CROSSWALK MAPPINGVerified Data

Mapping SOC 2 to ISO/IEC 27001

A practitioner-grade, domain-level crosswalk between SOC 2 and ISO/IEC 27001. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

One of the most frequently published crosswalks in GRC practice — CPA firms, ISO certification bodies, and every major compliance-automation vendor maintain a SOC 2 Trust Services Criteria to ISO/IEC 27001 Annex A mapping; both frameworks also share conceptual lineage through COSO's internal-control framework.

Overall Confidence:high
Last Verified:2026-08-07

Domain Correspondences

SOC 2
CC1–CC9: Common Criteria (Security)
ISO/IEC 27001
A.5: Organizational Controls

Control environment, risk assessment, and monitoring — the governance core of the Common Criteria — sit within ISO's Organizational Controls theme.

SOC 2
CC1–CC9: Common Criteria (Security)
ISO/IEC 27001
A.7: Physical Controls

The Common Criteria's physical-access provisions (CC6) are a narrower slice of Physical Controls' overall scope, so this correspondence is real but partial.

SOC 2
CC1–CC9: Common Criteria (Security)
ISO/IEC 27001
A.8: Technological Controls

Logical access, system operations, and change management in the Common Criteria are addressed by ISO's Technological Controls theme.

SOC 2
C1: Confidentiality
ISO/IEC 27001
A.5: Organizational Controls

SOC 2's Confidentiality criterion (identifying, handling, and disposing of confidential information) matches the information-classification controls named in ISO's Organizational theme.

SOC 2
A1: Availability
ISO/IEC 27001
A.8: Technological Controls

SOC 2's Availability criterion (capacity management, recovery infrastructure) has no dedicated ISO Annex A theme; Technological Controls' resilience provisions are the closest domain-level analogy.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between SOC 2, ISO/IEC 27001, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix