CyberNova Digital

ISO 27001 vs NIST CSF vs SOC 2: which framework fits your org

These three come up in the same sentence constantly, usually in a board paper, and they are not really alternatives. They answer different questions, for different audiences, with different consequences for getting it wrong.

Choosing between them becomes much easier once you stop comparing control counts and start asking who is going to read the result.

ISO/IEC 27001: a management system you certify

ISO 27001 certifies an information security management system. The distinction matters more than it sounds. The certificate is not primarily about your controls. It is about whether you have a governed, documented, repeating process for deciding which controls you need, implementing them, checking them, and improving them.

The requirements that get audited are Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A, which holds the 93 controls in the 2022 revision, is a reference set you select from and justify. You are allowed to exclude controls. You are not allowed to exclude them without a documented reason, which is what the Statement of Applicability exists to record.

The 2022 revision reorganised the previous 114 controls into 93 across four themes: organisational, people, physical, and technological. It introduced controls covering threat intelligence, cloud service security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. The transition window for organisations still certified against the 2013 text closed on 31 October 2025, so any live certificate is now against the 2022 version.

Choose it when you sell into Europe, the Middle East, or Asia, where it is the default expectation. When you need a certificate rather than a report. When you want the externally enforced discipline of annual surveillance audits. Or when you have several standards to satisfy and want one management system sitting underneath all of them.

The cost is real. An ISMS is an ongoing operational commitment rather than a project, and the internal audit and management review obligations do not pause between certification cycles.

NIST CSF 2.0: a common language, not a certificate

There is no such thing as being NIST CSF certified. The Cybersecurity Framework is a voluntary structure for describing and organising cybersecurity outcomes, and its value lies in communication and gap analysis rather than assurance.

Version 2.0, released in 2024, made two changes that matter. It dropped the explicit United States critical infrastructure framing and is now written for organisations of any size and sector. And it added a sixth Function, Govern, alongside Identify, Protect, Detect, Respond, and Recover.

Govern covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk management. Promoting governance into the core, rather than leaving it as assumed background, is a direct acknowledgement that most programmes fail on ownership rather than on technology.

Choose it when you need to explain your security posture to a non-technical executive or board and have them follow it. When you want a structured gap assessment without committing to an audit. When you operate in or sell into the United States, where it is the shared vocabulary. Or when you are early enough that certification would be premature but you need direction.

CSF is also the cheapest of the three to begin with, because a meaningful current-state versus target-state profile can be produced with a spreadsheet and a week of interviews.

SOC 2: an attestation for your customers

SOC 2 is not a certification either. It is an attestation report written by a licensed CPA firm, describing your controls and the auditor’s opinion on them, against the AICPA’s Trust Services Criteria. The current standard is the 2017 criteria with the revised points of focus issued in 2022. The criteria themselves did not change in that revision, only the guidance on how to evidence them.

There are five criteria categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Only Security, the common criteria, is mandatory. You select the others based on what you actually promise customers. Adding Availability when your contracts carry no uptime commitment simply buys you audit scope you did not need.

Type 1 reports on whether controls were suitably designed at a point in time. Type 2 reports on whether they operated effectively across a period, typically three to twelve months. Type 1 is a milestone rather than a destination. Enterprise buyers ask for Type 2, and a Type 1 is generally read as a signal that Type 2 is on the way.

Choose it when you are a B2B software or service provider selling into the United States and SOC 2 reports are appearing in your security questionnaires and slowing your deals. The driver here is commercial, and that is a perfectly legitimate reason.

One practical note that surprises people: the report is a confidential document shared under NDA, not a logo for your website. If what your buyers want is a public trust signal, that is a different conversation.

Where they overlap

Substantially. Access control, change management, vulnerability management, logging and monitoring, incident response, vendor management, and business continuity appear in all three. The underlying work is largely shared. What differs is the evidence format and who evaluates it.

This is why sequencing usually matters more than the choice itself. Organisations that build controls once and map them to multiple frameworks spend far less than organisations running three separate compliance projects with three separate owners. Pick the framework with the broadest requirements as your backbone, which is usually ISO 27001, and treat the others as views onto the same control set.

How to actually choose

  • If a specific customer or deal is blocked, do whatever unblocks it. That is usually SOC 2 in the United States and ISO 27001 elsewhere.
  • If nobody is asking yet and you want to build well, start with a NIST CSF 2.0 assessment, then decide on certification once you know your gaps.
  • If you are regulated, start with what your regulator expects and layer commercial frameworks on top of it.
  • If you are small and the honest answer is that you have no security programme, none of these first. Build the basics, then certify them. Certifying an absence is expensive and briefly convincing.

Where POPIA sits in all this

None of the three satisfies POPIA on its own, and none of them is required by it. Section 19(3) requires you to have due regard to generally accepted information security practices, which is exactly what these frameworks are, so alignment is strong supporting evidence that you took Condition 7 seriously.

But POPIA carries obligations that no security framework covers: lawful basis for processing, purpose limitation, data subject participation rights, cross-border transfer conditions, and the specific mechanics of Section 22 notification. Treat your framework of choice as satisfying Condition 7 and roughly nothing else, then handle the other seven conditions on their own terms.

Leave a Comment

Your email address will not be published. Required fields are marked *