Security Framework Crosswalk
Security Framework Crosswalk
A free reference tool mapping common security objectives across major compliance frameworks. Use it to understand how controls in one framework relate to requirements in another.
55 security objectives mapped across 4 frameworks
Frameworks:CMMC Level 2NIST CSF 2.0ISO 27001:2022SOC 2
Need the full 110-requirement, NIST 800-171-anchored view? See the Compliance Framework Crosswalk (adds ISO 27001 Annex A and PCI DSS 4.0.1, requirement-by-requirement) and the Rev 2 to Rev 3 Delta & ODP Guide.
| Security Objective | CMMC Level 2 | NIST CSF 2.0 | ISO 27001:2022 | SOC 2 | Confidence |
|---|---|---|---|---|---|
Authorized Access Control | AC.L2-3.1.1 | PR.AA-05 | A.5.15 | CC6.1 | HIGH |
Role-Based Access and Least Privilege | AC.L2-3.1.5 | PR.AA-05 | A.8.2 | CC6.3 | HIGH |
User Registration and Access Provisioning | AC.L2-3.1.1 | PR.AA-01 | A.5.18 | CC6.2 | HIGH |
Multi-Factor Authentication | IA.L2-3.5.3 | PR.AA-03 | A.8.5 | CC6.1 | HIGH |
Identity Management and Credential Lifecycle | IA.L2-3.5.1 | PR.AA-01 | A.5.16 | CC6.2 | HIGH |
Audit Log Generation | AU.L2-3.3.1 | PR.PS-04 | A.8.15 | CC7.2 | HIGH |
Audit Log Review and Correlation | AU.L2-3.3.5 | DE.AE-02 | A.8.16 | CC7.2 | HIGH |
Audit Log Protection and Integrity | AU.L2-3.3.8 | PR.PS-04 | A.8.15 | CC2.1 | MEDIUM |
Incident Response Planning | IR.L2-3.6.1 | RS.MA-01 | A.5.24 | CC7.4 | HIGH |
Incident Reporting and Communication | IR.L2-3.6.2 | RS.CO-02 | A.6.8 | CC7.3 | HIGH |
Incident Response Testing | IR.L2-3.6.3 | ID.IM-01 | A.5.27 | CC7.4 | MEDIUM |
Data-at-Rest Encryption | SC.L2-3.13.16 | PR.DS-01 | A.8.24 | CC6.7 | HIGH |
Data-in-Transit Encryption | SC.L2-3.13.8 | PR.DS-02 | A.8.24 | CC6.7 | HIGH |
Cryptographic Key Management | SC.L2-3.13.10 | PR.DS-01 | A.8.24 | CC6.1 | MEDIUM |
Baseline Configuration Management | CM.L2-3.4.1 | PR.PS-01 | A.8.9 | CC5.2 | HIGH |
Security Configuration Enforcement | CM.L2-3.4.2 | PR.PS-01 | A.8.9 | CC5.2 | HIGH |
Least Functionality and Service Hardening | CM.L2-3.4.6 | PR.PS-01 | A.8.9 | CC6.1 | MEDIUM |
Risk Assessment Process | RA.L2-3.11.1 | ID.RA-05 | A.5.7 | CC3.2 | HIGH |
Risk Response and Treatment | RA.L2-3.11.1 | ID.RA-06 | A.5.7 | CC3.2 | MEDIUM |
Risk Monitoring and Reassessment | CA.L2-3.12.3 | ID.RA-07 | A.5.7 | CC3.4 | MEDIUM |
Security Awareness Training | AT.L2-3.2.1 | PR.AT-01 | A.6.3 | CC1.4 | HIGH |
Role-Based Security Training | AT.L2-3.2.2 | PR.AT-02 | A.6.3 | CC1.4 | HIGH |
Media Sanitization and Disposal | MP.L2-3.8.3 | PR.DS-01 | A.7.14 | CC6.5 | HIGH |
Removable Media Protection | MP.L2-3.8.7 | PR.DS-01 | A.7.10 | CC6.7 | MEDIUM |
Malware Protection | SI.L2-3.14.2 | DE.CM-09 | A.8.7 | CC6.8 | HIGH |
Malware Signature and Definition Updates | SI.L2-3.14.4 | DE.CM-09 | A.8.7 | CC6.8 | HIGH |
System and File Integrity Monitoring | SI.L2-3.14.5 | DE.CM-09 | A.8.16 | CC7.2 | HIGH |
Network Boundary Protection | SC.L2-3.13.1 | PR.IR-01 | A.8.20 | CC6.6 | HIGH |
Network Monitoring and Intrusion Detection | SI.L2-3.14.6 | DE.CM-01 | A.8.16 | CC7.2 | HIGH |
Network Segmentation | SC.L2-3.13.5 | PR.IR-01 | A.8.22 | CC6.6 | HIGH |
Physical Access Control | PE.L2-3.10.1 | PR.AA-06 | A.7.2 | CC6.4 | HIGH |
Physical Security Monitoring | PE.L2-3.10.2 | DE.CM-02 | A.7.4 | CC6.4 | HIGH |
Personnel Screening | PS.L2-3.9.1 | GV.RR-04 | A.6.1 | CC1.4 | HIGH |
Personnel Termination and Transfer | PS.L2-3.9.2 | PR.AA-05 | A.6.5 | CC6.3 | HIGH |
Change Management Process | CM.L2-3.4.3 | PR.PS-01 | A.8.32 | CC8.1 | HIGH |
Change Impact Analysis | CM.L2-3.4.4 | PR.PS-01 | A.8.32 | CC8.1 | MEDIUM |
Session Lock and Termination | AC.L2-3.1.10 | PR.AA-05 | A.8.1 | CC6.1 | MEDIUM |
Session Termination | AC.L2-3.1.11 | PR.AA-05 | A.8.1 | CC6.1 | MEDIUM |
Remote Access Management | AC.L2-3.1.12 | PR.AA-03 | A.6.7 | CC6.6 | HIGH |
Remote Access Confidentiality | AC.L2-3.1.13 | PR.DS-02 | A.6.7 | CC6.7 | HIGH |
Information Flow Enforcement | AC.L2-3.1.3 | PR.DS-02 | A.5.14 | CC6.7 | HIGH |
Data Loss Prevention | AC.L2-3.1.3 | PR.DS-10 | A.8.12 | CC6.7 | MEDIUM |
System Recovery and Business Continuity | MP.L2-3.8.9 | RC.RP-01 | A.8.13 | CC7.5 | HIGH |
Business Continuity Planning | MP.L2-3.8.9 | RC.RP-04 | A.5.30 | CC9.1 | MEDIUM |
Vulnerability Scanning and Identification | RA.L2-3.11.2 | ID.RA-01 | A.8.8 | CC7.1 | HIGH |
Vulnerability Remediation | RA.L2-3.11.3 | RS.MI-02 | A.8.8 | CC7.1 | HIGH |
Supply Chain Risk Management | - | GV.SC-01 | A.5.19 | CC9.2 | HIGH |
Third-Party Security Requirements in Agreements | - | GV.SC-05 | A.5.20 | CC9.2 | HIGH |
Flaw Remediation and Patch Management | SI.L2-3.14.1 | PR.PS-02 | A.8.8 | CC7.1 | HIGH |
Security Policy Establishment | - | GV.PO-01 | A.5.1 | CC5.3 | HIGH |
Separation of Duties | AC.L2-3.1.4 | - | A.5.3 | CC5.1 | HIGH |
Software Installation Control | CM.L2-3.4.9 | PR.PS-05 | A.8.19 | CC6.8 | HIGH |
Time Synchronization | AU.L2-3.3.7 | - | A.8.17 | CC7.2 | HIGH |
Continuous Security Monitoring | CA.L2-3.12.3 | DE.CM-01 | A.8.16 | CC4.1 | HIGH |
Incident Containment and Eradication | IR.L2-3.6.1 | RS.MI-01 | A.5.26 | CC7.4 | HIGH |
See how your controls map in practice
CMMC Operator scores your compliance readiness across multiple frameworks simultaneously, using these crosswalk mappings to identify gaps and overlaps.
Turn this guide into a readiness plan
Start with the free tools: the Mac scope classifier and the POA&M eligibility checker turn control status into a prioritized plan. Do not enter CUI, FCI, credentials, or system evidence into any web tool.
Member discussion