Auditor routes on ISO 27001 platforms, and the 2026 AICPA guidance to read if you add SOC 2
By the Clause Desk · · Updated
Every ISO 27001 platform on this site except one describes a route to an auditor. The routes differ in who manages the audit. Whatever the route, the checks on the auditor are yours to make.
What routes do the vendors describe?
Three patterns appear. Built-in audit: Scytale lists Built-In Audit with partner auditors, an audit hub, and says it takes over full management of the audit process with your chosen auditor. Auditor networks: Vanta describes access to a network of experienced auditors and a Vanta Audit product; Secureframe lists access to its Audit Partner Network on Fundamentals; Drata lists auditors among 1300+ partners; Sprinto lists Sprinto network auditor access on Foundation. Bring your own auditor: Sprinto lists this option on Foundation too. We did not find an auditor route described on Scrut's pages.
Why does the route matter for ISO 27001?
Because an ISO 27001 certificate is issued by a certification body, not by the platform. The platform can prepare evidence, schedule the audit and give the auditor access, but the audit's credibility depends on the certification body. Buyers of your certificate may check who issued it and whether that body is accredited. A route that makes the audit easy to book is useful; a route that makes it easy to skip checks is not.
What should you check about any auditor?
Four things. The certification body's accreditation and the accreditation body behind it. Who will lead your audit and their experience with software companies of your size. The commercial relationship between the certification body and the platform vendor, and whether it affects price or scheduling. And the audit plan: which sites, systems and controls will be sampled in stage 1 and stage 2.
What changed for SOC 2 buyers in 2026?
If SOC 2 is on your roadmap after ISO 27001, the AICPA and its Journal of Accountancy published four items between February and May 2026 that are worth reading before you choose an auditor route. We cite titles and dates only: 1 February 2026, Journal of Accountancy, "Promises of 'fast and easy' threaten SOC credibility"; 13 April 2026, AICPA Ethics Staff Insights, "Business arrangements with SOC tool providers"; 30 April 2026, Journal of Accountancy podcast, "The risks of quick-turn SOC engagements and what CPAs should know"; 14 May 2026, Journal of Accountancy, "AICPA guides peer reviewers to address SOC 2 risks". The AICPA's SOC page also says SOC services should be thoroughly evaluated by service organizations and CPA firms.
What does that mean in practice?
For SOC 2, ask whether the auditor is a licensed CPA firm enrolled in AICPA peer review, and ask how the firm's business arrangements with the tool vendor are structured, in line with the AICPA's ethics guidance on business arrangements with SOC tool providers. SOC 2 is an examination that CPAs perform under AICPA standards, so the CPA firm's standing matters as much as the platform's features. For ISO 27001, the equivalent questions are about the certification body's accreditation.
How do the routes differ in effort?
A vendor-managed audit, as Scytale describes it, moves scheduling, evidence requests and follow-ups to the vendor side, which suits teams without a compliance lead. An auditor network, as Vanta, Secureframe, Drata and Sprinto describe, gives you a shortlist and a shared evidence view, but you manage the relationship. Bring your own auditor, which Sprinto lists, suits companies that already have a certification body, for example from another ISO standard. None of these routes changes what the auditor tests; they change who carries the coordination work between stage 1, stage 2 and the surveillance audits.
What is the takeaway?
Pick a platform for how it prepares you, and pick the auditor for its standing. When a vendor offers both, ask the same questions you would ask an auditor you found yourself, and get the answers in writing.