Skip to content
Resources · Trust

SOC 2 and ISO 27001, and What They Mean for Your Deposit

Illustration for SOC 2 and ISO 27001: What They Are and Why They Matter

When you hand a provider the materials that keep your software alive, a claim to be secure is not enough. SOC 2 and ISO 27001 are the two credentials that turn that claim into something an independent auditor has checked. Here is what each one actually proves, how they differ, and why both matter when the thing being protected is your source code.

The short version. ISO 27001 is an international standard; an accredited body certifies that you run a working information security management system. SOC 2 is an AICPA framework; a CPA firm attests, in a report, to how your controls are designed and operating. They overlap heavily. Holding both gives US and international buyers the proof in the form each expects.

Why this matters for an escrow deposit

Your deposit is only as protected as the organization holding it. Off-site physical storage is necessary but not sufficient; a buyer's risk team wants evidence that the provider's information-security controls are real, documented, and maintained. That is exactly what these two credentials supply, in independently verified form.

ISO 27001: a security system, certified

ISO/IEC 27001 is the international standard for an information security management system (ISMS), developed by ISO and the IEC. It is built around three properties of data: confidentiality (protected from unauthorized access), integrity (complete and unaltered), and availability (accessible to authorized users when needed). The current 2022 edition defines 93 Annex A controls grouped into four themes: organizational, people, physical, and technological.

An accredited external body certifies that the organization runs and maintains a conforming ISMS, not just a one-time set of controls. Certificates run on a three-year cycle with surveillance audits in between, and ISO 27001 is recognized worldwide. It is not legally required in the escrow industry, which is part of the point: pursuing it signals a commitment beyond the minimum.

SOC 2: controls, examined

SOC 2, from the American Institute of CPAs (AICPA), assesses a service organization's controls against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. The scope is customizable to the organization. Strictly, there is no SOC 2 "certificate"; a licensed CPA firm produces an attestation report, which is the document a US buyer's risk team most often asks to see.

SOC 2 comes in two forms. Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively over a period, typically several months to a year, which is the stronger evidence.

SOC 2 vs ISO 27001, side by side

The two compared
 SOC 2ISO 27001
What it isAICPA attestation of controlsInternational ISMS standard
OutputReport, attested by a CPA firmCertificate, from an accredited body
Scope5 Trust Services Criteria, customizableISMS with 93 Annex A controls
RecognitionMainly North AmericaGlobal
CadenceType II covers a period of operation3-year cycle with surveillance audits

Why hold both?

The control sets overlap heavily, but the audiences differ. ISO 27001 is the credential international buyers recognize; SOC 2 is the report US procurement teams ask for. Holding both means a buyer gets the proof in the form they expect, without a back-and-forth, and it shows a security program that is examined from two angles rather than one.

What this means for your deposit

These credentials cover how EscrowTech operates as an organization. They sit alongside two other things, not instead of them: verification, which checks whether your specific deposit would actually rebuild, and physical storage in two US-based vaults. Read more on the certifications page, or see how escrow supports a documented compliance control.

Frequently asked questions

What is the difference between SOC 2 and ISO 27001?

SOC 2 is an AICPA-governed examination that produces a report attested to by a CPA firm. ISO 27001 is an international standard under which an accredited body certifies an information security management system. The control sets overlap heavily.

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively over a period, usually several months to a year, which is the stronger form of evidence.

Is ISO 27001 a certificate and SOC 2 not?

Yes. ISO 27001 results in a certificate issued by an accredited body. SOC 2 produces an attestation report from a licensed CPA firm rather than a certificate.

Why do escrow customers care about these credentials?

Because the deposit is only as protected as the provider holding it. The credentials give a risk or procurement team independent evidence that the provider's controls are real and maintained.

Do these certifications mean my deposit will work?

No. They cover how the provider operates. Verification is the separate step that checks whether your specific deposit would actually rebuild and recover.

SOC 2 vs ISO 27001
SOC 2
  • Trust Services Criteria
  • Report on control effectiveness
  • Common in North America
  • Type I and Type II reports
ISO / IEC 27001
  • Information security management system
  • Certifiable against the standard
  • Recognized internationally
  • Continual improvement cycle

Trust that is independently checked.

See the certifications behind your deposit, and how they pair with verification and physical storage.

See our certifications → Or talk to our team
External references: AICPA: SOC 2 · ISO/IEC 27001
Call us(801) 852-8202 Get a quote