Compliance Intelligence

The Crosswalk Matrix

Domain-level alignment between frameworks, with the source of each mapping stated and its confidence marked. Pairs we cannot evidence are shown as unmapped rather than guessed.

I

ISO/IEC 27001

93 Total Controls

S

SOC 2

51 Total Controls

Basis for this alignment

PublishedVerified 2026-08-07

One of the most frequently published crosswalks in GRC practice — CPA firms, ISO certification bodies, and every major compliance-automation vendor maintain a SOC 2 Trust Services Criteria to ISO/IEC 27001 Annex A mapping; both frameworks also share conceptual lineage through COSO's internal-control framework.

Domain-level alignment, not control-by-control. Use it to scope a gap assessment, not to claim coverage.

View Indexed SEO Page ↗

Domain alignment · 5 mapped

A.5

Organizational Controls

CC1–CC9

Common Criteria (Security)

Published

Control environment, risk assessment, and monitoring — the governance core of the Common Criteria — sit within ISO's Organizational Controls theme.

A.7

Physical Controls

CC1–CC9

Common Criteria (Security)

Defensible

The Common Criteria's physical-access provisions (CC6) are a narrower slice of Physical Controls' overall scope, so this correspondence is real but partial.

A.8

Technological Controls

CC1–CC9

Common Criteria (Security)

Published

Logical access, system operations, and change management in the Common Criteria are addressed by ISO's Technological Controls theme.

A.5

Organizational Controls

C1

Confidentiality

Published

SOC 2's Confidentiality criterion (identifying, handling, and disposing of confidential information) matches the information-classification controls named in ISO's Organizational theme.

A.8

Technological Controls

A1

Availability

Defensible

SOC 2's Availability criterion (capacity management, recovery infrastructure) has no dedicated ISO Annex A theme; Technological Controls' resilience provisions are the closest domain-level analogy.