Skip to content

Essential EightSOC 2 crosswalk

A control-by-control mapping between ACSC Essential Eight and SOC 2 (AICPA Trust Services Criteria). 4 mappings.

Essential EightSOC 2RelationshipNotes
E8-1
Patch applications
CC7.1
Vulnerability detection and monitoring
EquivalentCurated
Vulnerability management
E8-2
Patch operating systems
CC7.1
Vulnerability detection and monitoring
EquivalentCurated
Vulnerability management
E8-3
Multi-factor authentication
CC6.1
Logical access security controls
PartialCurated
Access control & identity
E8-4
Restrict administrative privileges
CC6.1
Logical access security controls
PartialCurated
Access control & identity

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.