Keyvaci

Blog · Compliance · 16 August 2026

ISO 27001 vs SOC 2:
what each demands of your credentials

Sooner or later an enterprise customer asks for one of them, and the fastest route to failing either is the same: shared passwords nobody can account for. Here is how the two standards actually differ, the credential controls each one checks, and the evidence an auditor will ask you to produce.

The two standards, without the mystique

ISO/IEC 27001 is an international standard for running an information security management system (ISMS). You define scope and risks, implement controls drawn from Annex A (93 controls in the 2022 revision), and an accredited body certifies you, with surveillance audits in between. It answers: does this organisation manage security systematically?

SOC 2 is an attestation, not a certification: a licensed CPA firm examines your controls against the AICPA Trust Services Criteria (Security always; Availability, Confidentiality, Processing Integrity, Privacy optionally) and writes a report. A Type I report says the controls were designed properly on a date; a Type II says they actually operated over a period, typically 3 to 12 months. It answers: can this vendor be trusted with customer data, with an auditor's evidence behind the answer?

ISO 27001SOC 2
What it isCertification of a management systemAuditor's attestation report on controls
Who asks for itInternational and European enterprises, governmentsNorth American enterprise buyers, SaaS procurement
Control setAnnex A, 93 controls (2022 revision)Trust Services Criteria (CC-series plus optional categories)
FlexibilityControls selected via risk assessment, exclusions justifiedYou define the controls; the auditor tests they operate
OutputCertificate, renewed on a 3-year cycleReport (Type I or Type II), refreshed annually
OverlapSubstantial. Access control, credential lifecycle, logging, and cryptography sit at the heart of both

Similar frames exist elsewhere and rhyme with the same requirements: GDPR Article 32 ("appropriate technical measures", where encryption and access control are named explicitly), PCI DSS 4.0 (requirements 7 and 8: least privilege, 12-character minimums, MFA), HIPAA's access-control safeguards, and the UK's Cyber Essentials. Pass the credential discipline below and you are most of the way through the identity sections of all of them.

Where audits actually stall: shared credentials

Individual user accounts ride your identity provider and are easy to evidence. What stalls audits is the credential long tail that SSO cannot reach: the banking portal, the registrar, the shared admin login for the firewall, the API keys in scripts. Auditors under both standards ask the same four questions about exactly these:

  1. Inventory: what shared credentials exist, and who owns each one?
  2. Authorisation: who can access each, and does that match a documented need?
  3. Lifecycle: what happened when that person left in March? Show the record.
  4. Accountability: who actually used the shared account on this date? "It's shared" is a finding, not an answer.

A spreadsheet answers none of these; chat history answers them in the worst possible way. This is the gap a team credential vault exists to close, and it is why the fix is worth doing before the audit rather than for it: the same four questions are the ones a breach response asks under worse conditions.

The control map

What the auditor checksISO 27001 Annex ASOC 2 criteriaEvidence a vault produces
Access granted by role and needA.5.15, A.5.18CC6.1, CC6.2Per-vault reader/writer/admin roles, listable per person in one query
Management of authentication informationA.5.17CC6.1Credentials stored encrypted with owners, strength gates, and age reminders instead of chat threads
Privileged access restricted and reviewedA.8.2CC6.1, CC6.3Admin roles explicit per vault; access reviews read from the system, not from memory
Timely revocation on terminationA.5.18, A.6.5CC6.2, CC6.3Directory-linked sign-in dies with the account; vault revocation re-encrypts and is logged with a timestamp
Strong authenticationA.8.5CC6.1SSO with your IdP's MFA and Conditional Access; TOTP step-up before reveals
Event logging, protected from tamperingA.8.15CC7.2Append-only audit trail of opens, reveals, shares, and revocations that nobody, vendor included, can edit
Cryptography used appropriatelyA.8.24C1.1 (Confidentiality)Client-side XChaCha20-Poly1305 with Argon2id key derivation, documented publicly

Control references are indicative, not a compliance opinion: your auditor and your scoping decide the final mapping. But every row above is a question we have seen an assessor ask in practice, and each becomes a five-minute answer when the evidence is a system of record instead of an interview.

Where Keyvaci fits, stated honestly

Keyvaci is the system of record for that shared-credential layer: vaults with enforced roles, sign-in through the directory you already audit, countersigned member keys, revocation that re-encrypts rather than hopes, and the append-only log that turns four auditor questions into four queries. The offboarding evidence that usually takes an afternoon of archaeology becomes a printout.

And our own side of the vendor-assessment table, stated plainly: Keyvaci is operated by XNOR Group Pte. Ltd., whose information security management system is certified to ISO/IEC 27001; the certificate and scope statement are available to your procurement team on request via the contact page. A SOC 2 report for the Keyvaci service itself is on the roadmap and not yet issued; we would rather say that than imply otherwise. Alongside the certificate, we offer something a badge cannot carry: a zero-knowledge architecture under which we cannot read what you store, published in enough detail for your security team to verify, plus a signed Data Processing Addendum. A vendor who can prove it holds only ciphertext is a vendor your auditors have very few questions for.

The practical sequence

  1. This week: move the shared-credential long tail into a vault with owners and roles; one afternoon for the top twenty.
  2. This month: wire sign-in to your directory so joiner-leaver evidence is automatic, and turn on MFA-before-reveal.
  3. At audit time: export the access lists and audit events for the sample the assessor picks, and spend the recovered days on the controls that actually need thought.

Make the credential section of your audit boring

14 days, every feature, no credit card. Sign in with company SSO or a plain email address.