
How to Verify ISO 27001 Certificate and SOC 2 Report
Here's how to verify ISO 27001 certificate and SOC 2 report authenticity in 15 minutes. This is a practical guide for founders, buyers, and vendor diligence teams.
COMPLIANCE


TL;DR
An ISO 27001 certificate on a vendor's website does not always mean it is genuine. A SOC 2 report handed over under NDA does not always mean it was issued by a legitimate audit firm.
ISO 27001 verification is faster because there is a public accreditation chain. Verify the certificate on the certification body's registry, verify the body's accreditation with a recognised accreditation body, and check the accreditation scope covers ISO 27001 specifically.
SOC 2 verification requires more work because there is no public registry. You verify by reading the report itself: check the CPA firm's licence, its peer review standing, the audit period, the auditor's opinion, and the exceptions.
Common failure modes: certificates from unaccredited bodies, certificates issued outside the body's accredited scope, SOC 2 reports signed by non-CPA firms, and reports past their twelve-month validity with no bridge letter.
If you are IPO-bound, selling into enterprise, or evaluating a vendor before signing, buyer diligence teams will run these checks. Better to know before they do, whether you are the vendor or the buyer.
The 15-minute verification checklist
For a founder who wants to act on this without reading further, this is the fifteen-minute version. The narrative below unpacks the mechanics behind each item.
For an ISO 27001 certificate:
Certificate is listed on the issuing certification body's public registry.
The certification body is currently accredited by a named accreditation body.
The accreditation scope covers ISO 27001 specifically, not just ISO 9001 or other standards.
The accreditation validity dates cover the certificate's issuance date.
The accreditation body is a signatory of Global ACI's MRA, or the transitional IAF MLA / ILAC MRA.
For a SOC 2 report:
The signing CPA firm has an active licence, verified through NASBA at cpaverify.org.
The CPA firm has a "pass" rating on the AICPA Peer Review Public File.
The report is a Type 2, or a Type 1 that has been correctly represented as such.
The audit period is at least six months, ideally twelve.
The auditor's opinion is unqualified.
The Trust Services Criteria in scope match what your use case depends on.
The report is under twelve months old, or a bridge letter has been provided.
If your vendor's certificate or report clears every item on this checklist, you have a document that will hold up in enterprise diligence. If it fails on any item, that item is worth a direct conversation with the vendor before you rely on the document further.
An ISO 27001 certificate on a vendor's website does not always mean what a founder thinks it means. Neither does a SOC 2 report handed over under NDA. Both frameworks have known failure modes where documentation that looks real carries no weight in serious diligence.
This post is the fifteen-minute version of the check itself. The mechanics are the same whether you are verifying your own document or a vendor's.
Why this matters, whether you are the vendor or the buyer
Two audiences read this differently.
If you are the vendor, your certificate or your SOC 2 report is going to be checked. Enterprise buyers with mature security teams run these verifications as standard practice, and the check is faster and more mechanical than founders assume. Discovering a gap in your own paperwork before an enterprise customer does is a much better outcome than discovering it during a diligence call.
If you are the buyer evaluating a vendor, the check protects you from carrying vendor risk into your own audit or into your own product's data flow. A vendor operating on an invalid certificate does not make your compliance position stronger, even if you have collected the certificate in your vendor management folder.
The mechanics of verification are the same in both cases. What follows is the same fifteen-minute exercise, framed for both use cases.
How ISO 27001 verification works
ISO 27001 has a public accreditation chain, which makes verification quick if you know what to check.
The chain works in three layers. At the top sits Global Accreditation Cooperation Incorporated (Global ACI), which replaced the International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) on 1 January 2026. Global ACI operates a Multilateral Recognition Arrangement (MRA), which is the mechanism by which national accreditation bodies recognise each other's work across borders.
Below Global ACI sit the national accreditation bodies. These are the organisations that accredit certification bodies within their country or region. The ones your ICP will most often encounter:
India — NABCB (National Accreditation Board for Certification Bodies), operating under the Quality Council of India. Registry available at nabcb.qci.org.in.
United Arab Emirates — EIAC (Emirates International Accreditation Centre). Covers ISO 27001:2022 and most other major management system standards. Registry available at eiac.gov.ae.
Saudi Arabia — SAAC (Saudi Accreditation Center), the national accreditation body under the Saudi Standards, Metrology and Quality Organization. Registry available at saac.gov.sa.
United Kingdom — UKAS (United Kingdom Accreditation Service).
United States — ANAB (ANSI National Accreditation Board).
Other regions have their own equivalents (JAS-ANZ in Australia and New Zealand, EGAC in Egypt, and so on). The mechanic is the same: whatever national body is named on the certificate, verify against that body's registry.
At the bottom sit the certification bodies themselves, which are the organisations that audit companies and issue certificates. Familiar names include BSI, DNV, TÜV SÜD, TÜV Rheinland, Bureau Veritas, SGS, and Intertek, among many others. A certification body is only as credible as the accreditation body that accredits it, which is only as credible as its recognition under the Global ACI arrangement.
The failure modes to watch for
Four patterns come up often enough to be worth naming.
Certificates from unaccredited certification bodies. A body can issue certificates without being accredited. The certificates look real, carry a logo, and are technically not fraudulent, but they carry no international recognition. This is the most common failure mode and the easiest to catch.
Certificates issued after the body's own accreditation had expired. A certification body may have been legitimately accredited when it started auditing your vendor, but had lost accreditation by the time it issued the certificate. Checking accreditation validity against the issuance date catches this.
Certificates issued outside the body's accredited scope. A body accredited for ISO 9001 quality management is not automatically accredited for ISO 27001 information security. Standards are accredited separately. A certificate for ISO 27001 issued by a body accredited only for ISO 9001 is a scope violation that any serious buyer will flag.
Certificates that do not appear on the issuing body's public registry. Every legitimate certification body maintains a public registry of the certificates it has issued. If the certificate is not searchable there, something is wrong.
How SOC 2 verification works
SOC 2 verification is harder than ISO 27001 verification because there is no equivalent public accreditation chain. SOC 2 is an attestation, not a certification. The output is a report, not a badge, and there is no public registry of SOC 2 reports.
This shifts the verification burden onto reading the report itself. What follows are the checks that competent enterprise security teams run on every SOC 2 report they receive.
Why SOC 2 verification is different
SOC 2 reports are issued by CPA firms under the American Institute of Certified Public Accountants (AICPA) attestation standards, specifically SSAE 18. Only a licensed CPA firm can sign a SOC 2 report. A compliance automation platform or an advisory firm may support the readiness work that gets a company ready for the audit, but the attestation itself must come from a CPA firm. This is the single most important thing to verify, because everything else in the report only carries weight if the entity that signed it was permitted to sign it.
The report itself is not public. Vendors typically share it under NDA. A vendor who refuses to share the report at all is a red flag worth probing before assuming there is a legitimate reason. A summary letter is sometimes offered as a substitute, but a summary letter is not a substitute for the report itself if the diligence stakes are meaningful.
What each check tells you
The CPA firm's licence. The auditor's name appears at the bottom of Section 1, the auditor's opinion letter. Verify the firm's CPA licence through the National Association of State Boards of Accountancy (NASBA) at cpaverify.org. A firm that does not appear in NASBA's database is a serious red flag, because only licensed CPA firms can issue SOC 2 reports under AICPA standards.
The firm's peer review standing. CPA firms performing attestation engagements are required to undergo periodic peer reviews under the AICPA Peer Review Program. Search the AICPA Peer Review Public File for the firm and verify a "pass" rating. A firm with a "pass with deficiencies" or a "fail" rating on its most recent review is a concern worth raising with the vendor.
Type 1 or Type 2. A Type 1 report attests to the design of controls at a point in time. A Type 2 report attests to the operating effectiveness of those controls over a period, typically six to twelve months. For an enterprise buyer, a Type 2 report is materially stronger than a Type 1. A vendor presenting a Type 1 as though it were a Type 2 is either confused or hoping you are.
The audit period. Type 2 reports cover a defined observation window. Read it. A three-month observation period is meaningfully weaker than a twelve-month one, and reports covering unusually short periods deserve a conversation.
The auditor's opinion. The opinion letter states one of four possible conclusions: unqualified (the controls were suitably designed and operated effectively), qualified (there were exceptions material enough to note), adverse (the controls did not operate effectively), or disclaimer (the auditor could not form an opinion). An unqualified opinion is the baseline for a report a serious buyer will accept.
The Trust Services Criteria in scope. SOC 2 covers five Trust Services Criteria: Security (required), Availability, Confidentiality, Processing Integrity, and Privacy. Not every report covers every criterion. If your product's use case depends on Privacy or Availability commitments, verify those criteria are actually in scope.
Report age and bridge letters. Most SOC 2 reports are treated as valid for twelve months from the end of the audit period. If the report is older than that, ask for either a new report or a bridge letter, which is a short statement from the vendor confirming no material changes to controls since the report period ended.
Two additional signals worth noting during the read. Watermarks or branding from compliance automation tools on the report itself are worth investigating, because they can indicate the report was largely generated from automated evidence with limited independent auditor scrutiny. Section IV of the report, which describes the controls and testing, is worth reading for boilerplate language that could apply to any company. Reports with heavily boilerplate Section IV language often signal a shallow engagement.
What this post does not cover
This post is scoped to verification only. It does not cover how to prepare for an ISO 27001 or SOC 2 audit, how to select a certification body or CPA firm for your own product, or how to compare the two frameworks for your business. We covered the framework comparison in our SOC 2 vs ISO 27001 post. A wider vendor security review typically extends beyond certificate verification into questionnaires, pentest reports, and the underlying data flow governance, and each of those is a separate exercise.
Frequently asked questions
Our vendor's ISO 27001 certificate is issued by a body I have never heard of. Is that a red flag?
Not on its own. Many legitimate certification bodies operate regionally and do not have global brand recognition. The check is whether the body is accredited for ISO 27001 by a recognised accreditation body, not whether you have heard of it. Run the five ISO 27001 checks and the answer will be definitive.
A vendor refuses to share their full SOC 2 report, offering only a summary letter. Is this normal?
It is common but not necessarily acceptable, depending on the stakes. Summary letters are appropriate for low-risk vendor evaluations and for early-stage sales conversations. For material contracts, integration into your data flow, or your own SOC 2 subservice organisation evaluation, the full report under NDA is the standard ask. A vendor who refuses the full report at that stage is worth probing further.
Our vendor has a SOC 2 Type 1 and says they are working on Type 2. How should we treat it?
Type 1 is meaningful evidence that controls have been designed. It is not evidence that they have operated effectively over time. For a vendor in genuine transition from Type 1 to Type 2, the appropriate question is when the Type 2 report will be available and whether contractual terms can bridge the gap in the meantime.
A vendor has an ISO 27001 certificate but no SOC 2 report. Is that enough for a US enterprise buyer?
Depends on the buyer. Some US enterprises accept ISO 27001 as an equivalent, particularly for non-US vendors. Others require SOC 2 specifically. If you are the vendor, ask your buyer's security team directly which they need before committing to a certification path.
Where to start
If you have documentation sitting in your files that has never been through these checks, whether it is your own or a vendor's, working through them will surface the gaps that will fail scrutiny before your auditor or your enterprise customer surfaces them for you.
If you would like a second set of eyes on a specific certificate or report, our 30-minute discovery call exists for exactly this.
Secure your business with expert help
Company
Services
© 2026 Auro Security. All rights reserved.
Connect
insights

