ISO/IEC 27001:2022 (ISMS clauses) to PCI DSS v4.0.1 control mapping
ISO/IEC 27001:2022 (ISMS clauses) and PCI DSS v4.0.1 both map to 50 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.
- Shared NIST 800-53 controls
- 50
- ISO/IEC 27001:2022 (ISMS clauses) controls involved
- 23
- PCI DSS v4.0.1 controls involved
- 131
- NIST 800-53 families touched
- 20
How this pairing is derived
Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored ISO/IEC 27001:2022 (ISMS clauses) to PCI DSS v4.0.1 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.
Shared controls in full
| NIST 800-53 control | Family | ISO/IEC 27001:2022 (ISMS clauses) controls | PCI DSS v4.0.1 controls |
|---|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4 |
| AT-1Policy and Procedures | ATAwareness and Training | 5.1, 5.2, 7.4, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.5.1, 9.5.1.3, A3.1.4 |
| AT-2Literacy Training and Awareness | ATAwareness and Training | 7.4 | 12.6, 12.6.1, 12.6.3, 12.6.3.1, 8.3.8, 9.5.1, 9.5.1.3 |
| AU-1Policy and Procedures | AUAudit and Accountability | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1, 10.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.3.1, A3.5 |
| CA-1Policy and Procedures | CAAssessment, Authorization, and Monitoring | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| CA-2Control Assessments | CAAssessment, Authorization, and Monitoring | 8.1, 9.1 | 1.1, 1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.4.2 |
| CA-7Continuous Monitoring | CAAssessment, Authorization, and Monitoring | 10.1, 8.1 | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| CA-7(1)Independent Assessment | CAAssessment, Authorization, and Monitoring | 10.1, 8.1 | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| CM-1Policy and Procedures | CMConfiguration Management | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1, 2.1.1, 2.2, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 9.1.1 |
| CM-3Configuration Change Control | CMConfiguration Management | 6.3 | 1.2.2, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.3, 6.5.6 |
| CP-1Policy and Procedures | CPContingency Planning | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| IA-1Policy and Procedures | IAIdentification and Authentication | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4 |
| IR-1Policy and Procedures | IRIncident Response | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.10, 12.10.2, 12.10.6, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.5 |
| MA-1Policy and Procedures | MAMaintenance | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.7, 8.3.8, 9.1.1 |
| PE-1Policy and Procedures | PEPhysical and Environmental Protection | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1, 9.1.1, 9.2 |
| PE-22Component Marking | PEPhysical and Environmental Protection | 4.3 | A3.2.5 |
| PL-1Policy and Procedures | PLPlanning | 4.1, 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, 9.1, 9.2.1, 9.2.2 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 12.4.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1, A3.1.1 |
| PL-4Rules of Behavior | PLPlanning | 7.3 | 12.1.3, 12.2, 12.2.1 |
| PL-9Central Management | PLPlanning | 5.1, 5.3 | 1.1, 1.1.2, 10.1.2, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 5.3.4, 6.1.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| RA-1Policy and Procedures | RARisk Assessment | 5.1, 5.2, 6.1.1, 6.1.2, 7.5.1, 7.5.2, 7.5.3, 8.2 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| RA-2Security Categorization | RARisk Assessment | 6.1.2 | 9.4.2 |
| RA-3Risk Assessment | RARisk Assessment | 6.1.2, 8.2 | 1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.3, 12.3.1, 12.3.2, 12.4.2 |
| RA-7Risk Response | RARisk Assessment | 6.1.3, 8.3 | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| SA-1Policy and Procedures | SASystem and Services Acquisition | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 6.2.4, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| SA-5System Documentation | SASystem and Services Acquisition | 4.3 | A3.2.5 |
| SA-8(32)Sufficient Documentation | SASystem and Services Acquisition | 8.1 | 1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 3.7, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.5.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2 |
| SA-9(3)Establish and Maintain Trust Relationship with Providers | SASystem and Services Acquisition | 4.3 | 12.4.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2 |
| SC-1Policy and Procedures | SCSystem and Communications Protection | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1, 1.1.1, 1.2, 10.1.1, 11.1.1, 11.2.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1 |
| SC-38Operations Security | SCSystem and Communications Protection | 8.1 | 1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2 |
| SI-1Policy and Procedures | SISystem and Information Integrity | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1 |
| SI-5Security Alerts, Advisories, and Directives | SISystem and Information Integrity | 7.4 | 11.2, 4.1, 4.2.1, 6.3.1 |
| SI-5(1)Automated Alerts and Advisories | SISystem and Information Integrity | 7.4 | 6.3.1 |
| MP-1Policy and Procedures | MPMedia Protection | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.4, 9.4.1 |
| PS-1Policy and Procedures | PSPersonnel Security | 5.1, 5.2, 7.2, 7.3, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.2, 12.2.1, 12.7, 12.7.1, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| PS-2Position Risk Designation | PSPersonnel Security | 7.2 | 12.7, 12.7.1, 6.2.2 |
| PS-3Personnel Screening | PSPersonnel Security | 7.2 | 12.7, 12.7.1 |
| PS-9Position Descriptions | PSPersonnel Security | 5.3, 7.3 | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.3 |
| PM-1Information Security Program Plan | PMProgram Management | 10.1, 4.4, 5.1, 5.2, 6.1.1, 7.5.1, 7.5.2, 7.5.3, 8.1 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1.2 |
| PM-2Information Security Program Leadership Role | PMProgram Management | 5.1, 5.3 | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PM-6Measures of Performance | PMProgram Management | 5.1, 5.3, 9.1 | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PM-8Critical Infrastructure Plan | PMProgram Management | 4.1, 9.1, 9.2.1, 9.2.2 | 12.4, 12.4.2, A3.1, A3.1.1 |
| PM-9Risk Management Strategy | PMProgram Management | 6.1.1, 6.1.2, 8.2 | 12.3 |
| PM-13Security and Privacy Workforce | PMProgram Management | 5.3, 7.3, 7.4 | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 8.3.8, 9.1.2, 9.5.1, 9.5.1.3, A3.1.3, A3.1.4 |
| PM-14Testing, Training, and Monitoring | PMProgram Management | 10.1, 8.1 | 10.7, 10.7.1, 10.7.2, 10.7.3, A3.1.4 |
| PM-16(1)Automated Means for Sharing Threat Intelligence | PMProgram Management | 7.4 | 6.3.1 |
| PM-28Risk Framing | PMProgram Management | 6.1.2 | 12.3.1, 12.3.2 |
| PM-29Risk Management Program Leadership Roles | PMProgram Management | 5.1, 5.3, 6.1.1, 6.1.2, 8.2 | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.3, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PT-1Policy and Procedures | PTPII Processing and Transparency | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1 |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3 | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.3, 8.3.8, 9.1.1, A2.1.3 |
| SR-7Supply Chain Operations Security | SRSupply Chain Risk Management | 8.1 | 1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2 |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.
Related pairings
- PCI DSS v4.0.1 to NIST SP 800-53 Rev 5 control mapping326 shared controls
- SOC 2 Type II to PCI DSS v4.0.1 control mapping185 shared controls
- PCI DSS v4.0.1 to NIST CSF 2.0 control mapping166 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to NIST SP 800-53 Rev 5 control mapping53 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to NIST CSF 2.0 control mapping47 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to ISO/IEC 42001:2023 (clauses and Annex A) control mapping46 shared controls