GAISSF to SOC 2 Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to SOC 2, with scope, method, limitations and traceability.
1. Executive Summary
This crosswalk contains 215 outcome-based records covering all 59 GAISSF controls and all 60 Trust Services Criteria identifiers. It supports control rationalization, readiness planning, evidence reuse, and scoping discussions. It does not constitute a SOC 2 examination, report, certification, or opinion.
2. Assurance Architecture
The Trust Services Criteria are criteria used by management and practitioners. A SOC 2 engagement additionally requires a defined service organization system, management description and assertion, applicable trust services categories, examination procedures, evidence, treatment of subservice organizations and complementary user-entity controls, and an independent CPA report. These assurance layers are not collapsed into this crosswalk.
3. Scope and Method
All 61 criterion identifiers are included. Security/Common Criteria, Availability, Processing Integrity, Confidentiality, and Privacy are shown separately. Mappings compare control outcomes and expected evidence. They do not reproduce the full proprietary criteria or points of focus.
4. High-Alignment Areas
Governance, accountability and risk assessment
Logical access, boundary protection and secure transmission
Vulnerability, event and incident management
Change management and supplier risk
Availability and recovery
Processing integrity and data quality
Confidentiality and privacy-supporting controls
5. Material Residual Work
System boundary and service commitments
Management system description and assertion
Trust services category selection
Control design and operating-effectiveness evidence
Type I point-in-time versus Type II period coverage
Complementary user-entity and subservice-organization controls
Independent CPA testing, exceptions and opinion
6. Notably Absent
No basis was found to claim that GAISSF certification equals SOC 2, that a crosswalk produces auditor acceptance, that mapped controls have operated effectively, or that the AICPA or any CPA firm endorses this publication.
7. Criterion Coverage Register
| Criterion | Functional summary | Category | Mapped controls | Coverage |
|---|---|---|---|---|
| CC1.1 | Integrity and ethical values | Security / Common Criteria - Control Environment | 0 | Not Addressed |
| CC1.2 | Board oversight | Security / Common Criteria - Control Environment | 3 | Partially Addressed |
| CC1.3 | Structures, reporting lines, authority and responsibility | Security / Common Criteria - Control Environment | 3 | Partially Addressed |
| CC1.4 | Commitment to competence | Security / Common Criteria - Control Environment | 5 | Substantially Addressed |
| CC1.5 | Accountability | Security / Common Criteria - Control Environment | 6 | Substantially Addressed |
| CC2.1 | Quality information | Security / Common Criteria - Communication and Information | 1 | Indirectly Supported |
| CC2.2 | Internal communication | Security / Common Criteria - Communication and Information | 1 | Indirectly Supported |
| CC2.3 | External communication | Security / Common Criteria - Communication and Information | 1 | Indirectly Supported |
| CC3.1 | Suitable objectives | Security / Common Criteria - Risk Assessment | 1 | Indirectly Supported |
| CC3.2 | Risk identification and analysis | Security / Common Criteria - Risk Assessment | 1 | Indirectly Supported |
| CC3.3 | Fraud risk | Security / Common Criteria - Risk Assessment | 2 | Partially Addressed |
| CC3.4 | Significant change | Security / Common Criteria - Risk Assessment | 2 | Partially Addressed |
| CC4.1 | Ongoing and separate evaluations | Security / Common Criteria - Monitoring | 1 | Indirectly Supported |
| CC4.2 | Deficiency evaluation and communication | Security / Common Criteria - Monitoring | 1 | Indirectly Supported |
| CC5.1 | Control activity selection and development | Security / Common Criteria - Control Activities | 0 | Not Addressed |
| CC5.2 | Technology general controls | Security / Common Criteria - Control Activities | 0 | Not Addressed |
| CC5.3 | Policies and procedures | Security / Common Criteria - Control Activities | 0 | Not Addressed |
| CC6.1 | Logical access security architecture | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed |
| CC6.2 | User registration and authorization | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed |
| CC6.3 | Access modification and removal | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed |
| CC6.4 | Physical access restrictions | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed |
| CC6.5 | Asset disposal and removal | Security / Common Criteria - Logical and Physical Access | 4 | Partially Addressed |
| CC6.6 | System boundary protection | Security / Common Criteria - Logical and Physical Access | 4 | Partially Addressed |
| CC6.7 | Secure transmission and movement | Security / Common Criteria - Logical and Physical Access | 4 | Partially Addressed |
| CC6.8 | Malicious software prevention and detection | Security / Common Criteria - Logical and Physical Access | 6 | Substantially Addressed |
| CC7.1 | Configuration and vulnerability management | Security / Common Criteria - System Operations | 0 | Not Addressed |
| CC7.2 | Security event monitoring | Security / Common Criteria - System Operations | 13 | Substantially Addressed |
| CC7.3 | Security event evaluation | Security / Common Criteria - System Operations | 13 | Substantially Addressed |
| CC7.4 | Incident response | Security / Common Criteria - System Operations | 13 | Substantially Addressed |
| CC7.5 | Recovery from incidents | Security / Common Criteria - System Operations | 13 | Substantially Addressed |
| CC8.1 | Authorized and controlled changes | Security / Common Criteria - Change Management | 2 | Partially Addressed |
| CC9.1 | Risk mitigation activities | Security / Common Criteria - Risk Mitigation | 2 | Partially Addressed |
| CC9.2 | Vendor and business-partner risk | Security / Common Criteria - Risk Mitigation | 2 | Partially Addressed |
| A1.1 | Capacity and availability commitments | Availability | 2 | Partially Addressed |
| A1.2 | Environmental protections and recovery infrastructure | Availability | 2 | Partially Addressed |
| A1.3 | Recovery plan testing | Availability | 3 | Partially Addressed |
| PI1.1 | Processing objectives and specifications | Processing Integrity | 0 | Not Addressed |
| PI1.2 | Input completeness and accuracy | Processing Integrity | 11 | Substantially Addressed |
| PI1.3 | Processing completeness and accuracy | Processing Integrity | 12 | Substantially Addressed |
| PI1.4 | Output completeness and accuracy | Processing Integrity | 14 | Substantially Addressed |
| PI1.5 | Data storage integrity | Processing Integrity | 14 | Substantially Addressed |
| C1.1 | Identification and protection of confidential information | Confidentiality | 0 | Not Addressed |
| C1.2 | Confidential information disposal | Confidentiality | 0 | Not Addressed |
| P1.1 | Privacy notice and communication | Privacy | 2 | Partially Addressed |
| P2.1 | Choice and consent | Privacy | 2 | Partially Addressed |
| P3.1 | Collection limitation | Privacy | 1 | Indirectly Supported |
| P3.2 | Collection from third parties | Privacy | 1 | Indirectly Supported |
| P4.1 | Use limitation | Privacy | 5 | Substantially Addressed |
| P4.2 | Retention | Privacy | 5 | Substantially Addressed |
| P4.3 | Disposal | Privacy | 7 | Substantially Addressed |
| P5.1 | Data-subject access | Privacy | 0 | Not Addressed |
| P6.1 | Disclosure to third parties | Privacy | 0 | Not Addressed |
| P6.2 | Third-party data handling agreements | Privacy | 0 | Not Addressed |
| P6.3 | Third-party monitoring | Privacy | 0 | Not Addressed |
| P6.4 | Unauthorized disclosure response | Privacy | 6 | Substantially Addressed |
| P6.5 | Data quality communication | Privacy | 7 | Substantially Addressed |
| P6.6 | Correction and amendment | Privacy | 8 | Substantially Addressed |
| P6.7 | Disclosure accounting | Privacy | 8 | Substantially Addressed |
| P7.1 | Privacy data quality | Privacy | 0 | Not Addressed |
| P8.1 | Privacy inquiry, complaint and dispute handling | Privacy | 1 | Indirectly Supported |
Annex A — Complete Mapping Register
| Record | GAISSF | TSC | Rel. | Confidence | Rationale / Gap |
|---|---|---|---|---|---|
| CRO031-MAP-0001 | D1-CTL-01 | CC7.5 — Recovery from incidents | P | Medium | GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination. |
| CRO031-MAP-0002 | D1-CTL-01 | CC7.4 — Incident response | P | Medium | GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination. |
| CRO031-MAP-0003 | D1-CTL-01 | CC7.3 — Security event evaluation | P | Medium | GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination. |
| CRO031-MAP-0004 | D1-CTL-01 | CC7.2 — Security event monitoring | P | Medium | GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination. |
| CRO031-MAP-0005 | D1-CTL-02 | PI1.5 — Data storage integrity | S | Medium | GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination. |
| CRO031-MAP-0006 | D1-CTL-02 | PI1.4 — Output completeness and accuracy | S | Medium | GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination. |
Annex B — Source Register
| Source | Role | Status |
|---|---|---|
| GAISSF-NOR-001 v1.0 | Framework and conformance baseline | Normative |
| GAISSF-NOR-004 v1.0 | Authoritative 59-control catalogue | Normative |
| 2017 Trust Services Criteria, revised points of focus 2022 | Primary criterion baseline | AICPA criteria |
| 2018 SOC 2 Description Criteria, revised implementation guidance 2022 | System-description layer | Separate from criterion mapping |
| SOC 2 Guide and attestation standards | Examination and reporting layer | Independent practitioner application |
Limitations and Reliance Notice
Mapping is not a SOC 2 report, attestation, certification, readiness conclusion, or CPA opinion.
The Security category is generally common to SOC 2 engagements; selection of Availability, Processing Integrity, Confidentiality, and Privacy depends on engagement scope.
The 2018 SOC 2 Description Criteria and management system description must be addressed separately.
Type I and Type II conclusions depend on independent examination procedures and evidence.
Points of focus are implementation guidance and are not a separate checklist of mandatory controls.
AICPA copyrighted criteria must be used under applicable terms; this publication uses identifiers and concise functional summaries.
© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. AICPA, SOC 2 and related names and materials remain the property of their respective owners. No endorsement, affiliation or assurance conclusion is implied.