SOC 2 and ISO 27001 prove you run a security and management system: Access control, change management, risk treatment, vendor oversight. Auditors examine control design and operating effectiveness. Neither certification inventories every open-source license obligation in every shipped product by default.
Buyers treat certification as table stakes, then ask separately for third-party license disclosure (full text, attribution, product-scoped inventory). Passing SOC 2 does not answer "what GPL components are in the build we licensed."