What is the difference between SOC 2 and ISO 27001, and what does an auditor accept as evidence?
ISO 27001 certifies a management system against a fixed standard; SOC 2 is an attestation report whose scope you define and whose chosen controls a CPA firm opines on. Both separate the control from its implementation from the evidence, and only system-generated artefacts spanning the whole period count.