ISO 27001, ISO 42001, and SOC 2 Readiness Guide
A practical guide to the three assurance frameworks buyers most commonly raise with technology vendors — ISO 27001 for information security management, ISO 42001 for AI management, and SOC 2 for service-organization controls — what each actually attests, how the three differ as instruments, and what "ready" looks like for an organization that holds none of them yet.
Three Frameworks, Three Different Instruments
The most consequential fact about ISO 27001, ISO 42001, and SOC 2 is that they are not three versions of the same thing. The two ISO standards are certifiable management-system standards: an accredited certification body audits the organization's management system and issues a certificate against the standard. SOC 2 is not a certification at all — it is an attestation examination performed by a licensed CPA firm, whose deliverable is a report containing the auditor's opinion, not a certificate.
That difference drives everything downstream: who performs the assessment, what artifact exists at the end, how long it stays valid, and what a company may truthfully say about itself. "SOC 2 certified" is a category error; "certified against ISO 27001" is a real claim with a certificate number behind it. Buyers who understand the instruments read vendor claims far more accurately.
ISO 27001 Today: The 2022 Edition
The current edition of the standard is ISO/IEC 27001:2022, amended in 2024 with a short climate-action text. Its title now leads with information security, cybersecurity and privacy protection, replacing the older "information technology, security techniques" framing — a quick way to date a stale document.
The certification transition from the 2013 edition is complete: the transition window closed at the end of October 2025, and certifications to the 2013 edition expired or were withdrawn at that close. Any valid accredited ISO 27001 certificate presented in 2026 is to the 2022 edition — a diligence detail worth checking, because a lapsed 2013-only certificate holder re-enters certification as a new client with a full initial audit.
For an organization building toward ISO 27001, the management-system clauses (4 through 10) carry the real work: context, leadership, planning — risk assessment and treatment, objectives, and planning for changes — support, operation, performance evaluation, and improvement. The certificate attests that this system runs — not that any particular technology is deployed.
Inside ISO 27001 Annex A
The 2022 edition restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes — organizational, people, physical, and technological. Eleven controls are new (threat intelligence, cloud services security, data masking, data leakage prevention, and secure coding among them), and the old "control objectives" grouping is gone: each control now carries a stated purpose instead.
Practical consequences for readiness work:
| Change | What it means for your program |
|---|---|
| 4 themes replace 14 clauses | Ownership maps more cleanly: organizational controls to governance, technological to engineering |
| Purposes replace control objectives | The Statement of Applicability justifies inclusion per control, not per objective group |
| New controls | Cloud, threat-intelligence, and data-leakage practices that grew up informally now need documented owners |
A control mapping built against the 2013 Annex A structure is stale at the join points; re-derive it against the 93-control set rather than patching the old grid. ISO 27001 readiness in 2026 means the 2022 edition, full stop.
ISO 42001: The AI Management System Standard
ISO/IEC 42001:2023 is the first certifiable AI management system standard — the AI counterpart to ISO 27001's role for information security. Published in December 2023, it remains the current and only edition. It shares the harmonized management-system clause structure (4 through 10), which is what makes integrated audits with ISO 27001 practical, but it is a standalone standard: it neither requires nor contains an information security management system.
Its distinctive machinery is AI-specific: AI risk assessment and treatment, an AI system impact assessment discipline that considers effects on individuals and societies, and an Annex A of 38 AI controls in 9 objective areas — spanning areas such as policy, internal organization, resources, impact assessment, lifecycle, data, and third-party relationships — selected and justified through a Statement of Applicability. Notably, ISO 42001 has no control named "model risk"; organizations with model risk management programs map that vocabulary into the standard's risk assessment and impact assessment clauses rather than finding it ready-made.
For organizations already running an ISO 27001 management system, ISO 42001 readiness is largely a scoping and evidence exercise: the governance skeleton exists; the AI inventory, impact assessments, and AI-specific controls are the new work.
ISO 42001 Certification and the EU AI Act
Two currency facts shape what an ISO 42001 certificate means in 2026. First, accredited certification is real but young: the standard governing certification bodies for AI management systems was published in mid-2025, and the first accreditations followed from late 2025 into 2026 — so certificates exist, and asking which accreditation stands behind one is a fair question.
Second, ISO 42001 certification does not confer presumption of conformity with the EU AI Act. The European standardization deliverables intended to support the Act are still in development, and none has been cited in the Official Journal — the step that would create such a presumption. European adoption of ISO/IEC 42001 as an EN standard is standardization housekeeping, not Official Journal harmonization. The defensible framing: ISO 42001 certification is strong organizational evidence inside an AI Act readiness program — it demonstrates governed AI management — but conformity with the Act is a separate, system-level question with its own phased application sequence. Guides that print hard application dates age badly; the sequence and the distinction are the durable content.
SOC 2: Attestation, Not Certification
SOC 2 — System and Organization Controls 2, an AICPA framework — is an attestation examination performed under the AICPA attestation standards (AT-C sections 105 and 205) by a licensed CPA firm. The examination reports against the Trust Services Criteria (the 2017 criteria, with revised points of focus issued in 2022 — the criteria themselves are unchanged), across five categories: security, availability, processing integrity, confidentiality, and privacy. They are categories, not "principles" — the older naming is retired.
Only the security category is mandatory in every SOC 2 examination, through the common criteria CC1–CC9; the first five align to the seventeen principles of the COSO 2013 internal control framework, and CC6–CC9 add the technical series: logical and physical access, system operations, change management, and risk mitigation. The remaining categories enter scope when the organization's service commitments warrant them — so "we have a SOC 2" says little until you know which categories the report covers.
There is no certificate, no certification body, and no accreditation scheme: the artifact is the CPA firm's report and its opinion. Points of focus are implementation aids, not requirements — an organization need not address every one.
SOC 2 Type 1 vs Type 2, and Reading the Report
A type 1 report opines on the fairness of the system description and the suitability of control design as of a point in time. A type 2 report adds control operating effectiveness over a specified review period — commonly a multi-month window — and discloses the auditor's tests and their results. Neither speaks to future periods, and neither is a pass/fail badge: the opinion can be unmodified, qualified, adverse, or a disclaimer, so "holds a SOC 2 report" is not the same claim as "holds an unmodified opinion."
Reading a SOC 2 report well is buyer skill: check the opinion type, the categories in scope, the review period's recency, the complementary user entity controls (the things you must do for the vendor's controls to work), and how subservice organizations are handled — carved out of scope or included in it. SOC 2 reports are restricted-use documents for management, customers, and specified parties; the general-use, publicly distributable variant is SOC 3.
Choosing and Sequencing
For a technology vendor facing all three, the choice is rarely either/or — it is sequencing. The pattern that repays itself:
- Build one control set first. Run a single internal control program and map it outward to ISO 27001, SOC 2 criteria, and — for AI-relevant services — ISO 42001, rather than running three parallel programs.
- Let the buyer's instrument drive the first engagement. US enterprise buyers commonly ask for a SOC 2 type 2 report; European and regulated buyers often ask for ISO 27001 certification; AI-governance-sensitive buyers increasingly ask about ISO 42001. The first formal engagement should be the one your pipeline actually requests.
- Reuse the overlap. Access control, change management, incident handling, and supplier management evidence serve all three frameworks; the deltas are the ISO management-system formalities on one side and the CPA examination mechanics on the other.
What Readiness May Truthfully Claim
An organization that holds none of the three yet still has honest language available — and the boundary matters, because overclaiming here is a trust incident waiting for diligence to find it:
| May say | May not say |
|---|---|
| "Controls designed with reference to the AICPA Trust Services Criteria" | "SOC 2 certified" or "SOC 2 compliant" |
| "SOC 2 readiness program underway; type 2 examination planned" | Any implied opinion outcome |
| "Management system aligned to ISO/IEC 27001:2022, pre-certification" | "ISO 27001 certified" without a certificate |
| "AI governance practices informed by ISO/IEC 42001" | "ISO 42001 conformant" absent certification |
Readiness itself is demonstrable without any of the artifacts: a current risk assessment, a Statement of Applicability draft, an access-review that ran last quarter, an incident that produced a written lesson. Buyers who ask for those get a truer signal than a logo wall — and vendors who can produce them are, in every sense that matters, ready for the instrument their next contract requires.