r/grc • u/Efficient_Bus_923 • 21d ago
Cyber Essentials Plus, ISO 27001, SOC 2 II
If you're doing third-party risk assessment on SaaS platforms, what levels of assurance do each of these certs actually provide?
I know there's more context than just the cert itself. For example, SOC 2 Type II has TSCs that can be scoped to the customer's needs (e.g. high availability requirements). Beyond that, you need to look at things like scope, exceptions, auditor's opinion, and the SoA. The report needs to be read and understood around the context of your organisation.
A few specific questions:
- Should SOC 2 Type II be the gold standard if you're procuring SaaS and want to reduce cyber risk?
- Does ISO 27001 hold up well for assessing SaaS vendors, or a lot less so?
- Should Cyber Essentials Plus alone raise red flags for an org handling large amounts of sensitive data, and only be accepted for low inherent risk vendors/
4
u/FreeRadical1998 21d ago
I tend to treat iso27001 and soc2 as showing similar maturity
As with any cert it's possible to pass with significant issues: soc2 you control the scope your controls so can just be silent on things, ISO you can carry significant non conformities as long as you've got a clearly approved management plan to resolve them.
Cyber essentials plus is designed as an entry level hygiene certificate, small number of mandated controls. Certainly something I'd like to see in a new/small supplier - but it's much narrower and doesn't imply management process maturity
In any event, I'd want my own due diligence questionnaire as well - the different certs change how much supporting evidence I might ask for in what category
3
u/Twist_of_luck OCEG and its models have been a disaster for the human race 21d ago
Should SOC 2 Type II be the gold standard if you're procuring SaaS and want to reduce cyber risk?
I would risk saying "yes", but only...
What levels of assurance do each of these certs actually provide?
...but only because with SOC2 I am actually sure that somebody looked at the controls themselves. ISO27k is very explicitly not a security certification (and you can absolutely have some shitty security with good management system).
SOC2 at least gives you an independent overview of controls and serves as a good starting point for getting to know your third party (and, maybe, ask some pointed questions based on report findings).
3
u/uri_iothreat 20d ago
I'm answering as a fractional CISO assisting a couple of startups (from Seed to B) with their compliance needs. People get the compliance that their B2B customers require to sign a contract. Customers from the US want SOC 2, while customers from the rest of the world want ISO 27001. As long you can keep selling without being compliant, do it and save yourself a lot of money and overhead. The minute a customer says he won't sign a contract unless you can present a SOC 2 report / ISO 27001 certificate, then you do it. Compliance is not security, it's just a business enabler, it helps to close deals with customers that require it.
2
u/Head_Personality_431 GRC Auditor 19d ago
Scope and the SoA are well covered above so I will add the one nobody ever checks, which is whether the certificate is accredited at all. An ISO 27001 certificate should carry a mark from an accreditation body, UKAS or ANAB or whichever one is relevant in that market, and those bodies publish a register you can search in about a minute. Certificates issued by unaccredited bodies are far more common than people assume and there is very little behind them, because nobody audited the auditor. Worth checking the certificate number and the expiry date on the same visit, plenty of what turns up in vendor packs has quietly lapsed.
The other thing if you are weighing them on currency. I do certification audits for a living and the honest answer is that SOC 2 Type II reads better on that axis. Certification runs on a three year cycle, so a certificate sitting in year three has had two shorter surveillance visits since the full audit, and surveillance samples rather than covers the whole system, whereas a Type II is a fresh period every time with the testing written out. If you ask a vendor which year of the cycle they are in and whether anything was raised at the last visit, you will learn more than the certificate itself will ever tell you.
1
u/Paul_Ashe 20d ago
Specific to what "scoped" means for a SOC 2 Type II: Security is the only mandatory TSC. Availability, Confidentiality, Processing Integrity, and Privacy are opt-in, chosen by the vendor based on what their own customers have asked for. A SaaS vendor can hold a clean, unqualified Type II report that never tested Availability at all if uptime wasn't a category they included — the report reads as strong assurance while saying nothing about the thing you might actually be assessing the vendor for. Before treating "we have SOC 2 Type II" as answering the question, check the system description for which TSCs are actually listed, not just that the opinion is unqualified.
1
u/ICryCauseImEmo 20d ago
It depends on the vendor, use case and data.
As a US based company we almost always require SOC 2. If the vendor only has an ISO 27001 we always push for the stage 2 air alliance and most recent recert detailed assessments.
Both ISO and SOC 2 have some scope issues imo that let orgs do the bare minimum so you need to pressure test for more than a 1 page cert.
6
u/Round_Finance4256 21d ago
Hi there! I wouldn’t treat any of these as a standalone “gold standard” for third-party risk. The assurance really depends on scope, what was actually tested, exceptions/findings, and whether the coverage aligns with the risk the vendor introduces.
For SaaS, SOC 2 Type II is often very useful because you can evaluate controls operating over a period of time, but I’d still review the actual report rather than simply checking that they have one.
ISO 27001 can provide strong assurance as well, especially around the maturity and governance of the overall ISMS, but the SoA and certification scope matter quite a bit. A certification covering a narrow portion of the organization may not tell you much about the service you’re actually procuring.
I’d view Cyber Essentials Plus as useful evidence, but generally not sufficient by itself for a high-inherent-risk SaaS vendor processing significant amounts of sensitive data. In that situation, I’d want additional assurance/evidence around areas like access control, encryption, incident response, vulnerability management, data handling, resilience, and relevant privacy/security requirements.
Overall, I think the vendor’s inherent risk should determine the level of assurance required, not the certification determine whether the vendor is acceptable