ISO 27001 and SOC 2 are two auditors reading one control set. Build it once, sequence by revenue geography, and skip the "SOC 2 in two weeks" package the AICPA now flags.