CIS Controls v8 Mapping to AICPA Trust Services Criteria (SOC2)

Published on August 31, 2021

This mapping document demonstrates connections between AICPA Trust Services Criteria (SOC2) and the CIS Critical Security Controls v8.
Controls v8 SOC2 Mapping

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.