Sentrix

Analysis · Compliance

SOC 2 or ISO 27001: which comes first for a SaaS

A SOC 2 attestation report or ISO/IEC 27001 certification: what each one proves, what Quebec's Law 25 requires either way, and the order to follow for a SaaS.

By Sentrix · Published 2026-10-01

A software company in Quebec City receives two emails in the same week. A customer in Boston wants to read the latest SOC 2 report before signing. A prospect in Munich requires the ISO/IEC 27001 certificate in its call for tenders. Same service, same security, two different documents, and the team cannot run both projects at once. It has to choose an order.

What the sources say

SOC 2 is an attestation report. The AICPA describes SOC as a suite of services that certified public accountants (CPAs) provide on the controls of a service organization. A SOC 2 report covers controls relevant to security, availability, processing integrity, confidentiality or privacy: the five categories of the trust services criteria, which the AICPA calls outcome-based. The deliverable is a report the customer reads, not a certificate.

ISO/IEC 27001 is a standard, and the certificate comes from a third party. The third edition, published in October 2022 and amended in 2024, sets the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). ISO states that it does not perform certification and does not issue certificates: an external certification body provides the written assurance that the system meets the requirements. The ISO Survey 2022, cited on the standard's page, counts over 70,000 certificates in 150 countries.

The two overlap, and the AICPA documents it. The institute publishes a mapping that compares the requirements of ISO 27001 to the relevant categories of its criteria.

Law 25 names neither. Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25 (2021, chapter 25), requires security measures that are reasonable given, among other things, the sensitivity and the quantity of the information (section 10). It adds:

  • a person in charge of the protection of personal information, by default the person with the highest authority, whose title and contact information are published (section 3.1);
  • governance policies and practices (section 3.2);
  • a privacy impact assessment (PIA) for any project to acquire, develop or overhaul an information system involving personal information (section 3.3), and before any communication outside Quebec (section 17);
  • notice to the Commission d'accès à l'information and to the persons concerned when an incident presents a risk of serious injury (section 3.5), and a register of incidents (section 3.8).

Why it matters

QuestionSOC 2ISO/IEC 27001
NatureAttestation reportCertifiable standard
Who assessesA CPA, against the AICPA's criteriaAn external certification body, never ISO
Privacy componentPrivacy categoryISO/IEC 27701:2025, a standalone standard aligned with ISO/IEC 27001

A certificate ticks a box in a call for tenders; a report is read and discussed with the buyer's security team. Demand generally follows the origin of the framework: SOC 2 comes from the American accounting profession, ISO/IEC 27001 from an international standards body. But the only measure that counts is the document your customers name in their questionnaires and contracts.

Law 25, for its part, puts a Quebec software company on both sides of the contract. As an enterprise, it carries the obligations above, and section 17 applies as soon as it entrusts personal information to a service provider outside Quebec. As a service provider, it falls under section 18.3: its customer must entrust the contract in writing and specify the protection measures in it; the provider must notify the customer's person in charge without delay of any violation or attempted violation of confidentiality, and allow any verification. A SOC 2 report or an ISO certificate feeds that verification, without replacing the contract or the notice.

What we think at Sentrix

The right order depends on your contracts, not on the prestige of a framework. In order:

  1. Count the real demand. Go back through the questionnaires and clauses of the past year: which document is named, by whom, for what revenue.
  2. Build the foundation once. Inventory, risk assessment, access, logging, incidents, suppliers. Each control is written once, with its owner and its evidence, then linked to both frameworks starting from the AICPA mapping.
  3. Build Law 25 into the foundation, not after it. A published person in charge, governance policies, PIAs, a register of incidents, written contracts with your service providers: these obligations already apply, whichever framework you pick.
  4. Choose the first deliverable by the market that signs first. American contracts waiting for a report: SOC 2. European calls for tenders requiring a certificate: ISO/IEC 27001. If demand is equal, start with the ISMS, whose risk management and continual improvement will serve the SOC 2 examination.
  5. Plan the second one from the start. Same scope, same evidence, two staggered assessments rather than two projects.
  6. Do not confuse privacy with Law 25. The Privacy category of SOC 2 and ISO/IEC 27701 demonstrate a personal information protection program; neither attests compliance with Law 25.

The next step

Open your last three security questionnaires and highlight the name of the document required. If the same one comes up three times, you have your answer; otherwise, the contract that signs first decides. The Law 25 page of the site summarizes the obligations to build into the foundation.

Sources

Frequently asked questions

Is SOC 2 a certification, like ISO 27001?
No. SOC 2 is an attestation report: a certified public accountant (CPA) examines the controls of a service organization against the AICPA's trust services criteria, then issues a report. ISO/IEC 27001 is a standard: an external certification body issues a certificate stating that the management system meets the requirements. ISO itself points out that it does not perform certification and does not issue certificates.
Does a SOC 2 report or an ISO 27001 certificate prove compliance with Law 25?
No. The Act requires reasonable security measures (section 10), but also a person in charge of the protection of personal information, governance policies, privacy impact assessments, notice to the Commission d'accès à l'information when an incident presents a risk of serious injury, and a register of incidents. Both frameworks help demonstrate security; the other obligations remain untouched.
Do you have to redo everything to obtain the second one?
No. The AICPA itself publishes a mapping between its trust services criteria and the requirements of ISO 27001. A control written once, with its owner and its evidence, links to both frameworks. What changes is the assessor and the deliverable: a CPA and a report on one side, a certification body and a certificate on the other.

Let's talk about your compliance program.

Last updated: 2026-10-01