Two audits, one control set, the math only works one way
A few years back, our security lead printed out both audit checklists side by side just to prove a point to the rest of us. Same access review questions. Same incident response walkthrough, word for word in some places. Same vendor risk section. Two different auditors, two different PDFs, two different invoices for what was basically the same conversation twice a year.
ChatGPT Generated Image
Nobody had ever actually sat down and asked if that was necessary. It wasn’t. Once you look closely, ISO 27001 and SOC 2 aren’t really competing standards. They’re the same underlying idea wearing different clothes.
Same Question, Different Accent
Both frameworks exist to answer one thing: can this company be trusted with sensitive data? They just approach it from different angles.
ISO 27001 is the international one, a certification built around a full Information Security Management System, heavy on documentation, and the one European or APAC clients tend to ask for by name. SOC 2 isn’t technically a certification at all. It’s an attestation, built on the AICPA’s Trust Services Criteria, and it’s the one you’ll hear about constantly if you sell SaaS to U.S. companies.
Strip away the labels, though, and the controls underneath overlap more than most teams realize access control, encryption, incident response, onboarding and offboarding, vendor due diligence. Different numbering systems. Basically the same requirements.
What Actually Changes When You Merge Them
This isn’t about favoring one framework and letting the other one slide. It’s building one control environment that happens to satisfy both auditors without extra translation work.
Here’s roughly what that looked like for us:
One control matrix instead of two map Annex A against the Trust Services Criteria and most controls line up almost exactlyPolicies written once, referencing both frameworks by name, instead of an “ISO version” and a “SOC 2 version” that inevitably drift apart over timeEvidence collected in a format that works for either auditor the first time, not reformatted after the factA single risk assessment methodology (ISO requires this formally anyway) that then informs how SOC 2 controls get scopedOne internal audit pass covering both, instead of staggering internal reviews across the year
Small stuff individually. Adds up fast.
Where the Tooling Earns Its Keep
This is honestly the whole reason platforms like Vanta, Drata, Secureframe, and Sprinto took off. Configure a control once, and the platform maps it across ISO 27001, SOC 2, sometimes HIPAA and GDPR too, without you touching it again per framework.
The time savings are nice. What actually matters more is visibility when an offboarding ticket sits open three days too long, you see it’s a problem for both frameworks at once, not just whichever one an auditor happens to be looking at that quarter.
What You Get Back For the Effort
Nothing dramatic happens overnight. But over a couple of cycles, teams that do this properly tend to see:
Meaningfully less prep time the second year through, once the shared control set is actually built outLower audit fees, since a lot of firms will run combined engagements if you just askFewer internal arguments about which policy document is the “real” oneA security posture that’s closer to audit-ready most months, not just the six weeks before someone shows up
Don’t Pretend They’re Identical
Here’s the part I’d push back on if someone tells you to just collapse the two frameworks entirely. Don’t. ISO 27001 wants a documented ISMS, formal management review cycles, a Statement of Applicability, none of which SOC 2 asks for. And SOC 2 is scoped to a specific window, usually six to twelve months for a Type II report, while ISO certification is more of a snapshot with annual surveillance visits.
Merge the shared 80%. Fine. Keep the other 20% clearly labeled as framework-specific and don’t let anyone tell you it’s redundant just because it’s annoying.
If You’re Doing This For the First Time
Already certified in one and chasing the other? Skip the part where you rebuild everything from scratch.
Map your existing controls against the new framework first, the overlap will be obvious almost immediatelyAsk your current audit firm about combined engagements; more of them offer this now than even two years agoPut one person in charge of the whole program. Splitting ownership by framework is how you end up with two spreadsheets again in eighteen months
Compliance was never supposed to be a twice-a-year performance for two different audiences. Merge the frameworks properly, and it stops being theater, it just becomes part of how the company runs.
Why We Finally Merged Our ISO 27001 and SOC 2 Programs was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.
