Skip to main content

SOC 2 mapped to ISO 27001

Free · complete · nothing held back

Your American customer wants a SOC 2. You have ISO 27001. How much of it counts?

Nearly all of the controls, and almost none of the evidence. That sentence is the whole answer, and the thirty-eight rows below are the working. This is the same crosswalk we supply to clients, published in full, because a mapping is a map and maps are more useful when everyone has one.

It is not the controls. It is the evidence.

An organisation with a working ISO 27001 management system already has most of the controls a SOC 2 report tests. What it usually does not have is the way the evidence must be produced — and that, not the control set, is what makes a first SOC 2 take two or three quarters longer than anyone budgets for.

  1. Attestation, not certification. ISO 27001 gives you a certificate from an accredited certification body. SOC 2 gives you a report carrying an opinion from a licensed CPA firm. There is no such thing as a SOC 2 certificate, and a vendor claiming to be “SOC 2 certified” is telling you something about their care with language.
  2. A period, not a point in time. The big one. A Type 2 report covers a window — commonly six to twelve months — and the auditor tests whether each control operated throughout it. You cannot tidy up the week before. If your access reviews were skipped in March, the report says so.
  3. Sampling, not a sample. An ISO auditor looks for the process and some evidence that it runs. A service auditor pulls a statistical sample of changes, of leavers, of access reviews, and tests each one. A process that works nine times out of ten fails.
  4. A system, not an organisation. SOC 2 reports on a defined system — a product, a platform, the services around it. Your ISMS scope is usually wider. Getting the system description right is the first deliverable and the one most often rewritten.
  5. No Statement of Applicability. SOC 2 has no equivalent and cannot exclude a common criterion. All thirty-three apply to every report. Your SoA is still good evidence for CC5.1, but it does not let you scope anything out.
  6. Subservice organisations. Your cloud provider’s controls are either carved out of your report — with their SOC 2 relied on and the complementary user entity controls handed back to you — or included. Almost everyone carves out. Almost nobody reads the complementary controls they have just accepted responsibility for.

The expensive mistake

Do not open the observation window until the controls are actually running.

The commonest costly error is starting a twelve-month Type 2 window in month one, then failing criteria for the first four months because the process was still being built. Run a Type 1 first, or run the controls quietly for a quarter, and start the window when you could survive being sampled. The window is the product; the controls are only the input.

And the number people quote at each other: on our mapping, thirty-six of the thirty-eight criteria below are already covered, fully or nearly, by ISO 27001 work. That is a good starting position, not a short project. It measures control coverage and says nothing about the evidence, which is most of the effort.

The crosswalk

Thirty-three common criteria — every SOC 2 report contains all of them — plus availability and confidentiality, the two optional categories most often added. Criteria names and descriptions are written in our own words; the reference numbers follow the AICPA 2017 Trust Services Criteria with the 2022 revised points of focus, which remain the current version and which you will need to obtain from the AICPA. Nothing here reproduces that text.

CC1 — Control environment

Borrowed from COSO, and the part of SOC 2 that feels least like ISO 27001. This is where an ISO shop finds most of its gaps.

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC1.1
Integrity and ethical values
That the organisation demonstrates a commitment to integrity and ethics, and that this is visible in how people are hired, told what is expected, and dealt with when they fall short.
Mostly carries. Clause 5.1 leadership · A.5.1 · A.6.2 · A.6.4 ISO gives you the policy and the disciplinary process. Add a code of conduct with evidence that people acknowledged it.
CC1.2
Board oversight, independent of management
That those charged with governance are independent of management and actually exercise oversight of internal control.
Partly carries. Clause 5.1 · Clause 9.3 management review The real gap for a small Canadian firm. ISO expects management review; SOC 2 borrows COSO's expectation of INDEPENDENT oversight. If your board is the two founders, say so and describe the compensating oversight rather than pretending.
CC1.3
Structures, reporting lines and authority
That the organisation chart, reporting lines and delegated authorities are defined and match how decisions are actually taken.
Carries over. Clause 5.3 · A.5.2 · A.5.3
CC1.4
Attracting and keeping competent people
That the organisation hires, develops and retains people competent to operate the controls, with evidence rather than assertion.
Carries over. Clause 7.2 competence · A.6.1 screening · A.6.3 training
CC1.5
Holding people accountable
That individuals are held to account for their control responsibilities, including through performance measures and consequences.
Mostly carries. Clause 5.3 · A.5.4 · A.6.4 Add the link between control responsibilities and performance review, which ISO does not require explicitly.

CC2 — Communication and information

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC2.1
Relevant, quality information
That the organisation obtains and uses information good enough to support the functioning of internal control.
Mostly carries. Clause 7.5 documented information · A.5.9 inventory · A.8.15 logging Mostly present. Be able to show the information is current and complete, not merely that it exists.
CC2.2
Telling your own people
That security responsibilities and the information people need are communicated internally, and that there is a route to report problems.
Carries over. Clause 7.4 · A.5.1 · A.6.3 · A.6.8
CC2.3
Telling outside parties
That the organisation communicates with customers, suppliers and regulators about matters affecting internal control, including how outsiders report a problem.
Carries over. Clause 7.4 · A.5.5 · A.5.6 · A.5.20 Add a published route for an outsider to report a vulnerability if you do not have one.

CC3 — Risk assessment

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC3.1
Objectives, specified clearly enough to assess risk against
That objectives are stated with enough clarity that risks to them can be identified.
Carries over. Clause 6.2 information security objectives
CC3.2
Identifying and analysing risk
That risks to objectives are identified across the organisation and analysed as a basis for deciding how to manage them.
Carries over. Clause 6.1.2 risk assessment Your ISO risk assessment does this. Make sure it is scoped to the system in the report, which is usually narrower than your ISMS.
CC3.3
Considering the potential for fraud
That the organisation explicitly considers fraud — misappropriation, misreporting, management override — when assessing risk.
New work. No direct ISO equivalent A genuine gap. ISO 27001 does not require a fraud risk assessment. Add fraud scenarios to your risk assessment and record that you considered management override.
CC3.4
Identifying changes that matter
That significant changes — to the business, systems, people or suppliers — trigger a reassessment of risk rather than being noticed later.
Mostly carries. Clause 6.3 planning of changes · A.8.32 · A.5.22 Add an explicit trigger list so the reassessment is not left to judgement.

CC4 — Monitoring activities

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC4.1
Evaluating whether controls are working
That the organisation carries out ongoing and separate evaluations to establish that controls are present and functioning.
Carries over. Clause 9.1 monitoring · Clause 9.2 internal audit · A.5.35
CC4.2
Communicating what the evaluations found
That deficiencies are communicated to those responsible for corrective action, and to management, in time to act.
Carries over. Clause 9.2 · Clause 10.1 nonconformity and corrective action

CC5 — Control activities

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC5.1
Selecting controls that address the risk
That controls are selected and developed to bring risks to an acceptable level.
Carries over. Clause 6.1.3 risk treatment · the Statement of Applicability Your SoA is strong evidence here and has no SOC 2 equivalent — use it.
CC5.2
General technology controls
That general controls over technology are selected and developed to support the achievement of objectives.
Carries over. Annex A.8 as a whole
CC5.3
Controls deployed through policy and procedure
That policies establish what is expected and procedures put those policies into effect, with named responsibility.
Carries over. A.5.1 policies · A.5.37 documented operating procedures

CC6 — Logical and physical access

Almost entirely covered by Annex A.7 and A.8. If your ISMS is real, so is this section.

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC6.1
Logical access architecture
That logical access security software, infrastructure and architecture are implemented to protect information from unauthorised access.
Carries over. A.5.15 · A.8.3 · A.8.20 · A.8.24
CC6.2
Registering and authorising users
That new access is registered and authorised before it is granted, and that the authorisation is recorded.
Carries over. A.5.16 identity management · A.5.18 access rights
CC6.3
Changing and removing access
That access is modified and removed on role change and departure, on a least-privilege basis, and reviewed periodically.
Carries over. A.5.18 · A.8.2 privileged access Expect the auditor to sample leavers and check the date access ended against the date employment did.
CC6.4
Physical access to facilities
That physical access to facilities holding information assets is restricted to authorised people.
Carries over. A.7.1 · A.7.2 · A.7.3 · A.7.4 If you are fully remote, say so and point at your cloud provider's report. That is a normal answer, not a weakness.
CC6.5
Disposing of assets
That physical assets and media are disposed of in a way that makes the information unrecoverable.
Carries over. A.7.14 secure disposal · A.7.10 storage media
CC6.6
Keeping outsiders out
That the organisation protects its boundaries against threats from outside.
Carries over. A.8.20 · A.8.21 · A.8.22 · A.8.23
CC6.7
Protecting information in transit and on the move
That information is protected when transmitted, moved or removed, including on portable media and devices.
Carries over. A.5.14 · A.8.24 cryptography · A.8.12 · A.8.1
CC6.8
Stopping unauthorised software
That the organisation prevents or detects unauthorised or malicious software.
Carries over. A.8.7 malware · A.8.19 installing software · A.8.9 configuration

CC7 — System operations

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC7.1
Knowing your configuration, and its vulnerabilities
That the organisation maintains standard configurations and detects departures from them, and identifies vulnerabilities.
Carries over. A.8.9 configuration management · A.8.8 technical vulnerabilities
CC7.2
Monitoring for anomalies
That systems are monitored for anomalies that indicate a security event, and that someone looks at the result.
Carries over. A.8.15 logging · A.8.16 monitoring
CC7.3
Deciding whether an event is an incident
That security events are evaluated to determine whether they are incidents.
Carries over. A.5.25 assessment and decision on events
CC7.4
Responding to incidents
That identified incidents are responded to under a defined programme, with containment, communication and remediation.
Carries over. A.5.24 preparation · A.5.26 response · A.5.28 evidence SOC 2 pays more attention than ISO to whether affected customers were told, and when.
CC7.5
Recovering, and learning
That the organisation recovers from incidents and improves as a result.
Carries over. A.5.27 learning · A.5.29 · A.5.30 · A.8.13 backups

CC8 — Change management

One criterion, and the one an auditor samples hardest.

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC8.1
Change management
That changes to infrastructure, data, software and procedures are authorised, designed, developed, tested, approved and implemented under a defined process.
Carries over. A.8.32 change management · A.8.31 separation of environments · A.8.29 testing · A.8.25 The single criterion an auditor samples most heavily. Expect every sampled change to need an approval record and a test record.

CC9 — Risk mitigation

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
CC9.1
Mitigating the risk of business disruption
That the organisation identifies and mitigates risks from business disruption, including through insurance where appropriate.
Mostly carries. Clause 6.1.3 · A.5.29 · A.5.30 Insurance is not an ISO concept. Record your cyber and business interruption cover, or record the decision not to hold it.
CC9.2
Managing vendors and business partners
That the organisation assesses and manages risks from vendors and partners, including obtaining and reviewing their assurance reports.
Carries over. A.5.19 · A.5.20 · A.5.21 · A.5.22 · A.5.23 The twist: you must obtain your subservice organisations' SOC 2 reports AND record that someone read them, including the complementary user entity controls they hand back to you. Most ISO shops collect the report and never read it.

Availability — an optional category

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
A1.1
Capacity
That capacity is monitored and managed so that availability commitments are met.
Carries over. A.8.6 capacity management
A1.2
Environmental protections, backup and recovery
That environmental protections, backup processes and recovery infrastructure exist and are maintained.
Carries over. A.7.5 · A.7.11 · A.8.13 · A.8.14 · A.5.30
A1.3
Testing the recovery plan
That recovery procedures are tested, not merely written.
Carries over. A.5.30 ICT readiness · A.8.13 restore testing The test record is the evidence. An untested plan fails here and fails ISO too.

Confidentiality — an optional category

Criterion
What the service auditor is looking for
Where your ISO 27001 work already covers it
C1.1
Identifying and protecting confidential information
That confidential information is identified and maintained as such through its life.
Carries over. A.5.12 classification · A.5.13 labelling · A.5.33 protection of records
C1.2
Disposing of confidential information
That confidential information is disposed of when it is no longer needed to meet objectives.
Carries over. A.8.10 information deletion · A.7.14

Where the line falls

This is a mapping, not an audit, and we will never be your service auditor.

A SOC 2 report is issued only by a licensed CPA firm. We are not one and do not intend to become one. This crosswalk is our professional view of how the two frameworks relate; your service auditor’s view is the one that decides, and where the two differ, theirs wins. Treat every row as a starting point for that conversation rather than an answer to it.

Costs nothing, and there is nothing to give us for it — no email address, no form, no follow-up. If it is useful, the documentation packs are where we make our living, and the obligations you pick up abroad is the page to read next. This crosswalk is in English only; our runbooks are published in French Canadian as well, and if you need a paid document in French, ask.

If a US customer has just asked you for one

The first question is not which controls you need. It is what system the report covers, which categories the customer actually wants, and when the observation window can honestly begin. Those three answers decide the cost and the date, and they are worth an hour with somebody before you commit to either.

Ask us about itWhich states catch you — CAD $165

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.