Domain-level alignment between frameworks, with the source of each mapping stated and its confidence marked. Pairs we cannot evidence are shown as unmapped rather than guessed.
93 Total Controls
51 Total Controls
One of the most frequently published crosswalks in GRC practice — CPA firms, ISO certification bodies, and every major compliance-automation vendor maintain a SOC 2 Trust Services Criteria to ISO/IEC 27001 Annex A mapping; both frameworks also share conceptual lineage through COSO's internal-control framework.
Domain-level alignment, not control-by-control. Use it to scope a gap assessment, not to claim coverage.
View Indexed SEO Page ↗A.5
Organizational Controls
CC1–CC9
Common Criteria (Security)
Control environment, risk assessment, and monitoring — the governance core of the Common Criteria — sit within ISO's Organizational Controls theme.
A.7
Physical Controls
CC1–CC9
Common Criteria (Security)
The Common Criteria's physical-access provisions (CC6) are a narrower slice of Physical Controls' overall scope, so this correspondence is real but partial.
A.8
Technological Controls
CC1–CC9
Common Criteria (Security)
Logical access, system operations, and change management in the Common Criteria are addressed by ISO's Technological Controls theme.
A.5
Organizational Controls
C1
Confidentiality
SOC 2's Confidentiality criterion (identifying, handling, and disposing of confidential information) matches the information-classification controls named in ISO's Organizational theme.
A.8
Technological Controls
A1
Availability
SOC 2's Availability criterion (capacity management, recovery infrastructure) has no dedicated ISO Annex A theme; Technological Controls' resilience provisions are the closest domain-level analogy.