ISO 27001 And SOC 2,
Implemented To Pass And To Hold

The certificate is the milestone, a working security programme is the point. IrisInfosec implements ISO 27001, ISO 27701, ISO 42001, SOC 2 and NIST CSF 2.0 as one control set, prepares your evidence and stands beside you through the audit. We design for the certificate and for the year after it, so your second audit is a review, not a rebuild.

1

Control set producing evidence for several frameworks.

3-9 Months

Typical ISO 27001 or SOC 2 readiness timeline.

Audit

We prepare you and stand beside you through it.

Sustain

Maintained through surveillance, not left to lapse.

What this covers

One Foundation, Several Certificates

ISO 27001, SOC 2 and NIST CSF share most of their underlying controls. Run them as separate projects and you pay for the same work three times. We build one management system and one control set, then produce the specific evidence each standard requires.

The aim is a programme your teams can operate, not a binder that satisfies an auditor once and then drifts out of date. That is the difference between passing an audit and being secure.

In one line

Framework implementation is the work of designing, documenting and operating the controls a standard requires, then preparing the evidence and supporting you through certification or attestation.

Frameworks we implement

The Standards Your Customers And Auditors Ask For

Implemented from one foundation, so adding the next framework is an extension, not
a fresh start.

ISO 27001

The international information security management standard. The backbone most other frameworks extend from.

ISO 27701

The privacy extension to ISO 27001, aligning your information security and privacy management in one system.

ISO 42001

The AI management system standard, for organisations that build or deploy AI and want to govern it credibly.

SOC 2 (Type I & II)

The attestation report US customers expect, against the trust services criteria, at a point in time or over a period.

NIST CSF 2.0

A risk-based framework with the new Govern function, useful as an organising backbone across the others.

CIS, CSA STAR & FedRAMP

Benchmarks and cloud assurance schemes layered on where your sector or customers require them.

Common question

ISO 27001 Vs SOC 2

The two most requested, and the two most confused. Here is how they differ, and why
many firms run both from one programme.

ISO 27001 SOC 2
What it is Certification of a management system Attestation report on controls
Origin International standard, recognised globally US standard, common with US buyers
Covers The whole information security system Selected trust services criteria
Outcome A three-year certificate with surveillance A point-in-time or period report
Run together One control set produces evidence for both, so you are not running two parallel projects.

How we work

From Scope To Certificate

A staged programme that respects your delivery commitments and ends in evidence an
auditor accepts.

01

Scope & SoA

Define the boundary, the assets and the Statement of Applicability that frames the whole programme.

02

Gap & Risk Assessment

Measure current state against the standard and run a risk assessment that drives the treatment plan.

03

Design & Implement

Build the policies, processes and technical controls, working with your teams to make them stick.

04

Internal Audit & Review

Run internal audit and management review, then collect and organise the evidence each clause needs.

05

Certify & Sustain

Stand beside you through the external audit, then support surveillance so the certificate holds.

What you receive

Everything The Audit Will Ask For

The artefacts an external auditor will ask to see, written for your organisation and organised
against each clause.

SoA & Policy Set

A Statement of Applicability and a full policy and standards set written for your organisation.

Risk Assessment & Treatment Plan

A documented risk assessment and a treatment plan that ties every risk to an owner and a control.

Evidence & Audit Pack

Internal audit results, management review records and the evidence organised against each clause.

Built to pass, designed to hold

Get A Staged Certification Plan With Dates

Tell us your target standard and timeline. We will assess your current maturity and send a realistic plan to the certificate and beyond.

Questions, answered

Framework Implementation FAQ

ISO 27001 is an international standard that certifies an information security management system, recognised globally. SOC 2 is a US-originated attestation report against trust services criteria, common when selling to US customers. ISO 27001 certifies a system, SOC 2 reports on controls over a period. Many firms need both, so we design one control set that produces evidence for each.

A SOC 2 Type I report assesses whether controls are designed appropriately at a point in time. A Type II report tests whether those controls operated effectively over a period, usually three to twelve months. Type II carries more weight with customers because it shows controls work in practice, not just on paper.

For most mid-market organisations, a readiness programme runs three to nine months depending on scope and current maturity, followed by a two-stage certification audit by an accredited body. You get a staged plan with realistic dates after scoping.

ISO 42001 certifies an AI management system. It is relevant if you build or deploy AI and want to show responsible governance, and it pairs well with the EU AI Act. It is optional today but increasingly requested, and it reuses much of an existing ISO 27001 management system.

Yes. We run internal audit and management review, prepare your evidence, and stand beside you through the external audit. After certification we support surveillance audits so the certificate is maintained, not allowed to lapse.

Related services

Make Certification A Programme, Not A Scramble

Book a call with an advisor who has run these audits. We assess your maturity and send a staged plan to the certificate, no obligation.