Trust Center Database / Insights / 67% of SOC 2 holders have no ISO 27001

67% of SOC 2 holders have no ISO 27001

SOC 2 is the default credential in this market. ISO 27001 is not, and the two populations overlap far less than the badges on a trust center suggest.

70%

hold a confirmed SOC 2

1157 of 1,653 companies

38%

hold a confirmed ISO 27001

620 companies

67%

of SOC 2 holders have no ISO 27001

779 companies

How the two credentials overlap

SOC 2 only779 (47%)
SOC 2 and ISO 27001378 (23%)
ISO 27001 only242 (15%)
Neither confirmed254 (15%)

Why it matters

A SOC 2 report is an attestation written by a US audit firm; ISO 27001 is an accredited certification recognised worldwide. Buyers outside the US, and enterprise procurement teams anywhere, increasingly ask for the second. On this evidence most companies that have cleared the harder part, running a real security programme, stop one credential short of the one that travels.