This table shows the 27 compliance areas where SOC 2 and NIST CSF controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaSOC 2NIST CSF
EncryptionCC6.1, CC6.7PR.DS-01, PR.DS-02
Access ControlCC6.1PR.AA-01
Identity ManagementCC6.2PR.AA-01, PR.AA-03
Authentication & MFACC6.1, CC6.3PR.AA-03
Access Rights ReviewCC6.2, CC6.3PR.AA-05
Privileged Access ManagementCC6.3PR.AA-05
Network SecurityCC6.6PR.IR-01
Vulnerability ManagementCC7.1ID.RA-01, PR.PS-01
Logging & MonitoringCC7.1, CC7.2DE.CM-01, DE.AE-02
Incident ManagementCC7.3, CC7.4RS.MA-01, RS.AN-03
Incident ClassificationCC7.3DE.AE-04
Incident ReportingCC7.5RS.CO-02
Incident Response TeamCC7.4RS.MA-02
Business ContinuityA1.1, A1.2RC.RP-01, RC.RP-03
Backup & RestorationA1.2RC.RP-03
Third-Party Risk ManagementCC9.2GV.SC-03
Supplier Due DiligenceCC9.2GV.SC-06
Risk AssessmentCC3.2ID.RA-03, ID.RA-05
Information Security PolicyCC1.1GV.PO-01
Security Awareness & TrainingCC1.4PR.AT-01
Data ClassificationCC6.5, C1.1PR.DS-10
Change ManagementCC8.1PR.PS-01
Secure DevelopmentCC8.1PR.PS-06
Security TestingCC4.1ID.IM-02
Record KeepingCC7.2DE.CM-01
Configuration ManagementCC6.1PR.PS-01
Malware ProtectionCC6.8DE.CM-09
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.