ISO 27001 and SOC 2: the evidence your enterprise buyers demand
Every enterprise prospect vets you before they buy. In the vendor security review, security questionnaires, a signed DPA and certification evidence decide the deal. We make you provable: ISO 27001 through to certification by an accredited body, and SOC 2 readiness with a coordinated attestation, from one team.
Lead Auditor ISO 27001 (BSI)DE · FR · ENindependent, no in-house SOC business
For B2B SaaS providers who want to win enterprise and US deals
ISO 27001
certification via accredited body
SOC 2
readiness & coordinated attestation
Cloud controls
ISO 27017 / 27018
vCISO
keeps the ISMS alive
CH · EU · UK · US
multilingual DE/FR/EN
Responsible for this mandate
Philipp Staiger
M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)
Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.
In a vendor security review, certifications are not decoration, they are the entry ticket. Without them the deal stalls in procurement.
Before an enterprise customer buys your software, their third-party risk management vets you as a supplier. Procurement sends security questionnaires such as CAIQ or SIG, requires a signed data-processing agreement and asks for certification evidence. A valid ISO 27001 certificate or a current SOC 2 report answers a large share of these questions at once.
Which proof counts depends on the customer market. ISO 27001 is the internationally and EU-expected standard for an information-security management system. SOC 2 is the report most often requested by US and enterprise customers, frequently as Type II over an observation period. Sellers who address both markets often need both in practice.
For cloud-specific questions, ISO 27017 and ISO 27018 extend the ISMS with controls for cloud services and the protection of personal data in the cloud. That addresses exactly the points on data residency, tenant separation and sub-processor management that recur in questionnaires.
How SIDD delivers ISO 27001 and SOC 2
One team for both frameworks, with clear role allocation: we build, review and coordinate, while certification and attestation come from the bodies licensed for them.
For ISO 27001 we build your information-security management system up to certification readiness: scope and applicability, risk assessment, Statement of Applicability, policies and controls, internal audits and the management review. The certification itself is issued by an accredited certification body, while we consult and guide you through stage 1 and stage 2.
For SOC 2 we deliver the readiness: a gap analysis against the Trust Services Criteria, mapping of your controls to the relevant criteria, build-out of the missing controls and preparation of the evidence collection, so that an observation period for a Type II report is cleanly documented. We then coordinate the attestation with the auditing firm. We do not issue the SOC 2 report ourselves: it is produced by a licensed audit firm (CPA firm). We make you audit-ready and steer the process.
The advantage lies in the shared foundation. ISO 27001 and SOC 2 overlap in many controls. We build the ISMS so that the same policies, risks and evidence carry both frameworks. Added to that is the legal layer from the same house: the data-processing agreement, the sub-processor list and data-protection advice feed directly into the questionnaire answers.
From baseline to certification and attestation
1. Scope & baseline
We define the scope, platform, teams and data flows, and clarify whether ISO 27001, SOC 2 or both count for your customer market.
2. Gap analysis
We compare the current state with ISO 27001 requirements and the Trust Services Criteria and map existing controls to both frameworks.
3. Build controls
Policies, risk assessment, Statement of Applicability and the missing technical and organisational measures are created, jointly for both standards.
4. Collect evidence
We set up the evidence collection so that a SOC 2 observation period is cleanly documented and ISO evidence is audit-ready at any time.
5. Internal audit
Before the external check we run internal audits and a management review and close open points, so the external assessment runs smoothly.
6. Certification & attestation
The accredited body conducts the ISO audit (stage 1 and 2), the licensed CPA firm produces the SOC 2 report. We support and coordinate both.
Why SIDD for ISO 27001 and SOC 2
For a SaaS provider, security and compliance are a sales argument, not a cost centre. We deliver both frameworks and the legal layer as one mandate.
One team for both frameworks
You do not run two separate projects. We build ISMS controls once so that they carry ISO 27001 and SOC 2 at the same time. That saves effort and avoids contradictory evidence towards your customers.
The legal layer included
The data-processing agreement, sub-processor list and data-protection advice under the revised FADP and GDPR come from the same house. So your contractual and your security evidence match, instead of contradicting each other in the questionnaire.
The vCISO keeps it alive
A certificate is not an endpoint. Our fractional CISO maintains the ISMS, runs the surveillance audit and the next SOC 2 period and keeps your evidence current, so the next vendor security review is answered fast.
Lead auditor experience
Your mandate is led by an ISO 27001 Lead Auditor. We know the assessors' expectations and prepare your documentation so that stage 2 and the attestation run without surprises.
Audit-ready evidence in tooling
We maintain policies, risks, measures and the record of processing in the Swiss Priverion Platform. For a customer or auditor request, the evidence is ready as maintained tooling, not as scattered spreadsheets.
Multilingual & independent
We advise in German, French and English, fitting customers and parent companies in CH, EU, UK and US. Because we do not sell an in-house SOC, our recommendations on controls and providers stay independent.
Entry packages ISO 27001 and SOC 2
ISO 27001 Readiness Gap Assessment
Fixed fee
Baseline of your ISMS against ISO 27001, with a prioritised action plan to certification readiness.
Scope workshop and definition of the applicability area
Gap analysis against Annex A controls and management system
Prioritised action plan with effort estimate
Board-ready results report
ISO 27001 ISMS to certification
Fixed fee / on request
Full ISMS build and support through stage 1 and stage 2 to certification by an accredited body.
Risk assessment, Statement of Applicability, policies
Optional ISO 27017 / 27018 for cloud and data-protection controls
Internal audits, management review, audit support
Coordination with the accredited certification body
Gap analysis against the Trust Services Criteria, control and evidence build and coordination of the attestation by a licensed CPA firm.
Mapping to the relevant Trust Services Criteria
Build-out of missing controls and evidence preparation
Support for the Type II observation period
Coordination of the attestation with the CPA firm
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For ISO 27001 and SOC 2, concretely: LexCommand maps your Annex A controls onto the Trust Services Criteria so the same policies and evidence carry both frameworks, and works through security questionnaires such as CAIQ or SIG question by question, each answer sourced, exported as annotated Excel.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Do you issue the SOC 2 report?
No. The SOC 2 report is produced by a licensed audit firm, a CPA firm. We deliver the readiness, that is gap analysis, mapping to the Trust Services Criteria and control and evidence build, and we coordinate the attestation with the auditing firm. We make you audit-ready, we do not issue the report ourselves.
Does SIDD issue the ISO 27001 certificate?
No. The certificate is issued by an accredited certification body that conducts the stage 1 and stage 2 audit. SIDD consults and supports you through the build and the audit, the separation between consulting and certification is maintained.
Do I need ISO 27001, SOC 2 or both?
It depends on your customer market. ISO 27001 is expected internationally and in the EU, SOC 2 mainly by US and enterprise customers. Sellers who address both markets often need both. In the baseline we clarify which proof actually blocks your deals and prioritise accordingly.
How long until the certificate or report?
It depends on the maturity of your ISMS. With a solid starting state, ISO 27001 certification is often achievable within a few months. SOC 2 Type II additionally requires an observation period in which the controls are demonstrably effective. We produce a realistic timeline after the gap analysis.
What happens after certification?
Both proofs are not a one-off. ISO 27001 requires annual surveillance audits, SOC 2 Type II a recurring observation period. Our fractional CISO keeps the ISMS alive, maintains the evidence and, together with you, answers the ongoing vendor security reviews.
Related services
How you turn the certificate into lasting fast answers and won deals: