ISO 27001, SOC 2 and VDR certifications, explained
Most of the security logos on a data room’s website prove nothing at all. A padlock icon, the phrase “bank-grade encryption”, a coloured shield: none of them is a standard, and none can be checked.
Only two marks survive scrutiny, and they answer different questions. This guide is about telling the two that matter from the noise around them, and about turning either one from a claim into evidence before a single confidential document goes near the platform.
Start with the money, because it settles the first worry. Across a New Zealand deal, the monthly price of a data room lands anywhere from about NZD $150 to $6,000 and up, driven by deal size and page count, not by the badge on the login screen. Demanding certification barely shifts that number.
So the real question was never “can I afford a certified room.” It is “which proof does my deal actually need, and how do I confirm the logo is real.” We answer both, in that order.
Why do the numbers settle most of the argument?
Buyers overestimate how hard this is. The figures say otherwise.
An ISO 27001 certificate runs for three years, with lighter surveillance audits in the years between. A SOC 2 Type II report usually runs 40 pages or more and covers a window of 6 to 12 months. Checking either costs you one email and about an hour of reading. No fee. No specialist.
Hold those four numbers in mind and the anxiety drains out of the task.
Three years tells you a certificate can be genuine yet quietly out of date, so the year on the paper matters. Six to twelve months tells you a SOC 2 report describes a real stretch of ordinary operation, not a single tidy audit day. Forty pages tells you the document is substantive, not a badge. And one hour tells you there is no excuse to skip the check.
The cost figure is the one that reframes the decision. Because verification is nearly free, the calculation is not “is certified worth the premium.” It is “why would I trust an uncertified room when confirming a certified one costs an hour I was going to spend on the shortlist anyway.”
What do ISO 27001 and SOC 2 actually prove?
Every vendor prints a wall of security logos. Two of them mean something specific, and they do not mean the same thing.
ISO/IEC 27001 certifies an information security management system, usually shortened to ISMS. An accredited external auditor examines how the provider runs security as a business function, not just its software, and confirms it meets a global standard.
It certifies a habit, not a snapshot: risk identified, owners assigned, policies written, staff trained, incidents reviewed, improvements made.
- The certificate is valid for three years, with annual surveillance audits in between.
- It is short, and providers hand it over freely.
- It does not dictate technical settings. A provider can be certified and still store your data offshore.
The certificate says the process is sound. It does not answer every question for you.
SOC 2 comes from the American accounting profession and works differently. It is not a badge. It is a report in which an independent auditor describes a provider’s controls and tests whether they operated as intended.
- It is built around five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Most reports cover security; the better ones add confidentiality and availability, which is exactly what a deal cares about.
- Type I checks that controls are designed correctly at a single moment. Type II tests that they worked across a period, commonly 6 to 12 months.
- Because it details internal systems, it is rarely posted publicly. Vendors share it under a non-disclosure agreement on request.
For a data room, Type II is stronger evidence by a wide margin. A provider comfortable handing the report over has usually read it and is proud of it.
A SOC 2 Type II report is the closest thing you get to watching a provider’s security work on an ordinary Tuesday, not just on audit day.
How much certification does your deal actually need?
A certification is only worth what it protects. The honest question is not “does this provider hold ISO 27001” but “does the risk in my deal justify demanding it.”
Follow the data, not the deal size.
Context moves a deal to the right faster than size does.
A Marlborough winery selling to an Australian trade buyer carries an offshore-disclosure question a purely domestic sale would not. A Dunedin health-tech raise touches patient data. A Napier retirement village sale mixes both. None of those are large deals, yet each earns a firmer certification demand than a plain Tauranga packhouse trade sale of the same value.
The table maps common New Zealand scenarios to a sensible level of proof and an indicative monthly spend.
| Deal scenario | Certifications to demand | Indicative spend (NZD/month) | What pushes it higher |
|---|---|---|---|
| Small business sale under $2m | One of ISO 27001 or SOC 2 | $150 to $400 | Employee files, an offshore buyer |
| Startup seed or Series A raise | ISO 27001 or SOC 2 Type II | $300 to $700 | IP, source code, a crowded cap table |
| Property syndication offer | ISO 27001, plus strong privacy terms | $300 to $800 | Dozens of investors, personal data |
| Mid-market M&A ($10m to $50m) | ISO 27001 and SOC 2 Type II | $600 to $2,000 | Competing bidders, warranty risk |
| NZX listing or regulated raise | ISO 27001, SOC 2 Type II, cloud extensions | $1,500 to $6,000+ | Regulator scrutiny, market-sensitive data |
Read the pattern, not the exact figures. The more sensitive the documents and the more adversarial the counterparty, the more certification evidence is worth paying for.
And notice that certification barely changes the price. The strongest providers are certified as a matter of course, so demanding it rarely costs more; it removes the weakest options from your shortlist. Our NZ pricing guide breaks down what really drives those numbers, and the worth-it analysis helps size the decision for a small deal.
Compare data rooms by certification, security and price
Our comparison table shows which providers hold ISO 27001 and SOC 2, side by side with what they cost in NZD.
ISO 27001 or SOC 2: which answers which question?
They do not compete. They answer different questions, and the strongest providers carry both.
Put the attributes next to each other and the split is clean.
| Attribute | ISO 27001 | SOC 2 Type II |
|---|---|---|
| Is it a formal certificate | ✓ | ✗ |
| Is it a detailed report | ✗ | ✓ |
| Tests controls over a time period | ✗ | ✓ |
| Recognised globally | ✓ | ✓ |
| Usually shared publicly | ✓ | ✗ |
| Covers management process | ✓ | ✗ |
| Names specific control results | ✗ | ✓ |
| Renewed or refreshed regularly | ✓ | ✓ |
The short version: ISO 27001 tells you security is run as a managed system; SOC 2 Type II tells you the individual controls held up day to day.
If you can only get one, either is a solid baseline. Our wider guide to virtual data room security for NZ deals walks through the technical controls, from encryption to audit logs, that sit underneath both.
Which security marks are worth demanding, and which are noise?
Not every logo carries the same weight. Some are rigorous, independent and audited. Others are self-declared, region-specific, or simply irrelevant to a New Zealand corporate deal.
Here is how the common ones actually rank.
- ISO/IEC 27001. High weight. The clearest baseline signal that security is run as an audited system.
- SOC 2 Type II. High weight. The strongest evidence that specific controls actually worked over time.
- ISO 27017 and 27018. Useful. Cloud security and cloud privacy extensions; a genuine plus on top of 27001, and worth asking for on a regulated raise.
- GDPR alignment. Moderate, and contextual. Close to essential if a European fund or an EU-based acquirer is a counterparty, close to irrelevant for a purely domestic sale.
- HIPAA support. Niche. Only matters if United States health records are in play; a Dunedin health-tech deal with US patients is the rare case that needs it.
- “Bank-grade”, “military-grade”, or a padlock icon. None. Marketing language, not a standard, so give it no weight at all.
Two rules follow.
First, a mark only counts if an independent body issued it. A self-declared badge is a slogan.
Second, relevance is contextual. Do not pay a premium for a HIPAA-ready room to sell a cafe, but do insist on strong privacy terms the moment European investors or health records come near the deal.
How do you verify a certification is genuine?
A logo is a claim; a document is proof. Closing the gap takes a short email exchange, and how a provider responds tells you almost as much as the paperwork.
Work through it once, at the shortlist stage, before any confidential document goes near the platform.
Verifying a certification claim in five steps
Do this during your trial or shortlist stage, before any confidential document goes near the platform.
- 1
Ask for the document
Request the ISO 27001 certificate and the SOC 2 report directly. A screenshot of a logo is not evidence. Providers that hold these will send them, often the report under a short NDA.
- 2
Check who issued it
Confirm an accredited certification body issued the ISO certificate, and a licensed audit firm produced the SOC 2 report. Self-issued paperwork does not count.
- 3
Read the scope statement
The most common trap. Make sure the certificate covers the data room product and its hosting, not just the company's head office or an unrelated service.
- 4
Check the dates
An ISO certificate should be current, and a SOC 2 Type II window should be recent, ideally ending in the last year. A report from three years ago tells you little about today.
- 5
Map it to your deal
Match what the documents actually prove against your checklist and your Privacy Act duties. If a gap remains, ask the provider to explain how they cover it.
New Zealand’s national cyber agency, CERT NZ, publishes guidance on the basic controls every business should expect from a supplier. A certification is essentially a third party confirming a provider meets that bar, so you do not have to audit them yourself.
What are the red flags that a claim will not hold up?
Most of the risk hides in the gap between what a logo implies and what a document proves. These are the patterns that fall apart on inspection.
- A logo with no paperwork. If a provider cannot produce the certificate or report on request, assume the certification is aspirational.
- Scope that excludes the product. A company can hold ISO 27001 for its head office while the data room service you would actually use sits outside the certified boundary.
- A stale SOC 2 window. A Type II report covering a period that ended two years ago is a historical document. Controls, staff and infrastructure all change.
- Vague language dressed as a standard. “Bank-grade security” and a generic padlock are marketing, not certifications. They are unverifiable, so give them no weight.
- Type I passed off as Type II. A Type I report only confirms controls were designed well on one day. If a provider leans on SOC 2, confirm it is Type II before you count it as strong evidence.
If a provider stalls, sends a marketing PDF instead of the report, or cannot say what is in scope, that is your answer.
Working through options with these traps in mind is part of a sound buyer’s process for choosing a data room.
Ready to price a certified data room for your deal?
Use our NZD calculator to estimate the monthly cost for your page count, user numbers and deal length.
Where do GDPR, HIPAA and the Privacy Act 2020 fit?
This is where buyers most often confuse two separate things. A security certification proves a provider protects data well. It does not make your handling of that data lawful.
Those are different tests, and the legal one stays with you.
Load employee files, customer lists or health information into a data room and you are handling personal information under New Zealand law. The Office of the Privacy Commissioner sets out how the Privacy Act 2020 applies, and Information Privacy Principle 12 in the Privacy Act 2020 itself sets conditions on sending personal information to an overseas party. That is exactly what happens when your documents sit on a provider’s offshore servers.
No amount of ISO certification on the vendor’s side discharges those duties.
Treat certification and compliance as two columns on the same page. Certification tells you the tool is trustworthy. Your privacy obligations tell you how you must use it. A certified data room can still be used unlawfully; the certificate protects the data, the law governs what you are allowed to do with it. We cover that second column in depth in our guide to your Privacy Act 2020 obligations when sharing deal data.
GDPR and HIPAA sit in the same bucket: relevant only when the counterparties or the data type pull them in. The Marlborough winery selling into the EU, the Dunedin health-tech with US patients, the Napier village holding health records; each drags a different regime into the room, regardless of how well the platform is certified.
A logo is a claim; a document is proof. How a provider answers when you ask for the report tells you nearly as much as the report itself.
So what should you actually demand?
Certifications are not the whole security story, but they are the fastest, most reliable filter you have. Run every shortlisted provider through these eight checks, weighting each by deal size and document sensitivity.
- ISO 27001 certificate. Current, issued by an accredited body, with the data room product in scope.
- SOC 2 report. A Type II report covering a recent 6 to 12 month window, shared under NDA.
- Encryption. AES-256 at rest and TLS 1.2 or higher in transit, stated plainly.
- Access controls. Granular permissions, single sign-on and multi-factor authentication as standard.
- Data residency. You can find out which country your documents sit in, and whether that is fixed.
- Audit trail. A complete, exportable, tamper-evident log of who saw what and when.
- Privacy Act fit. The provider will sign terms that support your NZ Privacy Act 2020 obligations.
- Currency. Every certificate and report is in date, not lapsed or two years stale.
Do this once, at the shortlist stage, and you rarely have to think about it again.
Demand ISO 27001 or SOC 2 Type II as a baseline. Read the scope and dates rather than the logo. Keep your Privacy Act duties in the column next to them, never underneath. The weak options remove themselves, and you spend your energy on the deal instead of the platform.
Frequently asked questions
Do I really need ISO 27001 or SOC 2 for a small NZ deal?
For anything with genuinely confidential documents, yes, at least one of them. Because the stronger providers are certified as standard, insisting on it rarely costs more; it mostly just removes the weakest tools from your shortlist. For a very small, low-sensitivity deal you might accept one rather than both, but going with neither means you are trusting the provider's word alone.
Is ISO 27001 or SOC 2 better?
Neither is better; they answer different questions. ISO 27001 certifies that security is run as a managed, audited system. SOC 2 Type II reports on whether specific controls worked over a period of time. The strongest providers hold both, and if you can only get one, either is a solid baseline.
Does a certification mean the data room is Privacy Act compliant?
No. A certification proves the provider protects data well. It does not make your use of that data lawful. Your obligations under the Privacy Act 2020, including the rules on overseas disclosure, stay with you regardless of how well certified the tool is.
How do I actually check a provider's certification?
Ask for the certificate and the SOC 2 report directly, confirm an accredited body issued them, read the scope to make sure the data room product is covered, and check the dates are current. A provider that will not share the report under NDA has told you something useful.
What is the difference between SOC 2 Type I and Type II?
A Type I report confirms controls are designed correctly at a single point in time. A Type II report tests that they operated effectively across a period, usually 6 to 12 months. For a data room, a Type II report is much stronger evidence, so confirm which type a provider is offering.
Are 'bank-grade' or 'military-grade' security claims worth anything?
Not on their own. They are marketing phrases, not audited standards, so they are unverifiable. Look past them to the concrete claims you can check: a named certification, AES-256 encryption, and enforced multi-factor authentication.