Where the market actually is
67%of SOC 2 holders have no ISO 27001SOC 2 is the default credential, held by 70% of companies. ISO 27001 sits at 38%, and the two populations overlap far less than a wall of badges suggests.44%confirm exactly one standardFor 476 companies that single standard is SOC 2 and nothing else. This is what a thin trust center looks like from the buyer's side of the table.
What ISO 27001 actually marks
1.9xthe confirmed standardsISO 27001 holders average 2.26 confirmed standards against 1.18 for everyone else. The certificate marks a programme rather than one more logo.9/10of the most-certified companies hold itSort every listed trust center by independently confirmed standards and the same certificate sits at the top almost without exception.
Where adoption is uneven
38%is the line each industry is measured againstData & Analytics clears it comfortably. Cybersecurity does not, despite selling assurance for a living, and neither does Healthcare.77%of ISO 42001 holders also hold ISO 27001The new AI management standard is being layered on the security one rather than replacing it, and the largest category in this database has barely started on either.59%of trust centers run on Vanta28 platforms are in use across the database, but the long tail is very long. Who actually runs the market, and which industries they own.