SOC 2 vs ISO 27001 for UK startups: which one, and when
SOC 2 or ISO 27001? For UK startups the answer depends on who you sell to. What each one is, how they differ, and a simple way to decide which comes first.

Stabilise

For a UK startup, the right choice depends on who you sell to. SOC 2 is the report American enterprise buyers ask for. ISO 27001 is the certificate UK and European buyers tend to know. Don't start either because it sounds grown-up. Start Cyber Essentials first, then do whichever one a real buyer is asking for. The two share most of their technical controls, so the second is much easier once you have the first.
That's the short version. Here is how they differ, and how to decide.
What SOC 2 is
SOC 2 is a report, not a certificate. A licensed CPA firm examines your controls against the Trust Services Criteria set by the AICPA, the American body for accountants, and gives an opinion on them.
The criteria cover five areas: security, availability, processing integrity, confidentiality and privacy (opens in a new tab). Security is the one every report includes. The others are optional, and you pick the ones that matter to your customers.
Type 1 or Type 2. A Type 1 report looks at whether your controls are designed properly at one point in time. A Type 2 tests whether they worked in practice over a period, usually several months. Buyers give a Type 2 much more weight.
Choose the auditor carefully. The AICPA has said it is looking into anonymously published allegations about a compliance vendor offering SOC services, and has published guidance on the risks of quick-turn SOC engagements. A cheap, fast report that a buyer's security team doesn't trust is worse than no report.
What ISO 27001 is
ISO/IEC 27001 is an international standard for running an information security management system. The current version is the 2022 edition (opens in a new tab), the third.
You're certified against it by a certification body, which in the UK should be accredited by UKAS (opens in a new tab), the government-appointed accreditation service. The standard asks you to assess your risks, choose controls to manage them, and show the system works and improves. A UKAS-accredited certificate is the one buyers can check.
The practical difference from SOC 2: ISO 27001 certifies how you manage security as a system. SOC 2 reports on whether specific controls did their job.
Who asks for which
US enterprise buyers ask for SOC 2. If your pipeline is mostly American companies, it's the report their procurement and security teams expect to read.
UK and European buyers often know ISO 27001 better. Larger UK and EU customers, particularly in regulated sectors, tend to ask for an ISO 27001 certificate, and a SOC 2 report won't always satisfy them.
UK government asks for Cyber Essentials. Under PPN 014 (opens in a new tab), central government contracts can require Cyber Essentials or Cyber Essentials Plus, renewed every year. Neither SOC 2 nor ISO 27001 replaces it.
We haven't found a trustworthy survey putting numbers on these preferences, so we won't quote one. Ask the buyers in your pipeline. Their security questionnaire will tell you what they need.
How much they overlap
A lot. MFA, managed and encrypted devices, patching, access reviews, logging, incident response and supplier management turn up in both.
The overlap is official. The AICPA publishes a mapping between its Trust Services Criteria and ISO 27001 (opens in a new tab). Do the work properly once, keep the evidence, and the second framework reuses most of it.
What it takes
Time. Vanta, which sells compliance software, puts a SOC 2 Type 1 (opens in a new tab) at three to five months from a standing start, and a Type 2 at four to six months in total because of the observation period. Those are vendor estimates. ISO 27001 also takes months: the management system has to be built and running before the certification audit.
Money. Costs vary widely with company size, the auditor, and whether you use compliance software or a consultant. We'd rather not repeat the price ranges that circulate online, because most come from companies selling the tooling. Get two or three quotes once you know which framework you need.
The part that decides the timeline is the same for both: getting the controls working and producing evidence that they work. That's IT work more than paperwork.
Start with Cyber Essentials
For most UK startups, Cyber Essentials comes before either framework. It covers five controls: firewalls, secure configuration, security updates, user access control and malware protection. Since April 2026 it treats missing MFA on cloud services, and critical patches left unapplied beyond 14 days, as automatic fails. Our Cyber Essentials v3.3 guide has the detail.
Cyber Essentials Plus adds independent testing. It's quick and inexpensive next to SOC 2 or ISO 27001, UK government contracts can require it, and every control in it is something a SOC 2 or ISO 27001 auditor will expect to see anyway.
How to decide
- No buyer asking yet? Get Cyber Essentials, then Plus, and get the controls behind it working properly.
- Mostly US enterprise pipeline? SOC 2, aiming for Type 2. Use a Type 1 only to unblock a deal while the Type 2 period runs.
- UK or European enterprise, or regulated sectors? ISO 27001.
- UK public sector? Cyber Essentials or Plus, as the contract requires.
- Selling into both markets? Do one, then the other, reusing the evidence.
- Whichever you choose, pick a reputable, properly accredited auditor over the fastest or cheapest one.
Where we come in
We're Cyber Essentials Plus certified ourselves. We take startups through Cyber Essentials and Plus, then get them ready for SOC 2 and ISO 27001 audits: MFA everywhere, managed and encrypted Macs, patching you can evidence, access reviews and the policies auditors ask to see. The auditor runs the audit. We make sure you have the answers.
If a buyer's questionnaire is what's prompting the question, our guide to what security investors check at seed and Series A covers the same ground from the investor's side, and our IT support for startups is built around getting you there.
Frequently asked questions
- Is SOC 2 a certification?
- No. SOC 2 is an attestation report issued by a licensed CPA firm under standards set by the AICPA, the American body for accountants. You get a report describing your controls and the auditor's opinion on them, not a certificate. ISO 27001 is the one you are certified against, by an accredited certification body.
- Can a UK company get a SOC 2 report?
- Yes. SOC 2 has to be issued by a licensed CPA firm, so UK companies usually work with a US CPA firm, often through a UK partner or readiness consultant who helps prepare the evidence. The controls themselves are the same wherever you are based.
- What is the difference between SOC 2 Type 1 and Type 2?
- A Type 1 report looks at whether your controls are designed properly at a single point in time. A Type 2 report tests whether they worked in practice over a period, usually several months. Buyers give Type 2 far more weight; a Type 1 is mainly useful to unblock a deal while a Type 2 period is under way.
- Should we get SOC 2 and ISO 27001 at the same time?
- Usually not at first. Start with the one your buyers are asking for. The two share most of their technical controls, and the AICPA publishes an official mapping between its criteria and ISO 27001, so the second one is much less work once the first is done.
- Where does Cyber Essentials fit?
- Before either, for most UK startups. It is quick, inexpensive and independently tested at the Plus level, UK government contracts can require it, and its five controls are part of what SOC 2 and ISO 27001 auditors expect to see anyway.


