ISO 27001 and SOC 2 for technology companies
One platform for ISO 27001, SOC 2 and your customers' security questions. Evidence comes from AWS, GitHub and Azure, so your engineers stay on the product.
- ISO 27001 and SOC 2 on one set of controls
- Evidence from AWS, GitHub and Azure
- Built and hosted in the EU

What tech companies achieve with Tidal
- 13 weeks
- Median from kickoff to ISO 27001 certificate across our customers
- 0-2
- Findings on average at the certification audit
- 300+
- Automated tests on your cloud and tooling
Why ISO 27001 stalls at tech companies
Not because of the standard, but because of how the work is organised next to a product roadmap.
Security is everyone's side job
Your engineers build product. Compliance gets the leftovers of the sprint, so controls stay half done.
Evidence from screenshots
Fresh screenshots of cloud settings and reviews before every audit. By the next audit they are out of date again.
A new questionnaire for every prospect
Security questions keep landing with the same tech lead, who loses an afternoon each time.
Two standards, two projects
Treat ISO 27001 and SOC 2 separately and you do the work twice and keep two sets of records.
How technology companies use Tidal
From one set of controls to the answer your prospect's security team is waiting for.
One set of controls for ISO 27001 and SOC 2
The ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria overlap for the most part. In Tidal you set them up once, with an owner and a status per control, and see exactly which evidence counts for both.
More on ISO 27001
Evidence comes from your cloud, not from screenshots
Connect AWS, GitHub, Azure and Entra ID and your ticketing system. Tidal collects the evidence automatically and attaches it to the right control, so encryption, branch protection, MFA and access rights stay current without screenshots.
See all integrations
Show prospects how your security is organised
Every enterprise deal comes with security questions. Your trust center shares your certificates, policies and controls with prospects, so you do not need your tech lead for every questionnaire.
More on the trust centerTrust center
Shared with prospects
- ISO 27001 certificatePublic
- Information security policyPublic
- Penetration test reportAfter NDA
- SubprocessorsPublic
Shared through your trust center, you decide who sees what
One dossier for your auditor and your customer
Your Statement of Applicability, risk assessment and SOC 2 criteria build themselves from live data. When a prospect or auditor asks how you control access to customer data, the answer is already there.
More on controls and reportingAudit dossier
- Statement of ApplicabilityCurrent
- Risk analysisCurrent
- SOC 2 Trust Services CriteriaCurrent
- Management reviewCurrent
Manual or with Tidal
Collecting evidence
Manual
Screenshots per control
With Tidal
Automatic from AWS, GitHub and Azure
ISO 27001 and SOC 2
Manual
Two separate projects
With Tidal
One set of controls
Prospects' security questions
Manual
Answered from scratch each time
With Tidal
Shared through your trust center
Evidence current between audits
Manual
Not included
With Tidal
Continuous tests
Time to certificate
Manual
Often 6 to 12 months
With Tidal
A median of 13 weeks
The journey: a median of 13 weeks from kickoff to certificate
A realistic path, not a promise of compliance in a few days. You always see what is expected of your team.
Day 1
Setup
Connect your cloud, repositories and identity provider. Tidal shows straight away which controls are already in place.
Week 1-2
Plan
Together we set your scope and prepare the risk assessment and plan, with templates written for software companies.
Week 3-11
Implement
Policies, controls and evidence fall into place while your team keeps building. Engineering only gets involved where something technical has to change.
Week 12-13
Certify
An independent, accredited certification body carries out the audit. Your evidence is ready in one file.
After
Maintain
Annual audits, new customer questions and a SOC 2 track run in the same system, without starting over.
Connect the tools you already use
AWS
Azure
GitHub
GitLab
Google Cloud
Jira
Linear
Datadog
Cloudflare
Vercel
Aikido- All integrations
“With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.”

Chiel Bos
COO, CBYTE
In tech, certification is a condition of sale
Four standards your customers and tenders put to you.
- ISO 27001
- The international standard your enterprise customers and tenders require
- SOC 2
- What American customers ask for: an audit opinion on your controls
- GDPR
- As a processor you have to show that customer data is safe with you
- NIS2
- If you supply critical sectors, your customer's duty of care carries into your contract
Frequently asked questions
That depends on your customers. European and Dutch customers and tenders generally ask for ISO 27001; American customers almost always ask for SOC 2. If you serve both markets, you set up one set of controls in Tidal that covers both.
Across our customers the median is 13 weeks from kickoff to certificate. How long it takes for you depends on your scope and what is already in place. SOC 2 Type II adds an observation period in which you show your controls actually work, usually three to six months.
For everything an integration can check, yes. Encryption, MFA, access rights and branch protection come straight from AWS, GitHub and Azure. Anything that cannot be connected you record manually with an expiry date, so it does not go stale unnoticed.
Yes. Evidence you assign once counts for every framework the same control appears in. So you never start over when another standard is added.
No. The certificate comes from an independent, accredited certification body. Tidal makes sure your file is in order and guides you through the audit.
Less than you think. The integrations do the evidence work and your trust center answers much of what prospects ask. Engineering only gets involved where something technical has to change.