Back to Columns
ISMS & Certification12 min read

ISMS vs SOC 2: Choosing for Overseas Deals and SaaS Businesses

September 14, 2026

ISMS vs SOC 2: Choosing for Overseas Deals and SaaS Businesses
Share this article

Working through a SaaS contract with an overseas counterparty — a US company in particular — you will eventually be asked, "Do you have a SOC 2 report?" Answering with an ISO/IEC 27001 certificate often fails to land, even when the certificate is entirely valid.

The reason is that they are different kinds of artefact. ISO/IEC 27001 produces a certification: a certificate issued by an accredited certification body. SOC 2 produces an attestation report: a document, often dozens of pages, prepared by a CPA firm. One is something you either hold or do not. The other is something the counterparty reads.

This article sets out the difference in nature, the criteria each uses, the Type 1 / Type 2 distinction, and how each is disclosed — then asks which a Japanese healthcare company should pursue first. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.

Disclaimer: This article is general information. For ISMS, the authoritative sources are ISO/IEC 27001 (JIS Q 27001) and the publications of accreditation and certification bodies; for SOC 2, the attestation standards set by the AICPA and the explanations of the practitioner performing the engagement. Verify details against primary sources.

Certification vs. Attestation Report

ISO/IEC 27001 (ISMS)SOC 2
ArtefactA certificateAn attestation report
Issued byAn accredited certification bodyA CPA firm
BasisThe international standard ISO/IEC 27001Attestation standards set by the AICPA
What it expressesThat a management system conforms to the standardThe practitioner's opinion on whether controls were suitably designed (and operating) against defined criteria
DisclosureCertified organisations can be publicly listedGenerally shared with named recipients, commonly under NDA
How it is usedYou state that you hold itThe recipient reads and evaluates the report

The practical consequence is large. An ISO certificate communicates by being held; a SOC 2 report only works once someone reads it. In a US vendor review, a security team typically works through the report, examining the described controls and any noted exceptions.

The design philosophies also differ. ISO/IEC 27001 assesses conformity of a management system in which the organisation assesses its own risks, decides which controls apply, and justifies that in a Statement of Applicability. SOC 2 is a structure in which a practitioner expresses an opinion on the service organisation's stated controls against defined criteria. Conformity of a system, versus an opinion on controls.

What Each Is Assessed Against

ISO/IEC 27001

The management system requirements in clauses 4–10, plus the Annex A controls. The 2022 edition organises 93 controls into four themes.

ThemeControls
Organizational (A.5)37
People (A.6)8
Physical (A.7)14
Technological (A.8)34

There is no duty to implement all 93: you decide inclusion and exclusion from your risk assessment and justify it in the SoA. See Annex A 2022 and Writing the Statement of Applicability.

SOC 2

SOC 2 works against the Trust Services Criteria (TSC), comprising five categories. Security functions as the common criteria and forms the base; the others are selected according to scope.

CategoryConcern
SecurityProtection against unauthorised access; the common criteria
AvailabilityThe system is available as committed
Processing IntegrityProcessing is complete, accurate, timely, and authorised
ConfidentialityProtection of information designated confidential
PrivacyCollection, use, retention, disclosure, and disposal of personal information

Which categories to include follows from the nature of the service and what customers care about; SaaS reports commonly add Availability and Confidentiality to Security. The included categories are stated in the report, and readers judge scope from there.

The SoA and the SOC 2 category selection play a similar role: both declare what was covered. In either scheme, read the scope statement rather than the certificate or the cover page.

Type 1 and Type 2

Type 1Type 2
What is assessedThe design of controls at a point in timeThe design and operating effectiveness of controls over a period
The question answered"Were the controls suitably designed as of that date?""Did the controls operate as designed throughout the period?"
What you must haveControls in place, evidenced as at the dateControls operated over a period, with evidence accumulated
How counterparties treat itSometimes accepted as an interim first stepUsually what is actually wanted

When a counterparty says "SOC 2," they usually mean Type 2. Because Type 2 requires evidence across an observation period, the period itself takes calendar time between having controls in place and holding a report. The length is agreed between the organisation and the practitioner; a shorter first period followed by longer annual periods is a pattern seen in practice (verify with your practitioner).

That "you need an operating period" constraint closely parallels ISO/IEC 27001's requirement for records of one completed internal audit and management review cycle. Neither can be reached by assembling documents alone. See The ISMS Timeline.

Note also that SOC 1, SOC 2, and SOC 3 serve different purposes. SOC 1 concerns internal control over financial reporting; security requests normally mean SOC 2. SOC 3 is a summary report intended for general distribution. Confirm which one is being asked for.

Who Receives It, and How

ISO/IEC 27001: you present the certificate and, as needed, share the scope and the SoA. Accreditation bodies maintain searchable registries, so the counterparty can verify independently — which also makes it easy to satisfy a mandatory-requirements box in an RFP.

SOC 2: the report is typically shared under NDA. So stating "we have SOC 2" on your website starts nothing until you hand the report over — and the moment you do, a detailed review begins. Reports may note exceptions, which can themselves become a negotiation topic.

SituationWhat works
Procurement by Japanese hospitals, pharma, or governmentISMS
Japanese corporate security questionnairesISMS — the SoA lets you answer control by control
US vendor reviews, enterprise SaaS contractsSOC 2 (Type 2)
European deals turning on personal dataISMS plus ISO 27701 and similar
Extra evidence as a cloud providerISO 27017 / 27018

See When ISMS Becomes a Condition of Trade and Choosing Not to Certify.

Maintenance Cycles

ISMSSOC 2
InitialStage 1 (documentation) → Stage 2 (on-site)Type 1, or Type 2 with an agreed observation period
MaintenanceAnnual surveillance auditNormally an annual report, with periods run back-to-back
RenewalRecertification every three yearsNo "renewal" as such — reports accumulate period by period
If it lapsesThe certification cannot be maintainedA gap appears between report periods

Gaps are the SOC 2 hazard. Because a report is an opinion about a period, a discontinuity invites the question "what happened in between?" Design the operation so periods run without a break.

See Preparing for Surveillance Audits and The Full Cost of ISMS Certification.

Which Comes First for a Japanese Healthcare Company?

If your main counterparties are Japanese hospitals, pharmaceutical companies, and government bodies, ISMS comes first.

  1. It is what procurement specifies. Hospitals must satisfy the three-ministry guidelines and are pushed to require an equivalent standard of suppliers
  2. It fits domestic security questionnaires. With an SoA you can answer control by control: adopted, or excluded and why
  3. It underpins the rest. ISO 27017/27018 and ISO 27701 build on an ISMS, and three-ministry guideline documentation is most efficiently derived from ISMS documents

Consider SOC 2 first when:

  • US companies are your primary customers and vendor review explicitly demands SOC 2 Type 2
  • Your battleground is enterprise SaaS in overseas markets
  • The counterparty has explicitly said ISO/IEC 27001 will not substitute

Always test that last one. In practice, "ISO 27001 certificate + SoA + latest internal audit results" is frequently judged sufficient. SOC 2 is an ongoing engagement involving a practitioner; starting before the requirement is confirmed front-loads cost for nothing.

QuestionIf yes
Is Japanese healthcare procurement core to the business?ISMS first
Is a US enterprise explicitly demanding SOC 2 Type 2?Begin evaluating SOC 2
Is the requirement vaguely worded as "a security certification"?Ask what evidence they want; ISMS usually suffices
Do you also need to prove yourself as a cloud provider?ISMS plus ISO 27017 / 27018
Is personal data the centre of the business?Weigh ISMS vs Privacy Mark and ISO 27701

When You Need Both

As overseas business grows, being asked for both is a real scenario. The essential move is to keep a single underlying set of controls.

  • Access control, logging, change management, vulnerability management, and supplier management are examined by both
  • Evidence per control — who checked what, and when — accumulated in one place serves both engagements
  • Maintaining separate records per scheme duplicates the operation and does not last

If you built the ISMS first, the risk assessment, control operation records, and internal audit machinery already exist. SOC 2 then becomes the work of assembling period evidence on top of that. The same single-hierarchy principle applies to three-ministry guideline compliance: see Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Two-Guideline Framework.

Conclusion

  1. ISMS is a certification; SOC 2 is an attestation report. One is held; the other is read
  2. The criteria differ: clauses plus 93 Annex A controls and an SoA versus the Trust Services Criteria, with Security as common criteria and other categories selected
  3. Type 1 covers design at a point in time; Type 2 covers operating effectiveness over a period. Counterparties usually mean Type 2, which takes the observation period in calendar time
  4. Disclosure differs: a certificate can be presented and independently verified; a SOC 2 report is shared under NDA and scrutinised
  5. For B2B healthcare in Japan, ISMS comes first — it is what procurement specifies and it underpins questionnaires and further schemes
  6. If both are needed, run one control and evidence base and present it in each scheme's form; separate records break down

Pottech supports ISO/IEC 27001 certification with a focus on healthcare, and we are glad to help at the stage of working out which scheme a counterparty is actually asking for. We cover scope design, templates for procedures, registers and training, project management, and internal audit, and can advise on technical controls within your product.

See ISMS Certification Support for scope and pricing, or contact us — including about requirements arising in overseas deals.

References and Sources

Note: SOC 2 criteria, report form, and observation periods are governed by AICPA standards and the explanations of the practitioner performing the engagement. ISMS requirements and the handling of certification are governed by the standard and the publications of accreditation and certification bodies. Both schemes are subject to revision.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.