By Dr Joshua Scarpino
Most organizations do not have a compliance problem. They have a coordination problem that presents as a compliance problem. The security team runs the SOC 2. A separate workstream stands up ISO 27001. When CMMC arrives, a project team forms around it, often with its own consultants and its own timeline. When the EU AI Act lands on the roadmap, another effort begins. Each of these programs is competent on its own terms. Together, they do a large share of the same work several times over, and they leave gaps precisely where the work should connect.
This is the pattern worth naming, because the cost of it is rarely visible on any single invoice. The requirements these frameworks impose overlap heavily. The teams pursuing them do not. Requirements that align are driven toward separate outcomes by separate frameworks, and the effort fragments into parallel tracks that neither share evidence nor reconcile their results.
The work overlaps; the teams do not
The overlap is not a matter of opinion, and it is not marginal. ISO 27001 defines 93 controls in its Annex A. CMMC Level 2, the tier that governs contractors handling Controlled Unclassified Information, comprises 110 security requirements mapped directly to NIST SP 800-171.1 Analysis of ISO 42001, the AI management system standard, against a mature ISO 27001 program finds that roughly 60 to 70 percent of existing ISO 27001 controls apply directly to AI governance needs.2 These frameworks were written by different bodies for different audiences, and they still ask for the same operational behaviors: access control based on need-to-know, documented and tested incident response, recurring risk assessment, security awareness training, configuration management, and written policy governing each.1
When each framework is run as its own program, that shared substance gets rebuilt every time. One team documents the access control policy for the SOC 2. Another team documents what is substantially the same access control policy for CMMC, in a different vocabulary, against a different control identifier, on a different schedule. A third does it again for the AI governance effort. The control is one control. The organization pays to describe it, evidence it, and defend it three times, and it assigns three teams to do so.
The duplication is easiest to see at the point where the organization is asked to prove itself. A single security questionnaire takes 12 to 18 person-hours to complete across the teams it touches, and the larger instruments run past a thousand questions.3 Organizations that field these at volume report spending six figures annually on questionnaire labor.3 Much of that labor re-answers questions that a current SOC 2 report or ISO certificate has already settled, because the answer lives inside one program and the question arrives at another. The information exists. It simply has no shared home.
Parallel programs multiply cost and calendar
The financial signature of fragmentation is repetition. Preparing for and completing a SOC 2 audit runs from roughly $25,000 for a small organization to over $200,000 for a large enterprise, with annual maintenance adding a further $15,000 to $40,000.4 Those figures describe one framework, executed once. An organization that stands up an independent effort for each new requirement does not pay that cost a single time; it pays a version of it for every program it runs in parallel, and it pays in project-team hours as much as in fees.
The calendar compounds the same way. Each separate program carries its own readiness assessment, its own evidence-gathering cycle, its own audit preparation, and its own remediation backlog. Work that could be performed once and presented in several forms is instead performed several times in sequence, so the organization is perpetually mid-project on something. The people doing this work are capable; the structure they work within guarantees that their effort is spent more than once.
Disjointed efforts create gaps, not only cost
Duplication is the visible failure. The more serious failure is the gap. When aligned requirements are driven by separate frameworks, the seams between those programs become territory that no team clearly owns.
A control implemented for one framework and assumed to satisfy another is a common source of these seams. ISO 27001 and CMMC overlap substantially, but CMMC Level 2 requires specific handling of Controlled Unclassified Information and certain federal encryption standards that ISO 27001 does not explicitly demand.1 An organization that assumes its ISO program covers CMMC will find that most of it does and a critical portion does not, and the portion that does not is exactly the portion that determines eligibility to win the contract. The same holds between security frameworks and AI governance: ISO 42001 provides much of the management-system structure the EU AI Act expects, but it does not cover conformity assessment procedures or database registration obligations, which are legal requirements rather than operational controls.2 Coverage assumed across a seam is coverage not delivered.
Fragmentation produces a second kind of gap, which is inconsistency. When separate teams implement the same control against different framework language, they produce different versions of it. The access control described in the SOC 2 report and the access control described in the CMMC assessment are supposed to be the same control operating in the same environment. Under parallel programs they drift, and the drift surfaces at the worst possible moment: during an audit, a customer review, or an incident, when the organization must show that its evidence reconciles and discovers that it does not.
New requirements magnify the fragmentation
The requirements are not slowing, which is why the structure matters now rather than later. CMMC became effective on November 10, 2025, and phases in across defense contracts through 2028; certification by an accredited third party becomes a condition of award for contracts involving Controlled Unclassified Information.5 The EU AI Act is arriving on a staged timeline of its own: prohibitions on certain practices have applied since February 2, 2025, general-purpose AI obligations since August 2, 2025, and the obligations for high-risk systems under Annex III, originally set for August 2, 2026, were postponed to December 2, 2027 under the Digital Omnibus that the Council approved on June 29, 2026.6 Non-compliance carries penalties of up to 35 million euros or seven percent of worldwide annual turnover.7
Each new requirement, met as a new program, adds another parallel track to an organization already running several. It adds another team, another vocabulary for the same controls, another evidence set that does not reconcile with the others, and another set of seams where coverage is assumed rather than proven. Fragmentation does not stay constant as requirements accumulate. It grows with them.
Unify the work, not just the paperwork
The alternative is not a bigger compliance budget or a larger project team. It is a single control foundation where every requirement has a defined home, so that a control is implemented once and mapped to many frameworks rather than rebuilt for each. This is why we built the ARISE Framework™. Its seven domains, GOVERN, MANAGE, IDENTIFY, PROTECT, DETECT, RESPOND, and VALIDATE, give every obligation a place to land, so that one implementation of access control, one incident response process, and one risk cadence satisfy SOC 2, ISO 27001, CMMC, ISO 42001, and the EU AI Act at the same time.
Under a unified foundation, the work is done once and proven many ways. A single team maintains one version of each control rather than several teams maintaining several. Evidence is gathered once and presented in the form each framework expects. When a new requirement arrives, the question is not which program to start; it is which genuine gaps remain against a foundation the organization already operates. The overlapping work collapses into one effort, and the seams that produced gaps disappear because there is no longer a boundary between programs for coverage to fall through.
Organizations that already hold an ISO 27001 certification or a mature SOC 2 program enter this model with equity. The controls they operate today satisfy a large share of what the next framework will ask; unification makes that existing work provable everywhere it applies, rather than trapped inside the single program that produced it.
The choice is not between more compliance and less. It is between doing the work once and doing it repeatedly while leaving gaps in between. If a new framework just landed on your desk, decide whether it is a program to start or a delta to close before you assign a team and a budget to it.
Speak with an advisor first: assessedintelligence.com/contact.
Secure & Responsible Technology.
References
Footnotes
- Secureframe, “A Side-by-Side Comparison of CMMC 2.0, SOC 2, and ISO 27001.” https://secureframe.com/blog/cmmc-soc-2-iso-27001 ↩ ↩2 ↩3
- Truvo Cyber, “ISO 42001 and the EU AI Act: What Actually Maps and What Doesn’t.” https://truvocyber.com/blog/iso-42001-and-eu-ai-act ↩ ↩2
- Wolfia, “Security Questionnaires: Complete 2026 Guide.” https://wolfia.com/blog/security-questionnaires-complete-guide ↩ ↩2
- Drata, “How Much Does a SOC 2 Audit Cost?” https://drata.com/learn/soc-2/cost ↩
- U.S. Federal Register, “Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041),” effective November 10, 2025. https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of. Phased rollout detail: Scrut Automation, “The CMMC Final Rule.” https://www.scrut.io/hub/cmmc/final-rule ↩
- Council of the EU, “Artificial Intelligence: Council gives final green light to simplify and streamline rules,” June 29, 2026. https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/ ↩
- Legiscope, “EU AI Act Deadlines 2026-2027: Compliance Calendar and Fines.” https://www.legiscope.com/blog/eu-ai-act-timeline-deadlines.html ↩
