Live Founding Cohort open, limited seats remaining Back to main site →

ISO 27001 vs SOC 2 vs NIST CSF vs ISO 27701

Four different credentials. Each answers a different question for a different buyer. This lesson decodes which one your customer actually wants, when to add the second and third, and why founders lose months going down the wrong first path.

Free preview 10 min read Verified
Legal basis
ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.

Your buyer says "please share your security certificate". You spend two weeks trying to figure out which one they mean. If you have already been through this on the SOC 2 side (Module 1 of the SOC 2 Readiness Practitioner course walks the same trap for SOC 1 vs SOC 2 vs SOC 3), you know the pattern. Here is the ISO version.

Four different credentials. Each answers a different question. Each has a different reader.

The comparison table

CredentialStandards bodyWhat it coversCertifiable?Who reads it
ISO/IEC 27001:2022ISO / IEC (Geneva)Management system for information security (ISMS)Yes, by an accredited CBEnterprise procurement, especially Europe, UK, APAC, Middle East, government tenders
SOC 2 Type IIAICPA (New York)Attestation on controls meeting Trust Services Criteria over a periodNo (an examination report, not a certificate)Enterprise VRM and procurement, especially US and US-adjacent
NIST CSF 2.0NIST (US Department of Commerce)Voluntary cybersecurity framework, six FunctionsNo (voluntary, self-assessed)US federal contractors, critical infrastructure, board-level reporting
ISO/IEC 27701:2025ISO / IECStandalone Privacy Information Management System (since 14 October 2025)Yes, standalone since 2025 (previously required 27001)GDPR, DPDP Act 2023, LGPD, PIPL-exposed customers demanding formal privacy assurance

ISO 27001 vs SOC 2, the daily reality

ISO 27001 and SOC 2 are the two most common enterprise-security assurances globally. They overlap substantially. Both cover information security. Both require risk assessment, policies, access control, incident response, vendor management, business continuity. Both require independent third-party assurance. But the reader, the format and the buying preference differ by region.

ISO 27001 is preferred in Europe, UK, APAC, Middle East, government tenders and Indian enterprise. The certificate is a one-page artefact plus the Statement of Applicability. It is simple to present to procurement and easily verifiable via the CB's public register. The management-system focus (governance, continual improvement, top management commitment) reads naturally to European buyers who are used to ISO 9001 and ISO 14001 heritage.

SOC 2 is preferred in the US and US-adjacent buyers. The report is 40 to 80 pages, contains the auditor's opinion, description of the system, applicable Trust Services Criteria, tested controls, sample sizes and exceptions. The evidence-based operating-effectiveness focus reads naturally to US buyers who are used to SOX and SEC-filer discipline.

Sharp founders start with one and add the other 12 to 18 months later. Vanta, Drata, Sprinto and Secureframe all offer combined SOC 2 + ISO 27001 programmes that share 70 to 80 percent of the control set. Marginal cost of the second framework runs 40 to 60 percent of the first, not double.

The pragmatic Indian SaaS approach:

  • US-dominant revenue: start SOC 2 Type II, add ISO 27001 in Year 2
  • Europe / UK / APAC / Middle East / government dominant revenue: start ISO 27001, add SOC 2 in Year 2
  • Mixed geography with a large Series B or Series C GTM push: run both from Year 1 as a combined programme; expect 12 to 18 months to first cert on each

ISO 27001 vs NIST CSF, the frequently confused pair

NIST Cybersecurity Framework 2.0 is not a certification standard. It is a voluntary framework published by the US National Institute of Standards and Technology in February 2024 [L2-C1]. Six Functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover. No formal certification. No third-party audit. Widely used as a common vocabulary between security and business leadership and required for US federal contractors and critical infrastructure operators.

ISO 27001 is a certification standard with formal third-party audit and accredited CBs. NIST CSF is a self-assessment framework with no accredited certification.

Sharp Indian CISOs use NIST CSF as their board-reporting vocabulary and ISO 27001 as their external assurance credential. NIST CSF answers the internal question "how mature is our cybersecurity programme?" (via the four Tiers: Partial, Risk Informed, Repeatable, Adaptive). ISO 27001 answers the external question "will your procurement team accept us as a vendor?".

The two crosswalk cleanly. NIST CSF 2.0 Govern function maps to ISO 27001 Clauses 4 and 5 plus selected Annex A organisational controls (A.5.1 policies, A.5.2 roles, A.5.19 supplier relationships). Identify maps to Clause 6.1.2 risk assessment plus A.5.9 asset inventory. Protect maps to A.5.15 access control, A.8.5 authentication, A.8.24 cryptography, A.6.3 awareness. Detect maps to A.8.15 logging, A.8.16 monitoring activities. Respond maps to A.5.24 through A.5.27 incident management. Recover maps to A.5.29 information security during disruption and A.5.30 ICT readiness.

ISO 27001 vs ISO 27701, the privacy layer question

ISO/IEC 27701 is the Privacy Information Management System (PIMS) standard. Two editions currently exist: 27701:2019 (an extension of ISO/IEC 27001, so certification required a live 27001 certificate as a prerequisite) and 27701:2025 (published 14 October 2025 as the second edition, now a stand-alone management system standard) [L2-C2].

The 2025 change is material. Previously an organisation had to certify to ISO 27001 first and then extend to 27701. From October 2025 onward, an organisation can certify to 27701 directly. NABCB published its transition policy in January 2026 [L2-C3]. IAF transition arrangements are developing. 27701:2019 certificate holders have a three-year transition to October 2028 to migrate.

For a DPDP Act 2023-exposed Indian organisation, or a GDPR-exposed exporter of European personal data, ISO 27701 formalises the privacy operating model in a way ISO 27001 alone does not. ISO 27001 references privacy in Annex A.5.34 (Privacy and protection of PII) but does not detail the operational controls a data fiduciary needs. ISO 27701 fills that gap with PIMS-specific controls for PII controllers and PII processors.

Practical guidance for Indian organisations: add ISO 27701 in Year 2 of your ISMS after ISO 27001 is stable. Direct standalone certification is now possible but the practical operating layers (risk assessment, incident management, supplier management) are shared with 27001 and are better built once. Module 8 Lesson 3 walks the full ISO 27701:2025 + DPDP Act 2023 crosswalk.

What to tell your customer when they ask

Ask a clarifying question. "When you asked for our security certificate, do you mean ISO/IEC 27001:2022 (management system, one-page certificate + Statement of Applicability) or SOC 2 Type II (attestation report, 40 to 80 page document)? Both are widely accepted; happy to provide either or both under NDA."

Nine out of ten European, UK, APAC and Middle East buyers will name ISO 27001. Nine out of ten US buyers will name SOC 2. Government tenders in India, Middle East and APAC will name ISO 27001 specifically. Occasionally you will get "both please" from a mature buyer and that answers the question of what to run next.

Next lesson: the 2022 revision plus Amendment 1:2024. Substantive changes from 2013. The four-theme Annex A restructure. The 11 new controls. The climate change amendment. What actually shifted, and what did not.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
NIST Framework, NIST Cybersecurity Framework 2.0 (NIST CSF v2.0 (Feb 2024)) L2-C1
NIST CSF 2.0 published February 2024. Six Functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover. Referenced in this course for the NIST CSF to ISO 27001 crosswalk (Govern maps to ISO Clauses 4-5 + selected Annex A; Identify maps to Clause 6.1.2 + A.5 asset controls; Protect to A.5-A.8; Detect to A.8.15-A.8.16; Respond to A.5.24-A.5.27; Recover to A.5.29-A.5.30).
ISO/IEC 27701:2025, ISO/IEC 27701:2025 (standalone PIMS) (Privacy information management system standalone) L2-C2
ISO/IEC 27701:2025 published 14 October 2025 as the second edition. Transforms from a 27001 extension into a stand-alone Privacy Information Management System standard. Certification no longer requires prior 27001 certification. Three-year transition to October 2028 for 27701:2019 certificate holders. IAF transition arrangements developing as of course pin date. NABCB published transition policy January 2026.
NABCB Policy, NABCB 27701:2025 Transition Policy (Transition policy for ISO/IEC 27701:2025) L2-C3
NABCB Policy on Transition to ISO/IEC 27701:2025 published January 2026. Sets out how Indian CBs and certificate holders should transition from ISO/IEC 27701:2019 (extension of 27001) to ISO/IEC 27701:2025 (standalone PIMS). Aligned with IAF transition arrangements.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The ISO 27001 story
Module 2: Clauses 4 to 6: Context, Leadership, Planning
  • Clause 4 Context of the organisation (including Amendment 1:2024 climate change)
  • Clause 5 Leadership and the ISMS Policy
  • Clause 6.1 Actions to address risks and opportunities
  • Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology
  • Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes
Module 3: Clauses 7 to 10: Support, Operation, Evaluation, Improvement
  • Clause 7 Support — Resources, competence, awareness, communication
  • Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC
  • Clause 8 Operation — Executing the plan
  • Clause 9 — Monitoring, Internal Audit, Management Review
  • Clause 10 Improvement — Nonconformity and CAPA
Module 4: Annex A controls Part 1: Organizational + People
  • A.5 Organizational controls Part 1 (A.5.1 through A.5.20)
  • A.5 Organizational controls Part 2 (A.5.21 through A.5.37)
  • A.6 People controls (8 controls, A.6.1 through A.6.8)
  • The 11 new controls in ISO/IEC 27002:2022 walkthrough
  • Building the Statement of Applicability (all 93 controls)
Module 5: Annex A controls Part 2: Physical + Technological
  • A.7 Physical controls (14 controls, A.7.1 through A.7.14)
  • A.8 Technological controls Part 1 (A.8.1 through A.8.17)
  • A.8 Technological controls Part 2 (A.8.18 through A.8.34)
  • Cloud-specific controls and ISO 27017 / 27018 alignment
  • Control Ownership Matrix and evidence sources
Module 6: The risk assessment operating layer
  • Choosing a risk methodology (asset-based, scenario-based, hybrid)
  • Asset inventory and information classification
  • Threat identification, vulnerability identification, likelihood + impact scoring
  • Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan
  • GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer)
Module 7: Certification body selection + Stage 1 + Stage 2 audits
  • What NABCB accreditation means (and why IAF MLA matters)
  • CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS)
  • Stage 1 audit — documentation review
  • Stage 2 audit — operating effectiveness testing
  • Handling nonconformities, CAPA closure, certificate issuance
Module 8: Post-certification + adjacent standards
  • Surveillance Years 1 + 2, and recertification Year 3
  • Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires
  • ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk
  • ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions
  • ISO/IEC 42001 AI Management System as the next horizon