Skip to content
compliancebase

Theme comparison · access-control

Access control across frameworks

How logical access control shows up across SOC 2, ISO 27001, GDPR, and HIPAA — shared intent, different evidence shapes.

Frameworks covered: SOC 2, ISO/IEC 27001, GDPR, HIPAA

Key differences

DimensionSOC 2 / ISO (assurance)GDPR / HIPAA (legal)
Primary source of obligationSOC 2 CC6 criteria and ISO/IEC 27001:2022 Annex A access themes (customer attestation or certification artifacts)GDPR Article 32 technical and organisational measures and HIPAA Security Rule access controls at 45 CFR §164.312 (legal / regulatory duties)
Evidence shapePolicies, IdP configs, dated access reviews, MFA enforcement screenshots, joiner-mover-leaver tickets sampled over a Type II window or ISMS periodDocumented measures appropriate to risk (GDPR); HIPAA required vs addressable specifications with implementation or equivalent rationale on file
AudienceBuyers, CPA firms, and certification bodies evaluating a service organization or ISMSSupervisory authorities, covered entities, business associates, and contractual counterparties enforcing law — not interchangeable with a SOC 2 report
Failure modeSample exceptions, stale reviews, or system-description mismatches that qualify an attestation opinion or nonconformityRegulatory investigation, contractual breach, or OCR/EDPB scrutiny when access measures are missing, undocumented, or unjustified

Control overlap

Identity lifecycle, least privilege, MFA, encryption in transit, and periodic access reviews appear across SOC 2 CC6, ISO Annex A (for example A.5.15 / A.8.x themes), GDPR Article 32, and HIPAA §164.312. The operating system can be shared — one IdP, one review calendar, one remote-access pattern — while the vocabulary and artifacts differ. Map once in a crosswalk: control owner, evidence location, and which framework clause each artifact supports. Do not assume a SOC 2 sample set automatically satisfies HIPAA addressable documentation or GDPR accountability records.

Sequencing advice

Build one IAM and access-review operating rhythm first (usually against SOC 2 CC6.1–CC6.3 patterns), then annotate the same evidence for ISO SoA lines, GDPR Article 32 measures, and HIPAA required/addressable decisions. Avoid four parallel access programs with four review cadences. If you process PHI, complete HIPAA access and transmission decisions in parallel with SOC 2 — attestation does not replace the Security Rule. Start from /controls/soc-2/cc6-1 and expand outward; use /compare/soc-2-vs-iso-27001 for dual-track sequencing at the program level.

Frequently Asked Questions

The intent overlaps heavily — restrict who can reach systems and data — but the governing text, evidence language, and audit posture differ. Treat crosswalks as related requirements, not identical clauses. A dated IdP review may support SOC 2 and ISO, yet HIPAA may still need explicit required/addressable documentation for the same technical measure.

If you already have SOC 2 CC6.1 evidence, reuse it as the operational core and annotate gaps for ISO Annex A access themes, GDPR Article 32, and HIPAA §164.312. If you have no IAM program yet, stand up IdP MFA, joiner-mover-leaver tickets, and quarterly reviews before multiplying framework paperwork.

No. SOC 2 is an attestation against Trust Services Criteria. GDPR and HIPAA are legal regimes. Control work overlaps, but you still need accountability records (GDPR) and Security Rule implementation decisions (HIPAA) even with a clean Type II report.

Keep a single evidence store keyed by control owner and system, then tag which framework clauses each artifact supports. Prefer exports from systems of record (IdP, ticketing, cloud IAM) over one-off screenshots reinvented per framework questionnaire.

Program sequencing: /compare/soc-2-vs-iso-27001. Type I vs Type II inside SOC 2: /compare/soc-2-type-1-vs-type-2. Deep dives: /controls/soc-2/cc6-1 and related CC6 pages under this site’s SOC 2 hub.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)
  • ISO/IEC 27001ISO/IEC 27001:2022
  • GDPRRegulation (EU) 2016/679
  • HIPAA45 CFR Part 164

Last verified: July 2026 · Primary sources linked above