SOC2Prep

Preparing for SOC 2 and ISO 27001 at once

Roughly two thirds of the work is shared. The third that is not shared is the third that decides whether doing both at once saves you money or costs you a quarter.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Preparing for both at the same time is worth it if you already know that a second buyer has asked for ISO 27001 in writing. It is not worth it on speculation. The control work overlaps heavily, so the second framework adds around 30 to 40 percent to your preparation effort rather than doubling it, but the audit fees do not overlap at all and the management-system paperwork ISO demands has no SOC 2 equivalent. Expect roughly $30,000 to $55,000 CAD of certification-body fees on top of your SOC 2 audit fee for a first ISO certification at Canadian SaaS scale.

30 to 40% Extra preparation effort for the second framework

0% Overlap in audit and certification fees

3 to 5 months Added elapsed time if run in sequence instead

This page is the preparer's side. If your question is which of the two your buyer wants, that comparison lives on iso27k.ca. Read it first. The answer changes what you do here.

What actually overlaps between the two?

The overlap is in controls and evidence. It is not in structure. Every row below that says "shared" means one artifact satisfies both auditors, though you will still produce it twice because the two engagements happen at different times against different scopes.

Preparation work, SOC 2 security criterion against ISO 27001
Work itemSOC 2ISO 27001Shared?
Access control, MFA, joiner and leaver recordsCC6Annex A 5.15 to 5.18, 8.2Shared
Change management and secure developmentCC8Annex A 8.25 to 8.32Shared
Logging, monitoring, vulnerability managementCC7Annex A 8.15, 8.16, 8.8Shared
Incident response and the incident logCC7.3 to CC7.5Annex A 5.24 to 5.28Shared
Vendor and supplier managementCC9.2Annex A 5.19 to 5.22Shared
Training and confidentiality agreementsCC1.4, CC2.2Annex A 6.2 to 6.4Shared
Business continuity and restore testingA1 series if in scopeAnnex A 5.29, 5.30, 8.13Mostly shared
Risk assessmentCC3, method is yours to chooseClauses 6.1.2 and 8.2, method is prescribedPartly, ISO is stricter
Scope and system descriptionWritten narrative you authorClause 4.3 ISMS scope statementDifferent documents, same thinking
Statement of ApplicabilityNoneMandatory, all 93 Annex A controls justifiedISO only
Internal auditNoneClause 9.2, mandatory before certificationISO only
Management reviewExpected under CC1, informalClause 9.3, minuted, agenda fixed by the standardISO only
Measurable security objectivesNoneClause 6.2ISO only
Observation window3 to 12 months of records for a Type 2No window. Stage 1 and Stage 2 audits at a point in timeDifferent shape

Read the last five rows as the real cost of the second framework. Everything above them you were going to build anyway, and the preparation guide already sequences it. The Statement of Applicability, internal audit, management review and objectives are net new documents with no SOC 2 counterpart, and together they are most of the extra 30 to 40 percent.

Which direction is easier, SOC 2 first or ISO first?

SOC 2 first is easier for a Canadian SaaS company, and it is what we would recommend unless the ISO request came first and in writing. Two reasons.

The window is the constraint, not the controls
A Type 2 needs three to twelve months of records to exist before an auditor can start. ISO has no equivalent wait. So the SOC 2 clock is the one worth starting first, because ISO preparation can run inside the window you are already waiting through.
ISO's extra documents are cheap once the controls exist
A Statement of Applicability against controls you already operate is a week of writing. The same document written before the controls exist is a wish list you then have to go and make true, twice.
The reverse is defensible in one case
If your buyers are in the EU or UK, ISO 27001 is the report they actually recognize and SOC 2 may be the speculative one. Then invert everything on this page. The honest counter-case is that this site is written for a Canadian company selling into the United States, and for that reader ISO first is the more expensive order.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What order should the work go in?

  1. Fix scope once, for both. The ISMS scope statement and the SOC 2 system description describe the same boundary in different registers, so decide the boundary a single time. The scope and system description page has the boundary tests.
  2. Run one gap analysis mapped to both. Insist the output has an ISO column. A gap analysis priced for SOC 2 alone and then repeated for ISO is the single most common way companies pay twice for one week of work.
  3. Build the shared controls. Everything in the first seven rows of the table above. This is the bulk of the calendar and it counts for both.
  4. Open the SOC 2 observation window as soon as the shared controls run. Waiting for the ISO paperwork before starting the window adds that paperwork's duration to your report date for no benefit.
  5. Write the ISO-only documents during the window. Statement of Applicability, objectives, the internal audit plan, and the management review agenda. This is the quarter that would otherwise be dead time.
  6. Run the ISO internal audit near the end of the window, then book Stage 1. Certification bodies want the internal audit and at least one management review already done before Stage 2.

Do not let one auditor do both

An ISO 27001 certification body cannot also consult on your ISMS, and a CPA firm issuing your SOC 2 opinion cannot do your readiness work either. Independence rules on both sides mean the firm that helps you prepare is never the firm that signs. A single vendor offering to prepare you and certify you is describing something that does not exist.

What does running both cost in CAD?

First year, both frameworks, Canadian company of 25 to 75 people, 2026
LineSOC 2 aloneBoth, run together
Readiness or gap work$12,000 to $30,000$18,000 to $40,000
SOC 2 Type 2 audit fee$25,000 to $45,000$25,000 to $45,000
ISO certification body, Stage 1 and 2None$18,000 to $35,000
ISO surveillance audit, years 2 and 3None$6,000 to $12,000 per year
Penetration test$8,000 to $25,000$8,000 to $25,000
Platform, if you use one$12,000 to $30,000$14,000 to $36,000
First year, all in$57,000 to $130,000$83,000 to $181,000

The penetration test row is the one people miss when they budget. It is a single test that both frameworks accept, so it is shared, and what a SOC 2 auditor expects from that test is close enough to what a certification body expects that one scope covers both. Ranges are CAD and reflect Canadian firm quotes in 2026.

When is doing both at once the wrong call?

Three situations.

Signals that argue against running both frameworks together
SituationWhy it argues against
Under about 20 people with no dedicated ownerTwo frameworks is a full-time job. Below that headcount the person doing it also has a day job, and both slip rather than one finishing.
Nobody has asked for ISO in writingISO on speculation is $24,000 to $47,000 CAD of certification fees over three years spent on a buyer objection nobody has raised.
A deal is closing this quarterThe blocked deal wants the SOC 2 report. Adding ISO adds review cycles to the same scarce people and moves the SOC 2 date right.

The counter-case: if you have already decided ISO is coming within eighteen months, running it in sequence rather than together means building the same control twice under two different owners with two different sets of evidence conventions, and the rework there is real. The break-even is whether the second framework is a decision or a hypothesis.

Can we reuse SOC 2 evidence in an ISO audit?

Yes, for the shared control areas, and certification bodies are used to seeing it. What does not transfer is the framing: ISO auditors want to see the control traced back to a risk in your risk register and to a line in the Statement of Applicability, so the same screenshot needs a different sentence wrapped around it.

Does a SOC 2 report satisfy an ISO 27001 requirement?

Not as a substitute for certification, but yes as vendor evidence. If one of your suppliers holds a SOC 2 report, that report is legitimate evidence for your Annex A 5.19 supplier controls, and the reverse holds for your customers reviewing you.

How much longer does the combined program take?

About six to ten weeks longer than SOC 2 alone if the ISO documents are written during the observation window, and three to five months longer if the two are run in sequence. The window is what makes the combined version cheap in calendar terms.

Do we need two separate risk assessments?

No, one is enough, but write it to ISO's rules. ISO prescribes the method: identified risks with owners, criteria for acceptance, and a treatment plan tied to the Statement of Applicability. SOC 2's CC3 accepts that method happily. A risk assessment written to satisfy CC3 alone usually does not satisfy ISO, so build to the stricter one. Ours is on the risk assessment policy page.

Will a compliance platform handle both?

Partly. All three platforms we cover map controls to both frameworks and keep one evidence library, which is a genuine saving. None of them writes the Statement of Applicability, runs the internal audit or minutes the management review, and those are the ISO-only items. Our page on preparing with Vanta is the closest to this question.

Get quotes for a combined readiness engagement

Tell us both frameworks and your target dates and we will put it in front of firms that map the gap analysis to both rather than running it twice.

Get matched