ISO 27001 to SOC 2: reuse, retest or write new
Your ISMS already answers much of SOC 2. The certificate does not, and a few documents are new.
Moving from ISO 27001 to SOC 2 is mostly a reuse job. The records behind your Annex A controls already answer a large share of the Trust Services Criteria.1 The certificate itself answers none of them, because it is a conclusion someone else reached, and a SOC 2 examination under the AICPA attestation standards tests the records rather than the conclusion.2
So the useful questions are practical. Which evidence is read as it stands? Which is retested across a period? And which SOC 2 documents does an ISMS never produce?
What your certificate proves, and what it does not
A certificate says an accredited body audited your management system and found it conforming. That is valuable to a buyer. It is not something a SOC 2 auditor can test, since there is no population to sample and no artifact behind it that they produced. They go to your records instead.
One housekeeping point. ISO released the 2022 edition on 25 October 2022, and Annex A shrank from 114 controls in fourteen clauses to 93 in four: 11 new, 24 merged and 58 updated. The International Accreditation Forum set 31 October 2025 as the last transition date for 2013 certificates in IAF MD 26, issue 2, which we checked on 1 August 2026. A current certificate is a 2022 certificate. The mapping below assumes it.
Four ways your ISO evidence gets treated
Annex A groups controls into organizational, people, physical and technological themes. The Trust Services Criteria group them into nine common criteria series, plus optional categories for availability, confidentiality, processing integrity and privacy.1 The two do not line up control by control. They do line up by theme, and each theme lands in one of four outcomes.
- As is
- The artifact you keep today satisfies the criterion. The auditor reads it once.
- Re-tested
- The same kind of record works, but a Type 2 checks it across the whole period, not at a single visit. Same process, bigger population.
- Carved out
- A subservice organization runs the control, usually your cloud host. You name it and exclude its controls from your description.
- Net new
- Your ISMS has nothing for this. You write it from scratch.
Annex A themes mapped to the Trust Services Criteria
Use the clause numbers to match each row against your Statement of Applicability. We describe each Annex A area in our own words because ISO does not publish the control text for free. The criteria references come from the public AICPA document.1 The last group has no Annex A equivalent at all.
| Annex A area | Trust Services Criteria | Outcome |
|---|---|---|
| A.5 Organizational, 37 controls | ||
| Policies for information security (A.5.1) | CC1.5, CC2.2, CC5.3 | As is |
| Roles, segregation of duties, management responsibilities (A.5.2 to A.5.4) | CC1.3, CC1.4 | As is |
| Threat intelligence, contact with authorities and special interest groups (A.5.5 to A.5.7) | CC7.1 | As is |
| Asset inventory, ownership, acceptable use, return of assets (A.5.9 to A.5.11) | CC6.1, CC6.5 | Re-tested |
| Classification, labeling and transfer of information (A.5.12 to A.5.14) | CC6.7, C1.1 | As is |
| Access control, identity, authentication information, access rights (A.5.15 to A.5.18) | CC6.1, CC6.2, CC6.3 | Re-tested |
| Supplier relationships and information and communications technology supply chain (A.5.19 to A.5.23) | CC9.2 | As is |
| Incident planning, assessment, response and evidence collection (A.5.24 to A.5.28) | CC7.3, CC7.4, CC7.5 | Re-tested |
| Continuity of information security and readiness for continuity (A.5.29, A.5.30) | A1.2, A1.3 | Re-tested |
| Legal, contractual and privacy requirements, independent review, documented procedures (A.5.31 to A.5.37) | CC2.3, CC4.1, CC5.3 | As is |
| A.6 People, 8 controls | ||
| Screening (A.6.1) | CC1.4 | Re-tested |
| Terms and conditions of employment, disciplinary process (A.6.2, A.6.4) | CC1.1, CC1.5 | As is |
| Awareness, education and training (A.6.3) | CC1.4, CC2.2 | Re-tested |
| Responsibilities after termination or change of employment (A.6.5) | CC6.2, CC6.3 | Re-tested |
| Confidentiality agreements, remote working, event reporting (A.6.6 to A.6.8) | CC2.3, CC6.7, CC7.3 | As is |
| A.7 Physical, 14 controls | ||
| Perimeters, entry controls, securing offices, physical monitoring (A.7.1 to A.7.4) | CC6.4 | Carved out |
| Equipment siting, utilities, cabling, maintenance, off-site assets (A.7.5, A.7.8 to A.7.13) | CC6.4, A1.2 | Carved out |
| Clear desk, clear screen, unattended equipment (A.7.7) | CC6.7 | As is |
| Secure disposal and reuse of equipment and storage media (A.7.10, A.7.14) | CC6.5 | Re-tested |
| A.8 Technological, 34 controls | ||
| User endpoints, privileged access rights, information access restriction (A.8.1 to A.8.3) | CC6.1, CC6.3 | Re-tested |
| Access to source code, secure authentication (A.8.4, A.8.5) | CC6.1, CC8.1 | Re-tested |
| Capacity management (A.8.6) | A1.1 | Re-tested |
| Protection against malware, technical vulnerability management (A.8.7, A.8.8) | CC6.8, CC7.1 | Re-tested |
| Configuration management (A.8.9) | CC7.1, CC8.1 | Re-tested |
| Information deletion, data masking, data leakage prevention (A.8.10 to A.8.12) | CC6.5, C1.2 | As is |
| Backup and redundancy of processing facilities (A.8.13, A.8.14) | A1.2 | Re-tested |
| Logging, monitoring activities, clock synchronization (A.8.15 to A.8.17) | CC7.2 | Re-tested |
| Network security, segregation, filtering, use of cryptography (A.8.20 to A.8.24) | CC6.6, CC6.7 | As is |
| Secure development, testing, environment separation, change management (A.8.25 to A.8.34) | CC8.1 | Re-tested |
| No Annex A counterpart | ||
| A description of the system, its boundary, its components and its subservice organizations | Section 3 of the report | Net new |
| A written assertion signed by management about that description and the controls | Section 2 of the report | Net new |
| Service commitments and system requirements drawn from customer contracts and published documentation | CC2.3, CC3.1 | Net new |
| Carve-out or inclusive treatment of each subservice organization | CC9.2 | Net new |
| Complementary user entity controls, written as obligations on your customers | CC9.2 | Net new |
| Category criteria for availability, confidentiality or processing integrity, where scoped | A1, C1, PI1 | Net new |
Privacy is missing from the final group by design. It has more criteria than the other three optional categories combined,1 and a first report seldom needs it. Run the scoping tool to see which categories your buyer is asking for before you add any.
Documents you can hand over unchanged
The reusable set is paperwork you already maintain: the policy suite, the risk assessment and treatment plan, the Statement of Applicability, asset and supplier registers, signed confidentiality agreements, and role descriptions that carry security duties.
Two ISO records do more work than the rest. Your internal audit report speaks to CC4.1, which asks for periodic checks that controls exist and function.1 Management review minutes hit the same criterion from the governance side. Both are accepted in the format your ISMS produces.
The Statement of Applicability plays a different role. It is not evidence of a control. It is the best index you have for the mapping, because it already says which controls apply and why the excluded ones do not. That is half a scoping memo, written before anyone asked.
Why a Type 2 retests controls ISO already audited
A certification body checks that the management system conforms, sampling during its visit. A SOC 2 Type 2 opinion covers a stated period, so the service auditor draws instances from everything that happened inside that period and tests each one.3 The control is identical. The question is not.
ISO asks if the process exists and runs. SOC 2 asks how many times it ran between two dates, and whether each sampled run was right. So the access review your certifier saw once becomes every review in the window. Joiner and leaver records for the full period get pulled, not a handful.
The real extra work is proving completeness. You will be asked to show an export is the full population rather than a filtered slice, and your retention settings decide if you can. Our SOC 2 evidence checklist lists what each artifact needs to carry to be testable.
A-LIGN, a firm that performs both SOC 2 examinations and ISO 27001 certification, measures the overlap in the opposite direction: by its count, a completed SOC 2 already covers 43 percent of the evidence ISO 27001 requires. Source, published 4 September 2025, read 1 August 2026. The base differs by direction, so read it as a sense of scale.
The five SOC 2 documents your ISMS never produced
The remaining gap is not controls. It is a short stack of documents with no ISO counterpart. Expect to write each of these yourself, and start with the service commitments because they shape everything else on the list.
- Service commitments and system requirements. ISO measures controls against your own risk assessment. SOC 2 measures them against what you promised customers in contracts, service level agreements and public documentation.1 Write those promises down first.
- The system description. Section 3 of the report: what the service does, where the boundary sits, which components are inside it, and which subservice organizations it depends on.
- Subservice organization treatment. Carve-out or inclusive, decided per provider and stated in the description. Annex A has you manage suppliers but never asks you to declare what your report excludes.
- Complementary user entity controls. What your customers must do for your controls to work, written as their obligations. Our page on wording CUECs shows why a vague one transfers nothing.
- Management’s written assertion. Your signed statement about the description and the controls, which the CPA firm then examines. The Statement of Applicability cannot stand in for it.
You hold a certificate. SOC 2 produces a report with an opinion instead, which is why no SOC 2 certificate exists to sit beside your ISO one.4 cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Timeline: Type 1 first, Type 2 on the calendar
Treat the two report types separately, because their clocks are unrelated. A Type 1 speaks to one date and has no observation window. The work is the mapping, the five new documents, and whatever your Statement of Applicability excluded that a criterion still needs. With a live ISMS that is writing, not engineering.
A first Type 2 runs on elapsed time. Three months is the accepted minimum window and a certificate does not shorten it. Why three months is the floor explains the reasoning, and the SOC 2 timeline covers every other phase. ISO shortens one phase only: remediation, because the controls and policies already exist.
Cost: adding SOC 2 to what you have
If you hired help for this crosswalk, you would be paying for hours spent reading documents you already own. For context, here is one published range for the consultant route.
- Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.
You can do the mapping yourself with the table above and a copy of your Statement of Applicability. On our side, cybersoftware is SOC 2 software: $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. You bring the ISMS records you already keep, and the software turns them into SOC 2 policies, evidence and an audit package.
Audits go through our preferred pricing program, and we negotiate the fee on your behalf, for the SOC 2 Type 1 and every Type 2, and you see the price in your account before you book. Audits unlock after four paid months on monthly, or right away on yearly. Your ISO surveillance and recertification stay with your own certification body; cybersoftware does not do ISO 27001 work. Holding a certificate does not change any of these prices. It shortens the time you spend before the examination starts.
A first week plan
Five steps get you from a certificate to a scoped SOC 2 project. None of them needs an outside party, and each one produces something you will hand to the auditor later.
- Mark your exclusions. Walk the Statement of Applicability against the table above. Any excluded control that touches a common criterion is on your real gap list.
- List your service commitments from contracts, service level agreements and public docs, then confirm a control exists for each one.
- Choose carve-out or inclusive for every subservice organization before you draft the system description.
- Compare retention to the window. Logs that roll off at 90 days cannot cover a six month period.
- Let the deal pick the report type. A buyer who already has your ISO certificate and still asks for SOC 2 may want a Type 2, and may accept a Type 1 while the window runs. Ask them.
Then check your starting point. The free readiness assessment takes about 15 minutes and shows which SOC 2 gaps remain once your ISO controls are counted. Compare plans on the pricing page when you are ready.
Questions
Does ISO 27001 evidence count for a SOC 2 audit?
How do Annex A controls line up with the Trust Services Criteria?
Can an ISO 27001 certificate shorten the SOC 2 observation period?
What does SOC 2 ask for that ISO 27001 does not?
What does it cost to add SOC 2 with cybersoftware?
Sources
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- Statements on Standards for Attestation Engagements
- SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy
- SOC 2 Report
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.