Most conversations about compliance frameworks start from the wrong direction. An enterprise procurement team asks for SOC 2. A European client mentions GDPR. A sales process stalls because someone asks about ISO 27001. The instinct is to pick a framework, hire a consultant, and work through it as a standalone project. This approach is consistently more expensive and less effective than it needs to be.
SOC 2: a customer assurance framework
SOC 2 is primarily about telling your business customers that you handle their data appropriately. The Service Organisation Control 2 report is produced by an independent auditor and covers five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Most organisations pursue SOC 2 Type II, which covers a period of time (typically six to twelve months) rather than a point-in-time snapshot.
Who needs it: SaaS companies selling to enterprise or mid-market customers, particularly in regulated industries, will almost inevitably be asked for a SOC 2 report. It is not a legal requirement, but it is an effective de facto requirement for selling to organisations that take vendor security seriously.
SOC 2 in practice
SOC 2 readiness typically takes four to eight months for an organisation starting from a low baseline. The work involves implementing controls across the Trust Services Criteria, running them for the audit period, and then engaging a licensed CPA firm to produce the report. The audit itself is expensive. The remediation work before the audit is more expensive. Building for SOC 2 from the start of your infrastructure design is significantly cheaper than retrofitting controls to an existing environment.
ISO 27001: a management system standard
ISO 27001 is a management system standard, not a technical security benchmark. It specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Certification is awarded by an accredited certification body following a two-stage audit.
The distinction from SOC 2 is important: ISO 27001 demonstrates to auditors and enterprise procurement that you have a systematic, documented approach to information security as an organisational function. SOC 2 demonstrates that specific technical and process controls are operating effectively. They address different audiences and different questions, which is why large organisations pursuing enterprise sales often end up pursuing both.
GDPR: a legal obligation, not an audit programme
GDPR is different in kind from SOC 2 and ISO 27001. It is not an optional assurance framework that your sales team uses to win enterprise deals. It is a legal requirement that applies to any organisation processing the personal data of individuals in the European Union — regardless of where the organisation is based.
The key obligations for a technology company under GDPR include: having a lawful basis for every category of personal data processing; being able to respond to data subject rights requests (access, rectification, erasure, portability) within statutory timeframes; maintaining records of processing activities; and implementing appropriate technical and organisational security measures.
The overlap problem and how to use it
The controls that support SOC 2 Type II also provide significant coverage for ISO 27001. The data mapping required for GDPR provides a foundation for both. An access control programme that satisfies SOC 2's security criteria will overlap substantially with ISO 27001 Annex A controls. Incident response procedures required by GDPR align with SOC 2 security controls and ISO 27001 requirements simultaneously.
Organisations that treat each framework as a standalone initiative consistently spend more than they need to. The approach that produces better outcomes at lower cost treats the frameworks as overlapping requirements with a shared control foundation, and builds for that foundation explicitly.
Where to start when all three matter
- Build the control foundation first. Access management, encryption, logging, incident response, and vendor management address requirements across all three frameworks. Build these correctly from the start of your cloud environment design.
- Map your data. A comprehensive data inventory — what personal data you hold, where it lives, how it moves, and who can access it — is required explicitly by GDPR and provides the foundation for SOC 2 confidentiality and privacy criteria and ISO 27001 information asset management.
- Sequence deliberately. SOC 2 first if your near-term priority is enterprise sales in the US. ISO 27001 first if your buyers are primarily European enterprise or public sector. GDPR should be addressed in parallel with either, as it is a legal obligation rather than a sales requirement.
Compliance is not primarily a technology problem. It is a programme management problem that technology supports. The organisations that navigate it most effectively are the ones that understand which frameworks they actually need, why they need them, and how to build for them without treating each as an independent initiative.