Skip to content

PCI DSSSOC 2 crosswalk

A control-by-control mapping between PCI DSS v4.0 and SOC 2 (AICPA Trust Services Criteria). 7 mappings.

PCI DSSSOC 2RelationshipNotes
Req. 10
Log and monitor all access to system components and cardholder data
CC7.2
Security event monitoring
EquivalentCurated
Journalisation, surveillance et détection
Req. 11
Test security of systems and networks regularly
CC7.1
Vulnerability detection and monitoring
EquivalentCurated
Gestion des vulnérabilités
Req. 12
Support information security with organizational policies and programs
CC1.1
Integrity and ethical values
RelatedCurated
Gouvernance et politique de sécurité
Req. 3
Protect stored account data
CC6.7
Restricting data transmission
PartialCurated
Cryptographie et protection des données
Req. 4
Protect cardholder data with strong cryptography during transmission
CC6.7
Restricting data transmission
PartialCurated
Cryptographie et protection des données
Req. 7
Restrict access by business need to know
CC6.1
Logical access security controls
EquivalentCurated
Contrôle d'accès et identité
Req. 8
Identify users and authenticate access
CC6.1
Logical access security controls
EquivalentCurated
Contrôle d'accès et identité

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.