Certification questions usually arrive the same way: a prospect sends a security questionnaire, and somewhere in it is a row you cannot tick. The instinct is to start the biggest certification available. That is usually the wrong move, because these three artefacts prove different things to different buyers and cost very different amounts.
Here is how they actually differ.
| SOC 2 | ISO 27001 | ISO 42001 | |
|---|---|---|---|
| What it proves | Controls operated effectively over a period | You run a managed security system | You govern AI across its lifecycle |
| Form | Attestation report by a CPA firm | Certificate from an accredited body | Certificate from an accredited body |
| Primary buyer | US enterprises | EU and global enterprises, public sector | Anyone procuring AI, increasingly EU |
| Typical first-cycle time | 3–12 months incl. observation window | 6–12 months | 6–9 months with an ISMS in place |
| Renewal | Annual report | 3-year cycle, annual surveillance | 3-year cycle, annual surveillance |
Pick based on who is asking. A US SaaS buyer wants a SOC 2 report. A European enterprise or public body wants an ISO certificate. Doing the wrong one first costs a year.
#SOC 2: evidence that controls ran
SOC 2 is an attestation, not a certificate. A CPA firm examines your controls against the Trust Services Criteria — security, and optionally availability, confidentiality, processing integrity and privacy — and writes a report.
The distinction that matters commercially:
- Type I describes controls at a point in time. Faster, and increasingly treated as insufficient.
- Type II covers a period, typically 3–12 months, and evidences that controls actually operated. This is what serious buyers ask for.
When to do it first: your pipeline is predominantly US. SOC 2 is the lingua franca of American vendor security review, and an ISO certificate will still prompt a questionnaire.
#ISO 27001: a system, not a checklist
ISO 27001 certifies an Information Security Management System — the governance process around security, not just the controls. Risk assessments, an asset inventory, defined ownership, internal audit, management review, and continual improvement.
That framing matters. You do not pass ISO 27001 by having good firewalls; you pass by demonstrating a repeatable process that decides which risks matter and does something about them.
When to do it first: you sell into Europe, into regulated industries, or into the public sector. In EU procurement, an ISO certificate is often the row on the form, and nothing else fills it.
Note that ISO 27001:2022 is the current version and the transition from the 2013 edition has closed — if a supplier shows you a 2013 certificate today, it has expired.
#ISO 42001: the new one, and the one AI buyers now ask about
ISO/IEC 42001 is the first international management system standard for artificial intelligence, published in December 2023. Where ISO 27001 certifies that you manage information security, ISO 42001 certifies that you manage AI — its risks, its impact on affected people, and its behaviour across the lifecycle.
It has since stopped being theoretical in Europe: it was adopted as a European standard, with national adoption following, and the certification market is in its first real growth wave — early certifications through bodies like BSI, Schellman and A-LIGN have set the benchmark patterns.
For an organisation with an existing ISO 27001 ISMS, expect roughly 6–9 months to implementation and 9–15 months to a first external certification audit. Without an ISMS, longer.
Two constraints worth knowing before you commit:
- Auditor scarcity. The pool of accredited ISO 42001 auditors is still thin, and lead times reflect that.
- Documentation drift. AI systems change faster than management-system documentation. Keeping the two in sync is the recurring cost, not the audit fee.
Why it is worth tracking anyway: AI governance has become a procurement requirement, and it interacts directly with the EU AI Act. Demonstrable lifecycle governance is exactly what an Annex III high-risk conformity assessment will ask for when that obligation lands on 2 December 2027.
#The order that usually makes sense
- Get the basics real first. Access control with reviews, encryption in transit and at rest, centralised logging with alerting, an offboarding checklist that runs, and an annual penetration test. Every certification assumes these, and none of them are certification-specific work.
- Do a gap analysis against the standard your buyers actually name. A week of honest assessment saves months of misdirected effort.
- Certify the one your pipeline demands — SOC 2 for US-weighted pipelines, ISO 27001 for EU and public sector.
- Add ISO 42001 when you sell AI systems into procurement processes that ask about governance, or when Annex III applies to you.
#What not to do
Do not claim a certification you are pursuing. "SOC 2 ready", "ISO 27001-aligned" and "working towards certification" are phrases procurement teams have learned to read as not certified. Worse, in a questionnaire the claim becomes a representation, and a representation that turns out to be unsupported is a contractual problem rather than a marketing one.
If you are mid-process, say so plainly with a date. Buyers accept "audit scheduled for Q1" far more readily than they accept discovering the gap themselves.
Do not certify scope you do not need. Scope drives cost. A tightly drawn boundary around the product and the systems that touch customer data certifies faster and cheaper than an org-wide scope that impresses nobody.

