For those wondering about ISO 27001 - it's a standard for international security management, and popular in Europe.
However in the US it's not very relevant or even interesting to companies, and some European companies fail to understand that.
SOC 2 is the default and the preferred standard in the US - it's more domestic and less rigid than ISO 27001.