Ask for ISO 27001 when you need proof that a vendor runs a managed security system, and for SOC 2 when you need an auditor’s findings on specific controls over a period. ISO 27001 produces a certificate with a scope. SOC 2 produces a report with an opinion and any exceptions the auditor found.
What is ISO 27001?
ISO 27001 is an international standard for an information security management system, and it is certifiable. A vendor builds the system, an accredited certification body audits it, and the vendor receives a certificate naming what was in scope. In Germany the federal information security agency runs certification against the standard on the basis of IT-Grundschutz, which the BSI describes on its own site. The important word is system. The certificate says the organisation manages security, not that any single control worked on any single day.
What is SOC 2?
SOC 2 is an attestation report produced by a licensed accounting firm about a service organisation’s controls. The AICPA, which owns the framework, describes the family this way:
“System and Organization Controls (SOC) is a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations.”
AICPA and CIMA, System and Organization Controls, read 23 September 2026
The controls are tested against the Trust Services Criteria, published in 2017 with revised points of focus in 2022. A Type 1 report describes the design of the controls at a point in time. A Type 2 report tests whether they operated over a period, which is the one worth asking for.
ISO 27001 or SOC 2: what actually differs for a buyer?
| What you are checking | ISO 27001 | SOC 2 |
|---|---|---|
| What the vendor has | A certificate | An audit report |
| Who signs it off | An accredited certification body | A licensed accounting firm |
| What is examined | The whole management system | Controls the vendor selected |
| The criteria used | The published standard | AICPA Trust Services Criteria |
| Where it comes from | International standard (ISO/IEC) | US professional body (AICPA) |
| What you can read | Scope statement, certificate | Findings, exceptions, auditor opinion |
| Does tchop hold it | Yes, certified via TÜV SÜD | No |

When is ISO 27001 the answer?
- You are buying in Europe, or your own certification obliges you to check your suppliers.
- You want evidence that security is run as a process rather than assembled for an audit.
- You need something you can file. A certificate is a short document with a scope and an expiry, and procurement can read it without a lawyer.
When is SOC 2 the answer?
- Your buyers or auditors ask for a SOC 2 report by name.
- You want detail rather than a verdict. A Type 2 report names the controls, the test period and every exception the auditor found.
- You are assessing one specific service rather than a company. Scope in SOC 2 is chosen by the vendor, which is a weakness and also the reason it can be precise.
What should you actually ask a vendor that has one and not the other?
Most pages on this question are written for the company deciding which certification to buy. This one is written for the company on the other side of the table. That reader needs four questions rather than a verdict. Ask for the scope statement, not the logo. A certificate that covers a development office and not the production platform is a certificate about the wrong thing. Ask for the report date and the test period. A Type 2 report whose period ended 14 months ago describes a company that no longer exists, and a first period of 3 months tells you far less than one of 12 months. Ask what was excluded and why, since scope in SOC 2 is selected by the vendor and the exclusions are where the risk sits. Finally, ask what a missing framework would have added. A vendor with ISO 27001 and no SOC 2 is not less secure than one with both, and a vendor with neither may still answer every question well. The certificate is evidence, not the thing itself.
The honest limit on the whole comparison: neither framework tells you where your data is stored, who can read it, or whether a subprocessor sits outside the EU. Those are separate questions and no certificate answers them. Nor is either framework an EU instrument. The European Union runs its own cybersecurity certification work through the European Union Cybersecurity Certification programme, which is separate from both and which a buyer in a regulated European sector may eventually be asked about instead.
There is a second limit worth naming, because it changes what the evidence is worth. Both frameworks describe the vendor’s own systems. Neither of them says anything about the devices your workforce actually uses, and for an employee app that is where most of the exposure sits. In Germany 9.3 % of 42.6 million employed people worked at night in 2024, and in health care the share was 17.6 % (Destatis, Mikrozensus 2024). Work internet access is also uneven: across the EU, 64.6 % of people employed in enterprises with 10 or more staff have internet access for business purposes, falling to 39.2 % in German food, beverage and tobacco manufacturing (Eurostat, isoc_ci_cm_pn2, 2025). People without a work computer or work phone will often open the app on a private phone, on a shared home network. No certificate covers that phone. What covers it is a works agreement, a device policy and an app that stores as little as it can, and those three are worth more scrutiny in a security review than the difference between two audit frameworks.
Which one does tchop hold, and what does that mean for a buyer?
tchop is certified to ISO 27001, with the information security management system audited and certified by TÜV SÜD, and tchop does not hold a SOC 2 report. What a buyer can check is the hosting and the login: tchop runs only on servers in Germany, on AWS or Hetzner by customer choice, with no self-operated servers, and single sign-on connects to the customer’s own identity provider over OIDC or SAML 2.0. AOK, one of Germany’s largest statutory health insurers, runs its employee apps on tchop. If your procurement process requires a SOC 2 Type 2 report as a hard gate, tchop will not pass it today, and that is worth knowing before a security review rather than during one.
The current certificates and hosting details are on the tchop security page, and in German at Sicherheit.
Questions people ask
Is ISO 27001 equivalent to SOC 2?
No. They overlap heavily in the controls they touch and they are different kinds of evidence. ISO 27001 certifies that a management system meets a published standard. SOC 2 is an auditor’s report on controls the vendor selected, measured against the Trust Services Criteria. One is a pass mark, the other is a set of findings.
Is SOC 2 legally required?
No. SOC 2 is a voluntary framework owned by a professional body, not a law. Where a buyer requires it, the requirement comes from a contract or a procurement policy, which makes it a commercial obligation rather than a legal one.
What is better than SOC 2 compliance?
Nothing in this family is strictly better, because they answer different questions. A buyer who wants breadth asks for ISO 27001. A buyer who wants depth on one service asks for a SOC 2 Type 2 report. A buyer who wants both asks for both, and should expect the vendor’s price to reflect two audit programmes.
Is there a SOC 3?
Yes. A SOC 3 report covers the same ground as SOC 2 but is written for general distribution, without the detailed test results. It is useful as a public trust page and useless as evidence in a security review, because the part a reviewer needs has been removed.
Which one do you need from a communication app vendor?
Ask what the app actually holds. An employee communication app stores names, phone numbers, sometimes a works agreement and a stream of internal messages, so hosting location and access control matter more than the framework name. Ask where the data sits, who can read it, and whether the certificate’s scope covers that system. tchop answers those three on its security page.