What I did. Mapped each control to the specific cloud services and configurations implementing it. Ran a gap analysis against the framework, then built the change-management policy, security architecture documentation and IAM access-review cycle needed to close what was missing. Packaged it as an evidence pack an assessor can open.