Scrutineer.ai

Scrutineer · By framework

SOC 2 and ISO 27001 compliance software with mapping

Your US customers asked for a SOC 2 report and you have one. Now a European or global enterprise wants an ISO 27001 certificate, or the other way round, and nobody wants to run two compliance programs.

Scrutineer maps each control once to the Trust Services Criteria and to the 93 Annex A controls of ISO 27001:2022, keeps the Statement of Applicability, and tracks the management system work SOC 2 never asks for. Compliance software, not a certification.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with SOC 2 + ISO 27001

The AICPA mapping everyone cites predates ISO 27001:2022

The official crosswalk from the Trust Services Criteria to ISO 27001 is an AICPA spreadsheet published on May 4, 2018, for members only. A file from 2018 can only map the 2013 edition, with 114 Annex A controls in 14 domains. The 2022 edition has 93 controls in four themes, renumbered, with 11 that did not exist before, such as 5.23 cloud services, 5.7 threat intelligence and 8.28 secure coding. Any SOC 2 to ISO 27001 mapping that quotes 2022 control numbers was rebuilt by someone after the fact. Ask who built it.

SOC 2 gives you most of Annex A and very little of the management system

The control overlap is real: access, logging, change management, incident response, vendor review, encryption and backups line up closely. The gap sits in clauses 4 to 10, which SOC 2 never asks for. ISO 27001 requires a defined ISMS scope, a Statement of Applicability covering all 93 controls, measurable security objectives, an internal audit of the ISMS, a management review with set inputs, and nonconformity and corrective action records. A SOC 2 shop adding ISO 27001 mostly builds paperwork and governance, not new controls.

A certificate and an attestation are tested differently, so evidence has to serve both

ISO 27001 ends in a three-year certificate from an accredited certification body, with a surveillance audit every year in between. SOC 2 ends in a CPA firm's opinion, and a Type 2 tests whether controls operated across a period, usually 3 to 12 months, by sampling the whole window. One evidence set covers both only if it is dated and continuous, so the SOC 2 sample can be drawn from it and the ISO auditor can see the control running at the surveillance visit.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps every control in one library to both the 2017 Trust Services Criteria and the 93 Annex A controls of ISO 27001:2022, so one piece of evidence counts twice
  • Builds and keeps the Statement of Applicability, with an include or exclude decision and a reason for every Annex A control
  • Tracks the ISO clauses SOC 2 never asks for: ISMS scope, objectives, internal audit, management review and corrective actions
  • Collects dated evidence continuously from your cloud, identity and ticketing tools, so a Type 2 window and an ISO surveillance audit draw on the same record
  • Flags the 11 controls new in the 2022 edition that a 2013-era mapping leaves blank
  • Shows which SOC 2 categories you scoped, so Availability and Confidentiality gaps against Annex A show up before the auditor finds them
  • Runs the risk register that feeds both CC3.2 and ISO clause 6.1.2, with owners and treatment decisions recorded once
  • Answers customer security questionnaires from the same mapped controls, so a US buyer gets the SOC 2 answer and an EU buyer the ISO one, and they agree
SOC 2 + ISO 27001 readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Where SOC 2 covers ISO 27001 and where it stops

ISO 27001:2022 requirements against the SOC 2 criteria that cover them

Most SOC 2 and ISO 27001 mappings compare Annex A controls and stop there. This table starts with the management system clauses, where the real gap is, and ends with the one thing ISO 27001 cannot give a SOC 2 customer. Criteria are the 2017 Trust Services Criteria; clauses and controls are ISO/IEC 27001:2022.

ISO 27001:2022 requirement Clause or control SOC 2 criteria that cover it Covered by a SOC 2 program? Net-new work for ISO 27001
ISMS scope and context 4.1 to 4.4 System description (DC 200) in part Only in part A written ISMS scope with interfaces and dependencies, and interested parties
Leadership and information security policy 5.1 to 5.3 CC1.1 to CC1.3, CC5.3 Yes, mostly Top management commitment shown in records, not only in policy text
Risk assessment and treatment 6.1.2, 6.1.3 CC3.1 to CC3.4 Yes, mostly A risk treatment plan with owner sign-off on residual risk
Statement of Applicability 6.1.3 d) None No All 93 Annex A controls listed, each included or excluded with a reason
Measurable security objectives 6.2 CC2.1 in part Only in part Objectives with targets, owners and how they are measured
Planning of changes to the ISMS 6.3 (new in 2022) CC8.1 in part Only in part Changes to the ISMS itself planned, not only changes to systems
Competence, awareness, documented information 7.2, 7.3, 7.5 CC1.4, CC2.2 Yes, mostly Document control: versions, approval and retention of ISMS records
Internal audit of the ISMS 9.2 CC4.1 in part Only in part An audit program covering the whole ISMS, by someone independent of the work audited
Management review 9.3 None No A review meeting with the inputs 9.3.2 lists, and recorded decisions
Nonconformity and corrective action 10.2 CC4.2 in part Only in part Root cause and corrective action records for every nonconformity
Cloud services, threat intelligence, secure coding A 5.23, A 5.7, A 8.28 (new in 2022) CC9.2, CC7.1, CC8.1 in part Only in part Controls absent from the 2018 AICPA mapping, so map them by hand
Operating effectiveness over a period (the reverse gap) No ISO equivalent Type 2 testing across 3 to 12 months Not applicable None for ISO, but ISO alone will not satisfy a customer who asks for a Type 2

Sources: AICPA resource "Mapping: 2017 Trust Services Criteria to ISO 27001" (published May 4, 2018, members only), ISO/IEC 27001:2022 clause and Annex A structure (93 controls in four themes, 11 new), and the IAF transition that ended 2013-edition certificates on October 31, 2025. Scrutineer prepares and maintains evidence. A licensed CPA firm issues the SOC 2 report and an accredited certification body issues the ISO 27001 certificate.

Good questions

Questions about SOC 2 + ISO 27001

Yes. Most of the controls overlap, so one program can serve both, and several US firms are both a CPA firm and an accredited ISO certification body and run the audits in one season. Build the ISO management system clauses early, because the Stage 1 audit checks them, and start the SOC 2 observation window once the controls are running.
Get the one your next deal asks for. US enterprise buyers usually ask for a SOC 2 Type 2 report; European, Asian and global enterprise buyers usually ask for an ISO 27001 certificate. If you already have one, the second is cheaper than the first, because the controls and much of the evidence carry over.
At the control level, heavily: access control, logging, change management, incident response, vendor management, encryption and backups all line up. At the management system level, barely: SOC 2 has no equivalent of the Statement of Applicability, the ISMS internal audit or the management review. Published overlap percentages vary by who counts and by which edition they mapped.
The AICPA published one, "Mapping: 2017 Trust Services Criteria to ISO 27001", on May 4, 2018, available to AICPA and CIMA members. Because it predates ISO 27001:2022, it maps the 2013 edition and its 114 controls. Mappings to the current 93 controls are rebuilt by vendors and audit firms, so check who built yours.
No. They answer different questions. An ISO 27001 certificate says your management system meets the standard; a SOC 2 Type 2 report gives a CPA firm's opinion on whether specific controls worked across a period, with detailed test results. A US customer who asks for a SOC 2 report will rarely accept an ISO certificate instead, and the reverse is also common.
No. The transition to ISO 27001:2022 ended on October 31, 2025, and 2013-edition certificates are no longer valid after that date. If a vendor or a mapping still cites 2013 control numbers such as A.12 or A.14, it is working from the retired edition.
A defined ISMS scope, a Statement of Applicability for all 93 Annex A controls, measurable security objectives, a risk treatment plan with owner sign-off, an internal audit of the ISMS, a management review with set inputs, and nonconformity and corrective action records. Those are clauses 4 to 10 of the standard, and they are where SOC 2 teams spend most of their new effort.
Usually a few months rather than a year, because the controls already run. The time goes into the ISMS documents, the Statement of Applicability, one full internal audit and one management review before Stage 2. The certification body's calendar and any nonconformities found at Stage 1 decide the final date.
No. Scrutineer is compliance software. It maps your controls to both frameworks, collects the evidence, keeps the Statement of Applicability and flags gaps. A licensed CPA firm issues the SOC 2 report, and an accredited certification body issues the ISO 27001 certificate.

Keep reading

Guides for running SOC 2 and ISO 27001 together

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification