SOC 2 + ISO 27001 combined audits
Running SOC 2 and ISO 27001 as two separate audits means paying for overlapping work twice. A combined engagement shares one evidence set across both — here's how to plan it.
Why combine
SOC 2's Trust Services Criteria and ISO 27001's Annex A controls overlap substantially — access control, change management, incident response, risk assessment, and vendor management get tested under both. In a combined engagement, one evidence set feeds two reports: one fieldwork window, one relationship, one remediation cycle. The marginal cost of adding ISO 27001 to a SOC 2 engagement is typically well below a standalone ISO project.
How to sequence it
- One readiness pass. Map controls to both frameworks up front — your GRC platform should support dual mapping.
- Run fieldwork together. The auditor tests each control once and maps results to both frameworks' requirements.
- Two deliverables, possibly two issuers. The SOC 2 report comes from the licensed CPA firm; the ISO 27001 certificate comes from an accredited certification body — sometimes the same organization, sometimes a related entity. Confirm who issues what before signing.
- Align the cycles. Annual SOC 2 periods and the 3-year ISO certification cycle (with annual surveillance audits) can be synchronized so evidence stays fresh for both.
Which firms do both
Several directory firms run combined programs: A-LIGN, Schellman, BARR Advisory, 360 Advanced, and Sensiba all list SOC 2 and ISO 27001 among their services. Ask specifically for a combined proposal — not two quotes stapled together — with shared fieldwork and a single evidence request list.
Pitfalls
- Different issuers, different rules. ISO certification requires an accredited body (e.g. ANAB accreditation). Verify the accreditation — a SOC 2 auditor without it can't issue your ISO certificate.
- Scope mismatch. Your ISO ISMS scope and SOC 2 system boundaries should be defined together, or you'll test controls that only count for one framework.
- Timeline stacking. ISO Stage 1 and Stage 2 audits have their own cadence — map them against your SOC 2 observation period early.
- Don't let either framework bloat the other. Combined doesn't mean "audit everything twice." The proposal should show mapped, deduplicated testing.
Questions
Can one audit cover both SOC 2 and ISO 27001?
Yes. A combined engagement tests each control once and maps the results to both frameworks, producing a SOC 2 report from the CPA firm and an ISO 27001 certificate from an accredited certification body. Confirm both issuers before signing.
Is a combined audit cheaper than two separate audits?
Typically the marginal cost of adding ISO 27001 to a SOC 2 engagement is well below a standalone ISO project, because evidence collection and fieldwork are shared. Get a combined proposal — not two quotes stapled together.
Get combined-audit quotes
Ask matched firms for one proposal covering SOC 2 + ISO 27001 with shared fieldwork.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.