Most framework-selection debates are unnecessary, because the decision has usually already been made by someone outside the organisation. Before comparing merits, find out what is actually being asked of you - the answer is nearly always in a stalled deal, a regulator's remit, or a contract clause.
Step 1: find the forcing function
Work through these in order and stop at the first that applies:
- Is a regulator involved? Regulatory obligations are not optional and not negotiable. In Saudi Arabia the NCA ECC or SAMA CSF may apply by sector; in the EU, NIS2 or DORA; in US healthcare, HIPAA. This decides for you.
- Are contracts requiring something specific? Read the security schedules in your signed contracts and your largest pipeline deals. Organisations regularly discover they already committed to a certification nobody pursued.
- What are prospects asking for? If deals stall on the same request, that is your framework. Ask sales which specific document was requested - "SOC 2 report" and "ISO certificate" are different asks.
- Where do you sell? SOC 2 dominates North American software buying; ISO 27001 is the international default and expected across Europe, the Middle East and Asia. Selling in both usually means both eventually.
- Nothing external? Then choose for internal value, and ISO 27001 is usually the better structural choice because it builds a management system rather than producing a point-in-time report.
If the honest answer to all five is "nobody is asking", consider whether certification is the right spend at all. A gap assessment and closing the top risks may deliver more security per unit of effort than an audit nobody requested.
The main options, in one view
| Framework | Output | Best when |
|---|---|---|
| ISO 27001 | Certificate, 3-year cycle | International sales, structural rigour, several frameworks to follow |
| SOC 2 | Auditor report, annual | Selling software to North American enterprises |
| NIST CSF | No certification | Internal structuring and board reporting; pair with a certifiable standard |
| NCA ECC / SAMA CSF | Regulatory compliance | Mandated by sector and geography - not a choice |
| PCI DSS | Validation by level | You touch card data - scope-driven, runs alongside others |
| Cyber Essentials | Certificate, annual | UK public sector supply chain; fast and cheap as a first step |
Assess once, report against many
GRC Copilot maps a single control set across frameworks, so the second certification reuses the evidence you already gathered for the first.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Step 2: sequence, do not parallelise
The most expensive mistake is pursuing two frameworks simultaneously as separate programmes. The control work overlaps heavily - typically well over half - so the correct pattern is:
- Build one control set, mapped to the framework your forcing function selected.
- Certify or attest against that one.
- Map the same controls to the second framework and close only the genuine delta.
Done this way the second framework typically costs a fraction of the first. Done as parallel programmes, it costs nearly double and produces two sets of evidence for the same controls - which is also harder to maintain forever after.
One sequencing nuance worth knowing: SOC 2 Type II and ISO 27001 both need accumulated evidence, so whichever you start with sets the clock. If you need both and have no strong preference, starting with ISO 27001 tends to build the governance layer that SOC 2 assumes you already have.
Step 3: scope before you commit to a date
Scope drives cost more than framework choice does. A tightly scoped ISO certificate covering one product and its supporting functions is far cheaper than an enterprise-wide one, and it satisfies most customer requests. You can widen later; you cannot easily narrow without explaining why.
Be careful that the scope is defensible. A certificate whose scope excludes the product the customer is buying invites exactly the question you did not want.
Common mistakes
- Choosing by what competitors have rather than what your buyers ask for.
- Committing to an audit date before the gap analysis. This is how programmes fail publicly.
- Treating a regulatory obligation as satisfied by a voluntary certificate. ISO 27001 does not discharge an ECC or DORA obligation, though it helps considerably.
- Buying tooling before knowing the control set.
- Ignoring the recurring cost. Every framework adds annual surveillance, evidence collection and internal effort - forever. Three frameworks is a permanent operating commitment, not three projects.
Frequently asked questions
ISO 27001 or SOC 2 first?
Follow your buyers. North American enterprise software sales tend to demand SOC 2; international and Middle East buyers expect ISO 27001. Where both apply, ISO first often makes SOC 2 cheaper.
How much does the second framework cost?
Typically a fraction of the first if you mapped controls rather than rebuilding - the cost is the audit plus the genuine delta, not another full programme.
Can we do a framework without certifying?
Yes, and it is often sensible - adopt the control set for internal value and certify later when a customer requires evidence.
Do we need a consultant?
Helpful for a first certification where you do not know what "good" looks like. Keep ownership internal - an outsourced management system nobody internally understands fails at the first surveillance visit.
Key takeaways
- Regulators and contracts usually decide for you - look before debating merits.
- Sequence frameworks and reuse controls; parallel programmes nearly double the cost.
- Scope drives cost more than the choice of framework.
- Every framework is a permanent operating commitment, not a one-off project.