
ISO 27001 Certification: A Practical Guide for 2026
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.
Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

A SOC 2 report is an independent attestation, issued by a licensed CPA firm, on the controls a service organisation uses to protect its customers' data. It is written for your customers and their auditors, and it is governed by standards set by the American Institute of Certified Public Accountants (AICPA).
SOC 2 is not a certification and there is no pass mark. The auditor issues an opinion and lists any exceptions found during testing. A report with a handful of well-explained exceptions is normal; a report with exceptions in core areas such as access control or change management will raise difficult questions from customers.
| Type I | Type II | |
|---|---|---|
| What is assessed | Whether controls are suitably designed at a single point in time | Whether controls are suitably designed and operated effectively over a period |
| Period | A specific date | Typically 3 to 12 months; 6 and 12 are most common |
| Evidence | Policies, configurations, walkthroughs | Samples of records across the whole period |
| Customer value | A useful first step | What most enterprise buyers actually ask for |
Many organisations issue a Type I first to unblock sales, then move to Type II. That is sensible — provided the Type II observation period starts as soon as controls are genuinely operating, not after the Type I report lands.
The Security criteria — often called the Common Criteria — are mandatory for every SOC 2 report. The other four categories are included when they matter to your customers:
Adding categories your customers do not need increases audit cost and exception risk without adding commercial value. Scope to what your contracts actually promise.
During a Type II audit the auditor selects samples from the observation period and asks you to prove each control operated. These are the areas where first-time audits most often produce exceptions:
Almost every SaaS company relies on a cloud provider. Your report must explain how you treat these subservice organisations — usually the carve-out method, where the provider's controls are excluded from your report and your customers rely on the provider's own SOC report.
Your report will also list complementary user entity controls: things your customers must do for the overall control environment to work, such as managing their own users. Write these carefully; vague or unreasonable expectations become questions in every customer review.

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.

All future-dated requirements have been mandatory since March 2025. These are the ones assessors most often find incomplete — and what good evidence looks like.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.