The questionnaire rarely arrives at a good moment. A major customer wants to know in its supplier audit whether you hold ISO 27001 certification. Two weeks later a prospect from the US asks for your SOC 2 report. And suddenly the management team is debating a question that sounds like security but is not: ISO 27001 vs SOC 2, which one do we need? The answer sits in your customer list, not in a framework comparison.
ISO 27001 is a certificate for your security management system and the standard proof in Europe and Switzerland. SOC 2 is an audit report built on the US model, requested mainly by American customers. Which proof is right is decided by your target market, not by security. For most Swiss SMEs that means ISO 27001 first, SOC 2 only with a real US pipeline. Holding both at once is rarely necessary, because both build on the same ISMS.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard for information security management systems. An accredited certification body audits your ISMS and issues a certificate. SOC 2 is not a certificate but an audit report: an accounting firm assesses the controls of your service against the Trust Services Criteria of the US body AICPA. In short: a certificate against a standard, or a report on your controls.
The difference sounds academic but has tangible consequences. A certificate is one page of paper with a validity period that you can send to any prospect. A SOC 2 report is a substantial audit document describing in detail which controls were examined and what the auditors found. It usually goes to customers under confidentiality only, and their procurement team reads it, page by page.
| ISO 27001 | SOC 2 | |
|---|---|---|
| Form | Certificate | Audit report |
| Who audits | Accredited certification body | Accounting firm (CPA) |
| Benchmark | International standard ISO/IEC 27001 | Trust Services Criteria (AICPA) |
| Subject | The management system | The controls of a service |
| Typical demand | Switzerland, Europe, regulated industries | USA, SaaS and tech procurement |
SOC 2 comes in two variants: Type 1 assesses your controls at a single point in time, Type 2 over an observation period. In our experience, customers who ask for SOC 2 almost always mean Type 2. A point-in-time report does not answer whether your controls also work in daily operations, and that is exactly what procurement wants to know.
One more detail that regularly gets lost in customer audits: both proofs have a scope. An ISO certificate can cover the whole company or only one site or one service. A SOC 2 report always describes a defined service. A good buyer therefore asks first: What exactly does your proof cover? A certificate that does not cover the service the contract runs on gets noticed in the audit at the latest.
Which proof does which customer demand?
In Switzerland and in Europe, ISO 27001 is the proof that customer audits and tenders ask about first. SOC 2 is demanded mainly by American companies, especially if you deliver software or hosted services. The right proof follows your customers' procurement process, not the quality of your security.
This has less to do with content than with origin. SOC 2 comes out of American public accounting, where the report is the document a vendor risk process expects and can feed into its own workflow. ISO 27001 is the standard that European buyers, auditors and insurers know. A Swiss bank, an industrial group or a public authority has a field in its supplier questionnaire for a certificate number, not for a CPA report.
For the decision you therefore need no framework analysis, but three answers from your own house:
- Where are your customers based? Revenue share by region, today and per the sales plan two years out. The real pipeline counts, not the wish list.
- What do the questionnaires literally say? Your recent customer questionnaires and tenders tell you what your market demands. The result rarely surprises, but it ends internal debates.
- Who pays for the proof? If it hangs on a single deal, it belongs in that deal's business case. If many customers demand it, it is infrastructure and belongs in the annual budget.
Then there is Swiss regulation. The Information Security Act (ISG) requires organisations within its scope to run a working ISMS by the end of 2026, along with a duty to report cyberattacks within 24 hours to the Federal Office for Cyber Security (BACS). Through contracts, this requirement reaches suppliers too. For the choice of proof that means: ISO 27001 structures exactly such a management system. SOC 2 attests controls but no management system, and helps you correspondingly little with the ISG.
An example from practice
A Swiss software provider, around 130 employees. Three existing customers demand ISO 27001 in their annual supplier audit: two banks, one industrial group. At the same time a US prospect sits in the pipeline, whose procurement wants to see a SOC 2 Type 2 report. The management team's first reaction: fine, we will do both.
The second reaction, after a look at the numbers: both means two audit processes, two invoices, two schedules, and all of it alongside the day-to-day business. The decision went the other way. ISO 27001 first, because three paying customers demand it today and the US deal has no signature yet. The US prospect received the certificate together with a properly completed security questionnaire, with the offer to add SOC 2 on contract signing. With that, the SOC 2 costs moved to where they belong: into the business case of that one deal, not into the general security budget.
The aftermath is the real point. The ISMS built for the certification has since answered the banks' questionnaires in a fraction of the former time: clear responsibilities, a maintained risk register, solid answers instead of an annual scavenger hunt across the company. That would have had value even without a logo. With a logo it just sells better.
The proof is a sales document. Your security level changes by exactly zero on the day the certificate is handed over. What changes: which deals you can win and how many questionnaires you no longer fill in by hand. That is why the ISO 27001 or SOC 2 decision belongs in sales planning, next to target markets and pipeline, not in a framework debate.
Why the question lands with the management team
The trigger is almost never a security incident but a deal: a tender, a customer audit, a questionnaire with a deadline. That makes the choice of proof an investment decision with revenue attached, and it belongs with the management team, not with IT. The trade-off is the same as in any market entry: What does the proof cost over three years, what revenue does it secure or open, and what happens with existing customers if we do not deliver it.
Preparing exactly this proposal is leadership work. A CISO who understands the job does not walk into the management meeting with a standards comparison but with a basis for a decision: which customers demand what, what each route costs, what we recommend and why. The board then wants to know only two things: that the question was examined properly and that the chosen proof fits the market plan. Where this proposal is missing, the most expensive variant happens by itself: at some point somebody under time pressure decides on both.
Is it worth holding both at once?
Rarely. Both proofs rest on the same foundations: risk analysis, access control, incident handling, supplier management. Whoever runs a working ISMS can serve both from it. The order follows the market: first the proof that paying customers demand today, then the one for the pipeline.
This is the sizing problem in a new disguise. Just as many SMEs buy too many security tools, some buy too many proofs: the main thing is every logo on the website. Two audit processes started in parallel double audit costs and internal effort without a single risk getting smaller. A living ISMS, by contrast, is the one investment that feeds every future proof, including TISAX or a customer audit with no framework name attached.
If both do become necessary later, the second proof is not a second project. The risk analysis exists, the policies exist, the operational evidence exists. What comes on top: the audit itself, a mapping of the existing controls to the other criteria and a second annual date in the calendar. That is extra effort, but manageable, as long as the ISMS runs in daily operations and is not just woken up for audits.
What building such an ISMS means in effort, duration and money is broken down in our article on ISO 27001 in an SME. If you want to know how we deliver this as a 90-day programme at a fixed price, you will find the packages and prices on the homepage.
Frequently asked questions
Is a SOC 2 report enough for Swiss customer audits?
Sometimes. Some questionnaires accept equivalent proofs, and a Type 2 report demonstrates substance. But if the questionnaire explicitly says ISO 27001, you are arguing against a checkbox in a procurement process. In our experience that is a conversation you rarely win, however good your report is.
Is SOC 2 cheaper than ISO 27001?
The costs depend less on the framework than on the state of your organisation. A Type 2 report needs an observation period with working controls, a certificate needs an auditable management system. Whoever starts from zero pays in both cases mostly for the foundation, not for the logo at the end.
Can we even get SOC 2 as a Swiss company?
Yes. SOC 2 is not a government approval but a report from an audit firm under AICPA standards. Swiss companies can be audited too, often through local branches of the large audit firms. The question is not whether you may, but whether enough revenue hangs on it.
And if you want to know which question your next major customer will ask: look at their industry and their headquarters, not at framework comparisons. The answer is usually already there. If you would rather think it through together before the next questionnaire arrives, we are happy to talk it over for half an hour.
