Compliance & Certifications • Pillar Guide

SOC 2 vs ISO 27001 vs IEC 62443:
SCADA Certifications Explained

Merobix Engineering • • 12 min read

Every SCADA procurement eventually hits the certification question: the security questionnaire asks for SOC 2, the corporate policy asks for ISO 27001, and the OT engineer asks about IEC 62443 - and the three answers rarely line up. These frameworks measure different things, are earned through different processes, and prove different claims. This guide explains what each one actually covers, how a vendor earns each (process, realistic timelines, honest cost ranges), what "readiness" versus "certified" really means, and exactly which documents to request before you sign a cloud SCADA contract.

Back to Blog

From the Merobix industrial security hub - every security, compliance & certification guide in one place.

5SOC 2 Trust Services Criteria
93ISO 27001:2022 Annex A Controls
4IEC 62443 Security Levels

Why Certification Questions Decide SCADA Deals

The short answer: SOC 2 is a CPA-issued attestation of a cloud service's operational controls, ISO 27001 is a certifiable international standard for a security management system, and IEC 62443 is the standards series written specifically for industrial control systems. They are complements, not substitutes - a credible cloud SCADA vendor needs an answer on all three.

Certifications exist because buyers cannot audit every vendor themselves. A water utility evaluating a cloud SCADA platform has no practical way to inspect the vendor's access-control discipline, change management, or tenant isolation - so it relies on an independent third party that did. That is the entire value proposition of SOC 2, ISO 27001, and IEC 62443: someone qualified looked, on your behalf, at things you cannot see from a sales demo.

The problem is that the three frameworks get used interchangeably in RFPs when they are not interchangeable at all. SOC 2 says nothing about PLC protocols. IEC 62443 says nothing about how the vendor's finance-adjacent cloud controls operate. ISO 27001 can be certified with a scope so narrow it excludes the product you are actually buying. A buyer who understands what each framework proves - and, just as importantly, what it does not - asks sharper questions and gets materially better answers. If you want the architectural half of that evaluation, start with our secure SCADA for OT networks guide; this post covers the paper half.

One vocabulary point up front, because vendors blur it constantly: ISO 27001 and IEC 62443 produce certificates; SOC 2 does not. SOC 2 is an attestation - an auditor's written opinion - and treating it as a certificate is the single most common compliance-language error in the industry. We will unpack why that distinction matters below.

SOC 2: The Cloud Operations Attestation

SOC 2 comes from the AICPA, the US accounting profession's standards body, and it is performed exclusively by licensed CPA firms. The auditor examines a service organization's controls against the five Trust Services Criteria - security (mandatory), availability, processing integrity, confidentiality, and privacy - and issues a detailed report. A Type I report describes control design at a point in time; a Type II report tests whether the controls actually operated over an observation window, typically 3–12 months. Type II is the one that carries weight, because it proves the controls ran, not just that they were written down.

For cloud SCADA, SOC 2 answers the questions an IT security team asks about any SaaS vendor: who can access production, how are changes deployed, how is customer data protected, how are incidents handled, is there monitoring and alerting. It is the de facto entry ticket for selling cloud services to North American enterprises. What it does not do is evaluate the industrial-specific surface - device identity, telemetry integrity, setpoint write safety, protocol security. A vendor can hold a clean SOC 2 report and still ship a gateway that accepts unsigned telemetry.

The full mechanics - scoping, the observation window, how to read the auditor's opinion and exceptions - are covered in our deep dive, What Is SOC 2 Certification? Guide for Industrial Buyers.

ISO 27001: The Certifiable Security Management System

ISO/IEC 27001 - published jointly by ISO and IEC, with the full text available for purchase from the IEC webstore - is the international standard for an information security management system (ISMS) - the ongoing management process by which an organization identifies risks, selects controls, and continually improves. The 2022 revision organizes 93 reference controls in Annex A across four themes: organizational, people, physical, and technological. Unlike SOC 2, ISO 27001 is a true certification: an accredited certification body performs a stage 1 audit (documentation) and a stage 2 audit (implementation), issues a certificate valid for three years, and returns annually for surveillance audits.

ISO 27001's strength is that it certifies the management system, which means the vendor is committed to risk assessment, internal audit, and corrective action as ongoing disciplines, not one-time projects. Its weakness for SCADA buyers is scope: the certificate applies only to what the scope statement says it applies to, and scope statements can be drawn narrowly enough to exclude the engineering team or the product itself. Always read the scope. We walk through the certification process, costs, the surveillance cycle, and the scope-gaming problem in What Is ISO 27001 Certification? Process, Cost & Timeline.

IEC 62443: The Standard Written for Control Systems

IEC 62443 is the only framework of the three written specifically for industrial automation and control systems. As the ISA/IEC 62443 series overview at ISA describes, it splits requirements across the ecosystem: product suppliers (62443-4-1 secure development lifecycle, 62443-4-2 component requirements), system-level architecture (62443-3-3), service providers (62443-2-4), and asset owners (62443-2-1). Its signature concept is the security level - SL1 through SL4 - which rates the sophistication of the attacker a system is designed to resist, from casual misuse up to state-level actors, across seven foundational requirements covering identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely event response, and resource availability.

Certification against IEC 62443 exists - schemes such as ISASecure and assessments by firms like exida and TÜV certify products and development lifecycles - but it is still far less common than SOC 2 or ISO 27001, and plenty of credible OT vendors are "aligned" rather than certified. That makes the buyer's job subtler: you are evaluating the quality of the vendor's mapping and evidence, not just the presence of a logo. The full picture - parts of the standard, SL levels, certification schemes, steps, and realistic cost and timeline ranges - is in our deep dive, IEC 62443 Certification: Levels, Process, Cost & Timeline.

Side by Side: What Each Framework Actually Proves

Attribute SOC 2 ISO 27001 IEC 62443
What it isAttestation report (auditor's opinion), not a certificateCertification of an information security management systemStandards series for industrial automation and control systems; certification available for products and lifecycles
Who assessesLicensed CPA firms under AICPA standardsAccredited certification bodies (accredited by ANAB, UKAS, etc.)Scheme-based labs and assessors (ISASecure, exida, TÜV)
What it coversService organization controls: security, availability, processing integrity, confidentiality, privacyThe management system: risk process plus 93 Annex A reference controlsControl-system architecture, components, development lifecycle, security levels SL1–SL4
Output you can readType I or Type II report, usually shared under NDACertificate plus scope statement; Statement of Applicability on requestCertificate per product/process, or a control mapping if not certified
Validity rhythmRe-examined every 12 months (new observation period)3-year certificate with annual surveillance auditsScheme-dependent; typically periodic reassessment and per-version evaluation
Geographic weightDominant in North AmericaDominant internationally; widely accepted everywhereGlobal; referenced by regulators and sector standards (water, pipelines, chemicals)
Blind spot for SCADA buyersNothing industrial: no protocols, devices, or control safetyScope can exclude the product; controls are generic, not OT-specificSays little about the vendor's cloud business operations

The practical conclusion: for a cloud SCADA platform these frameworks are complements, not substitutes. SOC 2 or ISO 27001 covers the operating company and its cloud; IEC 62443 covers the control-system product. A vendor answer that leans on only one of the three is leaving a third of your risk surface unexamined - which is why sector rules like API 1164 for pipelines and AWIA for water utilities increasingly reference 62443 alongside enterprise frameworks. Industry-specific guidance lives in our compliance posts for water utilities and other verticals.

How a Vendor Earns Each One: Process, Timeline & Cost

Understanding the earning process tells you how much signal each claim carries. All figures below are indicative ranges - actual numbers vary widely with organization size, scope, and starting maturity, and vendors' own disclosures differ.

SOC 2 (Type II)

  1. Scoping - choose the criteria (security is mandatory; availability and confidentiality are the usual additions) and the system boundary.
  2. Gap assessment and remediation - typically 3–6 months of readiness work: writing policies, closing control gaps, standing up evidence collection.
  3. Observation window - controls must operate for 3–12 months while evidence accumulates.
  4. Audit and report - the CPA firm tests the evidence and issues the report. Combined preparation and audit costs are commonly cited from the tens of thousands of dollars upward.

ISO 27001

  1. Build the ISMS - risk assessment, Statement of Applicability, control implementation, internal audit, management review. Often 6–12 months from a standing start.
  2. Stage 1 audit - the certification body reviews documentation and readiness.
  3. Stage 2 audit - on-site or remote testing of implementation; nonconformities must be closed.
  4. Certificate and surveillance - three-year certificate, annual surveillance audits, full recertification in year three. Certification-body fees plus internal cost typically land in the tens of thousands to low six figures over a cycle.

IEC 62443 (product/lifecycle certification)

  1. Choose scope and scheme - development lifecycle (4-1), component (4-2), or system (3-3), through ISASecure or an assessor such as exida or TÜV.
  2. Gap assessment against the target security level - SL-C capability claims are made per foundational requirement.
  3. Remediate and document - threat models, secure-development evidence, security testing.
  4. Evaluation and certification - lab assessment of product and process. Per-product efforts of 6–18 months and five-to-six-figure total costs are typical of what is publicly discussed; complex systems cost more.

"Certified" vs "Compliant" vs "Readiness": Decoding Vendor Language

Vendor security pages use these words with very different amounts of substance behind them. A working decoder:

The red flag is not the absence of a certificate - young platforms and even large OT incumbents often lack them for specific products. The red flag is vague language that resists verification: "enterprise-grade security," "bank-level encryption," or "SOC 2 certified" with no report available. For a structured way to pressure-test any vendor's claims, use our enterprise SCADA buyer's guide alongside this post.

Key takeaway: SOC 2, ISO 27001, and IEC 62443 answer three different questions - is the cloud service operated with discipline, is there a certified management system behind it, and is the control-system product itself built to resist a defined attacker class. Demand evidence on all three axes from any cloud SCADA vendor, accept "readiness plus evidence" as an honest interim answer, and treat unverifiable certification language as the real disqualifier.

What to Verify Before You Sign

Turn this into your procurement checklist. For any cloud SCADA vendor, request:

Deployment model changes the division of labor too: in a cloud deployment the vendor holds most of these obligations, while on-premise shifts them to you - our cloud vs on-premise comparison covers that split in detail.

Frequently Asked Questions

What is the difference between SOC 2, ISO 27001, and IEC 62443?

SOC 2 is an attestation report, issued by a licensed CPA firm, describing how a service organization's controls meet the AICPA Trust Services Criteria - it is common for US cloud services. ISO 27001 is an international certification of an information security management system (ISMS), issued by an accredited certification body after stage 1 and stage 2 audits. IEC 62443 is the standards series written specifically for industrial automation and control systems; it defines security levels SL1–SL4 and separate requirements for product suppliers, integrators, and asset owners, with certification available through schemes such as ISASecure. They overlap but answer different questions: SOC 2 covers cloud operations, ISO 27001 covers the security management system, and IEC 62443 covers the control-system product and architecture itself.

Is SOC 2 a certification?

No. SOC 2 is an attestation, not a certification. A licensed CPA firm examines the service organization's controls and issues a report containing the auditor's opinion - there is no certificate, no badge-issuing body, and no pass/fail registry. A vendor that says it is SOC 2 certified is using the term loosely; the accurate phrasing is that the vendor has completed a SOC 2 Type I or Type II examination and can share the report under NDA. Buyers should always ask for the report itself, check the opinion, the period covered, the criteria in scope, and any exceptions the auditor noted.

Which certification matters most for SCADA and OT systems?

For the control-system layer, IEC 62443 matters most because it is the only one of the three written for industrial automation: it addresses zones and conduits, security levels against defined attacker classes, and component-level requirements that SOC 2 and ISO 27001 never touch. For the cloud service wrapped around a SCADA platform, SOC 2 Type II is the most commonly requested evidence in North America, and ISO 27001 is often preferred internationally. A mature cloud SCADA vendor should be able to speak to all three: 62443 alignment for the product architecture, and SOC 2 or ISO 27001 progress for the operating organization.

How much does it cost a vendor to earn these certifications?

Ranges vary widely with company size and scope, so treat all figures as indicative. A SOC 2 Type II typically involves a readiness phase of roughly 3–6 months, an observation window of 3–12 months, and combined audit plus preparation costs commonly cited from the tens of thousands of dollars into six figures for larger scopes. ISO 27001 certification often takes 6–18 months from a standing start, with certification-body fees plus internal and consulting costs in a similar range, then annual surveillance audits. IEC 62443 product certification through schemes like ISASecure is typically quoted per product and can take 6–18 months depending on development-lifecycle maturity. The honest takeaway: these are meaningful, multi-quarter investments, which is exactly why they carry signal.

What should I ask a SCADA vendor that is not yet certified?

Ask for substance instead of logos: which framework the vendor is working toward and where it is in the process; a control-by-control mapping to IEC 62443-3-3 or the SOC 2 Trust Services Criteria; architectural evidence such as tenant isolation design, MFA enforcement, audit logging, and encryption; and the results cadence of its internal and independent validation program. A vendor running a genuine readiness program - as Merobix does for SOC 2, alongside mapping its controls to IEC 62443 - can show you evidence today even though the audit report comes later. A vendor that can show neither certificates nor evidence is the actual red flag.

Sources & Further Reading

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

Ask Us the Hard Certification Questions

We will walk you through our SOC 2 readiness program, IEC 62443 control mapping, and the platform architecture behind them - evidence first, logos second.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →