NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →
SOC 2 vs ISO 27001: What EU Buyers Ask For
Learn

SOC 2 vs ISO 27001: What EU Buyers Ask For

·Alexander Sverdlov

If you sell to customers in the EU, start from one fact: no EU law requires either one. NIS2 does not name ISO 27001 in its articles, DORA mentions neither ISO 27001 nor SOC 2, and neither appears on the GDPR's register of approved certification mechanisms. So the requirement comes from your customer's procurement team, not from a regulator. What the legal texts do show is the direction those teams look in. NIS2 tells Member States to encourage "European and international standards", a recital names the ISO/IEC 27000 series, and ISO/IEC 27001 has been adopted unchanged as a European Standard. No EU text names SOC 2. A SOC 2 is still accepted in plenty of EU deals, and in Germany the BSI's cloud catalogue, C5, is reported in the form of a SOC 2 report. Which one to get depends on who is asking and what their contract says, and the cheapest way to find out is to ask before you commit.

This guide compares the two from the primary texts: the AICPA criteria, ISO's own pages, the EU acts your EU customers are subject to, and the BSI's C5 FAQ. What a SOC 2 report contains is in SOC 2 Type 1 vs Type 2. How ISO 27001 is organised is in ISO 27001 Annex A explained.

SOC 2ISO 27001
What it isAn attestation report on controls, against the AICPA's 2017 Trust Services Criteria (points of focus revised 2022)An international standard for an information security management system, ISO/IEC 27001:2022, published October 2022
Who signs itA CPA, the service auditor, under AT-C sections 105 and 205; outside the US, a practitioner may report under ISAE 3000 (Revised)A certification body; accreditation by a national accreditation body is optional but, in ISO's words, "may bring an additional layer of confidence"
What you receiveA report restricted to specified partiesA certificate you can show anyone
How long it lastsCovers a date (Type 1) or a period (Type 2); the AICPA sets no expiryA three year cycle with surveillance audits at least once a calendar year
European statusNo EU act or European Standard names itAdopted unchanged by CEN and CENELEC as EN ISO/IEC 27001:2023
SOC 2 and ISO 27001 at a glance: a SOC 2 is an attestation report restricted to specified parties, ISO 27001 ends in a public certificate on a three year cycle, ISO/IEC 27001:2022 has 93 Annex A controls, and no EU law requires either

What is the difference between SOC 2 and ISO 27001?

One is a report, the other a certificate, and they answer different questions. A SOC 2 examination, in the AICPA's words, "is performed in accordance with AT-C section 105 ... and AT-C section 205", and the CPA, "known as a service auditor", expresses an opinion on your description of the system and your controls against the Trust Services Criteria. A Type 1 covers the design of the controls as of a date; a Type 2 adds whether they operated effectively over a period. Every SOC 2 includes the common criteria, which are the security criteria, and you add availability, processing integrity, confidentiality or privacy where your commitments to customers need them.

ISO/IEC 27001:2022 sets requirements for a management system: scope, risk assessment, risk treatment, internal audit and management review. Its Annex A lists 93 controls in four themes, 37 organisational, 8 people, 14 physical and 34 technological. The standard itself calls Annex A "a list of possible information security controls" and requires a justification for any you exclude. A certification body audits the system and, if it conforms, issues a certificate.

Does EU law require SOC 2 or ISO 27001?

Neither, though the wording of the acts favours standards over reports.

NIS2. Article 21(1) of the NIS2 Directive asks for measures that take into account "the state-of-the-art and, where applicable, relevant European and international standards". Article 25(1) has Member States "encourage the use of European and international standards and technical specifications relevant to the security of network and information systems", and recital 79 points to "European and international standards, such as those included in the ISO/IEC 27000 series." For cloud, data centre, managed service and the other digital providers it covers, Commission Implementing Regulation (EU) 2024/2690 says in recital 3 that its requirements "are based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401". None of this makes certification compulsory. The details are in NIS2 vs ISO 27001.

Supply chain. NIS2 Article 21(2)(d) requires "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers". That is the provision that puts a security questionnaire in front of you. Point 5.1.4 of the Annex to Regulation 2024/2690 lists what the customer's contracts with suppliers should specify, including "the right to audit or right to receive audit reports". A SOC 2 report or an ISO audit report is how most suppliers satisfy the second half of that.

DORA. The text of Regulation (EU) 2022/2554 mentions neither ISO 27001 nor SOC 2. Article 28(5) says financial entities "may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards", and for critical or important functions they must "take due consideration of the use ... of the most up-to-date and highest quality information security standards". Either credential is evidence for that judgement; neither discharges the contract clauses in Article 30, which for critical or important functions include "unrestricted rights of access, inspection and audit". More in ISO 27001 vs DORA.

GDPR. Article 28(1) requires a controller to use "only processors providing sufficient guarantees", and Article 28(5) lets "an approved certification mechanism as referred to in Article 42" serve as evidence of them. Neither ISO 27001 nor SOC 2 is such a mechanism: the EDPB register lists schemes such as Europrivacy and EuroPriSe, and neither standard appears on it. A buyer can still weigh either as evidence under Article 32, but neither carries the Article 42 status.

What the texts say about each: NIS2 recital 79 names the ISO/IEC 27000 series, Regulation 2024/2690 recital 3 names ISO/IEC 27001, DORA names neither, neither is a GDPR Article 42 certification, German C5 is reported in SOC 2 form, and the EU cloud scheme EUCS is still under development

Which one do EU customers ask for?

We know of no official statistic that answers this by country, and you should distrust any article that gives one without a source. ISO reports that, per the ISO Survey 2022, "over 70 000 certificates were reported in 150 countries" for ISO/IEC 27001, which tells you how widespread the standard is but not what any given buyer requires. The legal texts above make ISO 27001 the easier fit for a European procurement team that has to cite "European and international standards", and the certificate is simpler to hand around because it is public. A SOC 2 report is restricted: the AICPA's guidance has management and the service auditor agree on "the intended users of the report (referred to as specified parties)", so it usually goes out under a non-disclosure agreement.

Two cases tip the other way. If the customer is a US group buying for its EU subsidiaries, or already holds SOC 2 reports from its other vendors, its security team may ask for a SOC 2 by default. And in Germany, cloud providers are often asked for C5, the BSI's Cloud Computing Compliance Criteria Catalogue. The BSI's C5 FAQ says "The test report must be written in the form of a SOC 2 report" and that "there are no C5 certificates". It also says that, for the basic criteria, "the C5 requires a management system that is based on ISO / IEC 27001". A C5 buyer is asking for both disciplines at once.

How each is proven: a SOC 2 is a report restricted to specified parties covering a date or a period, ISO 27001 is a public certificate on a three year cycle with yearly surveillance, C5 attestations are written in SOC 2 form, and there are no C5 certificates
Venvera SOC 2 Type 2 dashboard showing readiness score and control effectiveness

What the other results get wrong

Page one for this query is mostly vendors and consultancies, and three errors stand out. One says "SOC 2 reports are valid for only a year". The AICPA sets no validity period; a report covers a stated date or period, and annual renewal is what buyers ask for, not a rule. The same page says "In many cases, particularly in Europe and Asia, ISO 27001 is a mandatory requirement for suppliers in regulated sectors". No EU act we have read makes ISO 27001 certification mandatory for suppliers; a contract may. Another says "ISO 27001 certificates can only be issued by accredited certification bodies". Accreditation is not compulsory, which is why ISO says a certificate from an accredited body "may bring an additional layer of confidence". In the EU, accreditation is done by the single national accreditation body each Member State appoints under Regulation (EC) No 765/2008, so ask which body accredited the certification body and check the certificate there.

How do you choose between SOC 2 and ISO 27001?

Ask the customers who are holding up deals, then decide. If the answer is "either", take the one that serves the rest of your pipeline: ISO 27001 if most of it sits in the EU, the Middle East or Africa, SOC 2 if a large share is North American. If you sell cloud services into Germany, look at C5 before either. If you hold one and a buyer asks for the other, show what you have and ask whether it will do; some procurement teams accept a certificate in place of a report, or the reverse, with a bridging questionnaire. A non-US practitioner can also issue a SOC 2: the AICPA allows a CPA "licensed in a jurisdiction outside the U.S." to report under ISAE 3000 (Revised) where local rules permit, which is covered in SOC 2 cost outside the US.

Many companies end up with both. The control work overlaps heavily, because both rest on risk assessment, access control, change management, incident response and supplier management. Build one control set and map it to both, and the second credential costs mostly audit time rather than new controls.

Choosing and running both: ask the customers holding up deals, match the credential to where your pipeline sits, check whether German cloud buyers want C5, build one control set mapped to both, then certify or attest in the order buyers need
An illustrative view of one control set serving SOC 2 and ISO 27001: Annex A controls with current evidence, common criteria mapped to controls, supplier assessments overdue, and days until the next surveillance audit
Venvera ISO 27001:2022 dashboard showing control coverage, audits and control status by category

Check what your buyers need

Fill in the middle column for the three deals that matter most this quarter.

QuestionYour answerWhy it matters
Which credential did the customer name in the questionnaire or contract?The requirement is contractual; no EU act imposes either.
Will they accept the other one, or a bridging questionnaire?One email can save a second audit.
Is the customer in scope of NIS2 or DORA?Their own supplier duties shape what they ask you for.
Do they want a right to audit, or audit reports?2024/2690 Annex 5.1.4(e); DORA Article 30(3)(e).
Is it a German cloud deal that names C5?C5 is reported in SOC 2 form and needs an ISO 27001 based management system.
Can you share the report under NDA in time?A SOC 2 is restricted to specified parties.

If you are starting from nothing, the free compliance check gives you a baseline. In Venvera's SOC 2 module and ISO 27001 module, controls, evidence and supplier assessments are kept once and mapped to both, so the second audit reuses the first one's evidence. The SOC 2 readiness checklist and the Statement of Applicability template cover each side.

The bottom line on SOC 2 vs ISO 27001 for EU buyers: no EU law requires either, so ask the buyer, and build one control set that serves both

Frequently asked questions

Is SOC 2 recognised in the EU?

It is accepted by many EU customers, but no EU act or European Standard names it. It is a US attestation framework, and a non-US practitioner can issue one under ISAE 3000 (Revised) where local rules allow.

Does NIS2 require ISO 27001 certification?

No. NIS2 asks for measures that take relevant European and international standards into account, and recital 79 names the ISO/IEC 27000 series as an example, but certification is not required.

Is ISO 27001 a GDPR certification?

No. GDPR certification under Article 42 needs criteria approved by a supervisory authority or the EDPB, and ISO 27001 is not on the EDPB register. It can still support evidence of security under Article 32.

How long is a SOC 2 report valid?

The AICPA sets no validity period. The report covers a date or a period, and buyers decide how recent it must be; many ask for a new one each year.

What is C5?

The BSI's Cloud Computing Compliance Criteria Catalogue for cloud services. It is attested rather than certified, the report takes the form of a SOC 2 report, and its basic criteria need an ISO 27001 based management system. The BSI has published C5:2026, which it says applies to engagements from June 2027.

Is there an EU cloud certification instead?

Not yet. ENISA lists the EU cloud services scheme, EUCS, among schemes under development; the only scheme published under the Cybersecurity Act so far is EUCC, for ICT products.

Primary sources

SOC 2 definitions are from the AICPA's DC section 200 description criteria, TSP section 100 and the 2017 Trust Services Criteria (with revised points of focus, 2022), and the AICPA's SOC 3 page. ISO facts are from ISO's ISO/IEC 27001 page, ISO/IEC 27001:2022 clause 6.1.3 and the ISO/IEC 27002:2022 contents; the certification cycle from ISO/IEC 17021-1:2015 clause 9.1.3. EU texts are quoted from Directive (EU) 2022/2555, Implementing Regulation (EU) 2024/2690, Regulation (EU) 2022/2554, Regulation (EU) 2016/679 and Regulation (EC) No 765/2008; the GDPR register from the EDPB; C5 from the BSI's C5 FAQ; EUCS status from ENISA.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING