Subcontractor CMMC Tracker

Does SOC 2 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement

Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 52 are reuse candidates at high confidence, requirements SOC 2 may supply evidence toward, and 24 more at medium confidence; 34 have no candidate and need CMMC-specific evidence. A reuse candidate means a SOC 2 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.

reuse candidate, high 52reuse candidate, medium 24no candidate, CMMC-specific evidence needed 34

The 110, one by one

SOC 2
RequirementReuseSOC 2 requirements that may supply evidence
Access Control
AC.L2-3.1.1 Authorized Access Controlreuse candidate (high)SOC2-CC6.1, SOC2-CC6.2
AC.L2-3.1.10 Session Lockno candidate: CMMC-specific evidence
AC.L2-3.1.11 Session Terminationno candidate: CMMC-specific evidence
AC.L2-3.1.12 Control Remote Accessreuse candidate (high)SOC2-CC6.6, SOC2-CC6.6
AC.L2-3.1.13 Remote Access Confidentialityreuse candidate (high)SOC2-CC6.6, SOC2-CC6.7
AC.L2-3.1.14 Remote Access Routingno candidate: CMMC-specific evidence
AC.L2-3.1.15 Privileged Remote Accessno candidate: CMMC-specific evidence
AC.L2-3.1.16 Wireless Access Authorizationno candidate: CMMC-specific evidence
AC.L2-3.1.17 Wireless Access Protectionno candidate: CMMC-specific evidence
AC.L2-3.1.18 Mobile Device Connectionno candidate: CMMC-specific evidence
AC.L2-3.1.19 Encrypt CUI on Mobileno candidate: CMMC-specific evidence
AC.L2-3.1.2 Transaction & Function Controlreuse candidate (high)SOC2-CC6.1, SOC2-CC6.3
AC.L2-3.1.20 External Connectionsreuse candidate (high)SOC2-CC6.6, SOC2-CC9.2
AC.L2-3.1.21 Portable Storage Usereuse candidate (medium)SOC2-CC6.7
AC.L2-3.1.22 Control Public Informationreuse candidate (medium)SOC2-C1.1
AC.L2-3.1.3 Control CUI Flowreuse candidate (high)SOC2-CC6.7
AC.L2-3.1.4 Separation of Dutiesreuse candidate (high)SOC2-CC6.3
AC.L2-3.1.5 Least Privilegereuse candidate (high)SOC2-CC6.3
AC.L2-3.1.6 Non-Privileged Account Usereuse candidate (high)SOC2-CC6.3, SOC2-CC6.3
AC.L2-3.1.7 Privileged Functionsreuse candidate (medium)SOC2-CC6.3
AC.L2-3.1.8 Unsuccessful Logon Attemptsno candidate: CMMC-specific evidence
AC.L2-3.1.9 Privacy & Security Noticesreuse candidate (medium)SOC2-P1.1
Awareness and Training
AT.L2-3.2.1 Role-Based Risk Awarenessreuse candidate (high)SOC2-CC1.4, SOC2-CC2.2
AT.L2-3.2.2 Role-Based Trainingreuse candidate (high)SOC2-CC1.4, SOC2-CC1.4
AT.L2-3.2.3 Insider Threat Awarenessno candidate: CMMC-specific evidence
Audit and Accountability
AU.L2-3.3.1 System Auditingreuse candidate (high)SOC2-CC7.2, SOC2-CC2.1
AU.L2-3.3.2 User Accountabilityreuse candidate (medium)SOC2-CC6.2
AU.L2-3.3.3 Event Reviewreuse candidate (high)SOC2-CC7.2
AU.L2-3.3.4 Audit Failure Alertingno candidate: CMMC-specific evidence
AU.L2-3.3.5 Audit Correlationreuse candidate (high)SOC2-CC7.3, SOC2-CC7.2, SOC2-CC7.3
AU.L2-3.3.6 Reduction & Reportingreuse candidate (medium)SOC2-CC7.2
AU.L2-3.3.7 Time Stamps & Synchronizationno candidate: CMMC-specific evidence
AU.L2-3.3.8 Audit Protectionno candidate: CMMC-specific evidence
AU.L2-3.3.9 Audit Managementreuse candidate (medium)SOC2-CC6.3
Security Assessment
CA.L2-3.12.1 Security Control Assessmentreuse candidate (high)SOC2-CC4.1
CA.L2-3.12.2 Plan of Actionreuse candidate (high)SOC2-CC4.2
CA.L2-3.12.3 Security Control Monitoringreuse candidate (high)SOC2-CC4.1
CA.L2-3.12.4 System Security Planreuse candidate (medium)SOC2-CC5.3
Configuration Management
CM.L2-3.4.1 System Baseliningreuse candidate (high)SOC2-CC7.1
CM.L2-3.4.2 Security Configuration Enforcementreuse candidate (high)SOC2-CC7.1, SOC2-CC5.2
CM.L2-3.4.3 System Change Managementreuse candidate (high)SOC2-CC8.1
CM.L2-3.4.4 Security Impact Analysisreuse candidate (high)SOC2-CC3.4, SOC2-CC8.1
CM.L2-3.4.5 Access Restrictions for Changereuse candidate (high)SOC2-CC8.1, SOC2-CC6.3
CM.L2-3.4.6 Least Functionalityreuse candidate (medium)SOC2-CC6.1
CM.L2-3.4.7 Nonessential Functionalityno candidate: CMMC-specific evidence
CM.L2-3.4.8 Application Execution Policyreuse candidate (high)SOC2-CC6.8
CM.L2-3.4.9 User-Installed Softwarereuse candidate (high)SOC2-CC6.8
Identification and Authentication
IA.L2-3.5.1 Identificationreuse candidate (high)SOC2-CC6.2
IA.L2-3.5.10 Cryptographically-Protected Passwordsno candidate: CMMC-specific evidence
IA.L2-3.5.11 Obscure Feedbackno candidate: CMMC-specific evidence
IA.L2-3.5.2 Authenticationreuse candidate (high)SOC2-CC6.1
IA.L2-3.5.3 Multifactor Authenticationno candidate: CMMC-specific evidence
IA.L2-3.5.4 Replay-Resistant Authenticationno candidate: CMMC-specific evidence
IA.L2-3.5.5 Identifier Reusereuse candidate (medium)SOC2-CC6.2
IA.L2-3.5.6 Identifier Handlingreuse candidate (high)SOC2-CC6.2
IA.L2-3.5.7 Password Complexityno candidate: CMMC-specific evidence
IA.L2-3.5.8 Password Reuseno candidate: CMMC-specific evidence
IA.L2-3.5.9 Temporary Passwordsreuse candidate (medium)SOC2-CC6.2
Incident Response
IR.L2-3.6.1 Incident Handlingreuse candidate (high)SOC2-CC7.4, SOC2-CC7.3, SOC2-CC7.5
IR.L2-3.6.2 Incident Reportingreuse candidate (high)SOC2-CC7.4, SOC2-CC2.3
IR.L2-3.6.3 Incident Response Testingreuse candidate (medium)SOC2-A1.3
Maintenance
MA.L2-3.7.1 Perform Maintenanceno candidate: CMMC-specific evidence
MA.L2-3.7.2 System Maintenance Controlno candidate: CMMC-specific evidence
MA.L2-3.7.3 Equipment Sanitizationreuse candidate (high)SOC2-CC6.5
MA.L2-3.7.4 Media Inspectionreuse candidate (medium)SOC2-CC6.8
MA.L2-3.7.5 Nonlocal Maintenanceno candidate: CMMC-specific evidence
MA.L2-3.7.6 Maintenance Personnelreuse candidate (medium)SOC2-CC6.4
Media Protection
MP.L2-3.8.1 Media Protectionreuse candidate (high)SOC2-CC6.7, SOC2-C1.1
MP.L2-3.8.2 Media Accessreuse candidate (medium)SOC2-CC6.1
MP.L2-3.8.3 Media Disposalreuse candidate (high)SOC2-CC6.5, SOC2-C1.2, SOC2-P4.3
MP.L2-3.8.4 Media Markingsreuse candidate (high)SOC2-C1.1, SOC2-C1.1
MP.L2-3.8.5 Media Accountabilityreuse candidate (high)SOC2-CC6.7, SOC2-CC6.7
MP.L2-3.8.6 Portable Storage Encryptionreuse candidate (high)SOC2-CC6.7
MP.L2-3.8.7 Removable Mediareuse candidate (medium)SOC2-CC6.7
MP.L2-3.8.8 Shared Mediano candidate: CMMC-specific evidence
MP.L2-3.8.9 Protect Backupsreuse candidate (high)SOC2-A1.2, SOC2-A1.2
Physical Protection
PE.L2-3.10.1 Limit Physical Accessreuse candidate (high)SOC2-CC6.4
PE.L2-3.10.2 Monitor Facilityreuse candidate (medium)SOC2-CC6.4, SOC2-A1.2
PE.L2-3.10.3 Escort Visitorsreuse candidate (high)SOC2-CC6.4
PE.L2-3.10.4 Physical Access Logsreuse candidate (medium)SOC2-CC6.4
PE.L2-3.10.5 Manage Physical Accessreuse candidate (high)SOC2-CC6.4
PE.L2-3.10.6 Alternative Work Sitesno candidate: CMMC-specific evidence
Personnel Security
PS.L2-3.9.1 Screen Individualsreuse candidate (high)SOC2-CC1.4, SOC2-CC1.4
PS.L2-3.9.2 Personnel Actionsreuse candidate (high)SOC2-CC6.3, SOC2-CC6.2
Risk Assessment
RA.L2-3.11.1 Risk Assessmentsreuse candidate (high)SOC2-CC3.2, SOC2-CC9.1
RA.L2-3.11.2 Vulnerability Scanreuse candidate (high)SOC2-CC7.1
RA.L2-3.11.3 Vulnerability Remediationreuse candidate (medium)SOC2-CC7.1
System and Communications Protection
SC.L2-3.13.1 Boundary Protectionreuse candidate (high)SOC2-CC6.6
SC.L2-3.13.10 Key Managementno candidate: CMMC-specific evidence
SC.L2-3.13.11 CUI Encryptionno candidate: CMMC-specific evidence
SC.L2-3.13.12 Collaborative Device Controlno candidate: CMMC-specific evidence
SC.L2-3.13.13 Mobile Codeno candidate: CMMC-specific evidence
SC.L2-3.13.14 Voice over Internet Protocolno candidate: CMMC-specific evidence
SC.L2-3.13.15 Communications Authenticityno candidate: CMMC-specific evidence
SC.L2-3.13.16 Data at Restreuse candidate (high)SOC2-C1.1
SC.L2-3.13.2 Security Engineeringreuse candidate (medium)SOC2-CC6.1
SC.L2-3.13.3 Role Separationreuse candidate (medium)SOC2-CC6.3
SC.L2-3.13.4 Shared Resource Controlno candidate: CMMC-specific evidence
SC.L2-3.13.5 Public-Access System Separationreuse candidate (medium)SOC2-CC6.6
SC.L2-3.13.6 Network Communication by Exceptionreuse candidate (high)SOC2-CC6.6
SC.L2-3.13.7 Split Tunnelingno candidate: CMMC-specific evidence
SC.L2-3.13.8 Data in Transitreuse candidate (high)SOC2-CC6.7
SC.L2-3.13.9 Connections Terminationno candidate: CMMC-specific evidence
System and Information Integrity
SI.L2-3.14.1 Flaw Remediationreuse candidate (high)SOC2-CC8.1
SI.L2-3.14.2 Malicious Code Protectionreuse candidate (high)SOC2-CC6.8
SI.L2-3.14.3 Security Alerts & Advisoriesreuse candidate (medium)SOC2-CC7.1
SI.L2-3.14.4 Update Malicious Code Protectionreuse candidate (medium)SOC2-CC6.8
SI.L2-3.14.5 System & File Scanningreuse candidate (high)SOC2-CC6.8, SOC2-CC6.8
SI.L2-3.14.6 Monitor Communications for Attacksreuse candidate (high)SOC2-CC7.2
SI.L2-3.14.7 Identify Unauthorized Usereuse candidate (high)SOC2-CC7.2, SOC2-CC7.2

A subcontractor that ticks SOC 2 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; SOC 2 itself: SOC 2.