70%
hold a confirmed SOC 2
1157 of 1,653 companies
38%
hold a confirmed ISO 27001
620 companies
67%
of SOC 2 holders have no ISO 27001
779 companies
How the two credentials overlap
Why it matters
A SOC 2 report is an attestation written by a US audit firm; ISO 27001 is an accredited certification recognised worldwide. Buyers outside the US, and enterprise procurement teams anywhere, increasingly ask for the second. On this evidence most companies that have cleared the harder part, running a real security programme, stop one credential short of the one that travels.