SOC 2 vs ISO 27001 vs CPCSC

SOC 2 vs ISO 27001 vs CPCSC

Three security frameworks, three different buyers, three different ways of proving you meet them. Here is how to tell which one your contract or customer is actually asking for.

Side-by-side comparison

DimensionSOC 2ISO 27001CPCSC
OriginUnited States (AICPA)International (ISO/IEC)Canada (federal government)
OutputAudit report (Type I or II)Certificate (3-year with surveillances)Level 1: self-attestation. Level 2: certification, once live
Primary buyersUS enterprise buyersEuropean and global enterprise buyersCanadian defence contracts (National Defence)
StructureTrust Services Criteria (TSC)ISMS clauses + Annex A controlsITSP.10.171, tiered at 13, 98, or 200 controls
Who attests or assessesAICPA-licensed CPA firmAccredited certification body (BSI, SGS, etc.)Level 1: you. Level 2: a Standards Council of Canada-accredited body
TimelineType I: 3 to 5 months. Type II: 8 to 14 months6 to 12 months to certificationLevel 1 live now. Level 2 expected in 2027, no month published
RenewalAnnual auditAnnual surveillance + 3-year recertificationLevel 1: annual self-assessment. Level 2: annual affirmation
ScopeDefined system scopeFull ISMS scopeSpecified Information named in the contract
Risk assessmentImplicit in TSC criteriaExplicit, mandatory, documentedScoping exercise against Specified Information, per ITSP.10.171

CPCSC facts sourced from canada.ca's CPCSC program overview. Full breakdown on what CPCSC requires.

Who asks for each

Different buyers, different frameworks

SOC 2: US SaaS buyers

The default ask from US enterprise procurement. If your pipeline is mostly US B2B SaaS deals, a security questionnaire or vendor review will almost always ask for a SOC 2 report before it asks for anything else.

ISO 27001: international and EU buyers

The standard European, UK, and global enterprise buyers recognize and often require. Government and regulated-industry procurement outside North America leans on ISO 27001 more than SOC 2.

CPCSC: Canadian defence contracts

Applies when a National Defence contract says it applies, not as a blanket rule for every Canadian supplier. It shows up as a clause in select solicitations and contracts, tracked through your CanadaBuys profile.

How each is attested

Report, certificate, or self-attestation

SOC 2: a CPA firm’s audit report

An AICPA-licensed CPA firm examines your controls and issues a report (Type I or Type II). It is an attestation engagement, not a certification, and the report itself is what you hand a customer.

ISO 27001: an accredited certification body

A certification body accredited to audit against ISO/IEC 27001 runs a two-stage audit and issues a certificate valid for three years, with surveillance audits in between.

CPCSC: it depends on the level

Level 1 is a self-assessment: you attest to your own environment and post the result, with its expiry date, to your CanadaBuys profile. Level 2, once live, moves to an external assessment by a certification body accredited by the Standards Council of Canada, plus an annual affirmation.

Control overlap

Where the work reuses

All three frameworks touch the same handful of security domains: access control, incident response, change management, risk assessment, and vendor or supplier management. SOC 2's Common Criteria and ISO 27001's Annex A overlap heavily for exactly this reason, and a program built for one accelerates the other.

CPCSC is built on ITSP.10.171, the Canadian Centre for Cyber Security's standard modeled on NIST SP 800-171, organized into 17 security requirement families that cover much of the same ground: access control, incident response, configuration management, and risk assessment among them. If you have already built SOC 2 or ISO 27001, most of your existing policies and controls map onto CPCSC's requirement families, even though CPCSC's tiered control count (13, 98, or 200) and self-attestation model at Level 1 are structured differently from either.

Timelines

How long each one takes

SOC 2

Type I: 3 to 5 months. Type II adds an observation period, typically bringing the total to 8 to 14 months.

ISO 27001

4 to 12 months to initial certification for most startups, depending on size, then annual surveillance audits and a full recertification audit in year three.

CPCSC

Level 1 is live now and self-run once you have scoped your Specified Information. Level 2 is under development, expected in select defence contracts in 2027; canada.ca has not published a month.

Which do you need?

Selling to US enterprise SaaS buyers

Start with SOC 2. It is the near-universal ask in US B2B procurement, and Type II is what most enterprise deals eventually require.

Selling to European, UK, or global enterprise buyers

Start with ISO 27001, or run it alongside SOC 2 if you sell into both markets. The control overlap means the second framework costs less than the first.

Holding or bidding on a National Defence contract

CPCSC applies only if your contract requires it, at the level the contract specifies. Check your CanadaBuys profile and the contract terms before assuming a level.

Selling across all three markets

Sequence matters less than scoping. Map which controls each framework already shares before starting the second or third, so you are not rebuilding the same access review process three separate times.

Frequently asked

Do I need SOC 2, ISO 27001, or CPCSC?

It depends on who is asking. US enterprise SaaS buyers ask for SOC 2. European, UK, or global enterprise buyers ask for ISO 27001. CPCSC only applies if a National Defence contract names it, at the level that contract specifies.

What is the difference in how each is attested?

SOC 2 is an audit report issued by an AICPA-licensed CPA firm. ISO 27001 is a certificate issued by an accredited certification body after a two-stage audit. CPCSC Level 1 is a self-assessment you attest to yourself; Level 2, once live, will be an external assessment by a Standards Council of Canada-accredited body.

Can one framework satisfy more than one requirement?

Not directly. Each framework has its own attestation and its own buyer expectations, so a SOC 2 report will not substitute for an ISO 27001 certificate or a CPCSC attestation. What does carry over is the underlying work: access control, incident response, and risk assessment controls built for one framework reduce the effort for the next.

When does CPCSC apply to my company?

When a National Defence contract or solicitation says it applies. It is not a general small-business cyber security law. The contract identifies the Specified Information in scope and the CPCSC level required, and Level 1 attestation is completed at contract award, with the result posted to your CanadaBuys profile.

Is ISO 27001 required for Canadian government contracts?

Not by default. ISO 27001 is a globally recognized certificate that some enterprise and government buyers request or prefer, but Canadian defence contracts that carry a cyber security requirement use CPCSC, not ISO 27001, as the named program.

Does Xorabyte certify companies for any of these?

No. Xorabyte is not a CPA firm, an accredited ISO 27001 certification body, or a Standards Council of Canada-accredited CPCSC assessor. We run the readiness work: scoping, controls, evidence, and preparing you for whichever body issues the actual report, certificate, or assessment.

Related: SOC 2 readiness, ISO 27001 readiness, what CPCSC requires, SOC 2 readiness engagement, CPCSC readiness engagement

Get help scoping the right framework