Compliance framework crosswalk & control mapper
Pick any two of SOC 2, ISO 27001, HIPAA, CMMC 2.0, and FedRAMP and see domain-by-domain how their requirements line up — what maps directly, what only partially, and where the gaps are.
Compare two frameworks
Across 13 control domains, 8 map directly between SOC 2 and ISO 27001, 5 map partially, and 0 have no equivalent on one side.
| Control domain | SOC 2 reference | ISO 27001 reference | Match & notes |
|---|---|---|---|
| Governance & risk assessment | CC1.1–CC1.5, CC3.1–CC3.4 | ISMS clauses 4–6 (esp. 6.1.2), Annex A 5.1 | Direct match Both squarely require a governance structure and a documented risk assessment. ISO 27001 makes the risk methodology and treatment mandatory ISMS clauses, so the process is more prescriptive than SOC 2's criteria. |
| Policies & documentation | CC5.1–CC5.3, CC2.2–CC2.3 | Annex A 5.1, ISMS clause 7.5 | Direct match Each framework requires documented policies and controlled information. ISO's clause 7.5 adds explicit rules for creating, updating, and controlling documented information that SOC 2 addresses less formally. |
| Access control & identity | CC6.1–CC6.3 | Annex A 5.15–5.18 | Direct match Logical access provisioning, authentication, and privileged-access restrictions line up closely. Access reviews and joiner-mover-leaver evidence generally satisfy both. |
| Change management | CC8.1 | Annex A 8.32 | Direct match Both require controlled, authorized, and tested changes to systems. Change tickets and approval records typically serve as shared evidence. |
| Data protection & encryption | CC6.1, CC6.7 | Annex A 8.24, 5.12–5.14 | Partial SOC 2 treats encryption as a means of restricting access and transmission and only firmly requires it when the Confidentiality category is in scope, whereas ISO 27001 has a dedicated cryptography control plus explicit information classification and transfer controls. |
| Logging & monitoring | CC7.1–CC7.3, CC4.1–CC4.2 | Annex A 8.15–8.16 | Direct match System operations, anomaly detection, and ongoing monitoring map cleanly to ISO's logging and monitoring controls. Log configurations and alerting evidence are largely reusable. |
| Incident response | CC7.3–CC7.5 | Annex A 5.24–5.28 | Direct match Detection, response, and remediation of security events are required by both. Incident tickets, playbooks, and post-incident reviews support each audit. |
| Vendor & third-party risk | CC9.2 | Annex A 5.19–5.23 | Direct match Both require managing risks from suppliers and business partners. ISO's supplier and cloud-service controls are more granular, but vendor due-diligence files generally satisfy both. |
| Business continuity & availability | CC9.1, A1.1–A1.3 (if Availability in scope) | Annex A 5.29–5.30 | Partial SOC 2's dedicated availability, backup, and recovery criteria (A1.x) only apply when the Availability category is in scope, and CC9.1 is BCP-adjacent risk mitigation. ISO 27001 requires continuity and ICT readiness within the ISMS regardless. |
| Personnel security & training | CC1.4, CC2.2 | Annex A 6.1–6.6 (esp. 6.3) | Partial SOC 2 folds competence and security awareness into its governance and communication criteria, while ISO 27001 has explicit people controls covering screening, terms of employment, and confidentiality agreements that SOC 2 does not call out directly. |
| Asset & configuration management | CC6.1, CC7.1 | Annex A 5.9–5.11, 8.9 | Partial SOC 2 handles asset inventory and configuration implicitly within logical access and system operations, whereas ISO 27001 has dedicated asset-management and configuration-management controls, making its expectations more explicit. |
| Physical & environmental security | CC6.4–CC6.5 | Annex A 7.1–7.4 | Direct match Both require restricting physical access to facilities and equipment. ISO's physical theme is more granular, but data-center attestations and entry logs typically satisfy each. |
| Vulnerability & patch management | CC7.1–CC7.2 | Annex A 8.8 | Partial SOC 2 addresses vulnerability detection and monitoring under its system-operations criteria without prescribing a scanning cadence, whereas ISO 27001 has an explicit technical vulnerability management control. |
Counts and rows come straight from the AuditNex mapping database. Practical planning guidance — not an official crosswalk from the standards bodies. The mapper needs JavaScript; every pairing is also available as a plain page below.
All framework crosswalks
Every pairing gets a full guide: domain-by-domain mapping, which audit to run first, what evidence carries over, and auditors covering both.
Doing more than one framework?
Tell us your scope once and compare transparent quotes from vetted firms that cover every framework on your roadmap.
Get matched →