Last updated: July 26, 2026
Framework Crosswalk

SOC 2 to CMMC 2.0: control mapping & evidence reuse

6 of 13 control domains map directly. See exactly where SOC 2 and CMMC 2.0 overlap, which evidence carries over, and which engagement to run first.

How SOC 2 and CMMC 2.0 relate

Companies that sell to both commercial buyers and the U.S. Department of Defense often end up needing SOC 2 and CMMC 2.0 Level 2 at the same time. SOC 2 is what enterprise and SaaS customers ask for during procurement, while CMMC Level 2 is what a defense contractor or subcontractor must reach to handle Controlled Unclassified Information (CUI) on a DoD contract. If your organization is chasing both markets, the same underlying security program has to satisfy two very different review regimes.

Structurally the two frameworks come from different worlds. SOC 2 is an AICPA attestation performed by a CPA firm against the Trust Services Criteria, organized as Common Criteria CC1 through CC9 plus optional categories for Availability, Confidentiality, Processing Integrity, and Privacy; the result is a Type 1 or Type 2 report, not a certificate. CMMC 2.0 Level 2 is a DoD assessment of 110 practices drawn from NIST SP 800-171 Revision 2, grouped into 14 control families (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, and SI) and assessed by a certified third-party assessment organization (C3PAO). SOC 2 states outcomes as criteria to be met by controls, whereas 800-171 lists prescriptive, individually numbered practices.

The mapping below is practical guidance from AuditNex to help teams plan a combined program and reuse work across engagements. It is not an official government or standards-body crosswalk, and it is not a substitute for scoping decisions made with your CPA firm and your C3PAO.

Domain-by-domain mapping

Each row pairs the closest SOC 2 and CMMC 2.0 requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.

Direct matches
6
of 13 control domains
Partial overlap
6
scope or rigor differs
No equivalent
1
one framework only
Domains compared
13
same spine on every crosswalk

Across 13 control domains, 6 map directly between SOC 2 and CMMC 2.0, 6 map partially, and 1 have no equivalent on one side. Counts are computed live from the mapping table below.

Control domainSOC 2 referenceCMMC referenceMatch & notes
Governance & risk assessment CC1.1–CC1.5; CC3.1–CC3.4 3.11.1–3.11.3 (RA) Partial
Both require a periodic, documented risk assessment, but CMMC's RA family targets risk to CUI specifically, while SOC 2 CC1.x adds board and management governance that 800-171 does not spell out.
Policies & documentation CC5.1–CC5.3 3.12.x (CA), incl. System Security Plan Partial
SOC 2 CC5.x expects formal, standalone policies, whereas CMMC has no dedicated policy family and instead documents control implementation through the System Security Plan under the CA family (3.12.x).
Access control & identity CC6.1–CC6.3 3.1.x (AC); 3.5.x (IA) Direct match
Both squarely require logical access control, least privilege, and authentication; CMMC splits this into prescriptive AC and IA practices, while SOC 2 states the same outcomes as criteria met by controls.
Change management CC8.1 3.4.3–3.4.4 (CM) Direct match
Both require tracking and approving system changes; CMMC 3.4.3–3.4.4 mandates change control and approval within its configuration-management family, aligning closely with SOC 2 CC8.1.
Data protection & encryption CC6.1, CC6.7 3.13.x (SC) Partial
SOC 2 treats encryption as a point of focus under CC6.1 and CC6.7 rather than a hard mandate, whereas CMMC's SC family explicitly requires cryptographic protection of CUI in transit and at rest.
Logging & monitoring CC7.1–CC7.2; CC4.1–CC4.2 3.3.x (AU); 3.14.x (SI) Direct match
Both require event logging, review, and monitoring for anomalies; CMMC's AU family is more prescriptive about audit record content and retention than SOC 2 CC7.1–CC7.2.
Incident response CC7.3–CC7.5 3.6.x (IR) Direct match
Both require detection, response, and recovery from incidents; CMMC's IR family adds explicit reporting expectations tied to DoD requirements beyond what SOC 2 CC7.3–CC7.5 states.
Vendor & third-party risk CC9.2 3.1.20 (external systems); DFARS 252.204-7012 flow-down Partial
SOC 2 CC9.2 requires a formal vendor and business-partner risk program, while CMMC has no supplier family and instead pushes third-party obligations through DFARS 252.204-7012 flow-down and the external-systems practice 3.1.20.
Business continuity & availability A1.1–A1.3 (if Availability category in scope) No direct equivalent No equivalent
SOC 2's optional Availability category covers backup and recovery, but NIST SP 800-171 has no continuity or contingency family, so CMMC Level 2 does not address this domain.
Personnel security & training CC1.4; CC2.2 3.9.x (PS); 3.2.x (AT) Direct match
Both require personnel screening and security awareness training; CMMC separates these into the PS and AT families, while SOC 2 folds training under CC1.4 and CC2.2.
Asset & configuration management CC6.1, CC7.1 3.4.1–3.4.2 (CM) Partial
CMMC's CM family explicitly requires baseline configurations and asset inventories (3.4.1–3.4.2), whereas SOC 2 addresses asset and configuration management only implicitly through CC6.1 and CC7.1.
Physical & environmental security CC6.4–CC6.5 3.10.x (PE) Direct match
Both require controlling physical access to facilities and equipment; CMMC's PE family and SOC 2 CC6.4–CC6.5 align closely, though CMMC is more explicit about escorting visitors and managing physical access devices.
Vulnerability & patch management CC7.1 3.11.2 (RA); 3.14.1 (SI) Partial
CMMC explicitly requires vulnerability scanning and flaw remediation (3.11.2, 3.14.1), while SOC 2 covers this less directly through CC7.1's expectation to detect and address newly introduced vulnerabilities.

Which should you do first?

For most organizations the market decides the order. SOC 2 tends to come first because commercial and SaaS customers request it constantly during sales cycles, and a SOC 2 Type 2 report is usually renewed annually against an observation window. CMMC 2.0 Level 2, by contrast, is only relevant if you hold or pursue DoD contracts that involve CUI, and once that requirement is real it is mandatory rather than optional.

That said, sequencing should follow whichever deadline is binding. If a contract or DFARS flow-down obligation is driving a fixed date, CMMC readiness moves to the front, because a failed or delayed assessment can jeopardize the award. When there is no hard DoD deadline, running SOC 2 first is efficient: it forces you to stand up governance, access control, logging, incident response, and vendor management, all of which feed directly into the 800-171 practices CMMC will test later.

A company running both should treat SOC 2 as the broad control foundation and CMMC as the more prescriptive overlay for the CUI environment. Scope the CUI boundary early, since CMMC applies only to the systems that store, process, or transmit CUI, and align your SOC 2 evidence collection so that the same policies, tickets, and review artifacts can be pulled for the C3PAO assessment without duplicating fieldwork.

Evidence you can reuse

A large share of evidence carries over between the two engagements. Access control policies and user access reviews, authentication and multi-factor settings, incident response plans and post-incident records, security awareness training logs, change tickets and approvals, physical access records, and log and monitoring output all support both SOC 2 criteria and their 800-171 counterparts. Risk assessment documentation also serves both, since SOC 2 CC3.x and the CMMC RA family (3.11.x) each require a periodic, documented process.

What does not carry over cleanly is the framework-specific scaffolding. CMMC requires a System Security Plan and CUI boundary scoping, FIPS-validated cryptography evidence, and DFARS 252.204-7012 flow-down to subcontractors, none of which SOC 2 produces on its own. In the other direction, SOC 2 Availability evidence for backup and recovery has no CMMC home, because NIST SP 800-171 has no business-continuity family. The SOC 2 report itself is also not accepted as CMMC evidence, and the CMMC assessment is not a substitute for a SOC 2 report; only the underlying artifacts transfer.

Find auditors for each framework

No directory firm is currently confirmed for both SOC 2 and CMMC 2.0 — browse each ranking separately, or submit one request covering both and let firms respond.

Best SOC 2 auditors ›  ·  Best CMMC 2.0 auditors ›

Budget both engagements

AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.

SOC 2 cost data ›  ·  CMMC 2.0 cost data ›  ·  All compliance audit costs ›

One request, both frameworks

Tell us your scope once — get transparent quotes from vetted firms that can run SOC 2 and CMMC 2.0 together.

Get matched →

Sources: AICPA Trust Services Criteria (2017, revised 2022); NIST SP 800-171 Revision 2; CMMC 2.0 Level 2 assessment scope (U.S. Department of Defense); DFARS 252.204-7012. Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.