SOC 2 vs ISO 27001: which Australian teams actually need

Compare the assurance formats before buying readiness work. Reuse evidence carefully, without treating either framework as equivalent.

Last reviewed: · 5 min read

According to AICPA’s SOC 2 reporting guide (2022), SOC 2 examines a service organisation’s controls. ISO/IEC 27001:2022 defines an information security management system. Australian teams should distinguish a CPA report from certification. This guide compares the decisions and indicative evidence overlap, not one-to-one equivalence or an assurance of compliance.

Key takeaways

  • AICPA describes a controls examination, not ISO certification.
  • ISO defines management-system requirements, not a substitute SOC 2 report.
  • Shared evidence still needs separate assessment.
  • Customer geography alone does not decide acceptance.

What happened

AICPA and ISO publish different assurance foundations. AICPA’s public guide overview describes CPA examinations of the service organisation’s system description and controls. Its examination categories concern security and availability alongside processing integrity, confidentiality or privacy. AICPA’s criteria overview explains that criteria can apply at different organisational or system scopes.

IEC’s public abstract for ISO/IEC 27001:2022 describes establishing and continually improving an information security management system (ISMS). It includes assessing and treating information security risks. ISO’s certification overview distinguishes implementing the standard from choosing certification through a certification body.

These sources do not establish that a particular Australian customer accepts either format. The relevant contract or tender is the missing evidence for that decision.

What it means in plain language

The output and boundary differ. AICPA’s guide concerns an examination report on a described service system. ISO’s overview concerns an ISMS and its certification. Neither label tells a buyer that every product or environment was examined.

Indicative overlap, not a validated crosswalk. The examples below are Sorami’s planning prompts, not control mappings or compliance assurance. They draw on the risk-management and control-assessment purposes described by IEC and AICPA. They do not reproduce proprietary control text or assert a percentage of equivalence.

Illustrative evidence reuse questions, not one-to-one equivalence
DomainPossible shared evidenceSeparate check
Identity and accessAccess approvals and removal recordsCompare the actual user populations and system boundaries.
Change managementReviewed changes and release evidenceCheck that sampled changes belong to the examined service.
Incident handlingExercises and response recordsConfirm the relevant responsibilities and evidence period.
Risk and supplier reviewRisk decisions and supplier assessmentsISMS risks and service commitments need separate evaluation.

Why it matters for Australian teams

An Australian address does not resolve a buyer’s evidence requirement. Confirm the requested assurance format and the product boundary. Where public-sector requirements name Essential Eight, keep that question separate. ASD’s Essential Eight Maturity Model describes a minimum preventative baseline for internet-connected IT networks. It is not a SOC 2 or ISO certification crosswalk.

Sorami's view

We would ask for the exact procurement wording first. If a CPA report is required, scope SOC 2 readiness against the relevant service. If the requirement names ISMS certification, discuss ISO 27001 readiness. Where both are requested, maintain one evidence register but record each framework’s scope and reviewer decision separately. We would not buy two engagements solely because a customer is overseas. Readiness is preparation. Certification and the examiner’s opinion remain independent outcomes.

Practical checklist

  1. Obtain the requester’s exact wording.
  2. Confirm report type or certificate requirements.
  3. Define products and environments in scope.
  4. Agree evidence periods with the CPA.
  5. Record reusable evidence and separate gaps.
  6. Confirm acceptance before committing fees.

Frequently asked questions

Is SOC 2 the same as ISO 27001?

No. AICPA describes SOC 2 as an examination of a service organisation’s system and controls. ISO/IEC 27001 concerns an information security management system, with certification by a certification body. One does not automatically substitute for the other.

Can ISO 27001 evidence be reused for SOC 2?

Potentially, where the system boundaries and evidence periods align. The domain examples here are indicative overlap, not a validated crosswalk. Your CPA and certification body must assess the evidence against their own requirements.

Which should an Australian SaaS company choose first?

Sorami’s view is to start with the exact customer or tender requirement, not the customer’s country. Confirm the required report or certificate, system scope and deadline. Ask the requester whether an alternative is acceptable before buying readiness work.

Does SOC 2 require penetration testing?

Penetration testing is not universally required by SOC 2. AICPA’s points of focus describe it as an example evaluation activity, not a mandatory test for every organisation. Confirm your selected controls and the requester’s evidence requirements with your CPA.

Discuss the readiness scope

Bring the requirement to SOC 2 readiness or ISO 27001 readiness. Contact Sorami to confirm the work and boundaries.

Related guides

All Sorami guides

Sources

Public overviews checked 2026-10-07. ISO’s direct page returned a bot check; its indexed public overview and IEC’s full public abstract informed this comparison. No paid standard or detailed crosswalk was reviewed.