Working through a SaaS contract with an overseas counterparty — a US company in particular — you will eventually be asked, "Do you have a SOC 2 report?" Answering with an ISO/IEC 27001 certificate often fails to land, even when the certificate is entirely valid.
The reason is that they are different kinds of artefact. ISO/IEC 27001 produces a certification: a certificate issued by an accredited certification body. SOC 2 produces an attestation report: a document, often dozens of pages, prepared by a CPA firm. One is something you either hold or do not. The other is something the counterparty reads.
This article sets out the difference in nature, the criteria each uses, the Type 1 / Type 2 distinction, and how each is disclosed — then asks which a Japanese healthcare company should pursue first. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.
Disclaimer: This article is general information. For ISMS, the authoritative sources are ISO/IEC 27001 (JIS Q 27001) and the publications of accreditation and certification bodies; for SOC 2, the attestation standards set by the AICPA and the explanations of the practitioner performing the engagement. Verify details against primary sources.
Certification vs. Attestation Report
| ISO/IEC 27001 (ISMS) | SOC 2 | |
|---|---|---|
| Artefact | A certificate | An attestation report |
| Issued by | An accredited certification body | A CPA firm |
| Basis | The international standard ISO/IEC 27001 | Attestation standards set by the AICPA |
| What it expresses | That a management system conforms to the standard | The practitioner's opinion on whether controls were suitably designed (and operating) against defined criteria |
| Disclosure | Certified organisations can be publicly listed | Generally shared with named recipients, commonly under NDA |
| How it is used | You state that you hold it | The recipient reads and evaluates the report |
The practical consequence is large. An ISO certificate communicates by being held; a SOC 2 report only works once someone reads it. In a US vendor review, a security team typically works through the report, examining the described controls and any noted exceptions.
The design philosophies also differ. ISO/IEC 27001 assesses conformity of a management system in which the organisation assesses its own risks, decides which controls apply, and justifies that in a Statement of Applicability. SOC 2 is a structure in which a practitioner expresses an opinion on the service organisation's stated controls against defined criteria. Conformity of a system, versus an opinion on controls.
What Each Is Assessed Against
ISO/IEC 27001
The management system requirements in clauses 4–10, plus the Annex A controls. The 2022 edition organises 93 controls into four themes.
| Theme | Controls |
|---|---|
| Organizational (A.5) | 37 |
| People (A.6) | 8 |
| Physical (A.7) | 14 |
| Technological (A.8) | 34 |
There is no duty to implement all 93: you decide inclusion and exclusion from your risk assessment and justify it in the SoA. See Annex A 2022 and Writing the Statement of Applicability.
SOC 2
SOC 2 works against the Trust Services Criteria (TSC), comprising five categories. Security functions as the common criteria and forms the base; the others are selected according to scope.
| Category | Concern |
|---|---|
| Security | Protection against unauthorised access; the common criteria |
| Availability | The system is available as committed |
| Processing Integrity | Processing is complete, accurate, timely, and authorised |
| Confidentiality | Protection of information designated confidential |
| Privacy | Collection, use, retention, disclosure, and disposal of personal information |
Which categories to include follows from the nature of the service and what customers care about; SaaS reports commonly add Availability and Confidentiality to Security. The included categories are stated in the report, and readers judge scope from there.
The SoA and the SOC 2 category selection play a similar role: both declare what was covered. In either scheme, read the scope statement rather than the certificate or the cover page.
Type 1 and Type 2
| Type 1 | Type 2 | |
|---|---|---|
| What is assessed | The design of controls at a point in time | The design and operating effectiveness of controls over a period |
| The question answered | "Were the controls suitably designed as of that date?" | "Did the controls operate as designed throughout the period?" |
| What you must have | Controls in place, evidenced as at the date | Controls operated over a period, with evidence accumulated |
| How counterparties treat it | Sometimes accepted as an interim first step | Usually what is actually wanted |
When a counterparty says "SOC 2," they usually mean Type 2. Because Type 2 requires evidence across an observation period, the period itself takes calendar time between having controls in place and holding a report. The length is agreed between the organisation and the practitioner; a shorter first period followed by longer annual periods is a pattern seen in practice (verify with your practitioner).
That "you need an operating period" constraint closely parallels ISO/IEC 27001's requirement for records of one completed internal audit and management review cycle. Neither can be reached by assembling documents alone. See The ISMS Timeline.
Note also that SOC 1, SOC 2, and SOC 3 serve different purposes. SOC 1 concerns internal control over financial reporting; security requests normally mean SOC 2. SOC 3 is a summary report intended for general distribution. Confirm which one is being asked for.
Who Receives It, and How
ISO/IEC 27001: you present the certificate and, as needed, share the scope and the SoA. Accreditation bodies maintain searchable registries, so the counterparty can verify independently — which also makes it easy to satisfy a mandatory-requirements box in an RFP.
SOC 2: the report is typically shared under NDA. So stating "we have SOC 2" on your website starts nothing until you hand the report over — and the moment you do, a detailed review begins. Reports may note exceptions, which can themselves become a negotiation topic.
| Situation | What works |
|---|---|
| Procurement by Japanese hospitals, pharma, or government | ISMS |
| Japanese corporate security questionnaires | ISMS — the SoA lets you answer control by control |
| US vendor reviews, enterprise SaaS contracts | SOC 2 (Type 2) |
| European deals turning on personal data | ISMS plus ISO 27701 and similar |
| Extra evidence as a cloud provider | ISO 27017 / 27018 |
See When ISMS Becomes a Condition of Trade and Choosing Not to Certify.
Maintenance Cycles
| ISMS | SOC 2 | |
|---|---|---|
| Initial | Stage 1 (documentation) → Stage 2 (on-site) | Type 1, or Type 2 with an agreed observation period |
| Maintenance | Annual surveillance audit | Normally an annual report, with periods run back-to-back |
| Renewal | Recertification every three years | No "renewal" as such — reports accumulate period by period |
| If it lapses | The certification cannot be maintained | A gap appears between report periods |
Gaps are the SOC 2 hazard. Because a report is an opinion about a period, a discontinuity invites the question "what happened in between?" Design the operation so periods run without a break.
See Preparing for Surveillance Audits and The Full Cost of ISMS Certification.
Which Comes First for a Japanese Healthcare Company?
If your main counterparties are Japanese hospitals, pharmaceutical companies, and government bodies, ISMS comes first.
- It is what procurement specifies. Hospitals must satisfy the three-ministry guidelines and are pushed to require an equivalent standard of suppliers
- It fits domestic security questionnaires. With an SoA you can answer control by control: adopted, or excluded and why
- It underpins the rest. ISO 27017/27018 and ISO 27701 build on an ISMS, and three-ministry guideline documentation is most efficiently derived from ISMS documents
Consider SOC 2 first when:
- US companies are your primary customers and vendor review explicitly demands SOC 2 Type 2
- Your battleground is enterprise SaaS in overseas markets
- The counterparty has explicitly said ISO/IEC 27001 will not substitute
Always test that last one. In practice, "ISO 27001 certificate + SoA + latest internal audit results" is frequently judged sufficient. SOC 2 is an ongoing engagement involving a practitioner; starting before the requirement is confirmed front-loads cost for nothing.
| Question | If yes |
|---|---|
| Is Japanese healthcare procurement core to the business? | ISMS first |
| Is a US enterprise explicitly demanding SOC 2 Type 2? | Begin evaluating SOC 2 |
| Is the requirement vaguely worded as "a security certification"? | Ask what evidence they want; ISMS usually suffices |
| Do you also need to prove yourself as a cloud provider? | ISMS plus ISO 27017 / 27018 |
| Is personal data the centre of the business? | Weigh ISMS vs Privacy Mark and ISO 27701 |
When You Need Both
As overseas business grows, being asked for both is a real scenario. The essential move is to keep a single underlying set of controls.
- Access control, logging, change management, vulnerability management, and supplier management are examined by both
- Evidence per control — who checked what, and when — accumulated in one place serves both engagements
- Maintaining separate records per scheme duplicates the operation and does not last
If you built the ISMS first, the risk assessment, control operation records, and internal audit machinery already exist. SOC 2 then becomes the work of assembling period evidence on top of that. The same single-hierarchy principle applies to three-ministry guideline compliance: see Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Two-Guideline Framework.
Conclusion
- ISMS is a certification; SOC 2 is an attestation report. One is held; the other is read
- The criteria differ: clauses plus 93 Annex A controls and an SoA versus the Trust Services Criteria, with Security as common criteria and other categories selected
- Type 1 covers design at a point in time; Type 2 covers operating effectiveness over a period. Counterparties usually mean Type 2, which takes the observation period in calendar time
- Disclosure differs: a certificate can be presented and independently verified; a SOC 2 report is shared under NDA and scrutinised
- For B2B healthcare in Japan, ISMS comes first — it is what procurement specifies and it underpins questionnaires and further schemes
- If both are needed, run one control and evidence base and present it in each scheme's form; separate records break down
Pottech supports ISO/IEC 27001 certification with a focus on healthcare, and we are glad to help at the stage of working out which scheme a counterparty is actually asking for. We cover scope design, templates for procedures, registers and training, project management, and internal audit, and can advise on technical controls within your product.
See ISMS Certification Support for scope and pricing, or contact us — including about requirements arising in overseas deals.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- AICPA & CIMA
- The Japanese Institute of Certified Public Accountants
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: SOC 2 criteria, report form, and observation periods are governed by AICPA standards and the explanations of the practitioner performing the engagement. ISMS requirements and the handling of certification are governed by the standard and the publications of accreditation and certification bodies. Both schemes are subject to revision.