Framework overlap

Does SOC 2 cover NIST SP 800-171?

You hold SOC 2 and have been told to do NIST SP 800-171. Here is how much overlaps, control by control.

5% of NIST SP 800-171 you already have

SOC 2 already covers about 5% of NIST SP 800-171, leaving 88 of 93 controls as genuinely new work.

Already covered 1 Likely covered 4 New work 88

What is genuinely new work

Nothing in SOC 2 reaches these. This is the list to scope.

171-AC-1
Access Control Policy and Procedures
171-AC-2
Least Privilege and Separation of Duties
171-AC-3
Remote Access and Mobile Devices
171-AT-1
Security Awareness and Role-Based Training
171-AU-1
Audit Event Capture
171-AU-2
Audit Review and Analysis
171-CM-1
Baseline Configuration and Inventory
171-IA-1
Identification and Authentication
171-IA-2
Multi-Factor Authentication
171-IR-1
Incident Handling Capability
171-IR-2
Incident Reporting
171-MA-1
Maintenance Authorisation and Control
171-MP-1
Media Protection
171-PE-1
Physical Access Authorisations
171-RA-1
Risk Assessment
171-RA-2
Vulnerability Scanning and Remediation
171-SC-1
Boundary Protection
171-SC-2
Encryption of Controlled Unclassified Information
171-SI-1
Flaw Remediation
171-SI-2
Malicious Code Protection
3.1.1
Authorized Access Control
3.1.2
Transaction and Function Control
3.1.20
External Connections Control
3.10.6
Alternate Work Site Safeguards
3.11.1
Risk Assessments
3.11.2
Vulnerability Scanning
3.12.1
Security Control Assessment
3.13.11
Cryptographic Protection
3.13.5
Network Segmentation
3.13.8
Transmission Confidentiality
3.14.1
Flaw Remediation
3.14.6
Monitoring for Attacks
3.4.1
Baseline Configuration Maintenance
3.4.6
Least Functionality
3.5.3
Multi Factor Authentication
3.8.3
Media Sanitization
3.9.2
Personnel Transfer and Termination
A.03.01.01
Account Management Assessment
A.03.01.05
Least Privilege Assessment
A.03.01.12
Remote Access Assessment
A.03.03.01
Event Logging Assessment
A.03.04.01
Baseline Configuration Assessment
A.03.04.02
Configuration Settings Assessment
A.03.05.03
Multi Factor Authentication Assessment
A.03.06.01
Incident Handling Assessment
A.03.07.04
Maintenance Tools Assessment
A.03.08.03
Media Sanitization Assessment
A.03.09.02
Personnel Termination Assessment
A.03.10.01
Physical Access Authorization Assessment
A.03.11.01
Risk Assessment Process
A.03.11.02
Vulnerability Monitoring Assessment
A.03.12.01
Security Control Assessments
A.03.13.11
Cryptographic Protection of CUI at Rest
A.03.14.01
Flaw Remediation Assessment
A.03.14.06
System Monitoring Assessment
A.03.15.01
System Security Plan Assessment
SP800-171-3.10.6
Safeguard CUI at alternate work sites
SP800-171-3.11.1
Periodically assess risk
SP800-171-3.11.2
Scan for vulnerabilities
SP800-171-3.11.3
Remediate vulnerabilities
SP800-171-3.12.1
Periodically assess security controls
SP800-171-3.12.2
Plans of action for deficiencies
SP800-171-3.12.3
Continuously monitor controls
SP800-171-3.13.1
Monitor and protect communications at boundaries
SP800-171-3.13.11
Employ FIPS-validated cryptography
SP800-171-3.13.16
Protect confidentiality of CUI at rest
SP800-171-3.13.6
Deny network traffic by default
SP800-171-3.13.8
Encrypt CUI in transmission
SP800-171-3.14.1
Identify, report, and correct flaws
SP800-171-3.14.2
Malicious code protection
SP800-171-3.14.3
Monitor security alerts and advisories
SP800-171-3.14.6
Monitor systems and traffic for attacks
SP800-171-3.5.1
Identify system users, processes, and devices
SP800-171-3.5.10
Store and transmit only encrypted passwords
SP800-171-3.5.2
Authenticate identities before access
SP800-171-3.5.3
Multifactor authentication for privileged/network access
SP800-171-3.5.4
Replay-resistant authentication
SP800-171-3.6.2
Track, document, and report incidents
SP800-171-3.6.3
Test incident response capability
SP800-171-3.7.1
Perform system maintenance
SP800-171-3.7.2
Control maintenance tools and personnel
SP800-171-3.7.5
MFA for nonlocal maintenance
SP800-171-3.8.1
Protect system media containing CUI
SP800-171-3.8.3
Sanitize or destroy media before disposal
SP800-171-3.8.6
Encrypt CUI on digital media during transport
SP800-171-3.8.7
Control removable media
SP800-171-3.9.1
Screen individuals before CUI access
SP800-171-3.9.2
Protect CUI during personnel actions
Show the 5 you already have
3.6.1
Incident Response Capability
3.3.1
Audit Record Creation
SP800-171-3.10.1
Limit physical access
SP800-171-3.10.3
Escort and monitor visitors
SP800-171-3.6.1
Operational incident-handling capability

How this is calculated

Already covered means a mapping runs from a control in SOC 2 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition