ISO 27001 to SOC 2: reuse, retest or write new

Your ISMS already answers much of SOC 2. The certificate does not, and a few documents are new.

Moving from ISO 27001 to SOC 2 is mostly a reuse job. The records behind your Annex A controls already answer a large share of the Trust Services Criteria.1 The certificate itself answers none of them, because it is a conclusion someone else reached, and a SOC 2 examination under the AICPA attestation standards tests the records rather than the conclusion.2

So the useful questions are practical. Which evidence is read as it stands? Which is retested across a period? And which SOC 2 documents does an ISMS never produce?

What your certificate proves, and what it does not

A certificate says an accredited body audited your management system and found it conforming. That is valuable to a buyer. It is not something a SOC 2 auditor can test, since there is no population to sample and no artifact behind it that they produced. They go to your records instead.

One housekeeping point. ISO released the 2022 edition on 25 October 2022, and Annex A shrank from 114 controls in fourteen clauses to 93 in four: 11 new, 24 merged and 58 updated. The International Accreditation Forum set 31 October 2025 as the last transition date for 2013 certificates in IAF MD 26, issue 2, which we checked on 1 August 2026. A current certificate is a 2022 certificate. The mapping below assumes it.

Four ways your ISO evidence gets treated

Annex A groups controls into organizational, people, physical and technological themes. The Trust Services Criteria group them into nine common criteria series, plus optional categories for availability, confidentiality, processing integrity and privacy.1 The two do not line up control by control. They do line up by theme, and each theme lands in one of four outcomes.

As is
The artifact you keep today satisfies the criterion. The auditor reads it once.
Re-tested
The same kind of record works, but a Type 2 checks it across the whole period, not at a single visit. Same process, bigger population.
Carved out
A subservice organization runs the control, usually your cloud host. You name it and exclude its controls from your description.
Net new
Your ISMS has nothing for this. You write it from scratch.

Annex A themes mapped to the Trust Services Criteria

Use the clause numbers to match each row against your Statement of Applicability. We describe each Annex A area in our own words because ISO does not publish the control text for free. The criteria references come from the public AICPA document.1 The last group has no Annex A equivalent at all.

Annex A areaTrust Services CriteriaOutcome
A.5 Organizational, 37 controls
Policies for information security (A.5.1)CC1.5, CC2.2, CC5.3As is
Roles, segregation of duties, management responsibilities (A.5.2 to A.5.4)CC1.3, CC1.4As is
Threat intelligence, contact with authorities and special interest groups (A.5.5 to A.5.7)CC7.1As is
Asset inventory, ownership, acceptable use, return of assets (A.5.9 to A.5.11)CC6.1, CC6.5Re-tested
Classification, labeling and transfer of information (A.5.12 to A.5.14)CC6.7, C1.1As is
Access control, identity, authentication information, access rights (A.5.15 to A.5.18)CC6.1, CC6.2, CC6.3Re-tested
Supplier relationships and information and communications technology supply chain (A.5.19 to A.5.23)CC9.2As is
Incident planning, assessment, response and evidence collection (A.5.24 to A.5.28)CC7.3, CC7.4, CC7.5Re-tested
Continuity of information security and readiness for continuity (A.5.29, A.5.30)A1.2, A1.3Re-tested
Legal, contractual and privacy requirements, independent review, documented procedures (A.5.31 to A.5.37)CC2.3, CC4.1, CC5.3As is
A.6 People, 8 controls
Screening (A.6.1)CC1.4Re-tested
Terms and conditions of employment, disciplinary process (A.6.2, A.6.4)CC1.1, CC1.5As is
Awareness, education and training (A.6.3)CC1.4, CC2.2Re-tested
Responsibilities after termination or change of employment (A.6.5)CC6.2, CC6.3Re-tested
Confidentiality agreements, remote working, event reporting (A.6.6 to A.6.8)CC2.3, CC6.7, CC7.3As is
A.7 Physical, 14 controls
Perimeters, entry controls, securing offices, physical monitoring (A.7.1 to A.7.4)CC6.4Carved out
Equipment siting, utilities, cabling, maintenance, off-site assets (A.7.5, A.7.8 to A.7.13)CC6.4, A1.2Carved out
Clear desk, clear screen, unattended equipment (A.7.7)CC6.7As is
Secure disposal and reuse of equipment and storage media (A.7.10, A.7.14)CC6.5Re-tested
A.8 Technological, 34 controls
User endpoints, privileged access rights, information access restriction (A.8.1 to A.8.3)CC6.1, CC6.3Re-tested
Access to source code, secure authentication (A.8.4, A.8.5)CC6.1, CC8.1Re-tested
Capacity management (A.8.6)A1.1Re-tested
Protection against malware, technical vulnerability management (A.8.7, A.8.8)CC6.8, CC7.1Re-tested
Configuration management (A.8.9)CC7.1, CC8.1Re-tested
Information deletion, data masking, data leakage prevention (A.8.10 to A.8.12)CC6.5, C1.2As is
Backup and redundancy of processing facilities (A.8.13, A.8.14)A1.2Re-tested
Logging, monitoring activities, clock synchronization (A.8.15 to A.8.17)CC7.2Re-tested
Network security, segregation, filtering, use of cryptography (A.8.20 to A.8.24)CC6.6, CC6.7As is
Secure development, testing, environment separation, change management (A.8.25 to A.8.34)CC8.1Re-tested
No Annex A counterpart
A description of the system, its boundary, its components and its subservice organizationsSection 3 of the reportNet new
A written assertion signed by management about that description and the controlsSection 2 of the reportNet new
Service commitments and system requirements drawn from customer contracts and published documentationCC2.3, CC3.1Net new
Carve-out or inclusive treatment of each subservice organizationCC9.2Net new
Complementary user entity controls, written as obligations on your customersCC9.2Net new
Category criteria for availability, confidentiality or processing integrity, where scopedA1, C1, PI1Net new

Privacy is missing from the final group by design. It has more criteria than the other three optional categories combined,1 and a first report seldom needs it. Run the scoping tool to see which categories your buyer is asking for before you add any.

Documents you can hand over unchanged

The reusable set is paperwork you already maintain: the policy suite, the risk assessment and treatment plan, the Statement of Applicability, asset and supplier registers, signed confidentiality agreements, and role descriptions that carry security duties.

Two ISO records do more work than the rest. Your internal audit report speaks to CC4.1, which asks for periodic checks that controls exist and function.1 Management review minutes hit the same criterion from the governance side. Both are accepted in the format your ISMS produces.

The Statement of Applicability plays a different role. It is not evidence of a control. It is the best index you have for the mapping, because it already says which controls apply and why the excluded ones do not. That is half a scoping memo, written before anyone asked.

Why a Type 2 retests controls ISO already audited

A certification body checks that the management system conforms, sampling during its visit. A SOC 2 Type 2 opinion covers a stated period, so the service auditor draws instances from everything that happened inside that period and tests each one.3 The control is identical. The question is not.

ISO asks if the process exists and runs. SOC 2 asks how many times it ran between two dates, and whether each sampled run was right. So the access review your certifier saw once becomes every review in the window. Joiner and leaver records for the full period get pulled, not a handful.

The real extra work is proving completeness. You will be asked to show an export is the full population rather than a filtered slice, and your retention settings decide if you can. Our SOC 2 evidence checklist lists what each artifact needs to carry to be testable.

A third party view of the overlap

A-LIGN, a firm that performs both SOC 2 examinations and ISO 27001 certification, measures the overlap in the opposite direction: by its count, a completed SOC 2 already covers 43 percent of the evidence ISO 27001 requires. Source, published 4 September 2025, read 1 August 2026. The base differs by direction, so read it as a sense of scale.

The five SOC 2 documents your ISMS never produced

The remaining gap is not controls. It is a short stack of documents with no ISO counterpart. Expect to write each of these yourself, and start with the service commitments because they shape everything else on the list.

  1. Service commitments and system requirements. ISO measures controls against your own risk assessment. SOC 2 measures them against what you promised customers in contracts, service level agreements and public documentation.1 Write those promises down first.
  2. The system description. Section 3 of the report: what the service does, where the boundary sits, which components are inside it, and which subservice organizations it depends on.
  3. Subservice organization treatment. Carve-out or inclusive, decided per provider and stated in the description. Annex A has you manage suppliers but never asks you to declare what your report excludes.
  4. Complementary user entity controls. What your customers must do for your controls to work, written as their obligations. Our page on wording CUECs shows why a vague one transfers nothing.
  5. Management’s written assertion. Your signed statement about the description and the controls, which the CPA firm then examines. The Statement of Applicability cannot stand in for it.
Certificate versus report

You hold a certificate. SOC 2 produces a report with an opinion instead, which is why no SOC 2 certificate exists to sit beside your ISO one.4 cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Timeline: Type 1 first, Type 2 on the calendar

Treat the two report types separately, because their clocks are unrelated. A Type 1 speaks to one date and has no observation window. The work is the mapping, the five new documents, and whatever your Statement of Applicability excluded that a criterion still needs. With a live ISMS that is writing, not engineering.

A first Type 2 runs on elapsed time. Three months is the accepted minimum window and a certificate does not shorten it. Why three months is the floor explains the reasoning, and the SOC 2 timeline covers every other phase. ISO shortens one phase only: remediation, because the controls and policies already exist.

Cost: adding SOC 2 to what you have

If you hired help for this crosswalk, you would be paying for hours spent reading documents you already own. For context, here is one published range for the consultant route.

  • Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.

You can do the mapping yourself with the table above and a copy of your Statement of Applicability. On our side, cybersoftware is SOC 2 software: $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. You bring the ISMS records you already keep, and the software turns them into SOC 2 policies, evidence and an audit package.

Audits go through our preferred pricing program, and we negotiate the fee on your behalf, for the SOC 2 Type 1 and every Type 2, and you see the price in your account before you book. Audits unlock after four paid months on monthly, or right away on yearly. Your ISO surveillance and recertification stay with your own certification body; cybersoftware does not do ISO 27001 work. Holding a certificate does not change any of these prices. It shortens the time you spend before the examination starts.

A first week plan

Five steps get you from a certificate to a scoped SOC 2 project. None of them needs an outside party, and each one produces something you will hand to the auditor later.

  1. Mark your exclusions. Walk the Statement of Applicability against the table above. Any excluded control that touches a common criterion is on your real gap list.
  2. List your service commitments from contracts, service level agreements and public docs, then confirm a control exists for each one.
  3. Choose carve-out or inclusive for every subservice organization before you draft the system description.
  4. Compare retention to the window. Logs that roll off at 90 days cannot cover a six month period.
  5. Let the deal pick the report type. A buyer who already has your ISO certificate and still asks for SOC 2 may want a Type 2, and may accept a Type 1 while the window runs. Ask them.

Then check your starting point. The free readiness assessment takes about 15 minutes and shows which SOC 2 gaps remain once your ISO controls are counted. Compare plans on the pricing page when you are ready.

Questions

Does ISO 27001 evidence count for a SOC 2 audit?
Much of the documentary evidence does. Policies, the risk assessment and treatment plan, the Statement of Applicability, asset and supplier registers, internal audit reports and management review minutes are read in the form you keep them. Operational evidence for a Type 2 is tested again across a period. The certificate itself is not evidence, because it records a conclusion and the auditor needs the records underneath it.
How do Annex A controls line up with the Trust Services Criteria?
By theme rather than one to one. Annex A of ISO/IEC 27001:2022 has 93 controls across organizational, people, physical and technological clauses, while the Trust Services Criteria use nine common criteria series plus optional categories. Map each Annex A area to the criteria it supports and note what the auditor will do with the evidence.
Can an ISO 27001 certificate shorten the SOC 2 observation period?
No. A first Type 2 needs controls to operate across a window, and three months is the accepted minimum. That time has to pass whatever you hold. A Type 1 has no window because it looks at a single date, so a certified company that needs a report quickly often starts with a Type 1.
What does SOC 2 ask for that ISO 27001 does not?
A system description with a defined boundary, a signed management assertion, written service commitments and system requirements, a carve-out or inclusive decision for each subservice organization, and complementary user entity controls. Availability, confidentiality or processing integrity criteria apply only if you add those categories to scope.
What does it cost to add SOC 2 with cybersoftware?
cybersoftware is SOC 2 software: $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. Audits go through our preferred pricing program, and we negotiate the fee on your behalf. Your ISO 27001 certificate, its surveillance audits and your certification body stay exactly as they are; cybersoftware does not do ISO 27001 work.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.
  4. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.