Skip to content

    SOC 2 Type II to NIST AI RMF 1.0 control mapping

    SOC 2 Type II and NIST AI RMF 1.0 both map to 76 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    76
    SOC 2 Type II controls involved
    42
    NIST AI RMF 1.0 controls involved
    43
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored SOC 2 Type II to NIST AI RMF 1.0 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both SOC 2 Type II and NIST AI RMF 1.0, with the controls on each side that map to them.
    NIST 800-53 controlFamilySOC 2 Type II controlsNIST AI RMF 1.0 controls
    AC-1Policy and ProceduresACAccess ControlCC5.3, CC6.1, CC6.6GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    AC-23Data Mining ProtectionACAccess ControlP4.1MAP 1.6
    AT-1Policy and ProceduresATAwareness and TrainingCC1.4, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    AU-1Policy and ProceduresAUAudit and AccountabilityCC5.3, CC7.2GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    CA-1Policy and ProceduresCAAssessment, Authorization, and MonitoringCC4.1, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 4.3, GOVERN 5.1, GOVERN 6.1, MANAGE 1.1, MAP 3.5
    CA-2Control AssessmentsCAAssessment, Authorization, and MonitoringCC3.1, CC4.1, CC5.2GOVERN 1.5
    CA-2(2)Specialized AssessmentsCAAssessment, Authorization, and MonitoringCC4.1MAP 2.3, MEASURE 3.1, MEASURE 3.2
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and MonitoringCC4.2MANAGE 1.1, MANAGE 1.2, MANAGE 1.3, MANAGE 1.4, MANAGE 3.1, MEASURE 3.1, MEASURE 3.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3GOVERN 1.5
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3GOVERN 1.5
    CM-1Policy and ProceduresCMConfiguration ManagementCC5.3, CC7.1GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    CP-1Policy and ProceduresCPContingency PlanningA1.2, CC5.3, CC7.5, CC9.1GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, GOVERN 6.2, MAP 3.5
    CP-2Contingency PlanCPContingency PlanningA1.2, CC7.5, CC9.1GOVERN 6.2
    CP-2(8)Identify Critical AssetsCPContingency PlanningCC7.5GOVERN 1.6
    CP-10System Recovery and ReconstitutionCPContingency PlanningA1.2, CC7.5, CC9.1GOVERN 6.2
    IA-1Policy and ProceduresIAIdentification and AuthenticationCC5.3, CC6.1, CC6.6GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    IR-1Policy and ProceduresIRIncident ResponseCC5.3, CC7.3, CC7.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, GOVERN 6.2, MANAGE 2.3, MANAGE 2.4, MAP 3.5
    IR-4Incident HandlingIRIncident ResponseCC7.3, CC7.4GOVERN 6.2, MANAGE 2.3, MANAGE 2.4
    IR-4(3)Continuity of OperationsIRIncident ResponseA1.2, CC7.5, CC9.1GOVERN 6.2
    IR-6Incident ReportingIRIncident ResponseCC2.3, CC7.4, P6.3, P6.7MANAGE 4.3
    IR-8Incident Response PlanIRIncident ResponseCC7.3, CC7.4GOVERN 6.2
    MA-1Policy and ProceduresMAMaintenanceCC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionA1.2, CC5.3, CC6.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PL-1Policy and ProceduresPLPlanningCC1.5, CC2.2, CC2.3, CC3.1, CC3.4, CC5.2, CC5.3, PI1.2, PI1.3GOVERN 1.1, GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.1, GOVERN 3.2, GOVERN 4.1, GOVERN 4.2, GOVERN 5.1, GOVERN 6.1, MANAGE 2.1, MANAGE 2.2, MAP 3.5
    PL-4Rules of BehaviorPLPlanningCC1.1GOVERN 4.1
    PL-9Central ManagementPLPlanningCC1.1, CC1.3, CC5.1GOVERN 1.2, GOVERN 1.3, GOVERN 2.1, GOVERN 2.3
    RA-1Policy and ProceduresRARisk AssessmentCC3.1, CC4.1, CC5.1, CC5.3, CC9.1GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 1.5, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    RA-3Risk AssessmentRARisk AssessmentA1.2, CC4.1, CC7.3GOVERN 1.5
    RA-3(1)Supply Chain Risk AssessmentRARisk AssessmentCC9.2MANAGE 3.1
    RA-8Privacy Impact AssessmentsRARisk AssessmentCC3.2, CC5.2, PI1.1MAP 1.1, MEASURE 2.10
    RA-9Criticality AnalysisRARisk AssessmentCC2.2, CC4.1, CC5.2, CC9.1, PI1.1MAP 1.6
    SA-1Policy and ProceduresSASystem and Services AcquisitionCC5.2, CC5.3, P6.4, PI1.1, PI1.2, PI1.3, PI1.4, PI1.5GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.1, GOVERN 3.2, GOVERN 4.1, GOVERN 4.2, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SA-2Allocation of ResourcesSASystem and Services AcquisitionCC1.4, CC4.1MANAGE 2.1
    SA-3System Development Life CycleSASystem and Services AcquisitionCC5.2, CC8.1GOVERN 1.7, MANAGE 2.2
    SA-3(1)Manage Preproduction EnvironmentSASystem and Services AcquisitionCC5.2, CC8.1GOVERN 1.7, MANAGE 2.2
    SA-4Acquisition ProcessSASystem and Services AcquisitionCC3.3, CC3.4, CC5.2, CC9.1, CC9.2, P6.4, PI1.2, PI1.3GOVERN 1.2, GOVERN 3.1, GOVERN 4.2
    SA-4(3)Development Methods, Techniques, and PracticesSASystem and Services AcquisitionPI1.1, PI1.2, PI1.3, PI1.4, PI1.5GOVERN 4.1, GOVERN 4.2
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services AcquisitionCC2.2, CC3.2, CC5.1, CC5.2, CC7.1, CC8.1GOVERN 1.2
    SA-8(30)Procedural RigorSASystem and Services AcquisitionCC5.2, CC8.1GOVERN 1.7, MANAGE 2.2
    SA-8(32)Sufficient DocumentationSASystem and Services AcquisitionCC2.2, CC5.1, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SA-9(1)Risk Assessments and Organizational ApprovalsSASystem and Services AcquisitionCC3.4, CC9.2MANAGE 3.1
    SA-11(5)Penetration TestingSASystem and Services AcquisitionCC4.1, CC4.2MAP 2.3, MEASURE 3.1, MEASURE 3.2
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services AcquisitionCC4.2MANAGE 1.1, MANAGE 1.2, MANAGE 1.3, MANAGE 1.4, MANAGE 3.1, MEASURE 3.1, MEASURE 3.2
    SA-15(5)Attack Surface ReductionSASystem and Services AcquisitionCC2.2, CC3.2, CC5.1, CC5.2, CC7.1, CC8.1GOVERN 1.2
    SA-23SpecializationSASystem and Services AcquisitionCC5.2, PI1.2, PI1.3GOVERN 1.2, GOVERN 3.1, GOVERN 4.1, GOVERN 4.2, GOVERN 5.1, GOVERN 5.2, MANAGE 2.2, MAP 2.1
    SC-1Policy and ProceduresSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2, CC5.3, CC6.1, CC6.6GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SC-7(18)Fail SecureSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2GOVERN 1.2
    SC-38Operations SecuritySCSystem and Communications ProtectionCC2.2GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SI-1Policy and ProceduresSISystem and Information IntegrityCC2.2, CC3.2, CC5.1, CC5.2, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    MP-1Policy and ProceduresMPMedia ProtectionC1.1, CC2.1, CC5.3, CC6.5, CC6.7, PI1.5GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PS-1Policy and ProceduresPSPersonnel SecurityCC1.1, CC1.4, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PS-2Position Risk DesignationPSPersonnel SecurityCC1.2, CC1.3, CC1.5, CC5.3GOVERN 4.1, MAP 1.2, MAP 3.4
    PS-9Position DescriptionsPSPersonnel SecurityCC1.2, CC1.3, CC2.2GOVERN 2.1
    PM-1Information Security Program PlanPMProgram ManagementCC1.1, CC1.2, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PM-2Information Security Program Leadership RolePMProgram ManagementCC1.1, CC1.3GOVERN 1.3, GOVERN 2.1, GOVERN 2.3
    PM-3Information Security and Privacy ResourcesPMProgram ManagementCC1.4MANAGE 2.1
    PM-4Plan of Action and Milestones ProcessPMProgram ManagementCC4.2MANAGE 1.1, MANAGE 1.2, MANAGE 1.3, MANAGE 1.4, MANAGE 3.1, MEASURE 3.1, MEASURE 3.2
    PM-6Measures of PerformancePMProgram ManagementCC1.1, CC1.2, CC1.3, CC1.5, CC2.2, CC4.1GOVERN 1.3, GOVERN 1.5, GOVERN 2.1, GOVERN 2.3, MAP 5.2, MEASURE 1.1, MEASURE 1.2, MEASURE 4.3
    PM-8Critical Infrastructure PlanPMProgram ManagementA1.2, CC1.5, CC2.2, CC2.3, CC7.5, CC9.1GOVERN 1.1, GOVERN 6.2
    PM-9Risk Management StrategyPMProgram ManagementCC3.1, CC4.1, CC5.1, CC9.1GOVERN 1.3, GOVERN 1.4, GOVERN 1.5
    PM-10Authorization ProcessPMProgram ManagementCC4.1GOVERN 4.3, MANAGE 1.1
    PM-11Mission and Business Process DefinitionPMProgram ManagementCC1.3, CC3.1, CC3.4, CC4.1, CC5.1, CC5.2, PI1.1MAP 1.1, MAP 1.4, MAP 2.1
    PM-13Security and Privacy WorkforcePMProgram ManagementCC1.2, CC1.3, CC1.4, CC2.2GOVERN 2.1, GOVERN 4.1
    PM-14Testing, Training, and MonitoringPMProgram ManagementCC1.1, CC2.2, CC2.3GOVERN 1.5
    PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and ResearchPMProgram ManagementP4.1MAP 1.6
    PM-28Risk FramingPMProgram ManagementCC3.2GOVERN 1.3, GOVERN 1.4
    PM-29Risk Management Program Leadership RolesPMProgram ManagementCC1.1, CC1.3, CC3.1, CC3.2, CC4.1, CC5.1, CC9.1, CC9.2GOVERN 1.3, GOVERN 1.4, GOVERN 1.5, GOVERN 2.1, GOVERN 2.3
    PT-1Policy and ProceduresPTPII Processing and TransparencyCC2.2, CC3.2, CC5.1, CC5.2, CC5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 1.6, MAP 3.5
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and TransparencyP3.1, P4.1MAP 1.6
    PT-7Specific Categories of Personally Identifiable InformationPTPII Processing and TransparencyP4.1MAP 1.6
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementCC3.3, CC5.3, CC9.1, CC9.2GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SR-3(1)Diverse Supply BaseSRSupply Chain Risk ManagementCC3.3, CC9.1GOVERN 4.1, GOVERN 4.2
    SR-6Supplier Assessments and ReviewsSRSupply Chain Risk ManagementCC3.4, CC9.1MANAGE 3.1
    SR-6(1)Testing and AnalysisSRSupply Chain Risk ManagementCC3.4, CC9.1MANAGE 3.1
    SR-7Supply Chain Operations SecuritySRSupply Chain Risk ManagementCC2.2, CC3.1, CC3.2, CC4.1, CC9.2GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SR-12Component DisposalSRSupply Chain Risk ManagementCC6.5GOVERN 1.7

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.