Can one firm do both SOC 2 and ISO 27001?
ISO 27001 certification-body capability can sit alongside SOC 2 attestation in one provider group. The SOC 2 report and the ISO certificate remain separate deliverables, sometimes issued through related legal entities, so confirm the arrangement in writing before you sign.
Customers that require both a SOC 2 report and an accredited ISO 27001 certificate should verify current accreditation scope, legal entity, and certificate issuer. A generic ISO 27001 credential does not establish that a firm can issue the certificate.
Listed timelines cover SOC 2 fieldwork through report delivery and do not replace the Type 2 observation period or the ISO stage timetable. Treat the price range as a SOC 2 planning input and ask for renewal responsibilities in writing.