Home › SOC 2 + ISO 27001
Service packages

SOC 2 + ISO 27001 package

For companies selling both in the US and in Europe. We build one control system that is examined by a CPA firm (SOC 2) and an accredited certification body (ISO 27001) at the same time.

Who it is for

Product and service companies with customers on both sides of the Atlantic, EU/UK tender participants.

What's included

  • Everything in the SOC 2 package
  • ISMS scope, risk assessment and treatment
  • Statement of Applicability across 93 ISO 27001:2022 controls
  • Single TSC ↔ Annex A mapping matrix
  • Internal audit and management review
  • Support through the certification audit (stage 1 and 2)
  • One evidence set for both examinations

Result

SOC 2 report + ISO/IEC 27001:2022 certificate from an accredited body.

Duration

5–8 months to both documents (Type 2 per its observation period)

Price

Pricing on request. Fixed after scoping from five inputs — fill in the form.

Get a quote

Not sure which package? We advise in 15 minutes

Get a quote