Skip to content

NIS2SOC 2 crosswalk

A control-by-control mapping between NIS2 Directive (EU 2022/2555) and SOC 2 (AICPA Trust Services Criteria). 3 mappings.

NIS2SOC 2RelationshipNotes
Art. 21(2)(a)
Risk analysis and information system security policies
CC1.1
Integrity and ethical values
RelatedCurated
Governance & security policy
Art. 21(2)(h)
Cryptography and encryption
CC6.7
Restricting data transmission
PartialCurated
Cryptography & data protection
Art. 21(2)(i)
Access control and asset management
CC6.1
Logical access security controls
PartialCurated
Access control & identity

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.