SOC 2 in brief
Trust Services Criteria explained explains SOC 2 for European SaaS: CPA attestation on Trust Services Criteria (security often leading). ISO 27001 certifies an ISMS — different proof, different market.
Type I vs Type II
Type I is design at a point in time; Type II is operation over a period (often 6–12 months). Enterprise buyers usually want Type II.
Evidence and combining with ISO
Map TSC controls to your ISO SoA and risk register. Share logging, access reviews and change records — avoid duplicate policies. Use one evidence map tagged per framework.
Common mistakes
Presenting SOC 2 as ISO; no period for Type II; evidence on personal drives; manual vendor questionnaires without a register.
Checklist
- Choose Type I or II
- Map TSC ↔ ISO controls
- Shared evidence map
- Readiness scan before audit
- Link contracts and questionnaires
Practical next step
For Trust Services Criteria, ISO Ready keeps actions, evidence, risks and vendors aligned toward audit or supervision. Run the readiness scan on iso-ready.nl.
No certification guarantee — you retain ownership of scope, risks and decisions.
More in this cluster
- Soc 2 Uitleg
- Soc 2 Type 1 Vs Type 2
- Soc 2 Evidence Collection
- Iso 27001 Vs Soc 2
- Iso Audit Evidence
- Business Continuity Iso