Secure Controls Framework
Download The SCF

How to Map SOC 2 to ISO 27001 Using the SCF: A Worked Crosswalk Example

Compliance,SOC 2,Secure Controls Framework,Controls
SCF Council
•
September 29, 2026

The fastest way to map SOC 2 to ISO 27001 is to map both to one Common Controls Framework (CCF). The Secure Controls Framework (SCF) maps the AICPA's Trust Services Criteria (TSC) and ISO's 27001:2022 and 27002:2022 to the same SCF controls through NIST IR 8477-based Set Theory Relationship Mapping (STRM), so a control you implement and evidence once can support both an ISO 27001 certification audit and a SOC 2 examination.

Why map SOC 2 and ISO 27001 through a Common Controls Framework (CCF)?

A direct SOC 2 to ISO 27001 crosswalk is hard to maintain, because each framework changes on its own schedule. Mapping both to a CCF means you maintain one list of controls and let the mappings change underneath it.

The SCF is built for this. It is a free metaframework of 1,500+ controls in 34 domains, mapped to more than 200 laws, regulations and frameworks, and it maps each of them to the same SCF control catalog.

What does each framework contain?

SOC 2 and ISO 27001 are organized differently, which is why a one-to-one table rarely holds up. ISO 27001 and TSC / SOC 2 have entirely different missions:

  • ISO 27001 is designed to structure an Information Security Management System (ISMS).
  • The controls found in Appendix A of ISO 27001 are the controls in ISO 27002, so to implement an ISMS the expectation is to implement ISO 27002 to acheive ISO 27001.
  • AICPA's TSC consist of several categories of requirements, but it is not designed to built or maintain an ISMS - it is designed to provide assurance of secure practices for third parties.

    How does the SCF describe each mapping?

    The SCF uses NIST IR 8477 Set Theory Relationship Mapping (STRM) for every crosswalk. Each mapping records one of five relationship types and a strength score from 1 to 10. This provides unrivalled transparency for crosswalk mapping purposes and that helps provide assurance for stakeholders that defensible coverage exists. This matters for a crosswalk. An "Intersects With" mapping tells you that one piece of evidence will not cover both requirements on its own. You can read more on the STRM page

      What does a worked SOC 2 to ISO 27001 crosswalk look like?

      The very nature of a SOC 2 audit allows the organization to define the controls it wants its audit partner to assess, where it is uncommon for an organization to select all TSC requirements as part of a SOC 2 audit. This complicates crosswalks from TSC to other frameworks, since it first requires the organization to specific the specific TSC requirements that will be applicable to its SOC 2 audit. A that point, a crosswalk can group applicable TSC requirements with the ISO 27001:2022 requirements.

      Crosswalks for a SOC 2 are always a starting point for scoping, not a substitute for the requirement-level STRM mappings.

        SOC 2 vs ISO 27001: Frequently Asked Questions (FAQ)

        Can one set of controls satisfy both SOC 2 and ISO 27001?

        Through the use of the SCF, it is possible. The comprehensive nature of the SCF provides coverage for all TSC and ISO 27001:2022 requirements The two frameworks overlap heavily on access control, incident response, change management, supplier risk and monitoring. Each still has unique requirements, such as the ISO 27001 management system clauses, so plan for a small set of framework-specific controls.

        Is SOC 2 or ISO 27001 easier to map to the SCF?

        No. Both TSC / SOC 2 and ISO 27001:2022 maps with the same STRM method.

        Do I need a separate crosswalk for NIST CSF or NIST 800-53 later?

        No. Based on how the SCF maps those frameworks to the same controls, adding a third framework means reviewing its mappings against controls you already run, not building a new crosswalk.

        Does the SCF replace the SOC 2 report or ISO 27001 certificate?

        No. The SCF organizes your controls and evidence. A CPA firm still issues the SOC 2 report, and an accredited certification body still issues the ISO 27001 certificate. However, the Security, Compliance & Resilience Conformity Assessment Program (SCR CAP) provides an alternative to SOC 2 and ISO 27001.