Framework Mapping
Visualize how compliance frameworks overlap through NIST 800-53 control mappings. 4,123 cross-framework mappings across 19 frameworks.
Overlap Matrix
Shared NIST SP 800-53 Rev 5 controls between the most-requested compliance frameworks. Each value is the number of NIST 800-53 controls both frameworks map to, the overlap you can satisfy once and evidence for multiple audits.
| View through NIST 800-53 | SOC 2 | ISO 27001 | CMMC | HITRUST | PCI DSS | HIPAA |
|---|---|---|---|---|---|---|
| SOC 2 | 301 | 44 | 114 | 81 | 185 | 132 |
| ISO 27001 | 44 | 53 | 24 | 23 | 50 | 42 |
| CMMC | 114 | 24 | 218 | 70 | 151 | 77 |
| HITRUST | 81 | 23 | 70 | 108 | 81 | 53 |
| PCI DSS | 185 | 50 | 151 | 81 | 326 | 122 |
| HIPAA | 132 | 42 | 77 | 53 | 122 | 165 |
Click any cell to see the specific shared NIST 800-53 controls. Diagonal cells show total unique NIST controls mapped per framework.
Representative Control Mappings
A sample of how individual framework controls map to NIST SP 800-53 Rev 5. The full set spans 4,123 mapped controls across 19 frameworks, explorable in the interactive matrix, framework explorer and control search below.
| Framework | Control | Maps to NIST 800-53 |
|---|---|---|
| SOC 2 Type II | A1.1 | CP-2(2)SC-5SC-5(1)SC-5(2)SC-5(3)SC-6 |
| ISO/IEC 27001:2022 (ISMS clauses) | 10.1 | CA-7CA-7(1)PM-1PM-14 |
| ISO/IEC 27001:2022 (ISMS clauses) | 4.1 | PL-1PM-8 |
| CMMC Level 2 | AC.L1-3.1.1 | AC-1AC-2(1)AC-2(7)AC-3AC-6IA-1IA-2SA-4SR-1SR-3(3) |
| CMMC Level 2 | AC.L1-3.1.2 | AC-2AC-2(7) |
| HITRUST CSF v11 | HITRUST-01.a | PL-1PL-2 |
| PCI DSS v4.0.1 | 1.1.2 | AT-3AT-3(2)PL-9PM-13PM-2PM-29PM-6PS-9 |
| NIST CSF 2.0 | DE.AE-02 | IR-4IR-4(3) |
| NIST CSF 2.0 | DE.AE-04 | IR-4IR-4(3) |
| NIST SP 800-171 Rev 2 | 3.1.1 | AC-1AC-2(1)AC-2(7)AC-3AC-6IA-1IA-2SA-4SR-1SR-3(3) |
| NIST SP 800-171 Rev 2 | 3.1.10 | AC-11AC-11(1)AC-2(5) |
Framework Explorer & Control Search
Select any combination of 19 frameworks, switch the reference lens between NIST 800-53, ISO 27001, PCI DSS and more, drill into family-level breakdowns, and search across every mapped control. The interactive tools load momentarily.
Framework pair crosswalks
Each pairing below has its own page listing every NIST SP 800-53 Rev 5 control the two frameworks share, rendered server side and readable without JavaScript.
- SOC 2 Type II to ISO/IEC 27001:2022 (ISMS clauses) control mapping44 shared controls
- SOC 2 Type II to HIPAA (Security, Privacy and Breach Notification Rules) control mapping132 shared controls
- SOC 2 Type II to PCI DSS v4.0.1 control mapping185 shared controls
- SOC 2 Type II to CMMC Level 2 control mapping114 shared controls
- SOC 2 Type II to HITRUST CSF v11 control mapping81 shared controls
- SOC 2 Type II to GDPR control mapping55 shared controls
- SOC 2 Type II to ISO/IEC 42001:2023 (clauses and Annex A) control mapping78 shared controls
- SOC 2 Type II to NIST AI RMF 1.0 control mapping76 shared controls
- SOC 2 Type II to NIST CSF 2.0 control mapping175 shared controls
- SOC 2 Type II to NIST SP 800-171 Rev 2 control mapping114 shared controls
- SOC 2 Type II to NIST SP 800-53 Rev 5 control mapping301 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to HIPAA (Security, Privacy and Breach Notification Rules) control mapping42 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to PCI DSS v4.0.1 control mapping50 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to GDPR control mapping29 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to ISO/IEC 42001:2023 (clauses and Annex A) control mapping46 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to NIST CSF 2.0 control mapping47 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to NIST SP 800-53 Rev 5 control mapping53 shared controls
- HIPAA (Security, Privacy and Breach Notification Rules) to HITRUST CSF v11 control mapping53 shared controls
- HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 Rev 5 control mapping165 shared controls
- PCI DSS v4.0.1 to NIST CSF 2.0 control mapping166 shared controls
- PCI DSS v4.0.1 to NIST SP 800-53 Rev 5 control mapping326 shared controls
- CMMC Level 2 to NIST SP 800-171 Rev 2 control mapping218 shared controls
- CMMC Level 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls
- GDPR to CCPA/CPRA control mapping50 shared controls
- GDPR to NIST SP 800-53 Rev 5 control mapping59 shared controls
- ISO/IEC 42001:2023 (clauses and Annex A) to NIST AI RMF 1.0 control mapping63 shared controls
- NIST CSF 2.0 to NIST SP 800-171 Rev 2 control mapping100 shared controls
- NIST CSF 2.0 to CIS Controls v8.1 control mapping134 shared controls
- NIST CSF 2.0 to NIST SP 800-53 Rev 5 control mapping233 shared controls
- NIST SP 800-171 Rev 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls