The ISO 27001 → SOC 2 cross-walk: 71 mappings that save 3 weeks
If you already hold ISO 27001, most of your SOC 2 evidence already exists. Here is how a 71-entry cross-walk reuses it — and where it stops.
The Obligara team ·
If you hold ISO 27001 and a US customer has just asked for a SOC 2 report, here is the good news: you are not starting from zero. You are probably 70% of the way there and don't know it.
The reason is simple. ISO 27001's Annex A controls and SOC 2's Trust Services Criteria are two descriptions of the same underlying security practices. Access control, change management, incident response, monitoring, supplier risk, business continuity — both frameworks want them, both want the evidence that they work. What differs is the vocabulary and the shape of the report, not the substance of the controls.
So why do so many teams gather the same evidence twice?
The duplicate-evidence trap
Because the two frameworks live in different tools. The ISMS sits in one system (or a folder of Word documents and a spreadsheet Statement of Applicability). The SOC 2 push starts in a separate tool, with a blank set of criteria. Nobody wires the two together, so the access-review export you produced for A.5.15 gets produced again for CC6.1. The incident-response runbook you wrote for A.5.24 gets re-attached for CC7.4. Multiply that across ~60 overlapping controls and you have lost the best part of a month.
The shortcut most teams miss
The work isn't the evidence — you already have it. The work is re-finding and re-attaching it under a new set of names. Eliminate the re-finding and the SOC 2 readiness phase collapses.
What the cross-walk actually does
When you enable SOC 2 on a Obligara workspace that already runs ISO 27001, we apply a 71-entry cross-walk from your ISO 27001 controls onto the SOC 2 criteria. Concretely, that means:
- Each mapped Trust Services Criterion is pre-linked to the ISO 27001 control(s) that address it.
- The evidence already attached to those controls — policies, logs, review records — surfaces against the criterion, instead of being requested again.
- Your starting readiness reflects the work you've already done, rather than a wall of red.
A few representative mappings make the overlap concrete:
| ISO 27001 control | SOC 2 criteria | Shared evidence |
|---|---|---|
| A.5.15 Access control | CC6.1, CC6.2, CC6.3 | Access policy, joiner/leaver records, access reviews |
| A.8.16 Monitoring activities | CC7.2, CC7.3 | Alerting configuration, anomaly-detection runbook |
| A.5.24 Incident management planning | CC7.4, CC7.5 | Incident response plan, post-incident reviews |
| A.5.30 ICT readiness for continuity | A1.2, A1.3 | Backup tests, DR plan, capacity monitoring |
Across the full set, that is 71 mappings doing the connective work — typically around three weeks of duplicate evidence-gathering removed from the readiness phase.
No ISO 27001 yet? Start with the 40-control starter pack
The cross-walk is the fast path for teams that already have an ISMS. If SOC 2 is your first framework, enabling it instead instantiates a 40-control starter pack — a sensible baseline of controls to build from — so you are not staring at 71 empty criteria wondering where to begin.
Where the cross-walk stops (the honest part)
A cross-walk is a head start, not a rubber stamp. Three caveats worth stating plainly:
- Mapping is not certification. The cross-walk shows you which evidence is relevant to which criterion. A SOC 2 auditor still forms their own opinion on whether the control operated effectively over the period.
- SOC 2 has criteria ISO 27001 doesn't emphasise. The Availability, Confidentiality and Processing Integrity categories, and parts of the Common Criteria, may need evidence your ISO programme didn't prioritise. The readiness scorecard flags those gaps rather than hiding them.
- Type II is about duration. A Type II report covers a window of time. Even with perfect mappings, you still need the evidence to span the observation period — the cross-walk gets the right controls in front of you sooner, but the clock is still the clock.
The point
The fastest way through SOC 2, when you already have ISO 27001, is to stop treating them as separate projects. Run them in one workspace, let the cross-walk reuse the evidence, and spend your three saved weeks on the genuine gaps instead of on re-attaching files you produced months ago.
If you want to see the cross-walk applied to real controls, book a demo — or read how the SOC 2 module handles audit periods and readiness.