Every SCADA procurement eventually hits the certification question: the security questionnaire asks for SOC 2, the corporate policy asks for ISO 27001, and the OT engineer asks about IEC 62443 - and the three answers rarely line up. These frameworks measure different things, are earned through different processes, and prove different claims. This guide explains what each one actually covers, how a vendor earns each (process, realistic timelines, honest cost ranges), what "readiness" versus "certified" really means, and exactly which documents to request before you sign a cloud SCADA contract.
From the Merobix industrial security hub - every security, compliance & certification guide in one place.
The short answer: SOC 2 is a CPA-issued attestation of a cloud service's operational controls, ISO 27001 is a certifiable international standard for a security management system, and IEC 62443 is the standards series written specifically for industrial control systems. They are complements, not substitutes - a credible cloud SCADA vendor needs an answer on all three.
Certifications exist because buyers cannot audit every vendor themselves. A water utility evaluating a cloud SCADA platform has no practical way to inspect the vendor's access-control discipline, change management, or tenant isolation - so it relies on an independent third party that did. That is the entire value proposition of SOC 2, ISO 27001, and IEC 62443: someone qualified looked, on your behalf, at things you cannot see from a sales demo.
The problem is that the three frameworks get used interchangeably in RFPs when they are not interchangeable at all. SOC 2 says nothing about PLC protocols. IEC 62443 says nothing about how the vendor's finance-adjacent cloud controls operate. ISO 27001 can be certified with a scope so narrow it excludes the product you are actually buying. A buyer who understands what each framework proves - and, just as importantly, what it does not - asks sharper questions and gets materially better answers. If you want the architectural half of that evaluation, start with our secure SCADA for OT networks guide; this post covers the paper half.
One vocabulary point up front, because vendors blur it constantly: ISO 27001 and IEC 62443 produce certificates; SOC 2 does not. SOC 2 is an attestation - an auditor's written opinion - and treating it as a certificate is the single most common compliance-language error in the industry. We will unpack why that distinction matters below.
SOC 2 comes from the AICPA, the US accounting profession's standards body, and it is performed exclusively by licensed CPA firms. The auditor examines a service organization's controls against the five Trust Services Criteria - security (mandatory), availability, processing integrity, confidentiality, and privacy - and issues a detailed report. A Type I report describes control design at a point in time; a Type II report tests whether the controls actually operated over an observation window, typically 3–12 months. Type II is the one that carries weight, because it proves the controls ran, not just that they were written down.
For cloud SCADA, SOC 2 answers the questions an IT security team asks about any SaaS vendor: who can access production, how are changes deployed, how is customer data protected, how are incidents handled, is there monitoring and alerting. It is the de facto entry ticket for selling cloud services to North American enterprises. What it does not do is evaluate the industrial-specific surface - device identity, telemetry integrity, setpoint write safety, protocol security. A vendor can hold a clean SOC 2 report and still ship a gateway that accepts unsigned telemetry.
The full mechanics - scoping, the observation window, how to read the auditor's opinion and exceptions - are covered in our deep dive, What Is SOC 2 Certification? Guide for Industrial Buyers.
ISO/IEC 27001 - published jointly by ISO and IEC, with the full text available for purchase from the IEC webstore - is the international standard for an information security management system (ISMS) - the ongoing management process by which an organization identifies risks, selects controls, and continually improves. The 2022 revision organizes 93 reference controls in Annex A across four themes: organizational, people, physical, and technological. Unlike SOC 2, ISO 27001 is a true certification: an accredited certification body performs a stage 1 audit (documentation) and a stage 2 audit (implementation), issues a certificate valid for three years, and returns annually for surveillance audits.
ISO 27001's strength is that it certifies the management system, which means the vendor is committed to risk assessment, internal audit, and corrective action as ongoing disciplines, not one-time projects. Its weakness for SCADA buyers is scope: the certificate applies only to what the scope statement says it applies to, and scope statements can be drawn narrowly enough to exclude the engineering team or the product itself. Always read the scope. We walk through the certification process, costs, the surveillance cycle, and the scope-gaming problem in What Is ISO 27001 Certification? Process, Cost & Timeline.
IEC 62443 is the only framework of the three written specifically for industrial automation and control systems. As the ISA/IEC 62443 series overview at ISA describes, it splits requirements across the ecosystem: product suppliers (62443-4-1 secure development lifecycle, 62443-4-2 component requirements), system-level architecture (62443-3-3), service providers (62443-2-4), and asset owners (62443-2-1). Its signature concept is the security level - SL1 through SL4 - which rates the sophistication of the attacker a system is designed to resist, from casual misuse up to state-level actors, across seven foundational requirements covering identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely event response, and resource availability.
Certification against IEC 62443 exists - schemes such as ISASecure and assessments by firms like exida and TÜV certify products and development lifecycles - but it is still far less common than SOC 2 or ISO 27001, and plenty of credible OT vendors are "aligned" rather than certified. That makes the buyer's job subtler: you are evaluating the quality of the vendor's mapping and evidence, not just the presence of a logo. The full picture - parts of the standard, SL levels, certification schemes, steps, and realistic cost and timeline ranges - is in our deep dive, IEC 62443 Certification: Levels, Process, Cost & Timeline.
| Attribute | SOC 2 | ISO 27001 | IEC 62443 |
|---|---|---|---|
| What it is | Attestation report (auditor's opinion), not a certificate | Certification of an information security management system | Standards series for industrial automation and control systems; certification available for products and lifecycles |
| Who assesses | Licensed CPA firms under AICPA standards | Accredited certification bodies (accredited by ANAB, UKAS, etc.) | Scheme-based labs and assessors (ISASecure, exida, TÜV) |
| What it covers | Service organization controls: security, availability, processing integrity, confidentiality, privacy | The management system: risk process plus 93 Annex A reference controls | Control-system architecture, components, development lifecycle, security levels SL1–SL4 |
| Output you can read | Type I or Type II report, usually shared under NDA | Certificate plus scope statement; Statement of Applicability on request | Certificate per product/process, or a control mapping if not certified |
| Validity rhythm | Re-examined every 12 months (new observation period) | 3-year certificate with annual surveillance audits | Scheme-dependent; typically periodic reassessment and per-version evaluation |
| Geographic weight | Dominant in North America | Dominant internationally; widely accepted everywhere | Global; referenced by regulators and sector standards (water, pipelines, chemicals) |
| Blind spot for SCADA buyers | Nothing industrial: no protocols, devices, or control safety | Scope can exclude the product; controls are generic, not OT-specific | Says little about the vendor's cloud business operations |
The practical conclusion: for a cloud SCADA platform these frameworks are complements, not substitutes. SOC 2 or ISO 27001 covers the operating company and its cloud; IEC 62443 covers the control-system product. A vendor answer that leans on only one of the three is leaving a third of your risk surface unexamined - which is why sector rules like API 1164 for pipelines and AWIA for water utilities increasingly reference 62443 alongside enterprise frameworks. Industry-specific guidance lives in our compliance posts for water utilities and other verticals.
Understanding the earning process tells you how much signal each claim carries. All figures below are indicative ranges - actual numbers vary widely with organization size, scope, and starting maturity, and vendors' own disclosures differ.
Vendor security pages use these words with very different amounts of substance behind them. A working decoder:
The red flag is not the absence of a certificate - young platforms and even large OT incumbents often lack them for specific products. The red flag is vague language that resists verification: "enterprise-grade security," "bank-level encryption," or "SOC 2 certified" with no report available. For a structured way to pressure-test any vendor's claims, use our enterprise SCADA buyer's guide alongside this post.
Key takeaway: SOC 2, ISO 27001, and IEC 62443 answer three different questions - is the cloud service operated with discipline, is there a certified management system behind it, and is the control-system product itself built to resist a defined attacker class. Demand evidence on all three axes from any cloud SCADA vendor, accept "readiness plus evidence" as an honest interim answer, and treat unverifiable certification language as the real disqualifier.
Turn this into your procurement checklist. For any cloud SCADA vendor, request:
Deployment model changes the division of labor too: in a cloud deployment the vendor holds most of these obligations, while on-premise shifts them to you - our cloud vs on-premise comparison covers that split in detail.
SOC 2 is an attestation report, issued by a licensed CPA firm, describing how a service organization's controls meet the AICPA Trust Services Criteria - it is common for US cloud services. ISO 27001 is an international certification of an information security management system (ISMS), issued by an accredited certification body after stage 1 and stage 2 audits. IEC 62443 is the standards series written specifically for industrial automation and control systems; it defines security levels SL1–SL4 and separate requirements for product suppliers, integrators, and asset owners, with certification available through schemes such as ISASecure. They overlap but answer different questions: SOC 2 covers cloud operations, ISO 27001 covers the security management system, and IEC 62443 covers the control-system product and architecture itself.
No. SOC 2 is an attestation, not a certification. A licensed CPA firm examines the service organization's controls and issues a report containing the auditor's opinion - there is no certificate, no badge-issuing body, and no pass/fail registry. A vendor that says it is SOC 2 certified is using the term loosely; the accurate phrasing is that the vendor has completed a SOC 2 Type I or Type II examination and can share the report under NDA. Buyers should always ask for the report itself, check the opinion, the period covered, the criteria in scope, and any exceptions the auditor noted.
For the control-system layer, IEC 62443 matters most because it is the only one of the three written for industrial automation: it addresses zones and conduits, security levels against defined attacker classes, and component-level requirements that SOC 2 and ISO 27001 never touch. For the cloud service wrapped around a SCADA platform, SOC 2 Type II is the most commonly requested evidence in North America, and ISO 27001 is often preferred internationally. A mature cloud SCADA vendor should be able to speak to all three: 62443 alignment for the product architecture, and SOC 2 or ISO 27001 progress for the operating organization.
Ranges vary widely with company size and scope, so treat all figures as indicative. A SOC 2 Type II typically involves a readiness phase of roughly 3–6 months, an observation window of 3–12 months, and combined audit plus preparation costs commonly cited from the tens of thousands of dollars into six figures for larger scopes. ISO 27001 certification often takes 6–18 months from a standing start, with certification-body fees plus internal and consulting costs in a similar range, then annual surveillance audits. IEC 62443 product certification through schemes like ISASecure is typically quoted per product and can take 6–18 months depending on development-lifecycle maturity. The honest takeaway: these are meaningful, multi-quarter investments, which is exactly why they carry signal.
Ask for substance instead of logos: which framework the vendor is working toward and where it is in the process; a control-by-control mapping to IEC 62443-3-3 or the SOC 2 Trust Services Criteria; architectural evidence such as tenant isolation design, MFA enforcement, audit logging, and encryption; and the results cadence of its internal and independent validation program. A vendor running a genuine readiness program - as Merobix does for SOC 2, alongside mapping its controls to IEC 62443 - can show you evidence today even though the audit report comes later. A vendor that can show neither certificates nor evidence is the actual red flag.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
We will walk you through our SOC 2 readiness program, IEC 62443 control mapping, and the platform architecture behind them - evidence first, logos second.