Resources · Guides
Running SOC 2 and ISO 27001 on one set of evidence
Most evidence serves both frameworks, and the differences take most of the planning time. This guide explains how to run both as a single programme.
SOC 2 and ISO 27001 ask for many of the same things in different terms. Both cover access reviews, change management, incident response, vendor oversight, logging and encryption. A control implemented once can provide status and evidence for Trust Services Criteria CC6 and Annex A 5.15 at the same time.
The real differences between the two frameworks are structural. ISO 27001 requires a management system. This includes scope, risk assessment, a statement of applicability, internal audit, management review and continual improvement. SOC 2 requires a system description, the auditor's period, and evidence that controls operated throughout that period. A SOC 2 programme does not produce the ISMS documents. A certification audit does not produce the period evidence. Plan your calendar around these two differences.
Run both frameworks as one programme with two reporting views. Controls, evidence, policies and vendor assessments are stored once. Each framework checks its own requirements against that single set. Each auditor gets a scoped portal into the same evidence, showing whether each item is still valid. The main risk is two evidence folders that drift apart between audits. Storing everything once, with a mapping between the two frameworks, prevents this.
Reviewed September 2026.
See this approach in xmodo
A demo shows how xmodo supports the approach in this article, using the frameworks that apply to you.