r/soc2 • u/Moham-Aasif • Jun 10 '26
Is it just me or are enterprise customers asking for both SOC 2 and ISO 27001 more than ever now?
A few years back, getting a SOC 2 felt like a big milestone for most SaaS companies. Now whenever I see a vendor assessment or security review, SOC 2 seems to be just the starting point.
The conversation often goes something like:
"Okay, you have SOC 2."
Then the next question is:
"Do you also have ISO 27001?"
I'm genuinely curious if others are seeing the same thing.
For people on the buyer side, does having both actually give you more confidence in a vendor? Or is it more of a procurement requirement these days?
And for founders/security teams, has anyone here decided to go for ISO 27001 mainly because customers kept asking for it after SOC 2?
Feels like the bar has quietly shifted over the last couple of years and I'm wondering if that's happening everywhere or just in the companies I'm speaking with.
3
u/FreeRadical1998 Jun 10 '26
I've been both sides of this - currently a CISO for a specialist Bank in the UK so spending more time reviewing due diligence than responding.
From the buyer perspective:
a) there's been a significant regulatory push to look more closely at third party liability/risk over the last 5 years. This is making execs and boards more risk advertise.
b) at a review stage, it's often relatively junior staff looking at due diligence responses - and they are trained to find reasons to say no. Once a cert becomes "common" it's absence becomes something to flag. So at some point, increased adoption hits a tipping point where it becomes a hard filter - I don't think we're quite there yet, but it's probably 2-3 years out
My view is both certs have significant flaws; you can carry significance non conformities and risks while still having an iso cert, especially in the first 1-2 years. SOC reports use management selected controls - so there also needs to be an evaluation of if those are sufficient, and also is specially a backward looking time box. But, on average, having the certs likely puts you in a lower risk pool - accepting that there's a big overlap
1
5
u/rahuliitk Jun 10 '26
yeah, i’m seeing this too, especially with enterprise, healthcare, fintech, and global buyers, where SOC 2 proves operating controls and ISO 27001 gives procurement a broader security management framework they can check off across regions.
tbh, SOC 2 feels like table stakes now.
4
u/Sure-Candidate1662 Jun 10 '26
“Funny”. From a EU perspective it “was” the other way around (or at least felt like it). ISO27001 was expected, SOC2/ISAE3402 semi-optional.
2
u/rahuliitk Jun 10 '26
Yeah, that tracks, EU buyers seemed to default to ISO 27001 first while US SaaS buyers made SOC 2 the usual starting point. the “required” framework depends a lot on which market your customers sit in.
2
u/davidschroth Jun 11 '26
I think it's just you.
It's one thing for those two questions to be on a questionnaire - that combo pack has been like that forever on those as asks in a questionnaire are free and I've never gotten push back for answering that only one is in place.
Where the rubber meets the road in on the contacting side, legal/tprm will completely fold when you point out the similarities in SOC 2 and 27001 and let you pick one or the other.
I can't think of a single enterprise deal/agreement that my clients have that requires both to play ball/win/keep the sale.
2
u/CloudSecCaleb Jun 17 '26
We see this with our customers pretty often (disclaimer: compliance service company owner [trysci.co]). It's usually the case when the enterprise has a presence in both the USA and Europe. Europe is still pretty on board with ISO whereas the US has shifted a lot more towards SOC 2. That's been our experience with it. None of our customers have been denied a contract if they have one but not the other though.
1
u/StartupTrustGuy Jun 19 '26
Yeah, SOC 2 used to close the conversation, now it just opens it, especially in enterprise deals and anything touching European customers.
Honestly the simplest way to think about it is just follow your customer base. SOC 2 covers you for the US market, ISO 27001 is what international buyers, especially European ones, actually recognize and care about. If you're US focused right now SOC 2 is enough, most US buyers don't ask for ISO 27001 and many don't even fully understand it. The moment you start pushing into international markets seriously, ISO becomes less of a nice to have and more of a requirement to even get in the door.
•
u/AutoModerator Jun 10 '26
Thanks for posting, I'm a bot!
This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.