Skip to content

    SOC 2 Type II to HITRUST CSF v11 control mapping

    SOC 2 Type II and HITRUST CSF v11 both map to 81 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    81
    SOC 2 Type II controls involved
    46
    HITRUST CSF v11 controls involved
    78
    NIST 800-53 families touched
    17

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored SOC 2 Type II to HITRUST CSF v11 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both SOC 2 Type II and HITRUST CSF v11, with the controls on each side that map to them.
    NIST 800-53 controlFamilySOC 2 Type II controlsHITRUST CSF v11 controls
    AC-1Policy and ProceduresACAccess ControlCC5.3, CC6.1, CC6.6HITRUST-01.c
    AC-2Account ManagementACAccess ControlCC6.1, CC6.6HITRUST-01.d, HITRUST-01.h, HITRUST-01.p
    AC-3Access EnforcementACAccess ControlCC6.1, CC6.6HITRUST-01.c, HITRUST-01.i, HITRUST-01.p
    AC-4Information Flow EnforcementACAccess ControlCC6.1, CC6.6HITRUST-01.c
    AC-5Separation of DutiesACAccess ControlCC5.1, CC6.6HITRUST-01.h, HITRUST-01.j, HITRUST-09.c
    AC-6Least PrivilegeACAccess ControlCC6.1HITRUST-01.i, HITRUST-01.j
    AC-17Remote AccessACAccess ControlCC6.6HITRUST-01.c, HITRUST-01.n, HITRUST-01.o, HITRUST-01.r
    AC-20Use of External SystemsACAccess ControlCC6.7HITRUST-01.n, HITRUST-01.r
    AU-1Policy and ProceduresAUAudit and AccountabilityCC5.3, CC7.2HITRUST-09.aa
    AU-2Event LoggingAUAudit and AccountabilityCC7.2, CC7.3HITRUST-09.aa
    AU-3Content of Audit RecordsAUAudit and AccountabilityPI1.4HITRUST-09.aa
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and AccountabilityCC7.2, CC7.3HITRUST-09.aa
    AU-9Protection of Audit InformationAUAudit and AccountabilityPI1.4, PI1.5HITRUST-09.aa
    AU-11Audit Record RetentionAUAudit and AccountabilityC1.2HITRUST-09.ab
    AU-12Audit Record GenerationAUAudit and AccountabilityCC7.2, CC7.3HITRUST-09.aa
    CM-1Policy and ProceduresCMConfiguration ManagementCC5.3, CC7.1HITRUST-09.a
    CM-2Baseline ConfigurationCMConfiguration ManagementCC7.1, CC8.1HITRUST-06.d, HITRUST-10.h
    CM-3Configuration Change ControlCMConfiguration ManagementCC3.4, CC8.1HITRUST-06.d, HITRUST-09.b, HITRUST-10.i
    CM-4Impact AnalysesCMConfiguration ManagementCC3.4HITRUST-09.d
    CM-6Configuration SettingsCMConfiguration ManagementCC7.1, CC8.1HITRUST-06.d, HITRUST-10.h
    CP-1Policy and ProceduresCPContingency PlanningA1.2, CC5.3, CC7.5, CC9.1HITRUST-12.a
    CP-2Contingency PlanCPContingency PlanningA1.2, CC7.5, CC9.1HITRUST-12.a, HITRUST-12.b
    CP-4Contingency Plan TestingCPContingency PlanningA1.3, CC7.5HITRUST-12.a
    CP-6Alternate Storage SiteCPContingency PlanningA1.2HITRUST-12.b, HITRUST-12.c
    CP-7Alternate Processing SiteCPContingency PlanningA1.2HITRUST-12.c
    CP-9System BackupCPContingency PlanningA1.2, CC7.5HITRUST-12.a
    CP-10System Recovery and ReconstitutionCPContingency PlanningA1.2, CC7.5, CC9.1HITRUST-12.a
    IA-1Policy and ProceduresIAIdentification and AuthenticationCC5.3, CC6.1, CC6.6HITRUST-01.d
    IA-2Identification and Authentication (Organizational Users)IAIdentification and AuthenticationCC6.1HITRUST-01.l, HITRUST-01.m
    IA-4Identifier ManagementIAIdentification and AuthenticationCC6.1, CC6.6HITRUST-01.d
    IA-5Authenticator ManagementIAIdentification and AuthenticationCC6.1HITRUST-01.d, HITRUST-01.k, HITRUST-01.l, HITRUST-01.t
    IA-8Identification and Authentication (Non-organizational Users)IAIdentification and AuthenticationCC6.1HITRUST-01.m
    IR-1Policy and ProceduresIRIncident ResponseCC5.3, CC7.3, CC7.4HITRUST-11.a, HITRUST-11.c
    IR-4Incident HandlingIRIncident ResponseCC7.3, CC7.4HITRUST-11.a, HITRUST-11.c
    IR-6Incident ReportingIRIncident ResponseCC2.3, CC7.4, P6.3, P6.7HITRUST-11.b, HITRUST-13.c
    IR-8Incident Response PlanIRIncident ResponseCC7.3, CC7.4HITRUST-11.a
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionA1.2, CC5.3, CC6.4HITRUST-08.e
    PE-3Physical Access ControlPEPhysical and Environmental ProtectionCC6.4HITRUST-08.a, HITRUST-08.e
    PE-9Power Equipment and CablingPEPhysical and Environmental ProtectionA1.2HITRUST-08.h
    PE-10Emergency ShutoffPEPhysical and Environmental ProtectionA1.2HITRUST-08.h
    PE-11Emergency PowerPEPhysical and Environmental ProtectionA1.2HITRUST-08.d
    PE-13Fire ProtectionPEPhysical and Environmental ProtectionA1.2HITRUST-08.c, HITRUST-08.d
    PE-14Environmental ControlsPEPhysical and Environmental ProtectionA1.2HITRUST-08.c, HITRUST-08.d
    PE-16Delivery and RemovalPEPhysical and Environmental ProtectionA1.2HITRUST-08.f
    PE-17Alternate Work SitePEPhysical and Environmental ProtectionA1.2HITRUST-08.f
    PE-18Location of System ComponentsPEPhysical and Environmental ProtectionA1.2HITRUST-08.g
    PL-1Policy and ProceduresPLPlanningCC1.5, CC2.2, CC2.3, CC3.1, CC3.4, CC5.2, CC5.3, PI1.2, PI1.3HITRUST-01.a, HITRUST-01.b, HITRUST-01.e, HITRUST-01.g, HITRUST-04.b, HITRUST-09.a, HITRUST-10.a
    PL-2System Security and Privacy PlansPLPlanningCC2.1, CC4.1HITRUST-01.a
    PL-4Rules of BehaviorPLPlanningCC1.1HITRUST-04.b
    RA-1Policy and ProceduresRARisk AssessmentCC3.1, CC4.1, CC5.1, CC5.3, CC9.1HITRUST-03.a
    RA-2Security CategorizationRARisk AssessmentCC3.2HITRUST-03.a
    RA-3Risk AssessmentRARisk AssessmentA1.2, CC4.1, CC7.3HITRUST-03.a, HITRUST-03.b, HITRUST-03.c, HITRUST-05.j
    RA-5Vulnerability Monitoring and ScanningRARisk AssessmentCC7.1HITRUST-10.m
    SA-3System Development Life CycleSASystem and Services AcquisitionCC5.2, CC8.1HITRUST-10.a
    SA-4Acquisition ProcessSASystem and Services AcquisitionCC3.3, CC3.4, CC5.2, CC9.1, CC9.2, P6.4, PI1.2, PI1.3HITRUST-05.a, HITRUST-05.b, HITRUST-05.c, HITRUST-05.i, HITRUST-05.k, HITRUST-09.e
    SA-9External System ServicesSASystem and Services AcquisitionCC3.3, P6.4HITRUST-05.a, HITRUST-05.i, HITRUST-05.j, HITRUST-09.e
    SC-5Denial-of-service ProtectionSCSystem and Communications ProtectionA1.1HITRUST-09.m
    SC-7Boundary ProtectionSCSystem and Communications ProtectionCC6.1, CC6.6, CC6.8HITRUST-09.m, HITRUST-09.n, HITRUST-09.q
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications ProtectionCC6.1, CC6.7HITRUST-09.m, HITRUST-09.n, HITRUST-09.o
    SC-12Cryptographic Key Establishment and ManagementSCSystem and Communications ProtectionCC6.1HITRUST-09.s
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7HITRUST-09.r, HITRUST-09.s, HITRUST-13.d
    SC-17Public Key Infrastructure CertificatesSCSystem and Communications ProtectionCC6.1HITRUST-09.r
    SC-28Protection of Information at RestSCSystem and Communications ProtectionCC6.1, CC6.7HITRUST-09.v, HITRUST-13.d
    SI-3Malicious Code ProtectionSISystem and Information IntegrityCC6.6, CC6.8HITRUST-06.e, HITRUST-06.f
    SI-4System MonitoringSISystem and Information IntegrityCC6.6, CC7.2, CC7.3HITRUST-06.f, HITRUST-09.p, HITRUST-10.l
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information IntegrityCC6.6HITRUST-10.m
    SI-10Information Input ValidationSISystem and Information IntegrityCC6.6HITRUST-10.b, HITRUST-10.c, HITRUST-10.d
    SI-12Information Management and RetentionSISystem and Information IntegrityC1.2, CC6.5, P4.2, P4.3, PI1.5HITRUST-13.b
    MP-1Policy and ProceduresMPMedia ProtectionC1.1, CC2.1, CC5.3, CC6.5, CC6.7, PI1.5HITRUST-07.a
    MP-2Media AccessMPMedia ProtectionC1.1HITRUST-07.a
    MP-6Media SanitizationMPMedia ProtectionCC6.5, P4.3HITRUST-07.b, HITRUST-07.c
    PS-1Policy and ProceduresPSPersonnel SecurityCC1.1, CC1.4, CC5.3HITRUST-02.a
    PS-4Personnel TerminationPSPersonnel SecurityCC1.5HITRUST-02.e, HITRUST-02.f, HITRUST-02.g
    PS-5Personnel TransferPSPersonnel SecurityCC1.5HITRUST-02.e, HITRUST-02.f
    PM-1Information Security Program PlanPMProgram ManagementCC1.1, CC1.2, CC5.3HITRUST-04.a
    PM-2Information Security Program Leadership RolePMProgram ManagementCC1.1, CC1.3HITRUST-01.e
    PM-9Risk Management StrategyPMProgram ManagementCC3.1, CC4.1, CC5.1, CC9.1HITRUST-04.a, HITRUST-05.b
    PT-1Policy and ProceduresPTPII Processing and TransparencyCC2.2, CC3.2, CC5.1, CC5.2, CC5.3HITRUST-13.a
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and TransparencyP3.1, P4.1HITRUST-13.a
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and TransparencyP4.1HITRUST-13.a, HITRUST-13.b
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementCC3.3, CC5.3, CC9.1, CC9.2HITRUST-05.k

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.