
Your first U.S. customer asks for your SOC 2 report. You don’t have one, so they politely suggest they’ll “revisit when you do.” Welcome to the American enterprise market - where SOC 2 is what ISO/IEC 27001:2022 is in Europe: the default trust mechanism procurement teams ask for before they ask anything else.

Controls shared with ISO/IEC 27001:2022 Annex A
Trust Service Criteria - Security is mandatory
Type II observation period
Report types - Type I and Type II
1
Developed by the AICPA and governed by U.S. accounting standards, SOC 2 is used globally by anyone selling SaaS to American buyers. It reports against five Trust Service Criteria - Security, Availability, Processing Integrity, Confidentiality and Privacy - and you pick the ones that matter for your business, with Security always mandatory.
It comes in two flavours: Type I, a point-in-time snapshot of control design, and Type II, which proves operating effectiveness across a 3–12 month observation period - the only one serious enterprise buyers accept. Reports renew annually; technically it isn’t certification, but in practice every SaaS company treats it exactly like one.
2
SOC 2 stops being a “later” problem the moment one of these describes you.
Especially mid-market and enterprise. No SOC 2 means no contract for a meaningful share of your potential market.
These three sectors don’t even start the conversation without a SOC 2 Type II report on the table.
A surprising amount of due diligence asks “have they done their SOC 2 yet?” before it asks “what’s their ARR?”
60–70% of SOC 2 controls overlap with ISO/IEC 27001:2022’s Annex A - same evidence, different report.
3
We could write four paragraphs of marketing copy - instead:
Unlock the U.S. enterprise market. This is the whole point. Without it, half your TAM is sealed off.
End the “ISO/IEC 27001:2022 isn’t enough for us” objection. Many U.S. buyers won’t accept ISO/IEC 27001:2022 as a substitute. SOC 2 closes the conversation.
Build trust faster with sophisticated buyers. A SOC 2 Type II report tells a more dynamic story than a static certificate - it covers months of actual operations.
Stack with ISO/IEC 27001:2022 - one audit, two outputs. Our “One Audit” approach means a single evidence pool, two reports, and a dramatically lower combined cost.
Annual renewal = annual improvement. Continual improvement stops being a value statement and becomes a delivery schedule.
4
A SOC 2 report is scoped to the criteria you choose. Security is the mandatory Common Criteria every report shares; the other four are added based on the commitments you actually make to customers.
MANDATORY
Protection of systems and data against unauthorised access, use, or modification - the baseline every SOC 2 engagement is built on.
OPTIONAL
Systems are available for operation and use as committed or agreed - uptime, resilience and disaster recovery.
OPTIONAL
System processing is complete, valid, accurate, timely and authorised - the data does what it should, when it should.
OPTIONAL
Information designated as confidential is protected throughout its lifecycle, as committed to customers and partners.
OPTIONAL
Personal information is collected, used, retained, disclosed and disposed of in line with your stated commitments.
5
Both report on the same controls. The difference is whether they capture a single moment or a stretch of real operations.
WHAT BUYERS ACCEPT
A point-in-time snapshot - your controls are designed correctly as of a single specific date.
Control design
A specific date
Faster, cheaper
A useful early signal
WHAT BUYERS ACCEPT
Operating effectiveness of your controls, observed across a 3–12 month window.
Design + effectiveness
3 - 12 months
Slower, pricier
A serious candidate
6
A transparent, digital-first workflow. Your client portal gives real-time visibility into status, evidence and findings at every stage.
DIGITAL
Choose which of the five Trust Service Criteria apply. Security is mandatory; you add Availability, Processing Integrity, Confidentiality or Privacy based on your actual business - not a template’s idea of one.
HYBRID / ONSITE
We map the selected controls against your existing evidence - reusing your ISO/IEC 27001:2022 Annex A work where it overlaps - and close gaps before the observation window opens.
HYBRID / ONSITE
Controls are tested for operating effectiveness across a 3–12 month window - the report that serious enterprise buyers actually accept, rather than a point-in-time snapshot.
OUTCOME
A licensed CPA firm issues your SOC 2 report. Annual renewal keeps it current - and in practice every SaaS company treats it exactly like a certification.
7
Roughly 60–70% of SOC 2 controls overlap with ISO/IEC 27001:2022’s Annex A - the same evidence, presented as a different report. Our “One Audit” approach runs them together from a single evidence pool, producing two formal outputs at a dramatically lower combined cost.
And SOC 2 is rarely the last step. ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001:2023 and BSI C5 each assume an ISO/IEC 27001:2022-class foundation already exists. Build the ISMS once and every subsequent report costs less, not more - one coordinator across the whole engagement.
ISO/IEC 27001:2022
ISO/IEC 27017
ISO/IEC 27018
ISO/IEC 42001:2023
BSI C5
ISO 22301
Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.
8