Last updated: July 26, 2026
Framework Crosswalk

SOC 2 to ISO 27001: control mapping & evidence reuse

8 of 13 control domains map directly. See exactly where SOC 2 and ISO 27001 overlap, which evidence carries over, and which engagement to run first.

How SOC 2 and ISO 27001 relate

SOC 2 and ISO 27001 are the two most common security frameworks that growing SaaS and cloud companies are asked to satisfy. SOC 2 tends to come from North American buyers and procurement teams, while ISO 27001 is more often requested by European and other international customers. Teams that sell across both markets frequently end up pursuing the two in parallel, which is why a clear control-by-control view of where they overlap is useful.

Structurally the frameworks differ. SOC 2 is an attestation performed by a licensed CPA firm against the AICPA Trust Services Criteria, organized as Common Criteria CC1 through CC9 plus optional categories for availability, confidentiality, processing integrity, and privacy; the deliverable is a Type 1 or Type 2 report. ISO 27001:2022 is a certification against a management system: the mandatory clauses 4 through 10 that define the ISMS, backed by the 93 Annex A controls grouped into organizational, people, physical, and technological themes. The Common Criteria and Annex A cover much of the same ground, so most control domains line up closely even though the surrounding process requirements differ.

This crosswalk is practical guidance from AuditNex to help you plan combined work and reuse evidence. It is not an official AICPA or ISO crosswalk, and control mappings always depend on how your specific scope, systems, and Statement of Applicability are defined.

Domain-by-domain mapping

Each row pairs the closest SOC 2 and ISO 27001 requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.

Direct matches
8
of 13 control domains
Partial overlap
5
scope or rigor differs
No equivalent
0
one framework only
Domains compared
13
same spine on every crosswalk

Across 13 control domains, 8 map directly between SOC 2 and ISO 27001, 5 map partially, and 0 have no equivalent on one side. Counts are computed live from the mapping table below.

Control domainSOC 2 referenceISO 27001 referenceMatch & notes
Governance & risk assessment CC1.1–CC1.5, CC3.1–CC3.4 ISMS clauses 4–6 (esp. 6.1.2), Annex A 5.1 Direct match
Both squarely require a governance structure and a documented risk assessment. ISO 27001 makes the risk methodology and treatment mandatory ISMS clauses, so the process is more prescriptive than SOC 2's criteria.
Policies & documentation CC5.1–CC5.3, CC2.2–CC2.3 Annex A 5.1, ISMS clause 7.5 Direct match
Each framework requires documented policies and controlled information. ISO's clause 7.5 adds explicit rules for creating, updating, and controlling documented information that SOC 2 addresses less formally.
Access control & identity CC6.1–CC6.3 Annex A 5.15–5.18 Direct match
Logical access provisioning, authentication, and privileged-access restrictions line up closely. Access reviews and joiner-mover-leaver evidence generally satisfy both.
Change management CC8.1 Annex A 8.32 Direct match
Both require controlled, authorized, and tested changes to systems. Change tickets and approval records typically serve as shared evidence.
Data protection & encryption CC6.1, CC6.7 Annex A 8.24, 5.12–5.14 Partial
SOC 2 treats encryption as a means of restricting access and transmission and only firmly requires it when the Confidentiality category is in scope, whereas ISO 27001 has a dedicated cryptography control plus explicit information classification and transfer controls.
Logging & monitoring CC7.1–CC7.3, CC4.1–CC4.2 Annex A 8.15–8.16 Direct match
System operations, anomaly detection, and ongoing monitoring map cleanly to ISO's logging and monitoring controls. Log configurations and alerting evidence are largely reusable.
Incident response CC7.3–CC7.5 Annex A 5.24–5.28 Direct match
Detection, response, and remediation of security events are required by both. Incident tickets, playbooks, and post-incident reviews support each audit.
Vendor & third-party risk CC9.2 Annex A 5.19–5.23 Direct match
Both require managing risks from suppliers and business partners. ISO's supplier and cloud-service controls are more granular, but vendor due-diligence files generally satisfy both.
Business continuity & availability CC9.1, A1.1–A1.3 (if Availability in scope) Annex A 5.29–5.30 Partial
SOC 2's dedicated availability, backup, and recovery criteria (A1.x) only apply when the Availability category is in scope, and CC9.1 is BCP-adjacent risk mitigation. ISO 27001 requires continuity and ICT readiness within the ISMS regardless.
Personnel security & training CC1.4, CC2.2 Annex A 6.1–6.6 (esp. 6.3) Partial
SOC 2 folds competence and security awareness into its governance and communication criteria, while ISO 27001 has explicit people controls covering screening, terms of employment, and confidentiality agreements that SOC 2 does not call out directly.
Asset & configuration management CC6.1, CC7.1 Annex A 5.9–5.11, 8.9 Partial
SOC 2 handles asset inventory and configuration implicitly within logical access and system operations, whereas ISO 27001 has dedicated asset-management and configuration-management controls, making its expectations more explicit.
Physical & environmental security CC6.4–CC6.5 Annex A 7.1–7.4 Direct match
Both require restricting physical access to facilities and equipment. ISO's physical theme is more granular, but data-center attestations and entry logs typically satisfy each.
Vulnerability & patch management CC7.1–CC7.2 Annex A 8.8 Partial
SOC 2 addresses vulnerability detection and monitoring under its system-operations criteria without prescribing a scanning cadence, whereas ISO 27001 has an explicit technical vulnerability management control.

Which should you do first?

Which engagement to run first usually comes down to who is asking. Many US startups start with SOC 2 because a prospect or channel partner requires a report before signing, and a SOC 2 Type 2 covers an observation window that repeats annually. If your near-term revenue depends on North American buyers, leading with SOC 2 gets you a marketable deliverable faster.

ISO 27001 adds a formal management system on top of the shared technical controls: a defined ISMS scope, a documented risk assessment and treatment methodology, a Statement of Applicability, an internal audit program, and management reviews, all confirmed through a stage 1 and stage 2 certification audit on a three-year cycle with annual surveillance. That management-system discipline is broader than what SOC 2 asks for, so companies that expect to need both often build the ISMS once and let it feed the SOC 2 control narrative rather than the other way around.

If you are committed to both, stage them so the underlying controls are implemented once. Establish access control, change management, logging, incident response, vendor review, and continuity practices, then run a combined or back-to-back engagement. Many auditors and CPA firms coordinate SOC 2 and ISO 27001 work with shared evidence collection so you are not gathering the same artifacts twice.

Evidence you can reuse

A large share of evidence carries over between the two audits because they test the same operational controls. Security policies, access reviews and provisioning records, change tickets, penetration test reports, the risk assessment, vendor and third-party due-diligence files, security awareness training logs, incident records, and backup and recovery evidence can generally support both a SOC 2 report and an ISO 27001 audit with little rework.

Some artifacts do not transfer. ISO 27001's mandatory-clause outputs, including the ISMS scope statement, the Statement of Applicability, the risk treatment plan, internal audit results, and management review minutes, have no direct SOC 2 equivalent and must be produced specifically for certification. Likewise, SOC 2's period-of-time testing and the auditor's opinion letter are attestation deliverables that do not satisfy ISO's certification requirements, so plan to maintain both the management-system records and the SOC 2 evidence separately even when the controls beneath them are shared.

Find auditors for each framework

No directory firm is currently confirmed for both SOC 2 and ISO 27001 — browse each ranking separately, or submit one request covering both and let firms respond.

Best SOC 2 auditors ›  ·  Best ISO 27001 auditors ›

Budget both engagements

AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.

SOC 2 cost data ›  ·  ISO 27001 cost data ›  ·  All compliance audit costs ›

One request, both frameworks

Tell us your scope once — get transparent quotes from vetted firms that can run SOC 2 and ISO 27001 together.

Get matched →

Sources: AICPA Trust Services Criteria (TSC), 2017 (revised 2022); ISO/IEC 27001:2022, Information security management systems — Requirements (clauses 4–10 and Annex A); ISO/IEC 27002:2022, Information security controls (Annex A control guidance). Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.