SOC 2, ISO 27001, and FedRAMP each verify a different thing: SOC 2 is an AICPA-defined attestation of specific controls over an observation period; ISO/IEC 27001 is an internationally certified information security management system last revised in 2022; and FedRAMP is a US federal authorization required to sell cloud services to government agencies. None substitutes for the others.
Each certification verifies something different, was built for a different purpose, and matters more or less depending on who the buyer is and what data the vendor will handle. Understanding the distinction is the difference between checking a compliance box and actually knowing what you’re buying.
SOC 2: An Attestation, Not a Certification
SOC 2 is a report, not a certificate, and that distinction matters more than it sounds. An independent auditor examines a vendor’s controls against the AICPA’s Trust Services Criteria, covering areas like security, availability, and confidentiality, and issues a formal opinion on whether those controls are operating effectively.
A SOC 2 Type I report evaluates whether controls are designed properly at a single point in time. A SOC 2 Type II report, which carries significantly more weight, evaluates whether those controls actually operated effectively over an extended period, typically six to twelve months. Type II is the standard most enterprise buyers should be asking for, since Type I only confirms a policy exists, not that anyone follows it.
SOC 2 is primarily a North American standard and is what most US enterprise buyers expect to see from a SaaS vendor handling their data.
ISO 27001: A Certified Management System
ISO 27001 works differently. Rather than auditing specific controls over a period of time, it certifies that an organization has built and maintains an information security management system, or ISMS, that follows an internationally recognized framework for identifying risks, implementing controls, and continuously improving them. The certification is renewed periodically rather than reported on an ongoing observation period.
ISO 27001 carries more weight for international buyers and organizations operating outside North America, where it is often the default expectation rather than SOC 2. For a vendor doing business globally, holding both certifications signals security maturity to buyers on both sides of that expectation.
FedRAMP: Built for One Buyer, and Rare Outside It
FedRAMP is a US federal government program that authorizes cloud service providers to handle federal data, and it sits in a different category entirely from SOC 2 and ISO 27001. It is not a general-purpose security certification a vendor pursues to reassure the broader market. It is a specific, rigorous authorization process required to sell to federal agencies, evaluated at different impact levels depending on the sensitivity of the data involved.
FedRAMP authorization is uncommon among form and data collection vendors specifically, because the assessment process is lengthy and resource-intensive. A vendor that holds FedRAMP authorization, particularly at the High impact level, has cleared a bar that most competitors in the category have not attempted, which matters directly for government buyers and indirectly for any buyer who wants evidence of security depth beyond commercial-market certifications.
What to Actually Ask a Vendor
Buyers evaluating a form or data collection vendor’s certifications should ask a few direct questions rather than accepting a logo grid at face value.
- Is the SOC 2 report a Type I or Type II, and how recent is the audit period it covers?
- Is ISO 27001 certification current, and does it cover the specific product being purchased or only part of the vendor’s broader business?
- For buyers in or adjacent to the government, does the vendor hold FedRAMP authorization, and at what impact level?
None of these certifications alone guarantees a vendor is secure, and none of them substitutes for a buyer’s own security review. What they provide is independently verified evidence that a vendor has been evaluated against a defined standard, which is meaningfully different from a vendor’s own claims about its security practices.
Where FormAssembly Fits
FormAssembly holds SOC 2 Type II, meaning its security controls have been independently audited by A-LIGN over an extended observation period, not just assessed at a single point in time. The platform is also ISO 27001 certified, supporting buyers who need or prefer that international standard, and offers FedRAMP High Impact authorization (through our partnership with FedHIVE) a level of federal authorization uncommon among form and data collection vendors and directly relevant to government agencies and contractors.
FormAssembly is also PCI DSS Level 1 certified and supports HIPAA compliance for organizations handling protected health information. For buyers comparing vendors on security posture rather than marketing language, that combination of independently verified certifications, spanning US enterprise, international, and federal government standards, is the actual evidence to look for.