4 min read

Security Framework Crosswalk

Map common security objectives across CMMC, NIST CSF, ISO 27001, and SOC 2 for cross-framework planning.

Security Framework Crosswalk

A free reference tool mapping common security objectives across major compliance frameworks. Use it to understand how controls in one framework relate to requirements in another.

55 security objectives mapped across 4 frameworks

Frameworks:CMMC Level 2NIST CSF 2.0ISO 27001:2022SOC 2

Need the full 110-requirement, NIST 800-171-anchored view? See the Compliance Framework Crosswalk (adds ISO 27001 Annex A and PCI DSS 4.0.1, requirement-by-requirement) and the Rev 2 to Rev 3 Delta & ODP Guide.

Security ObjectiveCMMC Level 2NIST CSF 2.0ISO 27001:2022SOC 2Confidence
Authorized Access Control
AC.L2-3.1.1PR.AA-05A.5.15CC6.1HIGH
Role-Based Access and Least Privilege
AC.L2-3.1.5PR.AA-05A.8.2CC6.3HIGH
User Registration and Access Provisioning
AC.L2-3.1.1PR.AA-01A.5.18CC6.2HIGH
Multi-Factor Authentication
IA.L2-3.5.3PR.AA-03A.8.5CC6.1HIGH
Identity Management and Credential Lifecycle
IA.L2-3.5.1PR.AA-01A.5.16CC6.2HIGH
Audit Log Generation
AU.L2-3.3.1PR.PS-04A.8.15CC7.2HIGH
Audit Log Review and Correlation
AU.L2-3.3.5DE.AE-02A.8.16CC7.2HIGH
Audit Log Protection and Integrity
AU.L2-3.3.8PR.PS-04A.8.15CC2.1MEDIUM
Incident Response Planning
IR.L2-3.6.1RS.MA-01A.5.24CC7.4HIGH
Incident Reporting and Communication
IR.L2-3.6.2RS.CO-02A.6.8CC7.3HIGH
Incident Response Testing
IR.L2-3.6.3ID.IM-01A.5.27CC7.4MEDIUM
Data-at-Rest Encryption
SC.L2-3.13.16PR.DS-01A.8.24CC6.7HIGH
Data-in-Transit Encryption
SC.L2-3.13.8PR.DS-02A.8.24CC6.7HIGH
Cryptographic Key Management
SC.L2-3.13.10PR.DS-01A.8.24CC6.1MEDIUM
Baseline Configuration Management
CM.L2-3.4.1PR.PS-01A.8.9CC5.2HIGH
Security Configuration Enforcement
CM.L2-3.4.2PR.PS-01A.8.9CC5.2HIGH
Least Functionality and Service Hardening
CM.L2-3.4.6PR.PS-01A.8.9CC6.1MEDIUM
Risk Assessment Process
RA.L2-3.11.1ID.RA-05A.5.7CC3.2HIGH
Risk Response and Treatment
RA.L2-3.11.1ID.RA-06A.5.7CC3.2MEDIUM
Risk Monitoring and Reassessment
CA.L2-3.12.3ID.RA-07A.5.7CC3.4MEDIUM
Security Awareness Training
AT.L2-3.2.1PR.AT-01A.6.3CC1.4HIGH
Role-Based Security Training
AT.L2-3.2.2PR.AT-02A.6.3CC1.4HIGH
Media Sanitization and Disposal
MP.L2-3.8.3PR.DS-01A.7.14CC6.5HIGH
Removable Media Protection
MP.L2-3.8.7PR.DS-01A.7.10CC6.7MEDIUM
Malware Protection
SI.L2-3.14.2DE.CM-09A.8.7CC6.8HIGH
Malware Signature and Definition Updates
SI.L2-3.14.4DE.CM-09A.8.7CC6.8HIGH
System and File Integrity Monitoring
SI.L2-3.14.5DE.CM-09A.8.16CC7.2HIGH
Network Boundary Protection
SC.L2-3.13.1PR.IR-01A.8.20CC6.6HIGH
Network Monitoring and Intrusion Detection
SI.L2-3.14.6DE.CM-01A.8.16CC7.2HIGH
Network Segmentation
SC.L2-3.13.5PR.IR-01A.8.22CC6.6HIGH
Physical Access Control
PE.L2-3.10.1PR.AA-06A.7.2CC6.4HIGH
Physical Security Monitoring
PE.L2-3.10.2DE.CM-02A.7.4CC6.4HIGH
Personnel Screening
PS.L2-3.9.1GV.RR-04A.6.1CC1.4HIGH
Personnel Termination and Transfer
PS.L2-3.9.2PR.AA-05A.6.5CC6.3HIGH
Change Management Process
CM.L2-3.4.3PR.PS-01A.8.32CC8.1HIGH
Change Impact Analysis
CM.L2-3.4.4PR.PS-01A.8.32CC8.1MEDIUM
Session Lock and Termination
AC.L2-3.1.10PR.AA-05A.8.1CC6.1MEDIUM
Session Termination
AC.L2-3.1.11PR.AA-05A.8.1CC6.1MEDIUM
Remote Access Management
AC.L2-3.1.12PR.AA-03A.6.7CC6.6HIGH
Remote Access Confidentiality
AC.L2-3.1.13PR.DS-02A.6.7CC6.7HIGH
Information Flow Enforcement
AC.L2-3.1.3PR.DS-02A.5.14CC6.7HIGH
Data Loss Prevention
AC.L2-3.1.3PR.DS-10A.8.12CC6.7MEDIUM
System Recovery and Business Continuity
MP.L2-3.8.9RC.RP-01A.8.13CC7.5HIGH
Business Continuity Planning
MP.L2-3.8.9RC.RP-04A.5.30CC9.1MEDIUM
Vulnerability Scanning and Identification
RA.L2-3.11.2ID.RA-01A.8.8CC7.1HIGH
Vulnerability Remediation
RA.L2-3.11.3RS.MI-02A.8.8CC7.1HIGH
Supply Chain Risk Management
- GV.SC-01A.5.19CC9.2HIGH
Third-Party Security Requirements in Agreements
- GV.SC-05A.5.20CC9.2HIGH
Flaw Remediation and Patch Management
SI.L2-3.14.1PR.PS-02A.8.8CC7.1HIGH
Security Policy Establishment
- GV.PO-01A.5.1CC5.3HIGH
Separation of Duties
AC.L2-3.1.4 - A.5.3CC5.1HIGH
Software Installation Control
CM.L2-3.4.9PR.PS-05A.8.19CC6.8HIGH
Time Synchronization
AU.L2-3.3.7 - A.8.17CC7.2HIGH
Continuous Security Monitoring
CA.L2-3.12.3DE.CM-01A.8.16CC4.1HIGH
Incident Containment and Eradication
IR.L2-3.6.1RS.MI-01A.5.26CC7.4HIGH

See how your controls map in practice

CMMC Operator scores your compliance readiness across multiple frameworks simultaneously, using these crosswalk mappings to identify gaps and overlaps.

Start a free assessment

Turn this guide into a readiness plan

Start with the free tools: the Mac scope classifier and the POA&M eligibility checker turn control status into a prioritized plan. Do not enter CUI, FCI, credentials, or system evidence into any web tool.

Run the free CMMC readiness check