Guide

SOC 2 + ISO 27001 combined audits

Running SOC 2 and ISO 27001 as two separate audits means paying for overlapping work twice. A combined engagement shares one evidence set across both — here's how to plan it.

Why combine

SOC 2's Trust Services Criteria and ISO 27001's Annex A controls overlap substantially — access control, change management, incident response, risk assessment, and vendor management get tested under both. In a combined engagement, one evidence set feeds two reports: one fieldwork window, one relationship, one remediation cycle. The marginal cost of adding ISO 27001 to a SOC 2 engagement is typically well below a standalone ISO project.

How to sequence it

  1. One readiness pass. Map controls to both frameworks up front — your GRC platform should support dual mapping.
  2. Run fieldwork together. The auditor tests each control once and maps results to both frameworks' requirements.
  3. Two deliverables, possibly two issuers. The SOC 2 report comes from the licensed CPA firm; the ISO 27001 certificate comes from an accredited certification body — sometimes the same organization, sometimes a related entity. Confirm who issues what before signing.
  4. Align the cycles. Annual SOC 2 periods and the 3-year ISO certification cycle (with annual surveillance audits) can be synchronized so evidence stays fresh for both.

Which firms do both

Several directory firms run combined programs: A-LIGN, Schellman, BARR Advisory, 360 Advanced, and Sensiba all list SOC 2 and ISO 27001 among their services. Ask specifically for a combined proposal — not two quotes stapled together — with shared fieldwork and a single evidence request list.

Pitfalls

Questions

Can one audit cover both SOC 2 and ISO 27001?

Yes. A combined engagement tests each control once and maps the results to both frameworks, producing a SOC 2 report from the CPA firm and an ISO 27001 certificate from an accredited certification body. Confirm both issuers before signing.

Is a combined audit cheaper than two separate audits?

Typically the marginal cost of adding ISO 27001 to a SOC 2 engagement is well below a standalone ISO project, because evidence collection and fieldwork are shared. Get a combined proposal — not two quotes stapled together.

Get combined-audit quotes

Ask matched firms for one proposal covering SOC 2 + ISO 27001 with shared fieldwork.

Get a free quote