The fastest way to map SOC 2 to ISO 27001 is to map both to one Common Controls Framework (CCF). The Secure Controls Framework (SCF) maps the AICPA's Trust Services Criteria (TSC) and ISO's 27001:2022 and 27002:2022 to the same SCF controls through NIST IR 8477-based Set Theory Relationship Mapping (STRM), so a control you implement and evidence once can support both an ISO 27001 certification audit and a SOC 2 examination.
A direct SOC 2 to ISO 27001 crosswalk is hard to maintain, because each framework changes on its own schedule. Mapping both to a CCF means you maintain one list of controls and let the mappings change underneath it.
The SCF is built for this. It is a free metaframework of 1,500+ controls in 34 domains, mapped to more than 200 laws, regulations and frameworks, and it maps each of them to the same SCF control catalog.
SOC 2 and ISO 27001 are organized differently, which is why a one-to-one table rarely holds up. ISO 27001 and TSC / SOC 2 have entirely different missions:
The SCF uses NIST IR 8477 Set Theory Relationship Mapping (STRM) for every crosswalk. Each mapping records one of five relationship types and a strength score from 1 to 10. This provides unrivalled transparency for crosswalk mapping purposes and that helps provide assurance for stakeholders that defensible coverage exists. This matters for a crosswalk. An "Intersects With" mapping tells you that one piece of evidence will not cover both requirements on its own. You can read more on the STRM page
The very nature of a SOC 2 audit allows the organization to define the controls it wants its audit partner to assess, where it is uncommon for an organization to select all TSC requirements as part of a SOC 2 audit. This complicates crosswalks from TSC to other frameworks, since it first requires the organization to specific the specific TSC requirements that will be applicable to its SOC 2 audit. A that point, a crosswalk can group applicable TSC requirements with the ISO 27001:2022 requirements.
Crosswalks for a SOC 2 are always a starting point for scoping, not a substitute for the requirement-level STRM mappings.
Through the use of the SCF, it is possible. The comprehensive nature of the SCF provides coverage for all TSC and ISO 27001:2022 requirements The two frameworks overlap heavily on access control, incident response, change management, supplier risk and monitoring. Each still has unique requirements, such as the ISO 27001 management system clauses, so plan for a small set of framework-specific controls.
No. Both TSC / SOC 2 and ISO 27001:2022 maps with the same STRM method.
No. Based on how the SCF maps those frameworks to the same controls, adding a third framework means reviewing its mappings against controls you already run, not building a new crosswalk.
No. The SCF organizes your controls and evidence. A CPA firm still issues the SOC 2 report, and an accredited certification body still issues the ISO 27001 certificate. However, the Security, Compliance & Resilience Conformity Assessment Program (SCR CAP) provides an alternative to SOC 2 and ISO 27001.