SOC 2 to ISO 27001: control mapping & evidence reuse
8 of 13 control domains map directly. See exactly where SOC 2 and ISO 27001 overlap, which evidence carries over, and which engagement to run first.
How SOC 2 and ISO 27001 relate
SOC 2 and ISO 27001 are the two most common security frameworks that growing SaaS and cloud companies are asked to satisfy. SOC 2 tends to come from North American buyers and procurement teams, while ISO 27001 is more often requested by European and other international customers. Teams that sell across both markets frequently end up pursuing the two in parallel, which is why a clear control-by-control view of where they overlap is useful.
Structurally the frameworks differ. SOC 2 is an attestation performed by a licensed CPA firm against the AICPA Trust Services Criteria, organized as Common Criteria CC1 through CC9 plus optional categories for availability, confidentiality, processing integrity, and privacy; the deliverable is a Type 1 or Type 2 report. ISO 27001:2022 is a certification against a management system: the mandatory clauses 4 through 10 that define the ISMS, backed by the 93 Annex A controls grouped into organizational, people, physical, and technological themes. The Common Criteria and Annex A cover much of the same ground, so most control domains line up closely even though the surrounding process requirements differ.
This crosswalk is practical guidance from AuditNex to help you plan combined work and reuse evidence. It is not an official AICPA or ISO crosswalk, and control mappings always depend on how your specific scope, systems, and Statement of Applicability are defined.
Domain-by-domain mapping
Each row pairs the closest SOC 2 and ISO 27001 requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.
Across 13 control domains, 8 map directly between SOC 2 and ISO 27001, 5 map partially, and 0 have no equivalent on one side. Counts are computed live from the mapping table below.
| Control domain | SOC 2 reference | ISO 27001 reference | Match & notes |
|---|---|---|---|
| Governance & risk assessment | CC1.1–CC1.5, CC3.1–CC3.4 | ISMS clauses 4–6 (esp. 6.1.2), Annex A 5.1 | Direct match Both squarely require a governance structure and a documented risk assessment. ISO 27001 makes the risk methodology and treatment mandatory ISMS clauses, so the process is more prescriptive than SOC 2's criteria. |
| Policies & documentation | CC5.1–CC5.3, CC2.2–CC2.3 | Annex A 5.1, ISMS clause 7.5 | Direct match Each framework requires documented policies and controlled information. ISO's clause 7.5 adds explicit rules for creating, updating, and controlling documented information that SOC 2 addresses less formally. |
| Access control & identity | CC6.1–CC6.3 | Annex A 5.15–5.18 | Direct match Logical access provisioning, authentication, and privileged-access restrictions line up closely. Access reviews and joiner-mover-leaver evidence generally satisfy both. |
| Change management | CC8.1 | Annex A 8.32 | Direct match Both require controlled, authorized, and tested changes to systems. Change tickets and approval records typically serve as shared evidence. |
| Data protection & encryption | CC6.1, CC6.7 | Annex A 8.24, 5.12–5.14 | Partial SOC 2 treats encryption as a means of restricting access and transmission and only firmly requires it when the Confidentiality category is in scope, whereas ISO 27001 has a dedicated cryptography control plus explicit information classification and transfer controls. |
| Logging & monitoring | CC7.1–CC7.3, CC4.1–CC4.2 | Annex A 8.15–8.16 | Direct match System operations, anomaly detection, and ongoing monitoring map cleanly to ISO's logging and monitoring controls. Log configurations and alerting evidence are largely reusable. |
| Incident response | CC7.3–CC7.5 | Annex A 5.24–5.28 | Direct match Detection, response, and remediation of security events are required by both. Incident tickets, playbooks, and post-incident reviews support each audit. |
| Vendor & third-party risk | CC9.2 | Annex A 5.19–5.23 | Direct match Both require managing risks from suppliers and business partners. ISO's supplier and cloud-service controls are more granular, but vendor due-diligence files generally satisfy both. |
| Business continuity & availability | CC9.1, A1.1–A1.3 (if Availability in scope) | Annex A 5.29–5.30 | Partial SOC 2's dedicated availability, backup, and recovery criteria (A1.x) only apply when the Availability category is in scope, and CC9.1 is BCP-adjacent risk mitigation. ISO 27001 requires continuity and ICT readiness within the ISMS regardless. |
| Personnel security & training | CC1.4, CC2.2 | Annex A 6.1–6.6 (esp. 6.3) | Partial SOC 2 folds competence and security awareness into its governance and communication criteria, while ISO 27001 has explicit people controls covering screening, terms of employment, and confidentiality agreements that SOC 2 does not call out directly. |
| Asset & configuration management | CC6.1, CC7.1 | Annex A 5.9–5.11, 8.9 | Partial SOC 2 handles asset inventory and configuration implicitly within logical access and system operations, whereas ISO 27001 has dedicated asset-management and configuration-management controls, making its expectations more explicit. |
| Physical & environmental security | CC6.4–CC6.5 | Annex A 7.1–7.4 | Direct match Both require restricting physical access to facilities and equipment. ISO's physical theme is more granular, but data-center attestations and entry logs typically satisfy each. |
| Vulnerability & patch management | CC7.1–CC7.2 | Annex A 8.8 | Partial SOC 2 addresses vulnerability detection and monitoring under its system-operations criteria without prescribing a scanning cadence, whereas ISO 27001 has an explicit technical vulnerability management control. |
Which should you do first?
Which engagement to run first usually comes down to who is asking. Many US startups start with SOC 2 because a prospect or channel partner requires a report before signing, and a SOC 2 Type 2 covers an observation window that repeats annually. If your near-term revenue depends on North American buyers, leading with SOC 2 gets you a marketable deliverable faster.
ISO 27001 adds a formal management system on top of the shared technical controls: a defined ISMS scope, a documented risk assessment and treatment methodology, a Statement of Applicability, an internal audit program, and management reviews, all confirmed through a stage 1 and stage 2 certification audit on a three-year cycle with annual surveillance. That management-system discipline is broader than what SOC 2 asks for, so companies that expect to need both often build the ISMS once and let it feed the SOC 2 control narrative rather than the other way around.
If you are committed to both, stage them so the underlying controls are implemented once. Establish access control, change management, logging, incident response, vendor review, and continuity practices, then run a combined or back-to-back engagement. Many auditors and CPA firms coordinate SOC 2 and ISO 27001 work with shared evidence collection so you are not gathering the same artifacts twice.
Evidence you can reuse
A large share of evidence carries over between the two audits because they test the same operational controls. Security policies, access reviews and provisioning records, change tickets, penetration test reports, the risk assessment, vendor and third-party due-diligence files, security awareness training logs, incident records, and backup and recovery evidence can generally support both a SOC 2 report and an ISO 27001 audit with little rework.
Some artifacts do not transfer. ISO 27001's mandatory-clause outputs, including the ISMS scope statement, the Statement of Applicability, the risk treatment plan, internal audit results, and management review minutes, have no direct SOC 2 equivalent and must be produced specifically for certification. Likewise, SOC 2's period-of-time testing and the auditor's opinion letter are attestation deliverables that do not satisfy ISO's certification requirements, so plan to maintain both the management-system records and the SOC 2 evidence separately even when the controls beneath them are shared.
Find auditors for each framework
No directory firm is currently confirmed for both SOC 2 and ISO 27001 — browse each ranking separately, or submit one request covering both and let firms respond.
Budget both engagements
AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.
SOC 2 cost data › · ISO 27001 cost data › · All compliance audit costs ›
One request, both frameworks
Tell us your scope once — get transparent quotes from vetted firms that can run SOC 2 and ISO 27001 together.
Get matched →Related crosswalks
Sources: AICPA Trust Services Criteria (TSC), 2017 (revised 2022); ISO/IEC 27001:2022, Information security management systems — Requirements (clauses 4–10 and Annex A); ISO/IEC 27002:2022, Information security controls (Annex A control guidance). Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.