Skip to main content

ISO 27001 and SOC 2 for technology companies

One platform for ISO 27001, SOC 2 and your customers' security questions. Evidence comes from AWS, GitHub and Azure, so your engineers stay on the product.

  • ISO 27001 and SOC 2 on one set of controls
  • Evidence from AWS, GitHub and Azure
  • Built and hosted in the EU
The Tidal Control dashboard showing progress on SOC 2

What tech companies achieve with Tidal

13 weeks
Median from kickoff to ISO 27001 certificate across our customers
0-2
Findings on average at the certification audit
300+
Automated tests on your cloud and tooling

Why ISO 27001 stalls at tech companies

Not because of the standard, but because of how the work is organised next to a product roadmap.

  • Security is everyone's side job

    Your engineers build product. Compliance gets the leftovers of the sprint, so controls stay half done.

  • Evidence from screenshots

    Fresh screenshots of cloud settings and reviews before every audit. By the next audit they are out of date again.

  • A new questionnaire for every prospect

    Security questions keep landing with the same tech lead, who loses an afternoon each time.

  • Two standards, two projects

    Treat ISO 27001 and SOC 2 separately and you do the work twice and keep two sets of records.

How technology companies use Tidal

From one set of controls to the answer your prospect's security team is waiting for.

One set of controls for ISO 27001 and SOC 2

The ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria overlap for the most part. In Tidal you set them up once, with an owner and a status per control, and see exactly which evidence counts for both.

More on ISO 27001
The controls overview in Tidal Control, with status, progress and framework per control

Evidence comes from your cloud, not from screenshots

Connect AWS, GitHub, Azure and Entra ID and your ticketing system. Tidal collects the evidence automatically and attaches it to the right control, so encryption, branch protection, MFA and access rights stay current without screenshots.

See all integrations
Connected integrations in Tidal Control, including Azure, Google Workspace and Google Cloud

Show prospects how your security is organised

Every enterprise deal comes with security questions. Your trust center shares your certificates, policies and controls with prospects, so you do not need your tech lead for every questionnaire.

More on the trust center

Trust center

Shared with prospects

  • ISO 27001 certificatePublic
  • Information security policyPublic
  • Penetration test reportAfter NDA
  • SubprocessorsPublic

Shared through your trust center, you decide who sees what

One dossier for your auditor and your customer

Your Statement of Applicability, risk assessment and SOC 2 criteria build themselves from live data. When a prospect or auditor asks how you control access to customer data, the answer is already there.

More on controls and reporting

Audit dossier

PDF

  • Statement of ApplicabilityCurrent
  • Risk analysisCurrent
  • SOC 2 Trust Services CriteriaCurrent
  • Management reviewCurrent

Manual or with Tidal

  • Collecting evidence

    Manual

    Screenshots per control

    With Tidal

    Automatic from AWS, GitHub and Azure

  • ISO 27001 and SOC 2

    Manual

    Two separate projects

    With Tidal

    One set of controls

  • Prospects' security questions

    Manual

    Answered from scratch each time

    With Tidal

    Shared through your trust center

  • Evidence current between audits

    Manual

    Not included

    With Tidal

    Continuous tests

  • Time to certificate

    Manual

    Often 6 to 12 months

    With Tidal

    A median of 13 weeks

The journey: a median of 13 weeks from kickoff to certificate

A realistic path, not a promise of compliance in a few days. You always see what is expected of your team.

  1. Day 1

    Setup

    Connect your cloud, repositories and identity provider. Tidal shows straight away which controls are already in place.

  2. Week 1-2

    Plan

    Together we set your scope and prepare the risk assessment and plan, with templates written for software companies.

  3. Week 3-11

    Implement

    Policies, controls and evidence fall into place while your team keeps building. Engineering only gets involved where something technical has to change.

  4. Week 12-13

    Certify

    An independent, accredited certification body carries out the audit. Your evidence is ready in one file.

  5. After

    Maintain

    Annual audits, new customer questions and a SOC 2 track run in the same system, without starting over.

Connect the tools you already use

  • AWS
  • Azure
  • GitHub
  • GitLab
  • Google Cloud
  • Jira
  • Linear
  • Datadog
  • Cloudflare
  • Vercel
  • Aikido
  • All integrations

“With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.”

Chiel Bos

COO, CBYTE

Frequently asked questions

That depends on your customers. European and Dutch customers and tenders generally ask for ISO 27001; American customers almost always ask for SOC 2. If you serve both markets, you set up one set of controls in Tidal that covers both.

Across our customers the median is 13 weeks from kickoff to certificate. How long it takes for you depends on your scope and what is already in place. SOC 2 Type II adds an observation period in which you show your controls actually work, usually three to six months.

For everything an integration can check, yes. Encryption, MFA, access rights and branch protection come straight from AWS, GitHub and Azure. Anything that cannot be connected you record manually with an expiry date, so it does not go stale unnoticed.

Yes. Evidence you assign once counts for every framework the same control appears in. So you never start over when another standard is added.

No. The certificate comes from an independent, accredited certification body. Tidal makes sure your file is in order and guides you through the audit.

Less than you think. The integrations do the evidence work and your trust center answers much of what prospects ask. Engineering only gets involved where something technical has to change.