Home › Basics
Basics · reviewed July 2026Which compliance framework do you actually need?
Whichever one your customer is asking for. SOC 2 is what US enterprise buyers request most often, and it is a customer requirement, not a law. ISO 27001 is what international buyers expect. HIPAA is a legal duty that applies automatically if you handle protected health information. Start from who is asking and why, not from a list of standards.
The four you are most likely to meet
- SOC 2
- US B2B software. Triggered by a customer's security review, not by law
- ISO 27001
- International certification. Expected by EU and UK enterprise buyers
- HIPAA
- A legal obligation from handling health data. Not a certification you pass
- ISO 42001
- AI management systems. New, and asked for far less often than SOC 2
Work it out in four questions
- 01
Who asked, and in what form?
A named customer in a security questionnaire is a real requirement with a date attached. "Our competitors have it" is not, and will not survive contact with a budget conversation.
- 02
Where are your buyers?
US enterprise asks for SOC 2. EU and UK enterprise asks for ISO 27001. Selling into both eventually means both, which is when cross framework mapping starts to matter in a platform choice.
- 03
Do you touch health data?
If you create, receive, store or transmit protected health information as a covered entity or business associate, HIPAA already applies. It is not optional and there is no certificate at the end.
- 04
Type 1 or Type 2?
If the customer did not specify, assume Type 2. Type 1 can be a useful staging post when a deal needs something now, but most enterprise buyers eventually want the period report.
A Type 2 report covers a window, commonly three to twelve months of operating evidence. You cannot compress it by spending more. If a deal needs a report in eight weeks, the conversation to have is about a Type 1 now and a Type 2 later, not about which platform is fastest.
Common questions
Is SOC 2 a legal requirement?
No. SOC 2 is an attestation performed by a CPA firm against criteria published by the AICPA. No law requires it. It became near mandatory in US B2B software because enterprise procurement teams ask for it during security review, which makes it a commercial requirement rather than a legal one.
Should I do SOC 2 or ISO 27001 first?
Follow your buyers. If your revenue is US enterprise, SOC 2 first. If it is European, ISO 27001 first. If you sell into both, most teams start with the one attached to the nearest blocked deal, then add the second using the overlap, which is substantial.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 attests that your controls were designed appropriately at a single point in time. Type 2 attests that they operated effectively across a period. Type 1 is faster and is sometimes accepted as an interim answer. Type 2 is what most enterprise buyers eventually require.
Can one platform cover multiple frameworks at once?
Yes, and this is what cross mapping means: one piece of evidence counted toward controls in more than one framework. How well it works varies by platform and by your control set. Ask for a demo with two frameworks live and your own controls. Do not accept the claim on the pricing page.