Skip to content

    SOC 2 Type II to CMMC Level 2 control mapping

    SOC 2 Type II and CMMC Level 2 both map to 114 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    114
    SOC 2 Type II controls involved
    39
    CMMC Level 2 controls involved
    67
    NIST 800-53 families touched
    18

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored SOC 2 Type II to CMMC Level 2 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both SOC 2 Type II and CMMC Level 2, with the controls on each side that map to them.
    NIST 800-53 controlFamilySOC 2 Type II controlsCMMC Level 2 controls
    AC-1Policy and ProceduresACAccess ControlCC5.3, CC6.1, CC6.6AC.L1-3.1.1
    AC-2Account ManagementACAccess ControlCC6.1, CC6.6AC.L1-3.1.2
    AC-2(7)Privileged User AccountsACAccess ControlCC6.1, CC6.3AC.L1-3.1.1, AC.L1-3.1.2, AC.L2-3.1.3
    AC-2(12)Account Monitoring for Atypical UsageACAccess ControlCC7.2SI.L2-3.14.7
    AC-3Access EnforcementACAccess ControlCC6.1, CC6.6AC.L1-3.1.1
    AC-4Information Flow EnforcementACAccess ControlCC6.1, CC6.6AC.L2-3.1.3
    AC-4(21)Physical or Logical Separation of Information FlowsACAccess ControlCC6.1SC.L1-3.13.5
    AC-5Separation of DutiesACAccess ControlCC5.1, CC6.6AC.L2-3.1.4
    AC-6Least PrivilegeACAccess ControlCC6.1AC.L1-3.1.1, AC.L2-3.1.5
    AC-17Remote AccessACAccess ControlCC6.6AC.L2-3.1.12
    AC-17(6)Protection of Mechanism InformationACAccess ControlCC6.6AC.L2-3.1.12
    AC-19(5)Full Device or Container-based EncryptionACAccess ControlCC6.7AC.L2-3.1.19
    AC-20Use of External SystemsACAccess ControlCC6.7AC.L1-3.1.20
    AC-20(2)Portable Storage Devices — Restricted UseACAccess ControlCC6.7AC.L2-3.1.21
    AC-20(5)Portable Storage Devices — Prohibited UseACAccess ControlCC6.7AC.L2-3.1.21
    AU-1Policy and ProceduresAUAudit and AccountabilityCC5.3, CC7.2AU.L2-3.3.3, SI.L2-3.14.6
    AU-2Event LoggingAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9, SI.L2-3.14.3
    AU-3Content of Audit RecordsAUAudit and AccountabilityPI1.4AU.L2-3.3.2
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.5, SI.L2-3.14.7
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.5, SI.L2-3.14.7
    AU-7Audit Record Reduction and Report GenerationAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.6
    AU-7(1)Automatic ProcessingAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.6
    AU-9Protection of Audit InformationAUAudit and AccountabilityPI1.4, PI1.5AU.L2-3.3.8
    AU-11Audit Record RetentionAUAudit and AccountabilityC1.2AU.L2-3.3.1
    AU-12Audit Record GenerationAUAudit and AccountabilityCC7.2, CC7.3AU.L2-3.3.6
    CA-2Control AssessmentsCAAssessment, Authorization, and MonitoringCC3.1, CC4.1, CC5.2CA.L2-3.12.1
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and MonitoringCC4.2CA.L2-3.12.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3CA.L2-3.12.1, CA.L2-3.12.3
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3CA.L2-3.12.1, CA.L2-3.12.3
    CM-2Baseline ConfigurationCMConfiguration ManagementCC7.1, CC8.1AU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2
    CM-3Configuration Change ControlCMConfiguration ManagementCC3.4, CC8.1CM.L2-3.4.3
    CM-4Impact AnalysesCMConfiguration ManagementCC3.4CM.L2-3.4.4
    CM-6Configuration SettingsCMConfiguration ManagementCC7.1, CC8.1AU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2
    CP-9System BackupCPContingency PlanningA1.2, CC7.5MP.L2-3.8.9
    CP-9(8)Cryptographic ProtectionCPContingency PlanningA1.2MP.L2-3.8.9
    IA-1Policy and ProceduresIAIdentification and AuthenticationCC5.3, CC6.1, CC6.6AC.L1-3.1.1
    IA-2Identification and Authentication (Organizational Users)IAIdentification and AuthenticationCC6.1AC.L1-3.1.1, IA.L1-3.5.1, IA.L1-3.5.2
    IA-3Device Identification and AuthenticationIAIdentification and AuthenticationCC6.1IA.L1-3.5.1, IA.L1-3.5.2
    IA-3(1)Cryptographic Bidirectional AuthenticationIAIdentification and AuthenticationCC6.1IA.L1-3.5.1, IA.L1-3.5.2
    IA-3(4)Device AttestationIAIdentification and AuthenticationCC6.1IA.L1-3.5.1, IA.L1-3.5.2
    IA-4Identifier ManagementIAIdentification and AuthenticationCC6.1, CC6.6IA.L2-3.5.5
    IA-5Authenticator ManagementIAIdentification and AuthenticationCC6.1IA.L2-3.5.8, IA.L2-3.5.9
    IA-5(1)Password-based AuthenticationIAIdentification and AuthenticationCC6.1IA.L2-3.5.7, IA.L2-3.5.8, IA.L2-3.5.9
    IR-4Incident HandlingIRIncident ResponseCC7.3, CC7.4IR.L2-3.6.1, IR.L2-3.6.2
    IR-4(4)Information CorrelationIRIncident ResponseCC7.2, CC7.3AU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9, SI.L2-3.14.7
    IR-4(13)Behavior AnalysisIRIncident ResponseCC7.2SI.L2-3.14.7
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionA1.2, CC5.3, CC6.4PE.L2-3.10.2
    PE-2Physical Access AuthorizationsPEPhysical and Environmental ProtectionCC6.4PE.L1-3.10.1
    PE-2(1)Access by Position or RolePEPhysical and Environmental ProtectionCC6.4PE.L1-3.10.1
    PE-3Physical Access ControlPEPhysical and Environmental ProtectionCC6.4PE.L1-3.10.3, PE.L1-3.10.5
    PE-3(2)Facility and SystemsPEPhysical and Environmental ProtectionCC6.4PE.L1-3.10.3, PE.L1-3.10.5
    PE-3(3)Continuous GuardsPEPhysical and Environmental ProtectionCC6.4PE.L1-3.10.3, PE.L1-3.10.5
    PE-5Access Control for Output DevicesPEPhysical and Environmental ProtectionPI1.4PE.L1-3.10.1
    PE-17Alternate Work SitePEPhysical and Environmental ProtectionA1.2PE.L2-3.10.6
    PE-18Location of System ComponentsPEPhysical and Environmental ProtectionA1.2PE.L1-3.10.1
    PE-23Facility LocationPEPhysical and Environmental ProtectionA1.2, CC6.4, CC9.1PE.L1-3.10.1, PE.L2-3.10.2
    PL-2System Security and Privacy PlansPLPlanningCC2.1, CC4.1CA.L2-3.12.4
    PL-4Rules of BehaviorPLPlanningCC1.1AC.L1-3.1.22
    PL-10Baseline SelectionPLPlanningCC7.1, CC8.1AU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2
    RA-3Risk AssessmentRARisk AssessmentA1.2, CC4.1, CC7.3RA.L2-3.11.1
    RA-5Vulnerability Monitoring and ScanningRARisk AssessmentCC7.1RA.L2-3.11.2
    SA-4Acquisition ProcessSASystem and Services AcquisitionCC3.3, CC3.4, CC5.2, CC9.1, CC9.2, P6.4, PI1.2, PI1.3AC.L1-3.1.1
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services AcquisitionCC2.2, CC3.2, CC5.1, CC5.2, CC7.1, CC8.1AU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2, SC.L2-3.13.2
    SA-8(14)Least PrivilegeSASystem and Services AcquisitionCC6.1AC.L2-3.1.5
    SA-8(31)Secure System ModificationSASystem and Services AcquisitionCC3.4, CC8.1CM.L2-3.4.3
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services AcquisitionCC4.2CA.L2-3.12.2
    SA-15(5)Attack Surface ReductionSASystem and Services AcquisitionCC2.2, CC3.2, CC5.1, CC5.2, CC7.1, CC8.1AU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2, SC.L2-3.13.2
    SC-1Policy and ProceduresSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2, CC5.3, CC6.1, CC6.6SC.L1-3.13.1, SC.L2-3.13.2
    SC-7Boundary ProtectionSCSystem and Communications ProtectionCC6.1, CC6.6, CC6.8SC.L1-3.13.1
    SC-7(5)Deny by Default — Allow by ExceptionSCSystem and Communications ProtectionCC6.6SC.L2-3.13.6
    SC-7(9)Restrict Threatening Outgoing Communications TrafficSCSystem and Communications ProtectionCC6.1, CC6.6, CC6.8SC.L1-3.13.1
    SC-7(11)Restrict Incoming Communications TrafficSCSystem and Communications ProtectionCC6.1, CC6.6, CC6.8SC.L1-3.13.1, SC.L2-3.13.6
    SC-7(14)Protect Against Unauthorized Physical ConnectionsSCSystem and Communications ProtectionA1.2PE.L1-3.10.1
    SC-7(18)Fail SecureSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2SC.L2-3.13.2
    SC-7(29)Separate Subnets to Isolate FunctionsSCSystem and Communications ProtectionCC6.1SC.L2-3.13.2
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications ProtectionCC6.1, CC6.7SC.L2-3.13.8
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7MP.L2-3.8.6, SC.L2-3.13.11, SC.L2-3.13.8
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionCC6.1, CC6.7MP.L2-3.8.7, SC.L2-3.13.11
    SC-8(3)Cryptographic Protection for Message ExternalsSCSystem and Communications ProtectionCC6.6, CC6.7SC.L2-3.13.14
    SC-12Cryptographic Key Establishment and ManagementSCSystem and Communications ProtectionCC6.1SC.L2-3.13.10
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7MP.L2-3.8.6, SC.L2-3.13.11, SC.L2-3.13.16
    SC-17Public Key Infrastructure CertificatesSCSystem and Communications ProtectionCC6.1SC.L2-3.13.10
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications ProtectionCC4.2RA.L2-3.11.3, SC.L2-3.13.13, SI.L1-3.14.1
    SC-28Protection of Information at RestSCSystem and Communications ProtectionCC6.1, CC6.7MP.L2-3.8.6, SC.L2-3.13.16
    SC-28(1)Cryptographic ProtectionSCSystem and Communications ProtectionA1.2, CC6.1, CC6.7MP.L2-3.8.6, MP.L2-3.8.9, SC.L2-3.13.16
    SC-28(2)Offline StorageSCSystem and Communications ProtectionA1.2, CC7.5MP.L2-3.8.9
    SC-28(3)Cryptographic KeysSCSystem and Communications ProtectionCC6.1SC.L2-3.13.10
    SI-1Policy and ProceduresSISystem and Information IntegrityCC2.2, CC3.2, CC5.1, CC5.2, CC5.3SC.L2-3.13.2
    SI-3Malicious Code ProtectionSISystem and Information IntegrityCC6.6, CC6.8RA.L2-3.11.3, SI.L1-3.14.1, SI.L1-3.14.2, SI.L1-3.14.4, SI.L1-3.14.5
    SI-4System MonitoringSISystem and Information IntegrityCC6.6, CC7.2, CC7.3AU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9, SI.L2-3.14.6
    SI-4(4)Inbound and Outbound Communications TrafficSISystem and Information IntegrityCC7.2SI.L2-3.14.6
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information IntegrityCC7.2SI.L2-3.14.7
    SI-4(16)Correlate Monitoring InformationSISystem and Information IntegrityCC7.2, CC7.3AU.L2-3.3.5, SI.L2-3.14.7
    SI-4(24)Indicators of CompromiseSISystem and Information IntegrityCC6.8, CC7.1SI.L2-3.14.7
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information IntegrityCC6.6CA.L2-3.12.3, SI.L2-3.14.3
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegrityCC6.1SC.L2-3.13.11
    MP-1Policy and ProceduresMPMedia ProtectionC1.1, CC2.1, CC5.3, CC6.5, CC6.7, PI1.5MP.L1-3.8.3, MP.L2-3.8.1
    MP-2Media AccessMPMedia ProtectionC1.1AC.L2-3.1.3, MP.L2-3.8.2, SI.L1-3.14.2
    MP-6Media SanitizationMPMedia ProtectionCC6.5, P4.3MA.L2-3.7.3, MP.L1-3.8.3
    MP-6(3)Nondestructive TechniquesMPMedia ProtectionCC6.5, P4.3MA.L2-3.7.3, MP.L1-3.8.3
    MP-7Media UseMPMedia ProtectionCC6.7, PI1.5MP.L2-3.8.7, MP.L2-3.8.8
    PS-1Policy and ProceduresPSPersonnel SecurityCC1.1, CC1.4, CC5.3AC.L1-3.1.22
    PS-4Personnel TerminationPSPersonnel SecurityCC1.5PS.L2-3.9.2
    PS-5Personnel TransferPSPersonnel SecurityCC1.5PS.L2-3.9.2
    PM-4Plan of Action and Milestones ProcessPMProgram ManagementCC4.2CA.L2-3.12.2, SI.L1-3.14.1
    PM-14Testing, Training, and MonitoringPMProgram ManagementCC1.1, CC2.2, CC2.3CA.L2-3.12.1, CA.L2-3.12.3
    PM-15Security and Privacy Groups and AssociationsPMProgram ManagementCC2.3, CC3.3, CC9.1CA.L2-3.12.3, SI.L2-3.14.3
    PM-16Threat Awareness ProgramPMProgram ManagementCC3.3, CC9.1CA.L2-3.12.3, SI.L2-3.14.3
    PM-31Continuous Monitoring StrategyPMProgram ManagementCC7.2AU.L2-3.3.3, SI.L2-3.14.6
    PT-1Policy and ProceduresPTPII Processing and TransparencyCC2.2, CC3.2, CC5.1, CC5.2, CC5.3SC.L2-3.13.2
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementCC3.3, CC5.3, CC9.1, CC9.2AC.L1-3.1.1
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk ManagementCC9.1AC.L1-3.1.1
    SR-12Component DisposalSRSupply Chain Risk ManagementCC6.5MP.L1-3.8.3

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.