This table shows the 22 compliance areas where CMMC 2.0 and SOC 2 controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaCMMC 2.0SOC 2
Access ControlAC.L2-3.1.1, AC.L2-3.1.2CC6.1
Least PrivilegeAC.L2-3.1.5, AC.L2-3.1.6CC6.3
Remote AccessAC.L2-3.1.12, AC.L2-3.1.14CC6.1, CC6.6
Session ControlsAC.L2-3.1.10, AC.L2-3.1.11CC6.1
Authentication & MFAIA.L2-3.5.3, IA.L2-3.5.4CC6.1, CC6.3
Identifier ManagementIA.L2-3.5.1, IA.L2-3.5.2CC6.2
Security Awareness & TrainingAT.L2-3.2.1, AT.L2-3.2.2CC1.4
Audit LoggingAU.L2-3.3.1, AU.L2-3.3.2CC7.1, CC7.2
Audit Review & ReportingAU.L2-3.3.5, AU.L2-3.3.6CC7.2, CC4.1
Configuration ManagementCM.L2-3.4.1, CM.L2-3.4.2CC6.1
Change ControlCM.L2-3.4.3, CM.L2-3.4.4CC8.1
Incident ResponseIR.L2-3.6.1, IR.L2-3.6.2CC7.3, CC7.4
Incident ReportingIR.L2-3.6.3CC7.5
Maintenance ControlsMA.L2-3.7.1, MA.L2-3.7.2CC6.1, CC8.1
Media ProtectionMP.L2-3.8.1, MP.L2-3.8.2CC6.5, C1.1
Media SanitizationMP.L2-3.8.3CC6.5
Physical ProtectionPE.L2-3.10.1, PE.L2-3.10.2CC6.4
Risk AssessmentRA.L2-3.11.1, RA.L2-3.11.2CC3.2
Vulnerability ManagementRA.L2-3.11.2, RA.L2-3.11.3CC7.1
Security AssessmentCA.L2-3.12.1, CA.L2-3.12.3CC4.1
Boundary ProtectionSC.L2-3.13.1, SC.L2-3.13.5CC6.6
EncryptionSC.L2-3.13.8, SC.L2-3.13.11CC6.1, CC6.7
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.