Scrutineer · By framework
SOC 2 and ISO 27001 compliance software with mapping
Your US customers asked for a SOC 2 report and you have one. Now a European or global enterprise wants an ISO 27001 certificate, or the other way round, and nobody wants to run two compliance programs.
Scrutineer maps each control once to the Trust Services Criteria and to the 93 Annex A controls of ISO 27001:2022, keeps the Statement of Applicability, and tracks the management system work SOC 2 never asks for. Compliance software, not a certification.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with SOC 2 + ISO 27001
The AICPA mapping everyone cites predates ISO 27001:2022
The official crosswalk from the Trust Services Criteria to ISO 27001 is an AICPA spreadsheet published on May 4, 2018, for members only. A file from 2018 can only map the 2013 edition, with 114 Annex A controls in 14 domains. The 2022 edition has 93 controls in four themes, renumbered, with 11 that did not exist before, such as 5.23 cloud services, 5.7 threat intelligence and 8.28 secure coding. Any SOC 2 to ISO 27001 mapping that quotes 2022 control numbers was rebuilt by someone after the fact. Ask who built it.
SOC 2 gives you most of Annex A and very little of the management system
The control overlap is real: access, logging, change management, incident response, vendor review, encryption and backups line up closely. The gap sits in clauses 4 to 10, which SOC 2 never asks for. ISO 27001 requires a defined ISMS scope, a Statement of Applicability covering all 93 controls, measurable security objectives, an internal audit of the ISMS, a management review with set inputs, and nonconformity and corrective action records. A SOC 2 shop adding ISO 27001 mostly builds paperwork and governance, not new controls.
A certificate and an attestation are tested differently, so evidence has to serve both
ISO 27001 ends in a three-year certificate from an accredited certification body, with a surveillance audit every year in between. SOC 2 ends in a CPA firm's opinion, and a Type 2 tests whether controls operated across a period, usually 3 to 12 months, by sampling the whole window. One evidence set covers both only if it is dated and continuous, so the SOC 2 sample can be drawn from it and the ISO auditor can see the control running at the surveillance visit.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps every control in one library to both the 2017 Trust Services Criteria and the 93 Annex A controls of ISO 27001:2022, so one piece of evidence counts twice
- Builds and keeps the Statement of Applicability, with an include or exclude decision and a reason for every Annex A control
- Tracks the ISO clauses SOC 2 never asks for: ISMS scope, objectives, internal audit, management review and corrective actions
- Collects dated evidence continuously from your cloud, identity and ticketing tools, so a Type 2 window and an ISO surveillance audit draw on the same record
- Flags the 11 controls new in the 2022 edition that a 2013-era mapping leaves blank
- Shows which SOC 2 categories you scoped, so Availability and Confidentiality gaps against Annex A show up before the auditor finds them
- Runs the risk register that feeds both CC3.2 and ISO clause 6.1.2, with owners and treatment decisions recorded once
- Answers customer security questionnaires from the same mapped controls, so a US buyer gets the SOC 2 answer and an EU buyer the ISO one, and they agree
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Where SOC 2 covers ISO 27001 and where it stops
ISO 27001:2022 requirements against the SOC 2 criteria that cover them
Most SOC 2 and ISO 27001 mappings compare Annex A controls and stop there. This table starts with the management system clauses, where the real gap is, and ends with the one thing ISO 27001 cannot give a SOC 2 customer. Criteria are the 2017 Trust Services Criteria; clauses and controls are ISO/IEC 27001:2022.
| ISO 27001:2022 requirement | Clause or control | SOC 2 criteria that cover it | Covered by a SOC 2 program? | Net-new work for ISO 27001 |
|---|---|---|---|---|
| ISMS scope and context | 4.1 to 4.4 | System description (DC 200) in part | Only in part | A written ISMS scope with interfaces and dependencies, and interested parties |
| Leadership and information security policy | 5.1 to 5.3 | CC1.1 to CC1.3, CC5.3 | Yes, mostly | Top management commitment shown in records, not only in policy text |
| Risk assessment and treatment | 6.1.2, 6.1.3 | CC3.1 to CC3.4 | Yes, mostly | A risk treatment plan with owner sign-off on residual risk |
| Statement of Applicability | 6.1.3 d) | None | No | All 93 Annex A controls listed, each included or excluded with a reason |
| Measurable security objectives | 6.2 | CC2.1 in part | Only in part | Objectives with targets, owners and how they are measured |
| Planning of changes to the ISMS | 6.3 (new in 2022) | CC8.1 in part | Only in part | Changes to the ISMS itself planned, not only changes to systems |
| Competence, awareness, documented information | 7.2, 7.3, 7.5 | CC1.4, CC2.2 | Yes, mostly | Document control: versions, approval and retention of ISMS records |
| Internal audit of the ISMS | 9.2 | CC4.1 in part | Only in part | An audit program covering the whole ISMS, by someone independent of the work audited |
| Management review | 9.3 | None | No | A review meeting with the inputs 9.3.2 lists, and recorded decisions |
| Nonconformity and corrective action | 10.2 | CC4.2 in part | Only in part | Root cause and corrective action records for every nonconformity |
| Cloud services, threat intelligence, secure coding | A 5.23, A 5.7, A 8.28 (new in 2022) | CC9.2, CC7.1, CC8.1 in part | Only in part | Controls absent from the 2018 AICPA mapping, so map them by hand |
| Operating effectiveness over a period (the reverse gap) | No ISO equivalent | Type 2 testing across 3 to 12 months | Not applicable | None for ISO, but ISO alone will not satisfy a customer who asks for a Type 2 |
Sources: AICPA resource "Mapping: 2017 Trust Services Criteria to ISO 27001" (published May 4, 2018, members only), ISO/IEC 27001:2022 clause and Annex A structure (93 controls in four themes, 11 new), and the IAF transition that ended 2013-edition certificates on October 31, 2025. Scrutineer prepares and maintains evidence. A licensed CPA firm issues the SOC 2 report and an accredited certification body issues the ISO 27001 certificate.
Good questions
Questions about SOC 2 + ISO 27001
Keep reading
Guides for running SOC 2 and ISO 27001 together
ISO 27001 vs SOC 2
Which one your buyers will ask for, and what each audit actually tests.
Read the guideISO 27001 Annex A controls list
All 93 controls of the 2022 edition in their four themes.
Read the guideISO 27001 certification timeline
Stage 1, Stage 2 and the surveillance years, in order.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification