NIST, ISO 27001, and SOC 2: What Each Framework Is Actually For

Three frameworks that get lumped together but serve different purposes. What each is designed to do, and which one your organisation actually needs.

Frameworks are not interchangeable

NIST, ISO 27001, and SOC 2 get grouped together in security conversations as though they are variants of the same thing. They are not. They were built for different audiences, produce different artefacts, and answer different questions. Choosing between them starts with knowing which question you actually need to answer.

NIST CSF: a common language for risk

The NIST Cybersecurity Framework organises security work into five functions: Identify, Protect, Detect, Respond, and Recover. It is voluntary, flexible, and useful mainly as a shared vocabulary for describing where a programme is strong, weak, or absent.

NIST CSF is not a certification. Nobody audits you against it in the formal sense. Its value is internal: giving executives, engineers, and auditors a common way to talk about coverage and maturity.

ISO 27001: an information security management system

ISO 27001 is a certifiable international standard. Its focus is not the individual technical controls but the management system around them: how risks are identified, how controls are chosen, how effectiveness is measured, and how the whole thing is improved over time.

Certification requires an external audit. The value is that a customer or regulator can trust that a documented, working management system exists — regardless of what specific controls it implements.

SOC 2: how you handle customer data

SOC 2 is an American attestation report specifically about how a service provider handles customer data, evaluated against five “Trust Services Criteria” (security, availability, processing integrity, confidentiality, and privacy). The security criterion is the only mandatory one; the others are added based on what the business does.

SOC 2 is common in B2B SaaS because enterprise customers require it before purchase. It is less a broad security programme and more a targeted answer to “can we trust you with our data?”

Which one you actually need

  • Selling to enterprises in the US? A SOC 2 report is often the fastest unblocker.
  • Selling internationally, or subject to POPIA or GDPR scrutiny? ISO 27001 travels well.
  • Building an internal programme and want a common vocabulary? Start with NIST CSF.

Mature programmes usually pick one as the anchor, and map the others to it rather than running three parallel efforts.

Related in the Knowledge Base

Free Download

Know what an attacker sees before they do.

A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.

Free PDF · No spam · Unsubscribe anytime

Send me the checklist