SOC 2 to CMMC 2.0: control mapping & evidence reuse
6 of 13 control domains map directly. See exactly where SOC 2 and CMMC 2.0 overlap, which evidence carries over, and which engagement to run first.
How SOC 2 and CMMC 2.0 relate
Companies that sell to both commercial buyers and the U.S. Department of Defense often end up needing SOC 2 and CMMC 2.0 Level 2 at the same time. SOC 2 is what enterprise and SaaS customers ask for during procurement, while CMMC Level 2 is what a defense contractor or subcontractor must reach to handle Controlled Unclassified Information (CUI) on a DoD contract. If your organization is chasing both markets, the same underlying security program has to satisfy two very different review regimes.
Structurally the two frameworks come from different worlds. SOC 2 is an AICPA attestation performed by a CPA firm against the Trust Services Criteria, organized as Common Criteria CC1 through CC9 plus optional categories for Availability, Confidentiality, Processing Integrity, and Privacy; the result is a Type 1 or Type 2 report, not a certificate. CMMC 2.0 Level 2 is a DoD assessment of 110 practices drawn from NIST SP 800-171 Revision 2, grouped into 14 control families (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, and SI) and assessed by a certified third-party assessment organization (C3PAO). SOC 2 states outcomes as criteria to be met by controls, whereas 800-171 lists prescriptive, individually numbered practices.
The mapping below is practical guidance from AuditNex to help teams plan a combined program and reuse work across engagements. It is not an official government or standards-body crosswalk, and it is not a substitute for scoping decisions made with your CPA firm and your C3PAO.
Domain-by-domain mapping
Each row pairs the closest SOC 2 and CMMC 2.0 requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.
Across 13 control domains, 6 map directly between SOC 2 and CMMC 2.0, 6 map partially, and 1 have no equivalent on one side. Counts are computed live from the mapping table below.
| Control domain | SOC 2 reference | CMMC reference | Match & notes |
|---|---|---|---|
| Governance & risk assessment | CC1.1–CC1.5; CC3.1–CC3.4 | 3.11.1–3.11.3 (RA) | Partial Both require a periodic, documented risk assessment, but CMMC's RA family targets risk to CUI specifically, while SOC 2 CC1.x adds board and management governance that 800-171 does not spell out. |
| Policies & documentation | CC5.1–CC5.3 | 3.12.x (CA), incl. System Security Plan | Partial SOC 2 CC5.x expects formal, standalone policies, whereas CMMC has no dedicated policy family and instead documents control implementation through the System Security Plan under the CA family (3.12.x). |
| Access control & identity | CC6.1–CC6.3 | 3.1.x (AC); 3.5.x (IA) | Direct match Both squarely require logical access control, least privilege, and authentication; CMMC splits this into prescriptive AC and IA practices, while SOC 2 states the same outcomes as criteria met by controls. |
| Change management | CC8.1 | 3.4.3–3.4.4 (CM) | Direct match Both require tracking and approving system changes; CMMC 3.4.3–3.4.4 mandates change control and approval within its configuration-management family, aligning closely with SOC 2 CC8.1. |
| Data protection & encryption | CC6.1, CC6.7 | 3.13.x (SC) | Partial SOC 2 treats encryption as a point of focus under CC6.1 and CC6.7 rather than a hard mandate, whereas CMMC's SC family explicitly requires cryptographic protection of CUI in transit and at rest. |
| Logging & monitoring | CC7.1–CC7.2; CC4.1–CC4.2 | 3.3.x (AU); 3.14.x (SI) | Direct match Both require event logging, review, and monitoring for anomalies; CMMC's AU family is more prescriptive about audit record content and retention than SOC 2 CC7.1–CC7.2. |
| Incident response | CC7.3–CC7.5 | 3.6.x (IR) | Direct match Both require detection, response, and recovery from incidents; CMMC's IR family adds explicit reporting expectations tied to DoD requirements beyond what SOC 2 CC7.3–CC7.5 states. |
| Vendor & third-party risk | CC9.2 | 3.1.20 (external systems); DFARS 252.204-7012 flow-down | Partial SOC 2 CC9.2 requires a formal vendor and business-partner risk program, while CMMC has no supplier family and instead pushes third-party obligations through DFARS 252.204-7012 flow-down and the external-systems practice 3.1.20. |
| Business continuity & availability | A1.1–A1.3 (if Availability category in scope) | No direct equivalent | No equivalent SOC 2's optional Availability category covers backup and recovery, but NIST SP 800-171 has no continuity or contingency family, so CMMC Level 2 does not address this domain. |
| Personnel security & training | CC1.4; CC2.2 | 3.9.x (PS); 3.2.x (AT) | Direct match Both require personnel screening and security awareness training; CMMC separates these into the PS and AT families, while SOC 2 folds training under CC1.4 and CC2.2. |
| Asset & configuration management | CC6.1, CC7.1 | 3.4.1–3.4.2 (CM) | Partial CMMC's CM family explicitly requires baseline configurations and asset inventories (3.4.1–3.4.2), whereas SOC 2 addresses asset and configuration management only implicitly through CC6.1 and CC7.1. |
| Physical & environmental security | CC6.4–CC6.5 | 3.10.x (PE) | Direct match Both require controlling physical access to facilities and equipment; CMMC's PE family and SOC 2 CC6.4–CC6.5 align closely, though CMMC is more explicit about escorting visitors and managing physical access devices. |
| Vulnerability & patch management | CC7.1 | 3.11.2 (RA); 3.14.1 (SI) | Partial CMMC explicitly requires vulnerability scanning and flaw remediation (3.11.2, 3.14.1), while SOC 2 covers this less directly through CC7.1's expectation to detect and address newly introduced vulnerabilities. |
Which should you do first?
For most organizations the market decides the order. SOC 2 tends to come first because commercial and SaaS customers request it constantly during sales cycles, and a SOC 2 Type 2 report is usually renewed annually against an observation window. CMMC 2.0 Level 2, by contrast, is only relevant if you hold or pursue DoD contracts that involve CUI, and once that requirement is real it is mandatory rather than optional.
That said, sequencing should follow whichever deadline is binding. If a contract or DFARS flow-down obligation is driving a fixed date, CMMC readiness moves to the front, because a failed or delayed assessment can jeopardize the award. When there is no hard DoD deadline, running SOC 2 first is efficient: it forces you to stand up governance, access control, logging, incident response, and vendor management, all of which feed directly into the 800-171 practices CMMC will test later.
A company running both should treat SOC 2 as the broad control foundation and CMMC as the more prescriptive overlay for the CUI environment. Scope the CUI boundary early, since CMMC applies only to the systems that store, process, or transmit CUI, and align your SOC 2 evidence collection so that the same policies, tickets, and review artifacts can be pulled for the C3PAO assessment without duplicating fieldwork.
Evidence you can reuse
A large share of evidence carries over between the two engagements. Access control policies and user access reviews, authentication and multi-factor settings, incident response plans and post-incident records, security awareness training logs, change tickets and approvals, physical access records, and log and monitoring output all support both SOC 2 criteria and their 800-171 counterparts. Risk assessment documentation also serves both, since SOC 2 CC3.x and the CMMC RA family (3.11.x) each require a periodic, documented process.
What does not carry over cleanly is the framework-specific scaffolding. CMMC requires a System Security Plan and CUI boundary scoping, FIPS-validated cryptography evidence, and DFARS 252.204-7012 flow-down to subcontractors, none of which SOC 2 produces on its own. In the other direction, SOC 2 Availability evidence for backup and recovery has no CMMC home, because NIST SP 800-171 has no business-continuity family. The SOC 2 report itself is also not accepted as CMMC evidence, and the CMMC assessment is not a substitute for a SOC 2 report; only the underlying artifacts transfer.
Find auditors for each framework
No directory firm is currently confirmed for both SOC 2 and CMMC 2.0 — browse each ranking separately, or submit one request covering both and let firms respond.
Budget both engagements
AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.
SOC 2 cost data › · CMMC 2.0 cost data › · All compliance audit costs ›
One request, both frameworks
Tell us your scope once — get transparent quotes from vetted firms that can run SOC 2 and CMMC 2.0 together.
Get matched →Related crosswalks
Sources: AICPA Trust Services Criteria (2017, revised 2022); NIST SP 800-171 Revision 2; CMMC 2.0 Level 2 assessment scope (U.S. Department of Defense); DFARS 252.204-7012. Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.