly vendors and consultancies, and three errors stand out. One says "SOC 2 reports are valid for only a year". The AICPA sets no validity period; a report covers a stated date or period, and annual renewal is what buyers ask for, not a rule. The same page says "In many cases, particularly in Europe and Asia, ISO 27001 is a mandatory requirement for suppliers in regulated sectors". No EU act we have read makes ISO 27001 certification mandatory for suppliers; a contract may. Another says "ISO 27001 certificates can only be issued by accredited certification bodies". Accreditation is not compulsory, which is why ISO says a certificate from an accredited body "may bring an additional layer of confidence". In the EU, accreditation is done by the single national accreditation body each Member State appoints under Regulation (EC) No 765/2008, so ask which body accredited the certification body and check the certificate there.
How do you choose between SOC 2 and ISO 27001?
Ask the customers who are holding up deals, then decide. If the answer is "either", take the one that serves the rest of your pipeline: ISO 27001 if most of it sits in the EU, the Middle East or Africa, SOC 2 if a large share is North American. If you sell cloud services into Germany, look at C5 before either. If you hold one and a buyer asks for the other, show what you have and ask whether it will do; some procurement teams accept a certificate in place of a report, or the reverse, with a bridging questionnaire. A non-US practitioner can also issue a SOC 2: the AICPA allows a CPA "licensed in a jurisdiction outside the U.S." to report under ISAE 3000 (Revised) where local rules permit, which is covered in SOC 2 cost outside the US.
Many companies end up with both. The control work overlaps heavily, because both rest on risk assessment, access control, change management, incident response and supplier management. Build one control set and map it to both, and the second credential costs mostly audit time rather than new controls.

Check what your buyers need
Fill in the middle column for the three deals that matter most this quarter.
| Question | Your answer | Why it matters |
|---|---|---|
| Which credential did the customer name in the questionnaire or contract? | The requirement is contractual; no EU act imposes either. | |
| Will they accept the other one, or a bridging questionnaire? | One email can save a second audit. | |
| Is the customer in scope of NIS2 or DORA? | Their own supplier duties shape what they ask you for. | |
| Do they want a right to audit, or audit reports? | 2024/2690 Annex 5.1.4(e); DORA Article 30(3)(e). | |
| Is it a German cloud deal that names C5? | C5 is reported in SOC 2 form and needs an ISO 27001 based management system. | |
| Can you share the report under NDA in time? | A SOC 2 is restricted to specified parties. |
If you are starting from nothing, the free compliance check gives you a baseline. In Venvera's SOC 2 module and ISO 27001 module, controls, evidence and supplier assessments are kept once and mapped to both, so the second audit reuses the first one's evidence. The SOC 2 readiness checklist and the Statement of Applicability template cover each side.
Frequently asked questions
Is SOC 2 recognised in the EU?
It is accepted by many EU customers, but no EU act or European Standard names it. It is a US attestation framework, and a non-US practitioner can issue one under ISAE 3000 (Revised) where local rules allow.
Does NIS2 require ISO 27001 certification?
No. NIS2 asks for measures that take relevant European and international standards into account, and recital 79 names the ISO/IEC 27000 series as an example, but certification is not required.
Is ISO 27001 a GDPR certification?
No. GDPR certification under Article 42 needs criteria approved by a supervisory authority or the EDPB, and ISO 27001 is not on the EDPB register. It can still support evidence of security under Article 32.
How long is a SOC 2 report valid?
The AICPA sets no validity period. The report covers a date or a period, and buyers decide how recent it must be; many ask for a new one each year.
What is C5?
The BSI's Cloud Computing Compliance Criteria Catalogue for cloud services. It is attested rather than certified, the report takes the form of a SOC 2 report, and its basic criteria need an ISO 27001 based management system. The BSI has published C5:2026, which it says applies to engagements from June 2027.
Is there an EU cloud certification instead?
Not yet. ENISA lists the EU cloud services scheme, EUCS, among schemes under development; the only scheme published under the Cybersecurity Act so far is EUCC, for ICT products.
Primary sources
SOC 2 definitions are from the AICPA's DC section 200 description criteria, TSP section 100 and the 2017 Trust Services Criteria (with revised points of focus, 2022), and the AICPA's SOC 3 page. ISO facts are from ISO's ISO/IEC 27001 page, ISO/IEC 27001:2022 clause 6.1.3 and the ISO/IEC 27002:2022 contents; the certification cycle from ISO/IEC 17021-1:2015 clause 9.1.3. EU texts are quoted from Directive (EU) 2022/2555, Implementing Regulation (EU) 2024/2690, Regulation (EU) 2022/2554, Regulation (EU) 2016/679 and Regulation (EC) No 765/2008; the GDPR register from the EDPB; C5 from the BSI's C5 FAQ; EUCS status from ENISA.





