Skip to main content
All answers

How do CIS benchmarks map to SOC 2 Type II?

CIS benchmarks map to 25 SOC 2 Trust Services Criteria across the Security (Common Criteria), Availability, Confidentiality, and Privacy categories. Primary coverage spans CC6 (Logical and Physical Access), CC7 (System Operations) and CC8 (Change Management). CISGuard's continuous monitoring produces the period-spanning evidence a SOC 2 Type II operating-effectiveness review asks for.

The longer answer.

The 25 mapped criteria are CC6.1 to CC6.8 (logical and physical access), CC7.1 to CC7.5 (system operations), CC8.1 (change management), CC1.1, CC2.1, CC3.1, CC4.1, CC5.1 and CC5.2, plus A1.1 and A1.2 (availability), C1.1 and C1.2 (confidentiality) and P1.1 (privacy). Processing integrity criteria are not mapped, because they concern how data is processed rather than how systems are configured.

For a Type II report what matters is consistency over the audit window. Every scheduled scan is kept and compared with the previous one, so the historical posture trend shows how each criterion held across the period and when it drifted.

More questions on Framework Mapping?

Our compliance engineers can show you exactly how CISGuard handles Framework Mapping in a briefing scoped to your environment.