Data Protection

ISO 27001 vs SOC 2 vs GDPR: Mapping All Three to One Control Set

Where the requirements overlap, where they do not, and the order in which to tackle them.

Author
Catherine Higginson
Date
5.5.2026
Updated on
11.8.2026
ISO 27001 vs SOC 2 vs GDPR: Mapping All Three to One Control Set

Key takeaways

  • ISO 27001 leads to a certification, GDPR to compliance with no certificate attached, and SOC 2 to a report. There is no such thing as a SOC 2 certification, and using the term costs you credibility with auditors and buyers.
  • Annex A of ISO 27001:2022 contains 93 controls across four themes: 37 organizational, 8 people, 14 physical, and 34 technological. Most organizations mark 60 to 80 of them as applicable in the Statement of Applicability (SoA).
  • A certified ISMS covers most of Article 32 GDPR, but five obligations have no equivalent in ISO 27001: lawful basis (Art. 6), record of processing activities (RoPA, Art. 30), data subject rights (Art. 12 to 23), Data Protection Impact Assessment (DPIA, Art. 35), and international transfers (Art. 44 onwards).
  • SOC 2 has five Trust Services Criteria. Only Security is mandatory, tested through the Common Criteria CC1 to CC9. Availability, Processing Integrity, Confidentiality, and Privacy enter the scope only if you deliberately include them.
  • The notification deadlines differ, and the difference gets expensive during a real incident: 72 hours to the supervisory authority under Article 33 GDPR, a 24 hour early warning under NIS2, and no statutory deadline in ISO 27001 or SOC 2.

The three frameworks at a glance

Comparing ISO 27001 vs SOC 2 vs GDPR starts with a point that most side-by-side tables skip: they are three different kinds of object, not three versions of the same thing. One is a certifiable standard, one is a law, and one is an assurance engagement. That distinction is not academic. It determines who examines you, what you hold at the end, and what a buyer will accept as proof.

  ISO 27001 GDPR SOC 2
Type International standard, voluntary Directly applicable EU regulation Assurance standard, market driven
Issued by ISO and IEC, committee ISO/IEC JTC 1/SC 27 EU legislator, Regulation 2016/679 AICPA
Current version ISO/IEC 27001:2022 In force since May 25, 2018 Trust Services Criteria, 2017 version with later revisions
Outcome Certification Compliance, no certificate Report (Type I or Type II)
Who examines you Accredited certification body, for example TÜV Süd, TÜV Nord, DEKRA, or DQS Supervisory authority, on a case by case basis Public accounting firm (CPA firm)
Period of validity Three years, with annual surveillance audits Permanent obligation No expiry date, usually renewed annually
Scope is set by You, through the defined scope The law, for every processing activity You, through the criteria you select

The row that matters most in daily practice is the last one. In two of the three frameworks you set the scope yourself, so an ISO certificate and a SOC 2 report say something only about the part of the business you wrote into the scope. GDPR gives you no such discretion: it applies to every processing activity involving personal data, whether or not you documented it.

A widespread misconception: plenty of management teams treat the ISO 27001 certificate as evidence toward customers, supervisory authorities, and insurers that data protection has been handled. It does not carry that weight. Article 42 GDPR does provide for certification as a means of demonstrating compliance, but it requires approval by the competent supervisory authority or the European Data Protection Board, and no ISO standard has received that approval so far. Your certificate is strong supporting evidence for Article 32, and nothing beyond that.

How certification works in practice, from gap analysis to surveillance audits, is covered in our guide to ISO 27001 certification.

Where ISO 27001, GDPR, and SOC 2 overlap

The overlap sits almost entirely in technical and organizational security. Article 32 GDPR requires appropriate technical and organizational measures, then offers only four examples and leaves the word "appropriate" undefined. Annex A of ISO 27001 and the SOC 2 Common Criteria fill that gap, each with its own logic and vocabulary.

The mapping below is the core of a shared control set, and a starting point for your own mapping documentation.

Topic GDPR ISO 27001:2022, Annex A SOC 2, Common Criteria
Access control and authentication Art. 32(1)(b) A.5.15, A.8.2, A.8.5 CC6.1 to CC6.3
Encryption and pseudonymization Art. 32(1)(a) A.8.24, A.8.11, A.5.14 CC6.7
Backup and recoverability Art. 32(1)(c) A.8.13, A.5.29, A.5.30 A1.2, A1.3 (only if the Availability criterion is selected)
Vulnerability and patch management Art. 32(1)(b) A.8.8, A.8.19 CC7.1, CC7.2
Incident management Art. 33, Art. 34 A.5.24 to A.5.28, A.6.8 CC7.3, CC7.4, CC7.5
Change management No express requirement A.8.32 CC8.1
Suppliers and processors Art. 28, Art. 44 onwards A.5.19 to A.5.23 CC9.2
Risk assessment Art. 32(1), Art. 35 Clauses 6.1.2, 6.1.3 CC3.1 to CC3.4
Effectiveness testing and monitoring Art. 32(1)(d) Clauses 9.2, 9.3, A.5.35, A.5.36 CC4.1, CC4.2
Training and awareness Art. 39(1)(a) A.6.3 CC1.4, CC2.2

Do not read that table as a set of equations. The same measure can count in all three frameworks while the evidence each one expects differs. For an Annex A control, an auditor will often accept a documented policy, proof of approval, and a sample that shows it operating. A SOC 2 Type II engagement asks for evidence across the entire examination period, which means a continuous record rather than a snapshot taken the week before the audit. Teams that design their evidence practice around ISO 27001 alone find out at their first SOC 2 engagement that the history is missing.

Which of the 93 controls apply to you, and how to justify the selection you record in your Statement of Applicability, is the subject of our walkthrough of all 93 ISO 27001 Annex A controls.

Where ISO 27001 does not cover GDPR

Five central GDPR obligations have no equivalent in ISO 27001. A certified ISMS moves you no closer to satisfying them, and these are precisely the areas where findings appear once a supervisory authority starts asking questions.

The lawful basis under Article 6, or Article 9 for special categories of data, is a purely legal assessment, and no control exists that tests whether you balanced a legitimate interest correctly. The record of processing activities (RoPA) under Article 30 requires a process oriented view of purposes, data categories, recipients, and retention periods, whereas ISO 27001 knows only the inventory of information assets, organized by system and owner. Both registers describe the same data from two angles, and any team that maintains them separately maintains them twice.

Data subject rights under Articles 12 to 23 are the most operationally demanding of the five. An access request under Article 15 has to be answered within one month, extendable by two further months where the request is complex, which means verifying the requester's identity, searching every system that might hold their data, and documenting the sequence.

The Data Protection Impact Assessment (DPIA) under Article 35 is methodologically close to the risk assessment in clause 6.1.2 and asks a different question: it assesses risk to the rights and freedoms of natural persons rather than risk to the organization. International transfers under Article 44 onwards require standard contractual clauses (SCCs), a transfer impact assessment, and a check on whether an adequacy decision covers the destination country.

GDPR obligation Coverage by ISO 27001 Coverage by SOC 2 What you need in addition
Security of processing (Art. 32) Largely covered Largely covered through CC6 to CC8 Assessment of risk to data subjects
Personal data breach notification (Art. 33, 34) Process in place, deadline missing Process in place, deadline missing 72 hour trigger, notification template, assessment per EDPB Guidelines 9/2022
Use of processors (Art. 28) Partly, through A.5.19 to A.5.23 Partly, through CC9.2 Data processing agreements (DPAs), sub-processor approvals, right to issue instructions
Lawful basis (Art. 6, Art. 9) Not covered Not covered Legal assessment per processing activity, legitimate interests balancing test
Record of processing activities (Art. 30) Not covered Not covered Process oriented RoPA, linked to the asset inventory
Data subject rights (Art. 12 to 23) Not covered Touched on in part, only if the Privacy criterion is selected Request workflow, identity verification, deadline tracking
Data Protection Impact Assessment (Art. 35) Methodologically related, substantively not covered Not covered Dedicated DPIA assessing rights and freedoms
International transfers (Art. 44 onwards) Not covered Not covered Standard contractual clauses, transfer impact assessment

Those five building blocks form the core of a privacy management system. They attach to an existing ISMS and share its asset inventory and approval workflows, but each one has to be built in its own right. The practical question is how much of the upkeep you can automate, which we cover on our page on GDPR compliance automation.

The notification deadlines are not the same

This is where the frameworks diverge most sharply. Article 33 GDPR requires you to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the individuals affected. ISO 27001 requires an incident management process in A.5.24 to A.5.28 and sets no statutory deadline. SOC 2 tests through CC7.3 to CC7.5 whether your process works as described, and likewise imposes no external reporting deadline. NIS2 asks in scope entities for an early warning within 24 hours, a notification within 72 hours, and a final report within one month.

The mistake most teams make here: they build an incident process along ISO lines, optimized for technical containment, then bolt the notification duty on as a downstream step. In a real incident the clock starts the moment anyone in the organization becomes aware, not the moment the security team escalates to management.

An integrated process asks one extra question at the first ticket: could personal data be involved? The same logic applies when several duties overlap, because the deadlines run in parallel rather than in sequence, which we work through in our guide to NIS2 requirements interpreted through the ISO 27001 lens.

What SOC 2 adds on top

SOC 2 is the framework where European teams make the most incorrect assumptions, because it comes from a different assurance tradition. It is published by the AICPA, performed by a public accounting firm, and it ends in a report rather than a certificate.

The five Trust Services Criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy. Only Security is mandatory, tested through the Common Criteria CC1 to CC9, and the remaining four enter the scope of the engagement only if you deliberately include them. In practice, SaaS vendors usually select Security plus Availability and Confidentiality, because that combination matches what buyers ask about. The Privacy criterion is rarely chosen in Europe, since GDPR already regulates the same questions in more detail and to a higher standard.

The second difference is the time axis. A Type I report describes whether the controls were suitably designed as of a single date. A Type II report additionally tests whether they operated effectively across a period, typically three to twelve months, and enterprise buyers almost always ask for Type II with a twelve month period.

A second false assumption that regularly gets expensive: because a SOC 2 report has no expiry date, teams assume it can be used indefinitely. What buyers expect is a report whose examination period picks up where the previous one ended, with no gap in between. For the stretch between the end of that period and today's date, they ask for a bridge letter, in which management confirms that nothing material has changed. Let the rhythm slip once and you will be explaining the gap in every deal for the following year.

Your evidence practice therefore has to be designed around time series rather than audit dates. What we cover for this framework is set out on our page on SOC 2 compliance.

One control set for three frameworks

Integration rests on three building blocks: a shared control set, a central evidence repository, and a merged assurance calendar. You can introduce each one independently, and each one reduces effort immediately.

The shared control set is the foundation. Instead of maintaining three catalogs of measures, you define a measure once and record which requirements it satisfies. Your encryption policy satisfies A.8.24, CC6.7, and Article 32(1)(a) in one go, and framework specific additions sit on top only where no overlap exists. In practice you run one security and privacy policy management rather than three.

The central evidence repository makes sure that a piece of evidence collected once counts for every purpose. For that to work, evidence needs consistent metadata: collection date, responsible owner, validity period, and the requirements it relates to. The validity date is where home built folder structures fail, because SOC 2 Type II expects an unbroken history. Where evidence itself contains personal data, screenshots from an HR system being the usual example, data minimization under Article 5(1)(c) applies to your compliance program too.

The merged assurance calendar gives time back to the business functions. If your internal audit under clause 9.2 and your privacy review happen in the same session, the process owner gets interviewed once instead of twice. That is less a question of efficiency than of data quality, because people answer the second interview on the same topic more briefly.

A worked example

Take a SaaS company with 45 employees. It has covered GDPR for years with an external data protection officer, it is pursuing ISO 27001 because procurement teams in its core European markets ask for the certificate, and it needs a SOC 2 report because two US customers require one. Its Statement of Applicability marks 74 of the 93 controls as applicable. Its record of processing activities holds 38 entries, including 12 processors, three of them based in the US and needing a transfer impact assessment.

The mapping produces the pattern you would expect. Most security measures count for all three frameworks, and the remaining work falls into three blocks you can budget separately: the five privacy specific obligations, the time series evidence for SOC 2 Type II, and the management system clauses 4 to 10 for ISO 27001. The effort shifts from "everything three times" to "security once, plus three additions", and one internal owner at 50 percent capacity can run that structure once the mapping is in place. Comparable project timelines are documented in our customer success stories.

Roadmap and sequencing

Starting all three frameworks at once regularly fails, because the volume of change is more than the organization can absorb. The sequence that works starts with the management system and hangs the market driven requirements off it.

  1. ISO 27001 first (4 to 9 months to certification, owner: ISMS lead). The standard supplies the structure, the risk methodology, and the control catalog, and Annex A already covers most of the SOC 2 Common Criteria.
  2. Close the GDPR gaps (in parallel from month 2, owner: data protection officer). Build the five uncovered obligations and connect them to the ISMS, above all by reconciling the record of processing activities against the asset inventory.
  3. SOC 2 Type I (after the ISO certificate, owner: compliance). A Type I report confirms the design of your controls as of a date and is the cheapest way to find gaps before the Type II period starts.
  4. SOC 2 Type II (examination period of 3 to 12 months immediately afterward, owner: compliance). From here on, evidence management runs permanently rather than as a project with an end date.

One note on currency: the transition period from ISO 27001:2013 to the 2022 version ended on October 31, 2025, and certificates issued against the old version have not been valid since. If your mapping still rests on the 114 controls of the 2013 version, you are working against a structure that no longer exists.

What drives the effort

Reliable total cost figures depend so heavily on the individual case that blanket numbers mislead. Knowing the drivers is more useful, because those are the variables you can change.

Cost driver What increases it What reduces it
Scope Including every location and system Limiting it to the product and its infrastructure, extending later
Audit fees Two separate examinations for ISO and SOC 2 Aligning the examination periods, reusing evidence across both
Internal effort Collecting evidence by hand, shortly before the audit Automated collection with expiry dates, continuous rather than periodic
Number of processors Many vendors, several third countries Consolidating, favoring EU providers, reusing TIA templates
Documentation maturity Policies scattered across documents and drives Central policy management with versioning and approvals

The third driver has the most room to move. Audit fees are largely fixed and set by the certification body or the CPA firm, while the internal cost of collecting evidence is not, and it decides whether compliance stays a project with an end or becomes a permanent draw on capacity.

How Kertos brings the three frameworks onto one platform

Kertos runs ISO 27001, GDPR, and SOC 2 from a single control set. You record a measure once and see which Annex A requirements, which Common Criteria, and which GDPR articles it satisfies. Evidence is collected automatically from your systems through integrations, tagged with an expiry date, and mapped to every framework that needs it. The time series a Type II report expects then accumulates as a byproduct of normal operations instead of becoming its own project.

The modules sit in the same environment rather than in separate tools that need reconciling. The management system clauses 4 to 10, the Statement of Applicability, and the Annex A controls with their evidence live in the Kertos ISMS module.

Privacy work sits next to it rather than in a separate system with a separate owner. Because both draw on the same asset inventory, adding a system raises the security and the privacy question at the same moment. The record of processing activities, data processing agreements, sub-processor records, and data subject requests with their deadlines are handled in the privacy management module.

Risk is the third piece, and keeping it in one methodology stops a DPIA and an ISMS risk assessment on the same processing activity from reaching conclusions that contradict each other. Security risks and risks to data subjects are held side by side in the risk management module.

The platform is operated in the EU, and every customer project is accompanied by certified experts who set the mapping up with you rather than handing it to you as a task. When further frameworks arrive, whether NIS2, TISAX, ISO 27701, or the EU AI Act, you lay them against the control set you already have. An overview of every standard we support is on the compliance frameworks page.

Frequently asked questions

Does ISO 27001 certification replace GDPR compliance?

No. An ISO 27001 certification substantially demonstrates the security of processing requirements in Article 32 GDPR, but it does not cover central obligations including the lawful basis under Article 6, the record of processing activities under Article 30, and data subject rights under Articles 12 to 23. As a formal means of demonstrating compliance under Article 42 GDPR, no ISO standard has been approved to date.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard against which an accredited certification body examines your management system and issues a certificate valid for three years. SOC 2 is an assurance engagement against the AICPA Trust Services Criteria, performed by a public accounting firm, and it ends in a report rather than a certificate. ISO 27001 is the market standard in Europe, while SOC 2 dominates US business and SaaS procurement.

Is there such a thing as a SOC 2 certification?

No. A SOC 2 engagement produces a SOC 2 report, either Type I for a single point in time or Type II for a period of typically three to twelve months. The term "SOC 2 certification" is widely used and technically incorrect, and auditors read its use as a signal that the speaker has not been through the process before.

Do I need ISO 27001 and SOC 2 at the same time?

That depends on your sales motion rather than on your technology. If your European buyers ask for a certificate during procurement, you need ISO 27001. If you sell to US companies or to groups with a US parent, a SOC 2 Type II report is usually the requirement. Because the security requirements overlap so heavily, the second framework is much less work after the first than starting over.

Which ISO 27001 controls are most relevant to data protection?

The most directly relevant are A.5.34 on privacy and protection of personally identifiable information, A.8.24 on cryptography, A.8.11 on data masking, A.8.10 on information deletion, A.8.12 on data leakage prevention, and A.5.15 together with A.8.5 on access control and authentication. Many organizational controls contribute as well, incident management in A.5.24 to A.5.28 being the clearest example, because breach notification under Articles 33 and 34 depends on it working.

Three frameworks, one program

The question is not whether you bring ISO 27001, GDPR, and SOC 2 together, but when. For as long as the three run separately, you document the same measures three times and accept the risk that the three descriptions drift apart.

The mapping work happens once and takes two to four weeks for most organizations. The cost of maintaining three separate programs recurs every year, and it grows with every additional framework the market asks of you.

Book a Kertos demo and we will go through your existing mapping together, including the question of which of your current evidence can be counted toward all three frameworks.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Catherine Higginson

Catherine Higginson

Senior Content Marketing Manager

Catherine is a content marketer with several years of experience across DACH and European SaaS, drawn to the challenge of making complex, regulated technology, healthcare, fintech, compliance, make sense to the people who have to buy it. She's built go-to-market strategy from the ground up, translated technical depth into positioning that lands with both engineers and commercial buyers, and worked directly with founders and product

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check