A practitioner-grade, domain-level crosswalk between SOC 2 and ISO/IEC 27001. Understand how these compliance standards overlap to streamline your audit programs.
One of the most frequently published crosswalks in GRC practice — CPA firms, ISO certification bodies, and every major compliance-automation vendor maintain a SOC 2 Trust Services Criteria to ISO/IEC 27001 Annex A mapping; both frameworks also share conceptual lineage through COSO's internal-control framework.
Control environment, risk assessment, and monitoring — the governance core of the Common Criteria — sit within ISO's Organizational Controls theme.
The Common Criteria's physical-access provisions (CC6) are a narrower slice of Physical Controls' overall scope, so this correspondence is real but partial.
Logical access, system operations, and change management in the Common Criteria are addressed by ISO's Technological Controls theme.
SOC 2's Confidentiality criterion (identifying, handling, and disposing of confidential information) matches the information-classification controls named in ISO's Organizational theme.
SOC 2's Availability criterion (capacity management, recovery infrastructure) has no dedicated ISO Annex A theme; Technological Controls' resilience provisions are the closest domain-level analogy.
Use our interactive crosswalk matrix to explore mappings between SOC 2, ISO/IEC 27001, and 10 other compliance frameworks simultaneously.
Open Interactive Matrix