CREST, ISO 27001 and SOC 2: which assurance do your board and auditors need?
Organizations often pay for the wrong assurance first. A company builds a full ISO 27001 program when its customer only asked for an independent penetration test, or the other way round. The mix-up is understandable, because these three names describe different kinds of things.
Put simply, CREST accredits the company that tests you. ISO/IEC 27001 and SOC 2 look at your own organization.
Side by side
| Assurance | Question it answers | Who asks for it | How often |
|---|---|---|---|
| Penetration test by a CREST-accredited provider | Can we be breached? Real weaknesses and their impact, found by CREST-certified testers | Board, CISO, customers, auditors | Yearly and after major changes |
| ISO/IEC 27001:2022 | Do we manage security in an organized way? A certified information security management system (ISMS) | Regulators, large buyers | Three-year certificate with surveillance audits in between |
| SOC 2 Type II | Do our controls keep working over time? An independent auditor’s report against the Trust Services Criteria | US SaaS buyers, investors | Yearly |
You cannot certify your own organization against CREST. It accredits the provider that tests you, while ISO/IEC 27001 and SOC 2 assess you. The three are complementary, not interchangeable, and many software companies end up needing all of them in turn.
Which should come first?
- If you sell to US enterprises or are raising later-stage funding, buyers will ask for SOC 2. Add an independent penetration test as evidence for monitoring controls such as CC4.1 and CC7.1.
- If you need international credibility or answer tenders in Europe, the Middle East or Asia-Pacific, ISO/IEC 27001 is the usual request. A penetration test shows that the technical controls in your Statement of Applicability (the document listing which ISO controls you apply) work in practice. Using a CREST-accredited provider tells buyers who did the testing.
- If you store, process or transmit card data, PCI DSS applies. Requirement 11.4 calls for penetration testing that follows an industry-accepted method, such as NIST SP 800-115, carried out by qualified testers who are independent of the systems they test. PCI DSS does not require CREST, but CREST certifications are a clear way to show your testers are qualified.
- If you simply need to know whether you can be breached, start with a penetration test. It gives the board a direct answer, and the results feed your ISO 27001 and SOC 2 evidence.
“We have ISO 27001, so we don’t need a penetration test”
We hear this often. ISO/IEC 27001:2022 Annex A includes controls for managing technical vulnerabilities (A.8.8) and for security testing during development and acceptance (A.8.29). Certification auditors expect evidence that these controls work. Independent penetration test results are one of the clearest forms of that evidence. Without them, gaps can surface as nonconformities during the audit.
Covering all three with one piece of work
We run one scoping workshop and produce one set of evidence with three uses. You get a risk-rated penetration test report, findings mapped to ISO/IEC 27001 Annex A and SOC 2 criteria, and evidence for PCI DSS Requirement 11.4. The retest is included, so you can close findings before the auditor arrives.
Free template: get our Compliance Mapper: One Control, Three Reports (ISO/SOC 2/PCI) Excel template to map each control once instead of three times.