Most procurement scorecards treat security certifications like competing brands of the same product. One column for ISO 27001, one for SOC 2, one for CREST, a tick in each, and the vendor with the most ticks moves forward.
The problem is that these frameworks are not competing. They answer different business questions and comparing them as if one could substitute for another is how organizations end up with a heavily certified provider that still cannot run a security operations centre well.
Understanding CREST vs ISO 27001 vs SOC 2 properly means understanding what each one is actually looking at.
Four habits cause most of the confusion:
ISO 27001 certifies an Information Security Management System. It examines how an organization manages information security as a discipline: risk assessment methodology, security policies, defined governance, control selection, internal audit, management review, and continuous improvement.
It answers: does this organization manage information security in a structured, repeatable way?
It does not tell you whether their SOC analysts can spot lateral movement at 3 a.m.
SOC 2 is an attestation report produced by an independent auditor against the Trust Services Criteria: security, availability, confidentiality, processing integrity, and privacy. A Type II report goes further, testing whether controls operate effectively over a period rather than merely existing on paper.
It answers: are this organization’s operational controls designed properly and working as intended?
Any SOC 2 comparison should start with scope. Two reports can carry the same name and cover entirely different criteria, systems, and time periods. Always read which criteria were in scope and whether it is Type I or Type II.
CREST assesses the thing the other two frameworks largely leave alone: whether the provider can actually deliver managed security services. Assessors examine people and analysts for competency, governance, operational processes, technical capability, incident response maturity, quality assurance, service delivery, and continuous improvement.
It answers: can this provider run a security operations centre competently?
That is capability validation, not policy compliance.
| Framework | Primary focus | Validates | Best for |
| ISO 27001 | Information governance | ISMS, risk management, policies, management oversight, continuous improvement | Confirming the organization manages security in a structured way |
| SOC 2 | Operational controls | Control design and effectiveness across security, availability, confidentiality, integrity, privacy | Assurance that the controls protecting your data function |
| CREST | Security operations capability | Analyst competency, SOC processes, incident response, quality assurance, service delivery | Confirming the provider can deliver managed security services well |
Read across the table and the pattern is clear. ISO 27001 covers governance. SOC 2 covers control assurance. CREST covers operational maturity in the SOC itself. A provider can hold two of the three and still have a meaningful gap.
Rather than ranking these frameworks, layer them:
Together, they answer governance, assurance, and capability. Individually, each leaves an obvious question unanswered. A layered trust model is simply the recognition that vendor risk is multidimensional, and one compliance certification cannot cover all of it.
No framework, or combination of frameworks, guarantees service quality. Certifications tell you that a floor exists. They do not tell you where the ceiling is.
Behind every credential, look for experienced analysts, mature SOC operations, real governance, active detection engineering, tested incident response, continuous service improvement, executive oversight, and genuine customer accountability.
Automation triages. People decide. Every consequential decision in a live incident is still made by an analyst working under time pressure with incomplete information, and that judgment is built from years of real incident handling rather than from a certificate.
If a provider answers the certification questions fluently but struggles with the operational ones, that gap is your finding.
The cheapest provider is rarely the most economical. Underpriced contracts are subsidised somewhere, usually by understaffing, generic detection content, or an escalation process that consists of an automated email.
Evaluate total cost of ownership, long-term operational value, reduced business disruption, improved internal efficiency, lower staffing burden, and return on investment across the contract term.
Then remove the ambiguity from the commercials. Ask what services are included, whether incident response hours are covered, whether onboarding is billed separately, whether engineering improvements and reporting are included, how licensing costs are handled, and what triggers additional fees. Transparent pricing protects your budget and signals a provider that expects a long relationship.
Applied to a specific provider, the layered model above looks like this:
The certifications are evidence. The operating model is the reason.
ISO 27001, SOC 2, and CREST each validate a different dimension of trust, and none of them was designed to be the deciding factor on its own.
Evaluate governance, operational maturity, technical capability, analyst expertise, service quality, pricing transparency, and continuous improvement. A layered trust model gives you a defensible basis for choosing a managed security partner, where a single logo never could.
Providers such as Sattrix reflect that emphasis, building managed security services around operational excellence and internationally recognised best practices rather than credential count alone.
Verify the certificates. Then ask the operational questions anyway.
ISO 27001 certifies how an organization manages information security. SOC 2 attests that operational controls are designed and function effectively. CREST validates whether a provider can actually deliver managed security services. Governance, assurance, and capability, respectively.
The question misframes the decision. For SOC services specifically, CREST addresses operational capability most directly, but ISO 27001 and SOC 2 cover governance and control assurance that CREST does not. Use them together.
Not directly. It validates the management system around information security, including risk assessment and governance. It does not assess whether analysts can investigate and respond to live intrusions.
Analyst competency, operational processes, governance, technical capability, incident response maturity, quality assurance, service delivery, and continuous improvement, all examined against an external standard.
Controls mapped to the Trust Services Criteria: security, availability, confidentiality, processing integrity, and privacy. A Type II report tests whether those controls operated effectively over time, not just at a single point.
Yes, and mature providers usually do, because each framework closes a different gap in a buyer’s due diligence.
Because certifications confirm that processes exist, while analysts determine whether a subtle intrusion is caught or closed as noise. That judgment comes from experience, not accreditation.
Ask operational questions: years of service delivery, analyst experience and retention, detection improvement cadence, escalation ownership, quality measurement, governance model, and pricing transparency. Then compare how specific the answers are.