SOC 2 and ISO 27001 come up in almost every vendor conversation that touches data, and they are treated, often, as a pass-fail signal: certified means safe, uncertified means risky. That shorthand is useful for a first filter and genuinely misleading if it's where the evaluation stops.
What a SOC 2 report actually says
A SOC 2 Type II report confirms that a vendor's controls, as defined by the vendor themselves within a chosen scope, operated effectively over an observation period, as assessed by an independent auditor. Every part of that sentence matters. The vendor defines the scope. Ask what's actually covered, and ask to see the report itself rather than accepting the badge on the website, because the badge doesn't show you what was tested.
ISO 27001 confirms a system, not an outcome
ISO 27001 certifies that an organisation has an information security management system that meets a defined standard. It's a real and valuable signal about process maturity. It does not certify that the vendor has never had an incident, or that their specific product architecture is appropriate for your use case. Those require separate questions.
The gap between certified and appropriate for you
A vendor can hold every relevant certification and still be a poor fit, if their scope doesn't cover the specific service you're buying, if the certification is a year past its audit window, or if your regulatory obligations exceed what the certification was built to address. Certifications are a floor worth requiring. They are not a substitute for asking what happens in a real incident, and who is accountable for what when one occurs.
Treat the certification as the first filter, not the final answer, and the rest of the evaluation gets meaningfully more useful.