GRC Migrate

Home › Basics

Basics · reviewed July 2026

Which compliance framework do you actually need?

Short answer

Whichever one your customer is asking for. SOC 2 is what US enterprise buyers request most often, and it is a customer requirement, not a law. ISO 27001 is what international buyers expect. HIPAA is a legal duty that applies automatically if you handle protected health information. Start from who is asking and why, not from a list of standards.

The four you are most likely to meet

SOC 2
US B2B software. Triggered by a customer's security review, not by law
ISO 27001
International certification. Expected by EU and UK enterprise buyers
HIPAA
A legal obligation from handling health data. Not a certification you pass
ISO 42001
AI management systems. New, and asked for far less often than SOC 2
Who is askingand put it in writingA US customerSOC 2Most common ask in US softwareA European customerISO 27001Expected by EU and UK enterpriseNobody. You handle health dataHIPAAApplies by law, asked for or not
Start from who is asking. Only one of these three arrives without a request.

Work it out in four questions

  1. 01

    Who asked, and in what form?

    A named customer in a security questionnaire is a real requirement with a date attached. "Our competitors have it" is not, and will not survive contact with a budget conversation.

  2. 02

    Where are your buyers?

    US enterprise asks for SOC 2. EU and UK enterprise asks for ISO 27001. Selling into both eventually means both, which is when cross framework mapping starts to matter in a platform choice.

  3. 03

    Do you touch health data?

    If you create, receive, store or transmit protected health information as a covered entity or business associate, HIPAA already applies. It is not optional and there is no certificate at the end.

  4. 04

    Type 1 or Type 2?

    If the customer did not specify, assume Type 2. Type 1 can be a useful staging post when a deal needs something now, but most enterprise buyers eventually want the period report.

The scheduling fact that surprises people

A Type 2 report covers a window, commonly three to twelve months of operating evidence. You cannot compress it by spending more. If a deal needs a report in eight weeks, the conversation to have is about a Type 1 now and a Type 2 later, not about which platform is fastest.

Common questions

Is SOC 2 a legal requirement?

No. SOC 2 is an attestation performed by a CPA firm against criteria published by the AICPA. No law requires it. It became near mandatory in US B2B software because enterprise procurement teams ask for it during security review, which makes it a commercial requirement rather than a legal one.

Should I do SOC 2 or ISO 27001 first?

Follow your buyers. If your revenue is US enterprise, SOC 2 first. If it is European, ISO 27001 first. If you sell into both, most teams start with the one attached to the nearest blocked deal, then add the second using the overlap, which is substantial.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 attests that your controls were designed appropriately at a single point in time. Type 2 attests that they operated effectively across a period. Type 1 is faster and is sometimes accepted as an interim answer. Type 2 is what most enterprise buyers eventually require.

Can one platform cover multiple frameworks at once?

Yes, and this is what cross mapping means: one piece of evidence counted toward controls in more than one framework. How well it works varies by platform and by your control set. Ask for a demo with two frameworks live and your own controls. Do not accept the claim on the pricing page.