Skip to main content
Category: Technical Security Controls

Cryptography

Also known as: Cryptology
Simply put

Cryptography is the practice of protecting information by transforming it so that only intended parties can read or verify it. It uses mathematical techniques and algorithms to keep data secure both when it is being transmitted and when it is stored. In practice, it helps prevent unauthorized access to sensitive information and supports secure communication.

Formal definition

Cryptography is the science and practice of information hiding and verification, encompassing the protocols, algorithms, and methodologies used to secure communication and protect data at rest and in transit against adversarial behavior. Drawing on mathematics and computer science, it applies encryption and related mathematical techniques to prevent unauthorized access, preserve confidentiality and integrity, and enable authentication. Within compliance contexts, cryptographic measures are typically implemented as one of several technical controls; specific requirements and their evaluation depend on the applicable criteria, scope, and framework (for example, the relevant Trust Services Criteria under a SOC 2 examination or the applicable Annex A reference controls selected via an ISO/IEC 27001 Statement of Applicability), and the presence of cryptographic controls does not by itself guarantee against compromise.

Why it matters

Cryptography is one of the foundational technical controls for protecting the confidentiality and integrity of information, whether that information is moving across a network or sitting in storage. Because it uses mathematical techniques to render data unreadable to unintended parties, it is a primary means of preventing unauthorized access to sensitive information and of supporting secure communication in the presence of adversarial behavior. For organizations undergoing a SOC 2 examination or pursuing ISO/IEC 27001 certification, cryptographic measures are frequently among the controls that auditors and certification bodies expect to see evaluated, though the specific expectations depend on scope and the applicable criteria.

In a SOC 2 context, cryptographic controls are typically assessed as part of the Common Criteria (Security) and, where relevant to scope, categories such as Confidentiality. Under ISO/IEC 27001, cryptography appears among the Annex A reference controls, which are selected through the Statement of Applicability and informed by the organization's risk assessment rather than applied uniformly. In both frameworks, the depth and manner of evaluation vary by auditor, certification body, and the defined scope of the engagement, so the way a given cryptographic control is scoped and tested is not fixed across engagements.

It is important to recognize the limits of what cryptography provides. The presence of cryptographic controls does not by itself guarantee against compromise; keys can be mishandled, algorithms can be misconfigured or become outdated, and controls that exist on paper may not operate effectively in practice. This is why a SOC 2 Type II examination assesses operating effectiveness over a defined period rather than mere design, and why ISO/IEC 27001 ties control selection to ongoing risk assessment. A SOC 2 report attests only to the controls and period covered, and an ISO/IEC 27001 certificate covers only the defined ISMS scope, so neither should be read as an assurance that encrypted data can never be breached.

Who it's relevant to

Security Engineers and Architects
Those responsible for designing and operating systems apply cryptography to protect data in transit and at rest, using algorithms and encryption methods to prevent unauthorized access and support authentication. They are typically responsible for ensuring that cryptographic controls are configured and operating in a way that can withstand audit scrutiny, recognizing that implementation details, not just the presence of encryption, determine effectiveness.
Compliance Managers and GRC Professionals
In SOC 2 and ISO/IEC 27001 programs, these professionals map cryptographic measures to the applicable criteria, for example, the relevant Trust Services Criteria under a SOC 2 examination or the Annex A reference controls selected through an ISO/IEC 27001 Statement of Applicability. They must account for the fact that requirements depend on scope and framework, and that cryptographic controls form one part of a broader control environment rather than a guarantee against compromise.
Auditors and Assessors
CPA firms performing a SOC 2 examination and certification bodies assessing an ISO/IEC 27001 ISMS evaluate cryptographic controls according to the defined scope and applicable criteria. In a SOC 2 Type II engagement this includes assessing operating effectiveness over the defined review period, while under ISO/IEC 27001 the assessment considers how selected Annex A controls are justified via the Statement of Applicability and the underlying risk assessment. The manner and depth of evaluation vary by engagement.

Inside Cryptography

Encryption at Rest
Protection of stored data using cryptographic algorithms so that data on disks, databases, or backups remains unreadable without the appropriate keys. Whether and how this is implemented depends on scope and the risk assessment for a given engagement or ISMS.
Encryption in Transit
Protection of data moving across networks, typically through transport-layer protocols, to prevent interception or tampering. The specific protocols and configurations are determined by scoping decisions rather than a single mandated approach.
Key Management
The lifecycle processes for generating, distributing, storing, rotating, and destroying cryptographic keys. Effective key management is generally considered central to the reliability of any cryptographic control, since weak key handling can undermine otherwise strong encryption.
Cryptographic Controls under the Trust Services Criteria
In a SOC 2 examination, cryptography is commonly addressed within the Security category (the Common Criteria), and may also be relevant to Confidentiality where that optional category is in scope. The Trust Services Criteria describe control objectives rather than prescribe specific algorithms.
Cryptographic Controls under ISO 27001
ISO/IEC 27001 addresses cryptography through reference controls in Annex A, which are selected via the Statement of Applicability and informed by risk assessment. The certifiable requirements themselves reside in clauses 4 through 10; Annex A controls are chosen based on applicability. Control numbering and grouping differ between the 2013 and 2022 revisions, so the version should be specified when citing a particular control.
Policy on the Use of Cryptography
A documented approach describing when and how cryptographic controls are applied across the organization. In most engagements, auditors and certification bodies expect such practices to be defined and consistently followed, though the exact form depends on scope and applicable criteria.

Common questions

Answers to the questions practitioners most commonly ask about Cryptography.

Does implementing cryptography make my organization SOC 2 or ISO 27001 compliant?
No. Cryptography is one control area among many and does not by itself satisfy either framework. In a SOC 2 examination, encryption-related controls are evaluated against the applicable Trust Services Criteria, with Security (the Common Criteria) always in scope and categories such as Confidentiality selected depending on scope. In ISO 27001, cryptographic controls appear among the Annex A reference controls, but certification is granted against the ISMS requirements in clauses 4 through 10. Whether and how cryptography is applied depends on your risk assessment, scope, and the judgment of the auditor or certification body, so no single control is universally mandatory unless the standard itself requires it.
Is a specific encryption algorithm or key length required by SOC 2 or ISO 27001?
Neither framework prescribes a fixed algorithm or key length as a universal rule. SOC 2 assesses whether the controls you have defined are suitably designed and, in a Type II engagement, operating effectively over the review period; the specifics are informed by scoping decisions and auditor judgment. ISO 27001 treats cryptography as a reference control selected through the Statement of Applicability and informed by risk assessment. In most engagements, organizations reference recognized industry practice, but the appropriate choice depends on your scope, risk context, and applicable criteria rather than a mandated value stated in the standard.
How is cryptography evaluated differently in a SOC 2 Type I versus a Type II engagement?
In a SOC 2 Type I, cryptographic controls are assessed for suitability of design at a point in time, that is, whether they are designed appropriately to meet the applicable criteria. In a Type II, the same controls are assessed for both design and operating effectiveness over a defined review period, the length of which varies and is set by scoping decisions rather than fixed by the standard. A Type II therefore typically involves evidence that cryptographic controls functioned consistently throughout the period, not merely that they existed.
Where do cryptographic controls fit within the ISO 27001 structure?
The certifiable requirements of ISO 27001 sit in clauses 4 through 10, which define the ISMS. Cryptographic controls appear among the Annex A reference controls, which are selected via the Statement of Applicability and informed by your risk assessment. Note that Annex A was restructured in the 2022 revision into four themes, so the exact placement and grouping of cryptography-related controls depends on the edition you are working against; specify the version when citing any control detail. Implementation guidance beyond the reference control list is commonly drawn from ISO 27002.
Does having strong cryptography mean my data is guaranteed safe under either framework?
No. A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches. An ISO 27001 certificate covers only the defined scope of the ISMS. Cryptographic controls, even where well designed and operating effectively, address specific risks within those boundaries and do not represent an assurance that data cannot be compromised. Both frameworks describe controls and their assessment, not an absolute security outcome.
If I address cryptography for SOC 2, does that automatically satisfy ISO 27001, or vice versa?
Not automatically. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one framework does not automatically satisfy the other. Cryptographic controls implemented for SOC 2 are evaluated against the applicable Trust Services Criteria, while under ISO 27001 they are selected and evidenced through the Statement of Applicability and the ISMS requirements. Organizations pursuing both typically maintain a mapping but should expect gaps that depend on scope, applicable criteria, and the judgment of the auditor or certification body.

Common misconceptions

Implementing encryption automatically satisfies a specific control in both SOC 2 and ISO 27001.
Cryptographic controls are evaluated differently under each framework. SOC 2 assesses cryptography against the applicable Trust Services Criteria as part of a CPA attestation, while ISO 27001 evaluates it through Annex A reference controls selected via the Statement of Applicability. Mapping between the two is partial, and satisfying cryptographic expectations in one framework does not automatically satisfy the other.
Strong encryption alone guarantees data is protected and free from breaches.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches; an ISO 27001 certificate covers only the defined scope of the ISMS. Cryptography without sound key management and supporting processes may leave meaningful gaps, and no single control guarantees security.
A specific algorithm or key length is universally mandated by both frameworks.
Neither framework generally prescribes a single mandatory algorithm or configuration. Appropriate cryptographic choices depend on the auditor, certification body, scope, risk assessment, and applicable criteria, so requirements are better expressed as depending on scope rather than as fixed universal rules.

Best practices

Define a documented approach to the use of cryptography and apply it consistently, since auditors and certification bodies typically expect defined and repeatable practices.
Address encryption for data both at rest and in transit according to the risk assessment and the scope of the SOC 2 examination or ISMS certification.
Establish robust key management covering generation, storage, rotation, and destruction, as weak key handling can undermine otherwise strong encryption.
Where using ISO 27001, select cryptographic controls through the Statement of Applicability informed by risk assessment, and specify the standard version (2013 or 2022) when referencing particular controls to avoid ambiguity.
For SOC 2, confirm which Trust Services Criteria categories are in scope, recognizing that cryptography is commonly relevant to the required Security category and, where selected, the optional Confidentiality category.
Do not assume cryptographic controls satisfy both frameworks at once; treat any mapping between SOC 2 and ISO 27001 as partial and validate coverage against each framework's applicable criteria.