Skip to content
AtheronLABS

You're visiting from the United States. Prices are shown in US dollars. Not right?

labs@atheron:~/insights/soc2-iso27001$ audit --soc2 --iso27001 --explain

SOC 2 or ISO 27001?

Or neither, for now.

Sooner or later a larger customer sends you a security questionnaire and asks for a report. This guide explains what they are asking for, what it takes to get there, and when the honest answer is that you do not need one yet.

Compliance · Published October 2, 2026 · 5 min read

Who asks for what

The question usually arrives from a customer's vendor risk team. North American buyers, especially in technology and finance, tend to ask for a SOC 2 report. Buyers in Europe, and larger multinationals everywhere, often ask whether you hold ISO 27001 certification. Public bodies have their own requirements, such as a security classification for the data and accessibility to WCAG AA.

Before starting either, ask your next few customers what they will actually accept. Some will take a completed questionnaire and your architecture documents for now; others will not sign without a report. That answer decides whether this is a this-quarter project or a next-year one.

SOC 2 in plain terms

A SOC 2 report is an examination of a service organization's controls, carried out by an independent CPA firm under the AICPA's standards [1]. It covers security, and optionally availability, processing integrity, confidentiality and privacy. It is an attestation, not a certificate: the auditor reports on your controls, and your customer reads the report.

  • A Type I report looks at whether the controls are designed properly at a point in time. It is quicker and often the first step.
  • A Type II report looks at whether the controls operated effectively over an observation period. It is what most enterprise customers eventually want.
  • The report is shared with customers under a non-disclosure agreement; it is not a public badge.

ISO 27001 in plain terms

ISO/IEC 27001 is an international standard for an information security management system: how a company decides its risks, chooses controls and keeps improving them. Certification is issued by an accredited certification body after an audit, and is maintained with surveillance audits and periodic recertification.

The two overlap heavily in the controls themselves. A company that builds the controls once can usually map them to both, so a second framework costs mostly its difference: the management system and documentation ISO expects, or the reporting SOC 2 expects.

What is not a certification

Frameworks buyers mention, and what each one is
NameWhat it isWhat to say
SOC 2An attestation report by an independent CPA firmWe have a SOC 2 Type I or Type II report, available under NDA
ISO 27001A certification by an accredited certification bodyWe are certified to ISO 27001 by a named body, or we are working towards it
GDPRA European law on personal dataBuilt for GDPR; there is no official GDPR certification to hold
PIPEDA and Quebec Law 25Canadian privacy lawsBuilt for them, with your privacy officer
HIPAAA US law on health informationHIPAA-ready architecture; no official HIPAA certification exists
PCI DSSThe card industry's data security standardA self-assessment or an assessor's report, scoped by your payment design

What the work actually is

  1. 01

    Gap assessment

    Compare what you do today with what the framework expects, and list what is missing.

  2. 02

    Controls in the product

    Access by role and single sign-on, audit logs, encryption, backups with tested restores, monitoring, vulnerability scanning and change management, built into the system rather than described on paper.

  3. 03

    Policies

    A written policy set that matches what the team actually does, because the auditor tests the two against each other.

  4. 04

    Evidence

    Collected as the work happens, often in a compliance platform, so the observation period for a Type II report starts on a working system.

  5. 05

    Fieldwork and findings

    Support while the auditor tests, and fixes for anything they find.

Answering questionnaires in the meantime

Until there is a report, the security questionnaire is the report. Answer it well: keep one master set of answers, written by the people who run the system, and update it whenever the system changes. Attach what you can show rather than describe: an architecture diagram, the data flow, the backup and restore procedure, the access review, the result of the last penetration test. An honest answer that says a control is planned, with a date, reads better to a vendor risk team than a vague yes.

The same master answers become the starting point of the gap assessment when you do decide to pursue a report, so none of the effort is wasted.

Choosing an auditor

Choose the auditor early, before the readiness work is finished, and ask how they work: how they test, what evidence they expect, whether they accept evidence from your compliance platform, and how long fieldwork and the report take. Ask your customers whether they prefer particular firms. The auditor must be independent of whoever helped you prepare, which is one reason a studio that builds your controls can never be the one that reports on them.

What it costs, worked out now

The three worked examples below are priced by our estimator from the rate card in force when you open this page, for the same web product: readiness for a first SOC 2 Type I report, audit support through a Type II report, and both SOC 2 Type II and ISO 27001 kept up continuously. Our price covers the engineering and audit support; the auditor's fee and any compliance platform are shown by the estimator as indicative ranges on their own, because you pay them directly.

Worked example, priced now

Readiness for a first SOC 2 Type I report

Controls built into the product, a gap assessment and policies, with evidence in your compliance platform.

Build
≈ US$82,700 to US$127,000, delivered within 26 weeksCAD 117,800 to 180,300

Prices in your currency are estimates from today's Bank of Canada rate. All invoicing is in CAD or USD.

How it is paid

Deposit 20%
CAD 23,560 to 36,060
Discovery 6%
CAD 7,068 to 10,818
Design approved 6%
CAD 7,068 to 10,818
Core features 18.1%
CAD 21,321.80 to 32,634.30
Full build 12%
CAD 14,136 to 21,636
Testing and fixes 6%
CAD 7,068 to 10,818
Controls built and evidenced 7.7%
CAD 9,070.60 to 13,883.10
Readiness review 7.7%
CAD 9,070.60 to 13,883.10
Launch 6.5%
CAD 7,657.00 to 11,719.50
Holdback, 30 days after launch (10%)
CAD 11,780 to 18,030

Running it

Hosting
≈ US$492 a monthCAD 700 a month
Support
≈ US$2,500 a monthCAD 3,565 a month

Worked example, priced now

Through a SOC 2 Type II report

The same product, with audit support through a six-month observation period.

Build
≈ US$94,000 to US$144,000, delivered within 27 weeksCAD 133,800 to 204,700

Prices in your currency are estimates from today's Bank of Canada rate. All invoicing is in CAD or USD.

Estimated effort by role

Development
272 to 415 h
DevOps engineer
105 to 161 h
Project manager
102 to 156 h
Senior backend developer
76 to 116 h
QA engineer
66 to 101 h
Senior engineer
64 to 97 h
Software architect
58 to 89 h
Frontend developer
50 to 76 h
Backend developer
45 to 68 h
Technical writer
42 to 64 h
Product designer
34 to 51 h
Senior frontend developer
31 to 48 h
Senior product designer
22 to 34 h
Junior frontend developer
19 to 28 h
Junior backend developer
18 to 28 h

How it is paid

Deposit 20%
CAD 26,760 to 40,940
Discovery 5.4%
CAD 7,225.20 to 11,053.80
Design approved 5.4%
CAD 7,225.20 to 11,053.80
Core features 16.3%
CAD 21,809.40 to 33,366.10
Full build 10.8%
CAD 14,450.40 to 22,107.60
Testing and fixes 5.4%
CAD 7,225.20 to 11,053.80
Controls built and evidenced 7%
CAD 9,366 to 14,329
Readiness review 7%
CAD 9,366 to 14,329
Launch 5.4%
CAD 7,225.20 to 11,053.80
Audit support and remediation 7.3%
CAD 9,767.40 to 14,943.10
Holdback, 30 days after launch (10%)
CAD 13,380 to 20,470

Running it

Hosting
≈ US$492 a monthCAD 700 a month
Support
≈ US$2,500 a monthCAD 3,565 a month

Worked example, priced now

SOC 2 Type II and ISO 27001, kept up

Both frameworks mapped to one set of controls, with continuous compliance and annual renewal support.

Build
≈ US$112,000 to US$172,000, delivered within 42 weeksCAD 160,000 to 244,700

Prices in your currency are estimates from today's Bank of Canada rate. All invoicing is in CAD or USD.

How it is paid

Deposit 20%
CAD 32,000 to 48,940
Discovery 5.4%
CAD 8,640.00 to 13,213.80
Design approved 5.4%
CAD 8,640.00 to 13,213.80
Core features 16.3%
CAD 26,080.00 to 39,886.10
Full build 10.8%
CAD 17,280.00 to 26,427.60
Testing and fixes 5.4%
CAD 8,640.00 to 13,213.80
Controls built and evidenced 7%
CAD 11,200 to 17,129
Readiness review 7%
CAD 11,200 to 17,129
Launch 5.4%
CAD 8,640.00 to 13,213.80
Audit support and remediation 7.3%
CAD 11,680.00 to 17,863.10
Holdback, 30 days after launch (10%)
CAD 16,000 to 24,470

Running it

Hosting
≈ US$492 a monthCAD 700 a month
Support
≈ US$4,710 to US$5,870 a monthCAD 6,700 to 8,360 a month

When neither is the right answer yet

If no customer has asked, or the ones who asked will accept a questionnaire, a report can wait. What should not wait is the engineering: single sign-on, audit logs, encryption, backups that restore and change management cost far less to build in from the start than to retrofit before an audit. Build the controls now, and the report becomes a smaller project when a customer finally asks.

// sources

Where the figures come from.

Every statistic in this guide links here. Prices come from our estimator, not from a source.

  1. [1]AICPA and CIMA, SOC 2: SOC for Service Organizations. www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2

// questions

Short answers.

Will you certify us?

No. We build to the controls and support your audit; the report or certificate comes from an independent auditor or certification body you choose.

Do we need SOC 2 or ISO 27001 first?

Ask your customers. North American buyers usually ask for SOC 2; European and multinational buyers often ask for ISO 27001. The controls overlap, so the second one costs mostly its difference.

Is there a GDPR or HIPAA certification?

No official one exists. Systems can be built for GDPR and with HIPAA-ready architecture, and your organization remains responsible for compliance.

// next

Have a project in mind?

Put it through the estimator and get a range in a few minutes. Or tell us about it, and we will come back to you with questions.

SOC 2, ISO 27001 or neither: what customers ask for and the cost | Atheron Network Labs