Skip to content

    SOC 2 Type II to GDPR control mapping

    SOC 2 Type II and GDPR both map to 55 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    55
    SOC 2 Type II controls involved
    52
    GDPR controls involved
    53
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored SOC 2 Type II to GDPR crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both SOC 2 Type II and GDPR, with the controls on each side that map to them.
    NIST 800-53 controlFamilySOC 2 Type II controlsGDPR controls
    AC-1Policy and ProceduresACAccess ControlCC5.3, CC6.1, CC6.6Art 24.2
    AC-2(7)Privileged User AccountsACAccess ControlCC6.1, CC6.3Art 32.4
    AC-3(14)Individual AccessACAccess ControlP5.1Art 12.3, Art 12.5, Art 12.6, Art 15.1, Art 15.2, Art 15.3, Art 15.4, Art 16, Art 17.1, Art 18.1
    AC-4(25)Data SanitizationACAccess ControlC1.2, CC6.5, P4.2, P4.3Art 5.1
    AT-1Policy and ProceduresATAwareness and TrainingCC1.4, CC5.3Art 24.2
    AU-1Policy and ProceduresAUAudit and AccountabilityCC5.3, CC7.2Art 24.2
    CA-1Policy and ProceduresCAAssessment, Authorization, and MonitoringCC4.1, CC5.3Art 24.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3Art 32.1
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3Art 32.1
    CM-1Policy and ProceduresCMConfiguration ManagementCC5.3, CC7.1Art 24.2
    CP-1Policy and ProceduresCPContingency PlanningA1.2, CC5.3, CC7.5, CC9.1Art 24.2, Art 32.1
    CP-2Contingency PlanCPContingency PlanningA1.2, CC7.5, CC9.1Art 32.1
    CP-10System Recovery and ReconstitutionCPContingency PlanningA1.2, CC7.5, CC9.1Art 32.1
    IA-1Policy and ProceduresIAIdentification and AuthenticationCC5.3, CC6.1, CC6.6Art 24.2
    IR-1Policy and ProceduresIRIncident ResponseCC5.3, CC7.3, CC7.4Art 24.2
    IR-4(3)Continuity of OperationsIRIncident ResponseA1.2, CC7.5, CC9.1Art 32.1
    IR-5Incident MonitoringIRIncident ResponseCC7.4Art 33.5
    IR-6Incident ReportingIRIncident ResponseCC2.3, CC7.4, P6.3, P6.7Art 34.1, Art 34.2
    IR-8(1)BreachesIRIncident ResponseCC7.3, P6.3, P6.6, P6.7Art 33.1
    MA-1Policy and ProceduresMAMaintenanceCC5.3Art 24.2
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionA1.2, CC5.3, CC6.4Art 24.2
    PL-1Policy and ProceduresPLPlanningCC1.5, CC2.2, CC2.3, CC3.1, CC3.4, CC5.2, CC5.3, PI1.2, PI1.3Art 24.2
    RA-1Policy and ProceduresRARisk AssessmentCC3.1, CC4.1, CC5.1, CC5.3, CC9.1Art 24.2, Art 32.2
    RA-8Privacy Impact AssessmentsRARisk AssessmentCC3.2, CC5.2, PI1.1Art 35.1, Art 35.11, Art 35.3, Art 35.7, Art 35.8, Art 35.9, Art 36.1
    SA-1Policy and ProceduresSASystem and Services AcquisitionCC5.2, CC5.3, P6.4, PI1.1, PI1.2, PI1.3, PI1.4, PI1.5Art 24.2
    SC-1Policy and ProceduresSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2, CC5.3, CC6.1, CC6.6Art 24.2
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7Art 32.1
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionCC6.1, CC6.7Art 32.1
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7Art 32.1
    SI-1Policy and ProceduresSISystem and Information IntegrityCC2.2, CC3.2, CC5.1, CC5.2, CC5.3Art 24.2
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegrityCC6.1Art 32.1
    SI-12Information Management and RetentionSISystem and Information IntegrityC1.2, CC6.5, P4.2, P4.3, PI1.5Art 5.1
    SI-12(3)Information DisposalSISystem and Information IntegrityC1.2, CC6.5, P4.2, P4.3Art 5.1
    SI-18(4)Individual RequestsSISystem and Information IntegrityP5.1, P5.2Art 12.3, Art 12.5, Art 12.6, Art 15.1, Art 15.2, Art 15.3, Art 15.4, Art 16, Art 17.1, Art 18.1
    MP-1Policy and ProceduresMPMedia ProtectionC1.1, CC2.1, CC5.3, CC6.5, CC6.7, PI1.5Art 24.2
    PS-1Policy and ProceduresPSPersonnel SecurityCC1.1, CC1.4, CC5.3Art 24.2
    PS-2Position Risk DesignationPSPersonnel SecurityCC1.2, CC1.3, CC1.5, CC5.3Art 32.4
    PS-9Position DescriptionsPSPersonnel SecurityCC1.2, CC1.3, CC2.2Art 32.4
    PM-1Information Security Program PlanPMProgram ManagementCC1.1, CC1.2, CC5.3Art 24.2
    PM-8Critical Infrastructure PlanPMProgram ManagementA1.2, CC1.5, CC2.2, CC2.3, CC7.5, CC9.1Art 32.1
    PM-9Risk Management StrategyPMProgram ManagementCC3.1, CC4.1, CC5.1, CC9.1Art 32.2
    PM-13Security and Privacy WorkforcePMProgram ManagementCC1.2, CC1.3, CC1.4, CC2.2Art 32.4
    PM-14Testing, Training, and MonitoringPMProgram ManagementCC1.1, CC2.2, CC2.3Art 32.1
    PM-20(1)Privacy Policies on Websites, Applications, and Digital ServicesPMProgram ManagementP1.1Art 12.7, Art 13.1, Art 13.2, Art 13.3, Art 14.1, Art 14.2, Art 14.3, Art 14.4, Art 14.5
    PM-24Data Integrity BoardPMProgram ManagementP7.1Art 5.1
    PM-26Complaint ManagementPMProgram ManagementP5.1, P5.2, P8.1Art 12.4
    PM-27Privacy ReportingPMProgram ManagementCC2.3Art 30.1, Art 30.2, Art 30.3
    PM-29Risk Management Program Leadership RolesPMProgram ManagementCC1.1, CC1.3, CC3.1, CC3.2, CC4.1, CC5.1, CC9.1, CC9.2Art 32.2
    PT-1Policy and ProceduresPTPII Processing and TransparencyCC2.2, CC3.2, CC5.1, CC5.2, CC5.3Art 12.2, Art 24.2, Art 5.1, Art 9.1
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and TransparencyP3.1, P4.1Art 10, Art 5.1, Art 8.1, Art 9.2, Art 9.3
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and TransparencyP4.1Art 13.1, Art 14.1
    PT-4ConsentPTPII Processing and TransparencyP2.1, P3.2Art 21.1, Art 21.2, Art 21.3, Art 21.4, Art 21.5, Art 21.6, Art 7.1, Art 7.2, Art 9.2
    PT-5Privacy NoticePTPII Processing and TransparencyP1.1Art 12.7, Art 13.1, Art 13.2, Art 13.3, Art 14.1, Art 14.2, Art 14.3, Art 14.4, Art 14.5
    PT-7Specific Categories of Personally Identifiable InformationPTPII Processing and TransparencyP4.1Art 13.1, Art 14.1
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementCC3.3, CC5.3, CC9.1, CC9.2Art 24.2

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.