Guide · September 2026
SOC 2 vs ISO 27001 vs PCI DSS, compared
The three frameworks buyers confuse most. They answer different questions, for different audiences, with different outputs — here they are side by side.
| SOC 2 | ISO 27001 | PCI DSS | |
|---|---|---|---|
| What it is | AICPA attestation framework for service organizations' controls | International standard for an information security management system (ISMS) | The payment card industry's data security standard |
| Who issues it | A licensed CPA firm issues the report | An accredited certification body issues the certificate | A Qualified Security Assessor (QSA) validates; smaller merchants may self-assess |
| Certificate or not? | Not a certification — it is an attestation report | Yes — a certificate, typically on a 3-year cycle with surveillance audits | Validation — a Report on Compliance or Attestation of Compliance, not a certificate |
| Who asks for it | Enterprise B2B customers doing vendor due diligence | International customers and regulated industries wanting certified assurance | Card brands — required of anyone storing, processing, or transmitting cardholder data |
| What it covers | Controls against the Trust Services Criteria (Security required; Availability, Confidentiality, Processing Integrity, Privacy optional) | The ISMS: risk assessment, Annex A controls, continual improvement | Cardholder data environment: network, access, encryption, monitoring, testing |
| Time dimension | Type 1 is point-in-time; Type 2 covers an observation period (typically 6–12 months) | Certification audit in stages, then annual surveillance | Annual validation (plus quarterly scans for most merchants) |
Can you do more than one?
Yes — and many companies do. SOC 2 and ISO 27001 pair well because the evidence overlaps heavily; one evidence set can support both. PCI DSS is non-negotiable if you touch cardholder data, regardless of the others. If you're weighing combinations, start with the which-framework guide, then compare providers in each directory:
- soc2type2.com — SOC 2 auditors, cost guides, quotes
- bsicertification.com — ISO 27001 certification bodies and guides
- pcidsscompanies.com — PCI DSS providers and QSAs
The vocabulary test. If a provider offers you a "SOC 2 certificate" or a "guaranteed PCI certification," walk away — the words themselves prove they don't understand the frameworks. SOC 2 produces a report. ISO 27001 produces a certificate. PCI DSS produces a validation.
Get quotes for your framework
One brief, matched providers, competing scoped quotes. Free, no obligation.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.