SOC 2 to ISO 27001 mapping:
one control, tested once, evidenced twice.
Every SOC 2 criterion and ISO/IEC 27001:2022 Annex A control in the TryTrustable control library that is evidenced by the same control, and every one that is not.
Last updated Published by TryTrustableNot legal advice
How does SOC 2 map to ISO 27001?
In the TryTrustable control library, 20 shared controls are tested against both SOC 2 and ISO/IEC 27001. Those controls reach 55 of the 61 SOC 2 requirements the library models and 87 of the 93 ISO/IEC 27001 requirements. Each row below is one control and the requirements on each side it is evidence for.
The library breaks SOC 2 into its criteria and ISO/IEC 27001 into its 2022 Annex A controls, maps each to the controls that evidence it, and pairs two requirements only when they share a control. Many-to-many is normal: CC6.1 needs both MFA and single sign-on, and MFA also answers A.8.5. For the programme-level comparison of the two, see SOC 2 vs ISO 27001.
| Shared control | SOC 2 | ISO/IEC 27001 |
|---|---|---|
| Periodic logical access reviewCTL-ACCESS-REVIEW | CC1.3 COSO 3: Management establishes structures, reporting lines, authorities and responsibilities CC3.3 COSO 8: Potential for fraud considered in assessing risks to objectives CC4.1 COSO 16: Ongoing and separate evaluations ascertain whether controls are present and functioning CC6.2 New internal and external users registered and authorized prior to system access CC6.3 Quarterly logical access reviews performed and evidenced | A.5.3 Segregation of duties A.5.15 Access control A.5.18 Access rights provisioned, reviewed and revoked on schedule A.6.5 Responsibilities after termination or change of employment A.8.2 Privileged access rights A.8.3 Information access restriction A.8.4 Access to source code A.8.18 Use of privileged utility programs A.8.34 Protection of information systems during audit testing |
| Backup and restore testingCTL-BACKUP | A1.1 Capacity, backup and recovery objectives defined and load-tested A1.2 Environmental protections, backup processes and recovery infrastructure implemented CC7.5 Activities to recover from identified security incidents identified, developed and implemented PI1.5 Stored inputs, items in processing and outputs retained completely and accurately | A.5.30 ICT readiness for business continuity A.5.33 Protection of records A.8.13 Information backup maintained and restore-tested |
| Business continuity and disaster recoveryCTL-BCDR | A1.2 Environmental protections, backup processes and recovery infrastructure implemented A1.3 Recovery plan procedures supporting system recovery tested CC9.1 Risk mitigation activities identified and developed for business disruptions | A.5.29 Information security during disruption A.5.30 ICT readiness for business continuity A.7.11 Supporting utilities A.8.6 Capacity management A.8.14 Redundancy of information processing facilities |
| Formal change managementCTL-CHANGE-MGMT | CC3.4 COSO 9: Changes that could significantly impact internal control identified and assessed CC5.2 COSO 11: General control activities over technology selected and developed CC8.1 Formal change management with peer review and rollback | A.8.9 Configuration management A.8.19 Installation of software on operational systems A.8.31 Separation of development, test and production environments A.8.32 Change management for information processing facilities |
| Data retention and disposalCTL-DATA-RETENTION | C1.2 Confidential information disposed of to meet confidentiality objectives CC6.5 Logical and physical protections over decommissioned assets discontinued only after data removal P4.2 Retention: personal information retained no longer than necessary for stated purposes P4.3 Disposal: personal information securely disposed of when no longer required PI1.5 Stored inputs, items in processing and outputs retained completely and accurately | A.5.12 Classification of information A.5.13 Labelling of information A.5.33 Protection of records A.7.10 Storage media A.7.14 Secure disposal or re-use of equipment A.8.10 Information deletion |
| Data loss preventionCTL-DLP | CC6.7 Transmission, movement and removal of information restricted to authorized users and processes | A.8.12 Data leakage prevention |
| Data subject rights fulfilmentCTL-DSAR | P5.1 Access: data subjects able to access their personal information for review and update P5.2 Access: corrections, amendments or deletions recorded and communicated to relevant parties P6.7 Disclosure: accounting of disclosures provided to data subjects on request | A.5.34 Privacy and protection of personally identifiable information (PII) |
| Endpoint detection and responseCTL-EDR | CC6.8 Controls implemented to prevent or detect unauthorized or malicious software | A.6.7 Remote working A.7.9 Security of assets off-premises A.8.1 User endpoint devices A.8.7 Protection against malware A.8.23 Web filtering |
| Encryption of data at restCTL-ENCRYPT-REST | CC6.6 Encryption of sensitive data at rest and in transit | A.5.34 Privacy and protection of personally identifiable information (PII) A.7.10 Storage media A.8.11 Data masking A.8.24 Use of cryptography: data encrypted at rest and in transit |
| Encryption of data in transitCTL-ENCRYPT-TRANSIT | CC6.6 Encryption of sensitive data at rest and in transit CC6.7 Transmission, movement and removal of information restricted to authorized users and processes | A.5.14 Information transfer |
| Incident response plan and exerciseCTL-IR-PLAN | CC7.3 Security events evaluated to determine whether they represent security incidents CC7.4 Documented incident response plan tested annually CC7.5 Activities to recover from identified security incidents identified, developed and implemented P6.3 Disclosure: record maintained of detected or reported unauthorized disclosures P6.5 Disclosure: third-party unauthorized disclosures assessed and remediated P6.6 Disclosure: data subjects notified of incidents affecting their personal information | A.5.5 Contact with authorities A.5.6 Contact with special interest groups A.5.24 Information security incident management planning and preparation A.5.25 Assessment and decision on information security events A.5.26 Response to information security incidents per documented plan A.5.27 Learning from information security incidents A.6.8 Information security event reporting |
| Centralised, tamper-evident loggingCTL-LOGGING | CC2.1 COSO 13: Relevant, quality information obtained, generated and used for internal control CC4.1 COSO 16: Ongoing and separate evaluations ascertain whether controls are present and functioning CC7.2 Security event monitoring with centralized, tamper-evident logging CC7.3 Security events evaluated to determine whether they represent security incidents P6.2 Disclosure: record maintained of authorized disclosures of personal information P6.3 Disclosure: record maintained of detected or reported unauthorized disclosures PI1.1 Quality information about processing objectives obtained and communicated PI1.3 System processing is complete, accurate, timely and authorized PI1.4 System outputs are complete, accurate and delivered to specified recipients | A.5.25 Assessment and decision on information security events A.5.28 Collection of evidence A.7.4 Physical security monitoring A.8.15 Logging: event logs recorded, protected and analysed A.8.16 Monitoring activities A.8.17 Clock synchronization |
| Multi-factor authentication enforcedCTL-MFA | CC6.1 Logical access security: MFA enforced for all workforce users | A.5.17 Authentication information A.6.7 Remote working A.8.2 Privileged access rights A.8.5 Secure authentication: MFA on all information systems |
| Physical access controlCTL-PHYS-ACCESS | CC6.4 Physical access to facilities and protected information assets restricted | A.7.1 Physical security perimeters A.7.2 Physical entry A.7.3 Securing offices, rooms and facilities A.7.4 Physical security monitoring A.7.5 Protecting against physical and environmental threats A.7.6 Working in secure areas A.7.8 Equipment siting and protection A.7.12 Cabling security |
| Policy review and attestationCTL-POLICY-REVIEW | CC1.1 COSO 1: The entity demonstrates a commitment to integrity and ethical values CC1.2 COSO 2: The board demonstrates independence and exercises oversight of internal control CC1.5 COSO 5: Individuals are held accountable for their internal control responsibilities CC3.1 COSO 6: Objectives specified with sufficient clarity to identify and assess related risks CC4.2 COSO 17: Internal control deficiencies evaluated and communicated for corrective action CC5.1 COSO 10: Control activities selected and developed to mitigate risks to acceptable levels CC5.3 COSO 12: Control activities deployed through policies and procedures P8.1 Monitoring & enforcement: privacy complaints and disputes handled; compliance monitored | A.5.1 Policies for information security A.5.2 Information security roles and responsibilities A.5.4 Management responsibilities A.5.10 Acceptable use of information and other associated assets A.5.31 Legal, statutory, regulatory and contractual requirements A.5.32 Intellectual property rights A.5.35 Independent review of information security A.5.36 Compliance with policies, rules and standards for information security A.5.37 Documented operating procedures A.6.2 Terms and conditions of employment A.6.4 Disciplinary process |
| Secure software development lifecycleCTL-SDLC | CC5.2 COSO 11: General control activities over technology selected and developed PI1.2 System inputs are complete and accurate; input errors detected and corrected PI1.3 System processing is complete, accurate, timely and authorized | A.5.8 Information security in project management A.8.4 Access to source code A.8.25 Secure development life cycle A.8.26 Application security requirements A.8.27 Secure system architecture and engineering principles A.8.28 Secure coding A.8.29 Security testing in development and acceptance A.8.33 Test information |
| Single sign-on for workforce accessCTL-SSO | CC6.1 Logical access security: MFA enforced for all workforce users CC6.2 New internal and external users registered and authorized prior to system access | A.5.15 Access control A.5.16 Identity management A.8.5 Secure authentication: MFA on all information systems |
| Security awareness trainingCTL-TRAINING | CC1.4 Security awareness training completed by all personnel CC1.5 COSO 5: Individuals are held accountable for their internal control responsibilities CC2.2 COSO 14: Information including objectives and responsibilities communicated internally | A.5.10 Acceptable use of information and other associated assets A.6.1 Screening A.6.3 Information security awareness, education and training A.6.8 Information security event reporting A.7.7 Clear desk and clear screen |
| Vendor due diligence and monitoringCTL-VENDOR-DD | C1.1 Vendor due diligence and sub-processor confidentiality commitments CC2.3 COSO 15: Matters affecting internal control communicated with external parties CC9.2 Risks associated with vendors and business partners assessed and managed P6.1 Disclosure: personal information disclosed to third parties only for identified, consented purposes P6.4 Disclosure: third parties contractually bound to protect personal information consistently P6.5 Disclosure: third-party unauthorized disclosures assessed and remediated | A.5.19 Information security in supplier relationships A.5.20 Addressing information security within supplier agreements A.5.21 Managing information security in the ICT supply chain A.5.22 Monitoring, review and change management of supplier services A.5.23 Information security for use of cloud services A.6.6 Confidentiality or non-disclosure agreements A.8.30 Outsourced development |
| Vulnerability scanning and remediationCTL-VULN-SCAN | CC3.2 COSO 7: Risks to objectives identified and analysed as a basis for managing risk CC7.1 Vulnerability scanning and remediation within SLA | A.5.7 Threat intelligence A.8.8 Management of technical vulnerabilities |
Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.
169 rows: one per control and requirement, with the library description. Paste into a spreadsheet.
Which controls does only one side ask for?
A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.
Only SOC 2:
- Lawful basis and consent capture CTL-CONSENT: P2.1, P3.2
- Data quality and integrity CTL-DATA-QUALITY: P7.1
- Privacy notice and transparency CTL-PRIVACY-NOTICE: P1.1, P3.1, P4.1
Only ISO/IEC 27001:
- Asset inventory CTL-ASSET-INV: A.5.9, A.5.11, A.7.9, A.7.13
- Network segmentation CTL-NET-SEG: A.8.20, A.8.21, A.8.22, A.8.31
- Independent penetration testing CTL-PENTEST: A.8.29
What this mapping does not tell you
A shared control is shared evidence, not a shared verdict. A SOC 2 auditor tests whether the control operated over the report period against your own system description; an ISO certification auditor tests whether the control is in your Statement of Applicability, operating, and managed by the ISMS. The same MFA result serves both, and the two audits still ask different questions of it. The AICPA's own mapping of the Trust Services Criteria to ISO 27001 is available to its members and is worth reading alongside this one.
The controls with nothing on the other side are informative too. Network segmentation, penetration testing and the asset inventory are mapped to ISO Annex A but to no SOC 2 criterion in the library, while privacy notice, consent and data quality appear only on the SOC 2 side through the Privacy and Processing Integrity criteria. The SOC 2 guide and the ISO 27001 solution cover each programme, and the integrations show which of these controls are checked automatically.
The things people ask us
Can one set of controls satisfy SOC 2 and ISO 27001?
Largely, yes. Both ask for access control, change management, logging, incident response, vendor management and continuity, so one implemented control can be tested once and evidence both. What does not transfer is the wrapper: ISO 27001 requires a certified management system under clauses 4 to 10, and SOC 2 is an auditor's attestation report on your own system description.
Is there an official SOC 2 to ISO 27001 mapping?
The AICPA publishes a mapping of the 2017 Trust Services Criteria to ISO 27001 for its members. This page is not that document. It is generated from the TryTrustable control library and pairs criteria with Annex A controls only where the same control is tested against both.
Which ISO 27001 version does this mapping use?
ISO/IEC 27001:2022, whose Annex A has 93 controls in four themes: organisational, people, physical and technological. The library models all 93. It does not model clauses 4 to 10, the management system requirements, as separate rows, so those do not appear here.
Does this mapping include the SOC 2 privacy criteria?
Yes. The library holds the Security common criteria and the Availability, Confidentiality, Processing Integrity and Privacy criteria, 61 points in all. The privacy criteria pair with ISO 27001 mostly through rights fulfilment, incident response, vendor management and retention; for privacy as a management system, ISO/IEC 27701 is the closer standard.
Should we do SOC 2 or ISO 27001 first?
Follow your buyers. SOC 2 reports are the common ask from North American customers, ISO 27001 certificates in Europe, India and much of Asia. Because the controls overlap this heavily, the second costs far less than the first if the controls are held once and mapped, not copied into a second project.
Can I download this mapping?
Use Copy as CSV below the table. It copies one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the control library the product uses, so it changes when the library does.
Run SOC 2 and ISO 27001 on one control set.
Thirty minutes. We show one control tested once and landing against a SOC 2 criterion and an ISO 27001 control, with the evidence behind both.