If you sell into Europe, ISO 27001: over the last 365 days it appears in 3,408 tender notices on TED, the EU's own procurement portal, against 104 for SOC 2, about 33 times more often. If you sell mainly to US companies the answer runs the other way, because SOC 2 is the shape their procurement expects. The count is of mentions rather than hard requirements, TED's search API is public, and the query is below so you can re-run it.

This one is answerable with evidence that is not ours.

The measurement

TED is the European Union's own procurement portal. Every public tender above the EU thresholds is published there, and its search API is open to anyone with no key and no account. So "what does European procurement actually ask for" is a question with a checkable answer rather than an opinion.

Counting every spelling of both terms across the last 365 days:

Term Notices mentioning it
ISO 27001 3,408
SOC 2 104
NIS2 604
ISO 42001 18

ISO 27001 appears roughly 33 times more often than SOC 2.

What that number is and is not

It is a count of mentions, not of hard requirements. A notice that names ISO 27001 in a list of desirable qualifications counts the same as one that makes it a condition. The ratio compares like with like, so the comparison holds even though the absolute number overstates how many tenders truly demand it.

It is also public procurement only. Private enterprise buying is not in TED, and a large German manufacturer's vendor questionnaire does not become a tender notice. What public procurement gives you is the one slice of European buying where the requirements are published rather than inferred, which makes it the best available proxy and not a perfect one.

The honest version of the answer

If you sell into Europe, ISO 27001 is not a close call. It is the certification European buyers name, and the gap is not marginal.

If you sell mainly to US companies, the argument runs the other way. SOC 2 is the shape American procurement expects, its report format is what their security teams are trained to read, and an ISO certificate will often prompt a follow-up questionnaire rather than replace one.

If you sell to both, the sequencing question matters more than the choice. ISO 27001 builds a management system; SOC 2 attests to controls over a period. The ISO system is the thing that produces evidence continuously, so companies that build it first usually find a later SOC 2 cheaper than the reverse.

Run it yourself

The API is api.ted.europa.eu/v3/notices/search, it takes an expert query string, and it needs no credentials. Set paginationMode to ITERATION and count the notices matching each term. Our snapshot is dated and our script is in the open; if your numbers differ from ours, yours are the more recent ones.

Nothing about this is a claim you have to take from a vendor, which is the point.

Where in Europe

The same query split by buyer country: which EU countries name ISO 27001 in public tenders. Germany and Poland account for seven in ten mentions, and France, Spain and Italy name their national schemes instead.