SOC 2 and ISO 27001 certification tracking: What IT services firms need beyond a folder of PDFs

Client due diligence doesn't stop at your SOC 2 report – it wants to know the specific people behind it are still certified, right now.

Editorial Team
31.07.2026
Copy link

A SOC 2 Type II report tells a prospective client that your controls were tested and held over several months, signed off by an independent auditor. It says nothing about whether the engineer sitting on their account today still holds the certification your own security policy requires for that role. ISO 27001 certification tells a client your information security management system passed a surveillance audit. It says nothing about whether the person who left last quarter took a compliance-critical certification with them.

Client due diligence teams increasingly ask both questions. Most IT services firms can answer the systems question in minutes and the people question in days – if they can answer it at all. It's the same gap general-purpose certification tracking software is built to close, and it shows up in a specific way for SOC 2 and ISO 27001-scoped teams.

What a due diligence request actually looks like

In practice, this rarely arrives as a single pointed question. A prospective client's security team sends a vendor questionnaire – often a SIG Lite or CAIQ template, sometimes a bespoke one built by their own procurement or InfoSec function – and buried among the sections on data handling and incident response is a line asking for evidence that personnel with access to their systems or data hold current, relevant security certifications.

Answering that line well on the first pass is a different exercise from answering it eventually. A due diligence review with an open action item rarely kills a deal outright, but it slows it down, invites follow-up questions, and tells the client's security team the answer wasn't readily available – which is its own kind of answer.

What SOC 2 and ISO 27001 actually ask of your people

SOC 2's Common Criteria are built on the COSO framework, and CC1.4 asks a direct question: does the organisation demonstrate a commitment to attracting, developing, and retaining competent people aligned to its security objectives? ISO 27001:2022 asks something similar through two doors. Clause 7.2 requires organisations to determine, ensure, and document the competence of anyone whose work affects information security performance – the same competence clause that sits inside ISO 9001 and every other management system standard built on ISO's shared structure. Annex A control 6.3 then goes further on the operational side, requiring evidence that personnel understand and are trained on their specific security responsibilities.

Neither standard is satisfied by a training completion record from three years ago. Both want something closer to a live answer: who on this team is currently qualified for the security-sensitive work they're doing, and can you prove it without a week's notice.

A certificate folder proves attendance, not current competence

Individual security certifications carry their own expiry logic. A CISSP holder needs continuing professional education credits to stay current. An AWS Security Specialty certification lapses after three years without renewal. An ISO 27001 Lead Implementer or Lead Auditor credential has its own recertification cycle, separate from the organisation's own ISO surveillance audit. A folder of PDFs collected at hiring time answers none of these questions on an ongoing basis – it tells you someone passed an exam once, not that they're still current today.

MuchSkills tracks certifications against the specific role requirement they're meant to satisfy, with an expiry date that triggers before it becomes a problem – not a static record that quietly goes stale.

Acquisitions multiply the problem

IT services and cybersecurity firms grow through acquisition regularly, and each acquired business brings its own certification history, tracked its own way. One US-based, security-first IT services provider serving more than 1,500 clients made three acquisitions in a single year – and every one of them arrived with a certification record built for its own internal use, not designed to reconcile with anyone else's.

The pattern is familiar: one acquired team tracked security certifications in a shared drive, another in an HRIS free-text field, a third in whatever the outgoing compliance lead happened to remember. None of it answers the question a client due diligence team actually asks, which is usually some version of: across the whole delivery team assigned to our account, who holds what, and is it still valid. Reconciling that manually after each acquisition is a project in itself, repeated every time the company grows.

How one IT services firm consolidated its certification evidence

TBS (Telelink Business Services), a Bulgarian IT services firm, is ISO-certified across quality, environmental, occupational health and safety, and privacy standards, and runs its own Pearson VUE test centre – certification isn't a side concern for TBS, it's close to the core of the business. Before MuchSkills, the company's compliance and skills records were split across SharePoint, Dynamics 365, and a custom Power BI layer built to stitch the two together.

Asked how it compared, Hinka S., Learning Coordination Specialist at TBS, put it simply: "MuchSkills gave us more functionality and a truly user-friendly design." The move consolidated certification records that had previously lived in three separate systems, none of which was built to answer a client's or an auditor's question quickly.

The audit trail auditors and clients actually want

When a due diligence team or an ISO surveillance auditor asks who approved a certification renewal, or what changed in a record since the last review, "we believe it's current" is not an answer either group will accept. MuchSkills logs every certification change – added, edited, removed, renewed – with full attribution, so the answer is a lookup rather than a reconstruction from memory and email threads.

Certifications sit under three-way ownership: the employee uploads their own record, a manager validates it, and the requirement itself is attached to the role rather than to a named person – which means a coverage gap is more likely to surface before the audit than during it. If your Lead Cloud Architect leaves, for example, the role itself still shows a required AWS Security credential as unmet – visible to whoever inherits the role or reviews coverage next, rather than something that only surfaces when a client or auditor asks who's covering it now. That only holds if records are kept current as people renew, add, or let certifications lapse; the structure encourages it, but it doesn't happen automatically.

Where compliance automation platforms stop

Most IT services firms pursuing SOC 2 or ISO 27001 are already running a compliance automation platform – Vanta, Drata, or Secureframe are the names that come up most often. These tools are built to run the audit itself: continuous control monitoring, evidence collection, and built-in security-awareness training that satisfies part of the A.6.3 or CC1.4 requirement for everyone in the organisation.

What they're not typically built to do is map individual professional certifications against what specific roles on your delivery team actually require, or flag a gap before it becomes a client-facing problem. A completed security-awareness module answers "did everyone go through the training." A current CISSP answers "does this specific person still hold the credential." Proof of the first won't satisfy a request that's really asking the second.

Frequently asked questions

What is SOC 2 certification tracking software?

SOC 2 certification tracking software is a system that records and monitors the individual security certifications and training your team holds against the requirements SOC 2's Common Criteria expect – particularly CC1.4, which asks organisations to demonstrate ongoing commitment to competent, security-aligned staff. It's distinct from the audit itself, which is performed by an independent SOC 2 assessor.

What's the difference between SOC 2 and ISO 27001 certification requirements for employees?

SOC 2 addresses workforce competence through CC1.4, part of its Common Criteria built on the COSO framework. ISO 27001:2022 addresses it through Annex A control 6.3, information security awareness, education and training. Both ultimately ask the same underlying question – can you demonstrate your people are competent for security-sensitive roles – through different clause structures.

Do I still need certification tracking if we already use Vanta or Drata for SOC 2?

Usually, yes, for a specific reason. Compliance automation platforms like Vanta and Drata are built to run the audit itself – continuous control monitoring, evidence collection, and often built-in security-awareness training. They're generally not built to map individual professional certifications, such as CISSP or cloud security credentials, against what specific roles require, or to track each certification's own independent renewal cycle. Most IT services firms end up running both, for different reasons.

How often do IT security certifications need to be renewed?

It varies by certification. CISSP requires ongoing continuing professional education credits rather than a fixed exam retake. Many cloud security certifications, including AWS's, expire after three years without renewal. ISO 27001 Lead Implementer and Lead Auditor credentials follow their own recertification cycles, separate from the organisation's own ISO surveillance audit schedule.

Where to go from here

A SOC 2 report or an ISO 27001 certificate proves your organisation passed an audit. Proving the specific people behind it are still qualified, on demand, is a different – and ongoing – job. See how MuchSkills handles certification tracking for IT services and security-led organisations, or explore the Compliance solution page for the wider picture.

If your next client due diligence request is closer than your certification records are ready for, watch the Compliance Demo – eighteen minutes that walks through exactly this problem.

Cute fox
Contents

Subscribe to our newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Continue reading

SOC 2 and ISO 27001 certification tracking: What IT services firms need beyond a folder of PDFs

Learn more

Talent mapping software: What to look for and how to choose

Learn more

ISO 9001 Clause 7.2 and AS9100: Proving competence, not just certificates, across multi-site manufacturing

Learn more