Does SOC 2 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement
Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 52 are reuse candidates at high confidence, requirements SOC 2 may supply evidence toward, and 24 more at medium confidence; 34 have no candidate and need CMMC-specific evidence. A reuse candidate means a SOC 2 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.
The 110, one by one
SOC 2| Requirement | Reuse | SOC 2 requirements that may supply evidence |
|---|---|---|
| Access Control | ||
| AC.L2-3.1.1 Authorized Access Control | reuse candidate (high) | SOC2-CC6.1, SOC2-CC6.2 |
| AC.L2-3.1.10 Session Lock | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.11 Session Termination | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.12 Control Remote Access | reuse candidate (high) | SOC2-CC6.6, SOC2-CC6.6 |
| AC.L2-3.1.13 Remote Access Confidentiality | reuse candidate (high) | SOC2-CC6.6, SOC2-CC6.7 |
| AC.L2-3.1.14 Remote Access Routing | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.15 Privileged Remote Access | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.16 Wireless Access Authorization | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.17 Wireless Access Protection | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.18 Mobile Device Connection | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.19 Encrypt CUI on Mobile | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.2 Transaction & Function Control | reuse candidate (high) | SOC2-CC6.1, SOC2-CC6.3 |
| AC.L2-3.1.20 External Connections | reuse candidate (high) | SOC2-CC6.6, SOC2-CC9.2 |
| AC.L2-3.1.21 Portable Storage Use | reuse candidate (medium) | SOC2-CC6.7 |
| AC.L2-3.1.22 Control Public Information | reuse candidate (medium) | SOC2-C1.1 |
| AC.L2-3.1.3 Control CUI Flow | reuse candidate (high) | SOC2-CC6.7 |
| AC.L2-3.1.4 Separation of Duties | reuse candidate (high) | SOC2-CC6.3 |
| AC.L2-3.1.5 Least Privilege | reuse candidate (high) | SOC2-CC6.3 |
| AC.L2-3.1.6 Non-Privileged Account Use | reuse candidate (high) | SOC2-CC6.3, SOC2-CC6.3 |
| AC.L2-3.1.7 Privileged Functions | reuse candidate (medium) | SOC2-CC6.3 |
| AC.L2-3.1.8 Unsuccessful Logon Attempts | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.9 Privacy & Security Notices | reuse candidate (medium) | SOC2-P1.1 |
| Awareness and Training | ||
| AT.L2-3.2.1 Role-Based Risk Awareness | reuse candidate (high) | SOC2-CC1.4, SOC2-CC2.2 |
| AT.L2-3.2.2 Role-Based Training | reuse candidate (high) | SOC2-CC1.4, SOC2-CC1.4 |
| AT.L2-3.2.3 Insider Threat Awareness | no candidate: CMMC-specific evidence | |
| Audit and Accountability | ||
| AU.L2-3.3.1 System Auditing | reuse candidate (high) | SOC2-CC7.2, SOC2-CC2.1 |
| AU.L2-3.3.2 User Accountability | reuse candidate (medium) | SOC2-CC6.2 |
| AU.L2-3.3.3 Event Review | reuse candidate (high) | SOC2-CC7.2 |
| AU.L2-3.3.4 Audit Failure Alerting | no candidate: CMMC-specific evidence | |
| AU.L2-3.3.5 Audit Correlation | reuse candidate (high) | SOC2-CC7.3, SOC2-CC7.2, SOC2-CC7.3 |
| AU.L2-3.3.6 Reduction & Reporting | reuse candidate (medium) | SOC2-CC7.2 |
| AU.L2-3.3.7 Time Stamps & Synchronization | no candidate: CMMC-specific evidence | |
| AU.L2-3.3.8 Audit Protection | no candidate: CMMC-specific evidence | |
| AU.L2-3.3.9 Audit Management | reuse candidate (medium) | SOC2-CC6.3 |
| Security Assessment | ||
| CA.L2-3.12.1 Security Control Assessment | reuse candidate (high) | SOC2-CC4.1 |
| CA.L2-3.12.2 Plan of Action | reuse candidate (high) | SOC2-CC4.2 |
| CA.L2-3.12.3 Security Control Monitoring | reuse candidate (high) | SOC2-CC4.1 |
| CA.L2-3.12.4 System Security Plan | reuse candidate (medium) | SOC2-CC5.3 |
| Configuration Management | ||
| CM.L2-3.4.1 System Baselining | reuse candidate (high) | SOC2-CC7.1 |
| CM.L2-3.4.2 Security Configuration Enforcement | reuse candidate (high) | SOC2-CC7.1, SOC2-CC5.2 |
| CM.L2-3.4.3 System Change Management | reuse candidate (high) | SOC2-CC8.1 |
| CM.L2-3.4.4 Security Impact Analysis | reuse candidate (high) | SOC2-CC3.4, SOC2-CC8.1 |
| CM.L2-3.4.5 Access Restrictions for Change | reuse candidate (high) | SOC2-CC8.1, SOC2-CC6.3 |
| CM.L2-3.4.6 Least Functionality | reuse candidate (medium) | SOC2-CC6.1 |
| CM.L2-3.4.7 Nonessential Functionality | no candidate: CMMC-specific evidence | |
| CM.L2-3.4.8 Application Execution Policy | reuse candidate (high) | SOC2-CC6.8 |
| CM.L2-3.4.9 User-Installed Software | reuse candidate (high) | SOC2-CC6.8 |
| Identification and Authentication | ||
| IA.L2-3.5.1 Identification | reuse candidate (high) | SOC2-CC6.2 |
| IA.L2-3.5.10 Cryptographically-Protected Passwords | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.11 Obscure Feedback | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.2 Authentication | reuse candidate (high) | SOC2-CC6.1 |
| IA.L2-3.5.3 Multifactor Authentication | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.4 Replay-Resistant Authentication | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.5 Identifier Reuse | reuse candidate (medium) | SOC2-CC6.2 |
| IA.L2-3.5.6 Identifier Handling | reuse candidate (high) | SOC2-CC6.2 |
| IA.L2-3.5.7 Password Complexity | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.8 Password Reuse | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.9 Temporary Passwords | reuse candidate (medium) | SOC2-CC6.2 |
| Incident Response | ||
| IR.L2-3.6.1 Incident Handling | reuse candidate (high) | SOC2-CC7.4, SOC2-CC7.3, SOC2-CC7.5 |
| IR.L2-3.6.2 Incident Reporting | reuse candidate (high) | SOC2-CC7.4, SOC2-CC2.3 |
| IR.L2-3.6.3 Incident Response Testing | reuse candidate (medium) | SOC2-A1.3 |
| Maintenance | ||
| MA.L2-3.7.1 Perform Maintenance | no candidate: CMMC-specific evidence | |
| MA.L2-3.7.2 System Maintenance Control | no candidate: CMMC-specific evidence | |
| MA.L2-3.7.3 Equipment Sanitization | reuse candidate (high) | SOC2-CC6.5 |
| MA.L2-3.7.4 Media Inspection | reuse candidate (medium) | SOC2-CC6.8 |
| MA.L2-3.7.5 Nonlocal Maintenance | no candidate: CMMC-specific evidence | |
| MA.L2-3.7.6 Maintenance Personnel | reuse candidate (medium) | SOC2-CC6.4 |
| Media Protection | ||
| MP.L2-3.8.1 Media Protection | reuse candidate (high) | SOC2-CC6.7, SOC2-C1.1 |
| MP.L2-3.8.2 Media Access | reuse candidate (medium) | SOC2-CC6.1 |
| MP.L2-3.8.3 Media Disposal | reuse candidate (high) | SOC2-CC6.5, SOC2-C1.2, SOC2-P4.3 |
| MP.L2-3.8.4 Media Markings | reuse candidate (high) | SOC2-C1.1, SOC2-C1.1 |
| MP.L2-3.8.5 Media Accountability | reuse candidate (high) | SOC2-CC6.7, SOC2-CC6.7 |
| MP.L2-3.8.6 Portable Storage Encryption | reuse candidate (high) | SOC2-CC6.7 |
| MP.L2-3.8.7 Removable Media | reuse candidate (medium) | SOC2-CC6.7 |
| MP.L2-3.8.8 Shared Media | no candidate: CMMC-specific evidence | |
| MP.L2-3.8.9 Protect Backups | reuse candidate (high) | SOC2-A1.2, SOC2-A1.2 |
| Physical Protection | ||
| PE.L2-3.10.1 Limit Physical Access | reuse candidate (high) | SOC2-CC6.4 |
| PE.L2-3.10.2 Monitor Facility | reuse candidate (medium) | SOC2-CC6.4, SOC2-A1.2 |
| PE.L2-3.10.3 Escort Visitors | reuse candidate (high) | SOC2-CC6.4 |
| PE.L2-3.10.4 Physical Access Logs | reuse candidate (medium) | SOC2-CC6.4 |
| PE.L2-3.10.5 Manage Physical Access | reuse candidate (high) | SOC2-CC6.4 |
| PE.L2-3.10.6 Alternative Work Sites | no candidate: CMMC-specific evidence | |
| Personnel Security | ||
| PS.L2-3.9.1 Screen Individuals | reuse candidate (high) | SOC2-CC1.4, SOC2-CC1.4 |
| PS.L2-3.9.2 Personnel Actions | reuse candidate (high) | SOC2-CC6.3, SOC2-CC6.2 |
| Risk Assessment | ||
| RA.L2-3.11.1 Risk Assessments | reuse candidate (high) | SOC2-CC3.2, SOC2-CC9.1 |
| RA.L2-3.11.2 Vulnerability Scan | reuse candidate (high) | SOC2-CC7.1 |
| RA.L2-3.11.3 Vulnerability Remediation | reuse candidate (medium) | SOC2-CC7.1 |
| System and Communications Protection | ||
| SC.L2-3.13.1 Boundary Protection | reuse candidate (high) | SOC2-CC6.6 |
| SC.L2-3.13.10 Key Management | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.11 CUI Encryption | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.12 Collaborative Device Control | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.13 Mobile Code | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.14 Voice over Internet Protocol | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.15 Communications Authenticity | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.16 Data at Rest | reuse candidate (high) | SOC2-C1.1 |
| SC.L2-3.13.2 Security Engineering | reuse candidate (medium) | SOC2-CC6.1 |
| SC.L2-3.13.3 Role Separation | reuse candidate (medium) | SOC2-CC6.3 |
| SC.L2-3.13.4 Shared Resource Control | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.5 Public-Access System Separation | reuse candidate (medium) | SOC2-CC6.6 |
| SC.L2-3.13.6 Network Communication by Exception | reuse candidate (high) | SOC2-CC6.6 |
| SC.L2-3.13.7 Split Tunneling | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.8 Data in Transit | reuse candidate (high) | SOC2-CC6.7 |
| SC.L2-3.13.9 Connections Termination | no candidate: CMMC-specific evidence | |
| System and Information Integrity | ||
| SI.L2-3.14.1 Flaw Remediation | reuse candidate (high) | SOC2-CC8.1 |
| SI.L2-3.14.2 Malicious Code Protection | reuse candidate (high) | SOC2-CC6.8 |
| SI.L2-3.14.3 Security Alerts & Advisories | reuse candidate (medium) | SOC2-CC7.1 |
| SI.L2-3.14.4 Update Malicious Code Protection | reuse candidate (medium) | SOC2-CC6.8 |
| SI.L2-3.14.5 System & File Scanning | reuse candidate (high) | SOC2-CC6.8, SOC2-CC6.8 |
| SI.L2-3.14.6 Monitor Communications for Attacks | reuse candidate (high) | SOC2-CC7.2 |
| SI.L2-3.14.7 Identify Unauthorized Use | reuse candidate (high) | SOC2-CC7.2, SOC2-CC7.2 |
A subcontractor that ticks SOC 2 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; SOC 2 itself: SOC 2.