SOC 2, ISO 27001 and GDPR ask the same questions in three different accents.
Every framework wants to know who has access, who reviewed the code, what happens when it breaks and which vendors touch the data. Answer that once, properly, and you have answered most of all three. Answer it three times in three spreadsheets and you have invented a full-time job.
No framework upsell. Adding the second one does not change the invoice.
The same six habits, filed under different names
This is the whole pitch for doing it in one place. On the left is what your team actually does on a Thursday. On the right is what three separate standards call it.
| What you do | SOC 2® | ISO 27001 | GDPR |
|---|---|---|---|
| Check who still has access | CC6.2, CC6.3 | A.5.18 | Art. 32 |
| Have someone review code before it ships | CC8.1 | A.8.32 | Art. 32 |
| Encrypt it, in transit and at rest | CC6.7 | A.8.24 | Art. 32(1)(a) |
| Keep a real list of vendors that touch data | CC9.2 | A.5.19–A.5.22 | Art. 28 |
| Handle incidents the way you wrote down | CC7.3, CC7.4 | A.5.24–A.5.26 | Art. 33 |
| Know what happens if it all goes down | A1.2 | A.5.29, A.5.30 | Art. 32(1)(c) |
Indicative, not legal advice. Scope decides a lot — the availability row only applies if you are in scope for that trust services category — and your auditor has the final word on what counts. That is a feature.
The first framework is the expensive one
Almost everything you build for SOC 2 is reusable. If ISO 27001 feels like starting again, the problem is where the work was stored, not the standard.
Evidence is framework-agnostic
A dated access review proves the same thing to every standard. Collect it once, attach it to every control it satisfies.
Policies are shared
Your access policy does not need an ISO edition and a SOC 2 edition. It needs to be true, approved, and read by the team.
The registers carry over
Risks, vendors, assets and incidents are the same objects in every framework. Only the reporting expectations differ.
Gaps become visible
When one control set spans three frameworks, adding the second shows you a short list of genuinely new work instead of a blank project plan.
Questionnaires get shorter
Buyers ask in whatever dialect their own auditor uses. One mapped control set means you already have the answer, in their words.
Drift shows up early
One place to look means you notice the control that stopped happening in month four, not in the request list in month eleven.
Mapping suggests. It does not decide.
A cross-framework map is a very good starting position and a very bad place to stop thinking. Three things stay yours.
Scope
Which systems, which trust services categories, which processing activities. Getting scope wrong is the most expensive mistake available to you, and no tool can make that call.
Judgement
Which risks you accept and which you fix. Software can rank them; it cannot want things on your behalf.
The verdict
An independent CPA firm examines SOC 2® controls; an accredited body certifies ISO 27001. Neither of them works for us, which is exactly why their opinion is worth having.
An app called humadroid, a product called AuditBadger
Humadroid was the name before the compliance product ate the company. The domain stayed with us, and we send a modest amount of cold mail from it — spreading outbound across a few domains means one filter's bad mood cannot take the entire company off the internet.
The software, the pricing and the documentation are at auditbadger.com. Reply to the email if you would rather we stopped; a person reads it and acts on it.
Do it once, in one place
One flat price with every framework included, unlimited users, and onboarding run by the founders. Or take the free policy generator for a spin first.
Curious how we run our own program? Read our security page.