ISO 27001 for SaaS companies
ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Unlike SOC 2, it results in a certification from an accredited body, which international and enterprise buyers often prefer.
Why it matters for SaaS
SaaS companies selling into Europe and global enterprises frequently see ISO 27001 requested alongside or instead of SOC 2. The good news: the two overlap heavily, so a SaaS team with SOC 2 has already done much of the work.
What to focus on
ISO 27001 requires a managed system: scope, risk assessment and treatment, objectives, internal audits, and management review. The Annex A controls sit inside that system, they are not the whole of it.
The 2022 revision organizes Annex A into 93 controls across four themes: Organizational, People, Physical, and Technological. You select applicable controls and document the decisions in a Statement of Applicability.
Access control, change management, monitoring, vendor management, and incident response map closely between SOC 2 and ISO 27001. On one crosswalked control library, a control you implemented for SOC 2 counts toward ISO 27001 too.
Do it once, not twice
Keel is built on one crosswalked control library, so a control you implement for ISO/IEC 27001 counts toward every other framework it satisfies. Add a second framework later and it mostly reuses this work. See the crosswalk explorer for the exact overlap.
Start free Check your readinessCommon questions
Can we do SOC 2 and ISO 27001 together?
Yes, and it is efficient to. The frameworks share a large set of controls, so on Keel you implement once and it counts toward both. See the SOC 2 and ISO 27001 crosswalk to see exactly which controls overlap.
What is the Statement of Applicability?
The Statement of Applicability (SoA) records which Annex A controls apply to your ISMS, whether each is implemented, and why any are excluded. Keel generates and maintains it from your control set.
Framework names are referenced factually for guidance. Keel is not affiliated with or endorsed by the bodies that publish them. See our legal and trademarks page.