Framework overlap

Does NIS2 Directive cover SOC 2?

You hold NIS2 Directive and have been told to do SOC 2. Here is how much overlaps, control by control.

24% of SOC 2 you already have

NIS2 Directive already covers about 24% of SOC 2, leaving 41 of 54 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 41

No control in NIS2 Directive maps directly to one in SOC 2. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIS2 Directive reaches these. This is the list to scope.

SOC2-C1.1
Confidential information is identified and protected during receipt, processing, storage
SOC2-C1.2
Confidential information is disposed of securely
SOC2-CC1.1
COSO principle 1: Demonstrates commitment to integrity and ethical values
SOC2-CC1.2
COSO principle 2: Board exercises oversight responsibility
SOC2-CC1.3
COSO principle 3: Management establishes structures, reporting lines, and authorities
SOC2-CC1.4
COSO principle 4: Demonstrates commitment to attract and retain competent individuals
SOC2-CC1.5
COSO principle 5: Holds individuals accountable for internal control responsibilities
SOC2-CC2.1
COSO principle 13: Obtains and generates relevant, quality information
SOC2-CC2.2
COSO principle 14: Internally communicates information including objectives and responsibilities
SOC2-CC2.3
COSO principle 15: Communicates with external parties regarding matters affecting controls
SOC2-CC3.1
COSO principle 6: Specifies objectives to identify and assess risks
SOC2-CC3.2
COSO principle 7: Identifies risks and analyzes to determine how managed
SOC2-CC3.3
COSO principle 8: Considers potential for fraud
SOC2-CC3.4
COSO principle 9: Identifies and assesses changes that could impact internal controls
SOC2-CC4.1
COSO principle 16: Selects and develops ongoing and separate evaluations
SOC2-CC5.1
COSO principle 10: Selects and develops control activities to mitigate risks
SOC2-CC5.2
COSO principle 11: Selects and develops general controls over technology
SOC2-CC5.3
COSO principle 12: Deploys control activities through policies and procedures
SOC2-CC6.6
Measures against threats outside system boundaries are implemented
SOC2-CC6.7
Transmission of data is restricted to authorized users
SOC2-CC6.8
Controls to prevent or detect unauthorized or malicious software
SOC2-CC7.1
Detection and monitoring procedures for security events are in place
SOC2-CC7.2
Monitors system components for anomalies indicating malicious acts
SOC2-CC7.3
Evaluates security events to determine incident status
SOC2-CC9.1
Identifies, selects and develops risk mitigation activities
SOC2-CC9.2
Risk mitigation activities include assessment of vendor and business partner controls
SOC2-P1.1
Privacy notice provides clear notice about privacy practices
SOC2-P2.1
Consent is obtained for the collection, use, and disclosure of personal information
SOC2-P3.2
Explicit consent is obtained for sensitive personal information
SOC2-P4.1
Personal information is used for purposes identified in privacy commitments
SOC2-P4.2
Personal information is retained for only as long as needed
SOC2-P5.1
Personal information is accessed only by authorized personnel
SOC2-P5.2
Corrections to personal information are processed timely
SOC2-P6.2
Records of personal information disclosures are maintained
SOC2-P7.1
Personal information collected is limited to what is necessary and relevant
SOC2-P8.1
Inquiries, complaints, and disputes regarding personal information are addressed
SOC2-PI1.1
Obtains or generates and uses relevant quality information to support processing integrity
SOC2-PI1.2
System inputs are complete, accurate, and processed in a timely manner
SOC2-PI1.3
System processing is complete, valid, accurate, timely, and authorized
SOC2-PI1.4
System outputs are complete, valid, accurate, timely, and distributed
SOC2-PI1.5
Inputs are processed completely, accurately, and timely for stored data
Show the 13 you already have
SOC2-A1.1
Maintains capacity to meet availability commitments
SOC2-A1.2
Environmental protections, data backups, and recovery infrastructure support availability
SOC2-A1.3
Recovery plan procedures support system recovery from failures
SOC2-CC4.2
COSO principle 17: Evaluates and communicates deficiencies in a timely manner
SOC2-CC6.1
Logical and physical access security for information and assets
SOC2-CC6.2
Prior to granting access, registration and authorization processes are established
SOC2-CC6.3
Role-based access and least privilege are enforced
SOC2-CC7.4
Responds to identified security incidents through defined procedures
SOC2-CC7.5
Identifies the root cause of security incidents
SOC2-CC8.1
Change management processes are in place
SOC2-P3.1
Personal information is collected consistent with privacy commitments
SOC2-P4.3
Personal information is securely disposed of
SOC2-P6.1
Personal information is disclosed to third parties only as committed

How this is calculated

Already covered means a mapping runs from a control in NIS2 Directive to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition