At some point, almost every growing company runs into the same question from a prospect or a customer: “Do you have SOC 2?” Then a different deal stalls because a European partner asks about ISO 27001. Then a healthcare client wants to know if there’s a BAA in place, which means HIPAA just became relevant whether anyone planned for it or not.
These three frameworks get lumped together constantly, but they answer different questions, come from different bodies, and get requested by different kinds of buyers. Knowing which one actually applies to your situation — and which one to pursue first — saves months of chasing the wrong certification.
What each framework actually is
SOC 2 isn’t a law and isn’t healthcare-specific. It’s an attestation framework maintained by the AICPA, built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory; the other four are optional depending on what you’re claiming to protect. Unlike HIPAA or ISO 27001, SOC 2 doesn’t hand you a fixed list of controls — your organization defines the specific controls that satisfy each criterion, and an independent CPA firm attests that they exist and, for a Type II report, that they actually operated effectively over a defined period, typically three to twelve months. Type I only confirms the controls existed on a given day; Type II is the one most enterprise buyers actually want, because it proves the controls held up over time, not just on the day of the audit.
HIPAA is U.S. federal law, not a certification you can earn or a report you can generate. It applies if you’re a covered entity or a business associate handling Protected Health Information — the Security Rule, Privacy Rule, and Breach Notification Rule spell out roughly 88 specific safeguards spanning administrative, physical, and technical controls. There’s no official “HIPAA certified” badge; what you can demonstrate is that you’ve implemented the required safeguards, and that every vendor touching PHI on your behalf has signed a Business Associate Agreement.
ISO 27001 is an international standard for building and running an Information Security Management System, and it’s the only one of the three that results in an actual certificate, issued after a formal audit by an accredited certification body. The current 2022 version restructured its Annex A controls down to 93, from 114 in the older 2013 version — worth knowing, since plenty of reference material online still cites the outdated 114 figure. ISO 27001 tends to matter most for companies selling internationally, especially into Europe and Asia, or bidding on government and enterprise contracts where a recognized global standard carries more weight than a U.S.-specific attestation.
Who actually asks for which one
This is usually the fastest way to figure out where to start. If most of your deal friction comes from U.S. B2B enterprise customers running a vendor security review, SOC 2 Type II is almost always the one they mean, even if they just say “compliance” without naming it. If you’re processing health data for U.S. patients in any capacity — a health tech platform, a telehealth vendor, anyone with a healthcare client sending PHI your way — HIPAA isn’t optional, it’s a legal obligation, whether or not a customer ever explicitly requests it. If your growth is pulling you toward international markets, or you’re running into government or large-enterprise procurement processes that specifically name ISO 27001, that’s the signal to prioritize it.
It’s also common to need more than one. A healthcare SaaS company selling to U.S. hospital systems and also expanding into Europe can easily need HIPAA compliance, a SOC 2 Type II report, and ISO 27001 certification simultaneously — which is exactly the situation where doing all three from separate spreadsheets starts costing real time, since a meaningful share of the underlying evidence (access controls, encryption, incident response, audit logging) genuinely overlaps across all three frameworks even though each one names and organizes it differently.
How hard each one actually is to get
SOC 2 Type II is typically the fastest to a first report, mainly because the observation period can be as short as three months, though most companies run six to twelve. HIPAA has no formal certification timeline since there’s no certifying body — you’re either implementing the required safeguards or you’re not, and the real time cost is in doing it properly rather than waiting on an external auditor’s calendar. ISO 27001 is generally the longest and most involved path, since it requires building out a full ISMS, running a documented risk assessment, generating a Statement of Applicability, and passing a two-stage external audit before certification is issued — a process that traditionally runs close to a year for organizations doing it manually, though continuous evidence collection can meaningfully compress that.
The practical answer
If you’re not sure where to start, work backward from who’s actually asking. The framework a real deal is stalled on is the one to prioritize — not the one that sounds most impressive on a website. For most SaaS companies selling into the U.S. market, that’s SOC 2 Type II first. For anyone touching PHI, HIPAA isn’t a choice to sequence at all; it’s already a requirement the moment PHI enters the picture. ISO 27001 is worth pursuing once international or large-enterprise deals are a real, not hypothetical, part of the pipeline.
None of the three make the others unnecessary, and none of them are interchangeable substitutes — but building the underlying evidence once, in a way that maps cleanly to all three, is a lot more realistic than it sounds once you see how much of the actual control content genuinely repeats across frameworks.