Security Certification
ISO 27001 and SOC 2, explained end to end — who issues a certificate, what a certification body checks at Stage 1 and Stage 2, and why SOC 2 is an attestation.
7 guides. Published by Security Brigade. Last reviewed .
Buying one
What it costs, who is qualified to do it, and what you receive at the end.
Why the firm that prepares you cannot be the firm that certifies you
No certification body may prepare you for its own audit, nor may any entity under its organisational control. Where a related body prepares you,…
Who issues an ISO 27001 certificate, and what every other party produces
An ISO 27001 programme produces four kinds of document and no party produces more than two. Who holds the certificate, the accreditation, and the…
The Indian law that names ISO 27001 — and what changes on 13 May 2027
One Indian rule names IS/ISO/IEC 27001 in its own text and deems an audited implementation compliance with the IT Act. A later Act omits the prov…
SOC 2 Type 1 and Type 2: one date, one period, and a deadline already given
A Type 1 opinion speaks about one date. A Type 2 speaks about a stretch of time that has already closed by the time anyone reads the report. Most…
"SOC 2 certified" is a phrase that cannot be true — and what you receive instead
Ask a supplier for their SOC 2 certificate and you will be sent a PDF. It will not be a certificate, and the difference changes what the document…
ISO 27001 certification: what it costs, how long it takes, and what decides both
Two quotes for the same programme, and the gap is not a discount. Half of what is sold is derived under a normative annex and can be compared lin…
Internal audit and management review: the two clauses your certifier may not do
Clause 9.2 requires an internal audit and clause 9.3 a management review. A certification body looks for both at Stage 1, again at Stage 2, and a…
Getting to the certificate
Readiness and internal audit, from a party allowed to do both.
ISO/IEC 17021-1 bars a certification body from consulting on the management system it certifies, from running your internal audits, and from marketing itself alongside one. That work is ours: gap assessment, Statement of Applicability, clause 9.2 internal audit and clause 9.3 management review, through Stage 1 and Stage 2. Security Brigade holds ISO 27001 certificate AMER24908 and publishes this site.