CROSSWALK MAPPINGVerified Data

Mapping ISO/IEC 27001 to SOC 2

A practitioner-grade, domain-level crosswalk between ISO/IEC 27001 and SOC 2. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

One of the most frequently published crosswalks in GRC practice — CPA firms, ISO certification bodies, and every major compliance-automation vendor maintain a SOC 2 Trust Services Criteria to ISO/IEC 27001 Annex A mapping; both frameworks also share conceptual lineage through COSO's internal-control framework.

Overall Confidence:high
Last Verified:2026-08-07

Domain Correspondences

ISO/IEC 27001
A.5: Organizational Controls
SOC 2
CC1–CC9: Common Criteria (Security)

Control environment, risk assessment, and monitoring — the governance core of the Common Criteria — sit within ISO's Organizational Controls theme.

ISO/IEC 27001
A.7: Physical Controls
SOC 2
CC1–CC9: Common Criteria (Security)

The Common Criteria's physical-access provisions (CC6) are a narrower slice of Physical Controls' overall scope, so this correspondence is real but partial.

ISO/IEC 27001
A.8: Technological Controls
SOC 2
CC1–CC9: Common Criteria (Security)

Logical access, system operations, and change management in the Common Criteria are addressed by ISO's Technological Controls theme.

ISO/IEC 27001
A.5: Organizational Controls
SOC 2
C1: Confidentiality

SOC 2's Confidentiality criterion (identifying, handling, and disposing of confidential information) matches the information-classification controls named in ISO's Organizational theme.

ISO/IEC 27001
A.8: Technological Controls
SOC 2
A1: Availability

SOC 2's Availability criterion (capacity management, recovery infrastructure) has no dedicated ISO Annex A theme; Technological Controls' resilience provisions are the closest domain-level analogy.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between ISO/IEC 27001, SOC 2, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix