How Much Do Compliance Frameworks Actually Overlap?
There is no single overlap number, and the honest answer is a pair of numbers pointing in opposite directions. In the framework mapping dataset this site publishes (4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5), SOC 2 and the ISO/IEC 27001 ISMS clauses both map to 44 of the same NIST 800-53 controls. Divide that by everything the ISO clauses reach and you get 83 percent. Divide it by everything SOC 2 reaches and you get 15 percent. Same intersection, same dataset, same afternoon, a 68-point spread. The contrarian version: an overlap percentage published without naming its denominator is not a measurement, and between two ordinary frameworks on our own pair pages that spread reaches 79 percentage points.
This article shows where the numbers come from, publishes the directional measurements for the pairings buyers actually ask about, names the three pairings that really are close, and is explicit about what our own dataset cannot see.
Key takeaways
- Overlap is two numbers: the shared set over framework A's footprint, and the same shared set over framework B's. Quoting one without the other is where misleading percentages come from.
- Measured on this site's dataset, SOC 2 and the ISO 27001 ISMS clauses share 44 NIST SP 800-53 controls: 83 percent of the ISO clause footprint, 15 percent of the SOC 2 footprint.
- The widest asymmetry among the 22 pair pages that exclude NIST 800-53 itself is ISO 27001 to PCI DSS: 50 shared controls, 94 percent of one side and 15 percent of the other.
- Exactly one published pairing is an identity: CMMC Level 2 and NIST SP 800-171, at 218 shared controls out of a 218-control union, and that identity is inherited from the source rather than discovered.
- Frameworks differ in mapping density, from roughly 2 to roughly 9 NIST controls per source requirement, which drives much of the apparent difference in overlap.
Where these numbers come from
Every cross-mapping in our dataset points at the same place: NIST SP 800-53 Rev 5, "Security and Privacy Controls for Information Systems and Organizations", which NIST's publication page lists as Final and whose control families that page enumerates by name. Our dataset carries those 20 families as the family axis on every pair page. A row says "this PCI DSS requirement maps to these NIST 800-53 controls". Nothing in it says "this PCI DSS requirement is that GDPR article".
That pivot is what makes a pair page derivable. If both frameworks are mapped to the same catalogue, the ground they share is the intersection of the NIST controls they each reach, and that intersection is what our 30 pair pages list in full, one row per shared NIST control. Eight of the 30 put NIST 800-53 itself on one side, which is a different object: there the page is the authored mapping rather than an intersection of two of them. The 22 comparing two ordinary frameworks are what this article measures.
The denominator is the part almost nobody states. Each framework has a footprint: the count of distinct NIST 800-53 controls anything in it maps to. On our mapping hub's overlap matrix that is the diagonal cell, and the hub labels it in those words. SOC 2's footprint is 301 controls. The ISO 27001 ISMS clause footprint is 53. PCI DSS reaches 326. HIPAA reaches 165. CCPA and CPRA reach 215. Given two footprints and one intersection, "how much do they overlap" has three defensible answers and you have to say which you are giving.
NIST is careful about this in its own mapping programme. NIST IR 8278r1, "National Online Informative References (OLIR) Program: Overview, Benefits, and Use" (February 2024), describes a set theory relationship mapping as one that classifies each relationship "utilizing set theory principles (subset of, intersects with, equal, superset of, not related to)". Three of those five are direction-bearing, and there is no relationship type called "overlaps 75 percent". The same document says that of the two documents being compared, the first, "called the Focal Document, is used as the basis for the comparison", which is the same structural choice our dataset makes.
The same publication endorses the pivot itself. Describing two documents each mapped to a common third, NIST writes that "SP 800-53 would serve as a transitive link for identifying commonality between the Cybersecurity Framework and SP 800-171." A transitive link is what our pair pages are built on, and transitivity is also the limit of what they claim.
Overlap is two numbers, and the gap can reach 79 points
Here are the directional measurements for the pairings that come up most often in scoping calls. Each line is: shared NIST 800-53 controls, then that count as a share of each side's own footprint.
- SOC 2 to ISO 27001: 44 shared. 15 percent of SOC 2's 301, 83 percent of the ISO clauses' 53.
- ISO 27001 to PCI DSS: 50 shared. 94 percent of the ISO clauses' 53, 15 percent of PCI DSS's 326. The widest spread on the site.
- SOC 2 to PCI DSS: 185 shared. 61 percent of SOC 2, 57 percent of PCI DSS. Nearly symmetric, and the two largest security footprints among the pairings buyers ask about.
- SOC 2 to HIPAA: 132 shared. 44 percent of SOC 2, 80 percent of HIPAA.
- SOC 2 to NIST CSF: 175 shared. 58 percent of SOC 2, 75 percent of CSF's 233.
- GDPR to CCPA: 50 shared. 85 percent of GDPR's 59, 23 percent of CCPA's 215.
- HIPAA to HITRUST: 53 shared. 32 percent of HIPAA, 49 percent of HITRUST's 108. Under half in both directions, on a pairing buyers assume is close.
Read the first line the way a buyer would. If you hold SOC 2 and someone tells you ISO 27001 is "mostly the same", 83 percent is the number they mean, and in that direction it is roughly right: little of what the ISMS clauses reach sits outside what SOC 2 already reaches. If you hold ISO 27001 and someone tells you SOC 2 is mostly done, 15 percent is the honest number, and that is a different conversation. Direction here is not a technicality. It is the whole commercial content of the measurement.
The HIPAA to HITRUST line is the one that surprises people. Modest numbers in both directions mean the two documents reach mostly different parts of the NIST catalogue: 32 and 49 percent is not the near-identity that "HITRUST is HIPAA plus" implies.
The three pairings that really are close
Most published pairs are not close by any denominator. Three are, for three different reasons.
CMMC Level 2 and NIST SP 800-171. 218 shared controls against a combined footprint of 218, so the two sides agree on every control. That is not a good crosswalk, it is a regulation restated by a single source, and we work through what follows in is CMMC Level 2 the same as NIST 800-171.
ISO/IEC 42001 and the NIST AI Risk Management Framework. 63 shared against a combined footprint of 121. Two documents written within a couple of years of each other, about the same subject, by bodies reading each other's drafts. The closest genuinely independent pairing on the site.
SOC 2 and NIST CSF 2.0. 175 shared against a combined footprint of 359. Neither is a subset of the other, but they are the two broadest general-purpose security documents in the set.
Everything else is further apart than the marketing suggests. If a vendor says your next framework is mostly done, ask which two counts they divided.
Why footprints differ so much
Part of the answer is scope. Most of it is writing style, and this is the mechanic behind the strangest-looking numbers in the table.
Frameworks differ enormously in how many NIST controls a single requirement reaches. In our dataset, one SOC 2 trust services criterion maps on average to about 9.5 NIST 800-53 controls, because the criteria are written broadly. One HITRUST CSF control maps to about 2.0. One CCPA or CPRA regulation section maps to about 2.5. One CMMC practice maps to about 2.9.
So SOC 2 reaches 301 distinct NIST controls from 61 criteria, while HITRUST reaches 108 from 90 controls. The framework with fewer, broader requirements has the larger footprint. That is not a statement about which programme is more demanding, and reading it as one is the commonest error in crosswalk analysis.
The consequence: a framework with a small footprint will nearly always look "mostly covered" by a framework with a large one, in that direction, regardless of how much real work separates them. The GDPR to CCPA line is a clean example, and we take it apart in does GDPR compliance cover CCPA.
What the residue actually is
The interesting question is never the size of the overlap. It is what sits outside it, because that is what you will pay for.
Take SOC 2 and the ISO 27001 ISMS clauses again. Of the 53 NIST controls the ISO clauses reach, 44 are shared with SOC 2 and 9 are not: PE-22, SA-5, RA-7, PS-3, PS-3(2), PL-4(1), AT-2, PM-16(1) and SI-5(1). Component marking, system documentation, risk response, personnel screening and its formal indoctrination enhancement, social media and external site usage restrictions, literacy training, automated threat intelligence sharing, automated alerts. A short and cheap list.
Now compare that with where a SOC 2 to ISO 27001 move actually spends: the risk assessment methodology, the Statement of Applicability, the internal audit programme, management review. None of those appears in the nine, because none of them is a control in the NIST sense at all. They are management-system machinery, and a control crosswalk is structurally blind to them.
That is the most useful thing a crosswalk tells you, and it is the opposite of what it appears to say. A high overlap number between a control framework and a management-system standard is a warning that the crosswalk is measuring the wrong axis. Our piece on reusing evidence across frameworks walks through which artifacts genuinely transfer, and ISO 27001 versus SOC 2 covers the sequencing decision.
What this dataset cannot see
Five limits, stated plainly, because a mapping dataset that oversells itself is worse than none.
Our ISO 27001 lens is the ISMS clauses, not Annex A. The 53-control footprint comes from clauses 4 through 10 of ISO/IEC 27001:2022, the management-system requirements. Annex A is a different lens with different content, and every ISO number here is a statement about the clauses only. If you have seen a higher SOC 2 to ISO 27001 figure elsewhere, that is one reason it can be higher and still not be comparable.
A mapped control is not an implemented control. The dataset says two frameworks both point at AC-2. It says nothing about whether your account management is any good.
Two controls on the same row are related through the NIST control between them. They are not asserted to be equivalent. The pair pages say so in their own method section, and it is the difference between a derived intersection and an authored crosswalk. Publishing a control-to-control equivalence we have not sourced would be a fabrication, so we do not.
Density artifacts cut both ways. A framework whose requirements are written broadly gets a large footprint, and therefore a small-looking percentage in one direction and a large-looking one in the other. The numbers are correct; the intuition they trigger often is not.
Revisions move underneath you. Our NIST SP 800-171 lens is Revision 2, which NIST's publication page records as "Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3", while the CMMC rule that binds defense contractors still names Revision 2 by number. That mismatch is deliberate, and we take it apart in is CMMC Level 2 the same as NIST 800-171.
Against our own interest: none of this is the hard part, and the mapping resource is free and ungated for that reason. The mapping tells you where to look. Building the control register, collecting evidence once, and keeping the tagging discipline through two quarters of roadmap pressure is where the cost is, and no crosswalk shortens it.
Where Top Floor fits
If you already hold one framework, your scope is stable, and someone internal owns the control register, adding a second framework is a documentation project you can run without us. We say that to prospects and it occasionally costs us the engagement.
Where an outside team earns its fee is the case the numbers above describe badly: three frameworks in flight against three customer deadlines, a scope that keeps moving, or a register that does not exist yet. That is the shape of a compliance as a service engagement, and audit and assurance readiness is the independent look at whether your evidence survives a different examiner. Our SOC 2 and ISO 27001 pages cover the single-framework paths.
How to decide this week
Open the pair page for the two frameworks in front of you and read the number in your own direction, not the flattering one. If you hold framework A and are being sold framework B, the number that matters is the shared count divided by B's footprint: the fraction of the new thing you have already touched.
Then do what the crosswalk cannot. List the artifacts framework B asks for that are documents rather than controls: a management review record, a risk treatment plan, a system description, an assertion letter. Those appear in no control mapping, they are frequently the largest line in a second-framework budget, and they turn a comfortable percentage into a two-quarter project. If a proposal is priced off an overlap percentage, ask for the document list priced separately.
Frequently asked questions
What is the real overlap between SOC 2 and ISO 27001?
In our published dataset, SOC 2 and the ISO/IEC 27001 ISMS clauses both map to 44 of the same NIST SP 800-53 Rev 5 controls. That is 83 percent of the 53 controls the ISO clauses reach and 15 percent of the 301 SOC 2 reaches, so the answer depends on which direction you are asking about. This lens covers the ISMS management-system clauses rather than Annex A, and the expensive part of a SOC 2 to ISO 27001 move is management-system documentation that no control crosswalk measures.
Why do published framework overlap percentages vary so much?
Because almost none of them names a denominator, and the denominators differ by an order of magnitude. The same intersection can be 15 percent or 83 percent depending on which framework's footprint you divide by, and it can change again if the source counts requirements instead of mapped controls, or uses a different lens of the same standard. Before using any overlap figure, ask what was counted, what it was divided by, and which edition of each document was used.
Does a high overlap number mean the second framework will be cheap?
Not reliably. Overlap measures control content, and the largest costs in a second framework are frequently not control content: the independent examination, the scope extension, and the documents a management-system standard requires that a control framework never asks for. A high number is a good sign for evidence reuse and a poor predictor of total cost. Price the deliverables, not the percentage.
Can I use these mappings as an authored crosswalk between two frameworks?
No, and the pair pages say so in their own method sections. Both frameworks are mapped to NIST SP 800-53, so a shared row means both point at the same NIST control; it does not assert that the control on the left equals the one on the right. Use it to find where to look in your control register, then have a practitioner judge whether the evidence you hold answers the requirement you are adding.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.