We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance and regulation
US IT compliance hub

Which compliance framework applies to your business? It depends on your sector, your contracts, and your customers.

There is no single US IT compliance checklist, and anyone selling you one is selling a template. Your obligations come from three directions at once: what sector you operate in (HIPAA for health data, GLBA and the FTC Safeguards Rule for financial data), what your contracts require (CMMC for the defense supply chain, SOC 2 for enterprise customers, PCI DSS for card payments), and which states your customers live in (CCPA and CPRA in California, plus a growing list of state privacy laws). This page maps every framework we cover, tells you in one line who each applies to, and links to the detailed page where one exists. If you already know your framework, jump straight to it. If you do not, the decision section below gets you there in a minute.

Get a compliance scopeFind your framework
Compliance frameworks governing IT for US businesses
  • Scope-ledMapped to your obligations
  • 5 minP1 remote response
  • One setControls mapped to every framework
  • FreeInitial scoping call
What compliance actually demands from IT

Six things every framework asks for, whatever the acronym.

The frameworks differ in scope, language, and enforcement, but the technical substance overlaps heavily. Whichever regulation applies to you, the work lands in the same six places, which is why one well-built control set can serve several frameworks at once.

Know what data you hold and where it lives

Every data protection regime starts here: what personal, health, financial, or controlled data you process, why, where it is stored, who can reach it, and where the copies sit including backups. Most businesses cannot answer this on day one, and most findings trace back to that gap. A data inventory turns the question into an export.

Access control that survives an audit

Multi-factor authentication enforced rather than merely available, administrator accounts separated from daily accounts, joiner and leaver processes documented and followed, and dormant accounts removed. Assessors under every framework check this first because it is where breaches actually start.

Monitoring and the ability to detect an incident

Frameworks increasingly assume you will detect your own incidents rather than hear about them from a customer. That means logging that is retained, alerting that a human reviews, and an answer to the question of who noticed and when. HIPAA, the FTC Safeguards Rule, and NIST 800-171 all make this explicit.

A breach response you have rehearsed

HIPAA carries notification duties, every state has a breach notification statute, and cyber insurance policies impose their own reporting clocks. The difference between a controlled notification and a scramble is a written plan, named owners, and at least one rehearsal before the real event. We build and test the plan so the clock starts on a process rather than a panic.

Evidence, kept current, not assembled under deadline

Having controls and having proof of controls are different things, and assessments fail on the second one as often as the first. Policies, configurations, test results, training records, and restore evidence maintained continuously turn an auditor, insurer, or enterprise customer request into an export rather than a fortnight of archaeology.

People who know what the rules require of them

Awareness training, an acceptable use policy people have actually read, and clear ownership of compliance duties inside the business. HIPAA expects a named security official, the FTC Safeguards Rule expects a designated qualified individual, and SOC 2 auditors ask who owns each control.

The frameworks we cover

Find your framework, grouped by who imposes it.

One line on who each applies to, and a dedicated page behind each link where one exists. If you are not sure which of these reaches you, the decision section further down this page narrows it by sector and customer base, and the scoping call settles it for free.

Government and defense contracting

Frameworks that arrive through federal contracts and flow down the supply chain. If you sell to the Department of Defense or to federal agencies, directly or through a prime, these pages are yours.

  • CMMC compliance servicesThe DoD cybersecurity maturity model, built on NIST 800-171, flowing down to every contractor handling controlled unclassified information.
  • FedRAMP readinessThe authorization path for cloud products sold to federal agencies, and the readiness work before the formal assessment.

Financial data rules

If your business handles consumer financial data, lending, dealerships, tax preparation, advisory, the FTC Safeguards Rule under GLBA reaches you, and it is broader than most owners expect.

  • GLBA complianceThe Safeguards Rule: a written security program, a designated qualified individual, MFA, encryption, and monitoring for financial institutions broadly defined.

State privacy laws

Consumer privacy rights imposed by states, led by California. Applicability turns on revenue and data volume thresholds, not on where your office is.

  • CCPA and CPRA complianceCalifornia consumer privacy rights: data inventories, subject requests, opt-outs, and the security obligations behind them.

Assessment and audit

The engagements that establish where you actually stand, in writing, against the frameworks that apply to you.

  • Cybersecurity audit and complianceThe audit that starts most engagements: where you stand today against HIPAA, SOC 2, NIST, CMMC, or whatever applies, verified in the environment rather than in interviews.

The Microsoft compliance stack

Most US businesses already license part of the tooling their framework demands. These pages cover deploying it properly instead of buying something new.

  • Microsoft PurviewData classification, DLP, and retention: the technical spine of HIPAA, GLBA, and privacy law obligations.
  • Microsoft PrivaPrivacy risk management and subject rights requests, the operational side of CCPA and CPRA.
  • Compliance ManagerFramework assessments and improvement actions tracked inside the tenant you already run.
  • Microsoft SentinelThe logging and detection layer that satisfies the monitoring clauses in nearly every framework.
  • Tenant security baselineThe hardened Microsoft 365 configuration that most framework controls assume as a starting point.

Resilience obligations

Every serious framework, and every cyber insurance policy, asks the same two questions: can you restore, and how fast.

  • Data backupBackup designed around restore tests and retention rules, including Microsoft 365 data.
  • Disaster recovery and business continuityThe recovery plan and the rehearsal that HIPAA contingency planning and insurer questionnaires expect.
Why businesses run compliance through us

Four reasons this works better than a policy pack.

We map obligations before we quote controls

The first conversation is about your sector, your contracts, and your customers, because that is what determines which regimes reach you. Scoping by company size alone is how providers sell a SOC 2 project to a business whose actual deadline is a CMMC assessment. You get the map in writing, including the regimes we think do not apply to you and why.

We implement, not just document

A policy that says MFA is enforced while the tenant says otherwise fails the audit and, worse, fails the breach. We are an IT and security provider first, so the controls get built in your actual environment: identity, endpoints, logging, backup, mail authentication. The documents describe a real state instead of an aspiration.

One control set, mapped to every framework you face

Most of our compliance clients answer to more than one regime at once: a sector rule, a contractual framework a customer imposed, and the insurer's questionnaire. We build the control set once and maintain a mapping to each framework, so a SOC 2 audit, an insurance renewal, and a customer security review all draw from the same living evidence.

We stand next to you at the review

Audits and assessor interactions go better with the people who built the controls in the room. We prepare the evidence pack, sit in the sessions where you want us, handle the technical questions, and turn findings into a remediation plan with owners and dates rather than a PDF that gets filed.

Also covered, no dedicated page yet

Frameworks we work with that do not have their own page yet.

A dedicated page exists where we can write something genuinely useful. These frameworks are fully covered in our audit and remediation work today, scoped and evidenced through the cybersecurity audit engagement, and several are candidates for their own page.
  • HIPAA

    The Security and Privacy Rules for covered entities and their business associates: risk analysis, safeguards, and breach notification.

  • SOC 2

    The audit report enterprise customers demand from vendors: trust services criteria, evidenced over time by an independent CPA firm.

  • NIST Cybersecurity Framework

    The maturity baseline boards and insurers reference, and a sensible structure for any security program.

  • NIST 800-171

    The control set underneath CMMC, applying through DFARS clauses to contractors handling controlled unclassified information.

  • PCI DSS

    Required by the card schemes for any business that stores, processes, or transmits cardholder data, whatever its size.

  • State privacy laws beyond California

    Virginia, Colorado, Connecticut, Texas, and a growing list of states with their own consumer privacy statutes.

  • Cyber insurance questionnaires

    Not a law, but the assessment most SMBs actually face first: MFA, EDR, backup, and logging as conditions of coverage.

  • FERPA

    Student education records protection for schools and the vendors that serve them.

  • SOX IT general controls

    Access, change, and operations controls for public companies and businesses preparing for a listing or acquisition.

Who this hub is for

The six situations that bring businesses here.

Healthcare providers and health-tech vendors

Clinics, practices, and the SaaS and billing vendors that serve them, all inside HIPAA through the covered entity or business associate route. The risk analysis is the starting point OCR asks for first, and most businesses have never done one properly.

Defense contractors facing CMMC

Machine shops, engineering firms, and software vendors with DFARS clauses in their contracts. Scoping where controlled unclassified information actually lives, then building the 800-171 controls around that enclave, is usually far cheaper than treating the whole company as in scope.

SaaS businesses selling upmarket

The deal is waiting on a security review. SOC 2 is the unlock, a privacy-law readiness answer is the follow-up question, and if federal agencies are on the roadmap, FedRAMP readiness is the one after that.

Financial businesses under the Safeguards Rule

Lenders, dealerships, mortgage and tax practices that discovered the FTC Safeguards Rule applies to them. The rule names specific controls, MFA, encryption, monitoring, a qualified individual, and the gap between the rule and a typical small office is real but closeable.

Retail and ecommerce taking card payments

The acquirer asks for PCI DSS evidence and the honest answer is nobody has looked. Scoping down what actually touches card data usually shrinks the problem dramatically before any control work starts.

Firms whose insurer or big customer is asking questions

Cyber insurance renewals and supplier security assessments impose more compliance work on US SMBs in practice than regulators do. The questionnaire is long, the deadline is short, and the answers have to be true.

Which applies to me?

Narrow it down by what you do and who your customers are.

Start with your sector, then add your contracts, then add your customers. Most businesses end up with one primary regime, one or two contractual frameworks, and the insurer's questionnaire on top. The combinations below cover the common cases; the scoping call covers yours specifically.

By what you do

  • Healthcare providers and their vendors
    HIPAA applies to covered entities and, through business associate agreements, to the IT firms, billing companies, and SaaS vendors that touch protected health information. A signed BAA without the controls behind it is a liability, not a shield.
  • Defense supply chain
    DFARS clauses in your contracts pull in NIST 800-171 today and CMMC assessment requirements as the program phases in. The obligation flows down from primes to subcontractors, and scoping where controlled unclassified information actually lives usually shrinks the problem.
  • Financial services, broadly defined
    The FTC Safeguards Rule under GLBA reaches lenders, auto dealerships, mortgage brokers, tax preparers, and advisors, not just banks. It requires a written program, a designated qualified individual, MFA, encryption, and monitoring.
  • Anyone taking card payments
    PCI DSS applies through your acquirer whatever your size. Scoping down what actually touches card data usually shrinks the problem dramatically before any control work starts.

By who your customers are

  • Selling to enterprises
    Enterprise procurement asks for SOC 2 before regulators ask for anything. The report takes months because the controls must operate over a period before they can be audited, so start before the deal that needs it.
  • Selling to federal agencies
    Cloud products sold to federal agencies need FedRAMP authorization, and the readiness work is most of the journey. Selling to the DoD brings CMMC instead of, or on top of, FedRAMP.
  • Consumers in California and other privacy-law states
    CCPA and CPRA applicability turns on revenue and data volume thresholds. If you meet them, subject requests, opt-outs, and vendor contract terms become operational duties, and other state laws add their own variations.
  • Anyone renewing cyber insurance
    The questionnaire assumes MFA everywhere, EDR on endpoints, tested backup, and logging. Answers get verified at claim time, so the controls have to be real, not aspirational.
The five we get asked about most

HIPAA, SOC 2, CMMC, CCPA and CPRA, and PCI DSS, side by side.

These five come up in almost every scoping call. The table shows how differently they behave: who they reach, who enforces them, and what kind of deadline they carry. Penalties are described in kind rather than in figures, because the figures change and the useful question is what category of consequence you are exposed to.
What it is
HIPAAFederal health data law
SOC 2Independent audit framework
CMMCDoD contractor certification program
CCPA / CPRACalifornia consumer privacy law
PCI DSSCard industry security standard
Generally applies to
HIPAACovered entities and business associates handling PHI
SOC 2Vendors whose customers demand the report
CMMCDefense contractors and subcontractors handling CUI
CCPA / CPRABusinesses meeting revenue or data thresholds with California consumers
PCI DSSAny business handling cardholder data
Mandatory or voluntary
HIPAALaw
SOC 2Voluntary, required by contract in practice
CMMCContractual, via DoD contract clauses
CCPA / CPRALaw, where its thresholds apply
PCI DSSContractual, via the card schemes and your acquirer
Overseen or enforced by
HIPAAHHS Office for Civil Rights
SOC 2Independent CPA firms
CMMCThe DoD, via authorized assessors
CCPA / CPRAThe California Privacy Protection Agency and attorney general
PCI DSSCard schemes, via acquirers and assessors
Deadline style
HIPAAOngoing legal duty with breach notification clocks
SOC 2Audit period, then annual renewal
CMMCAssessment before contract award, then maintenance
CCPA / CPRAOngoing duty with response windows for consumer requests
PCI DSSAnnual validation plus quarterly requirements
Typical trigger for a US business
HIPAATouching patient data, directly or as a vendor
SOC 2An enterprise deal stalls on a security review
CMMCA DFARS clause appears in a contract or flow-down
CCPA / CPRAGrowth past the thresholds, or a customer asking
PCI DSSYour acquirer or payment provider requires evidence
Consequence style, described without figures
HIPAACivil penalties, corrective action plans, reputational harm
SOC 2Failed or qualified report, lost enterprise deals
CMMCIneligibility for contracts, lost awards
CCPA / CPRAAdministrative fines per violation, private actions after breaches
PCI DSSFines via the schemes, higher fees, loss of card acceptance
What IT must show
HIPAARisk analysis, safeguards, access control, breach response
SOC 2Controls operating over time across the trust criteria
CMMCThe NIST 800-171 control set, evidenced and scored
CCPA / CPRAData inventory, request handling, reasonable security
PCI DSSSegmented card data, hardening, logging, testing
Feature
HIPAA
SOC 2
CMMC
CCPA / CPRA
PCI DSS
What it is
Federal health data lawIndependent audit frameworkDoD contractor certification programCalifornia consumer privacy lawCard industry security standard
Generally applies to
Covered entities and business associates handling PHIVendors whose customers demand the reportDefense contractors and subcontractors handling CUIBusinesses meeting revenue or data thresholds with California consumersAny business handling cardholder data
Mandatory or voluntary
LawVoluntary, required by contract in practiceContractual, via DoD contract clausesLaw, where its thresholds applyContractual, via the card schemes and your acquirer
Overseen or enforced by
HHS Office for Civil RightsIndependent CPA firmsThe DoD, via authorized assessorsThe California Privacy Protection Agency and attorney generalCard schemes, via acquirers and assessors
Deadline style
Ongoing legal duty with breach notification clocksAudit period, then annual renewalAssessment before contract award, then maintenanceOngoing duty with response windows for consumer requestsAnnual validation plus quarterly requirements
Typical trigger for a US business
Touching patient data, directly or as a vendorAn enterprise deal stalls on a security reviewA DFARS clause appears in a contract or flow-downGrowth past the thresholds, or a customer askingYour acquirer or payment provider requires evidence
Consequence style, described without figures
Civil penalties, corrective action plans, reputational harmFailed or qualified report, lost enterprise dealsIneligibility for contracts, lost awardsAdministrative fines per violation, private actions after breachesFines via the schemes, higher fees, loss of card acceptance
What IT must show
Risk analysis, safeguards, access control, breach responseControls operating over time across the trust criteriaThe NIST 800-171 control set, evidenced and scoredData inventory, request handling, reasonable securitySegmented card data, hardening, logging, testing
The most common mistake

Treating compliance as a document rather than a running state.

The pattern we see most is a business that bought a policy pack, passed one review, and changed nothing operationally. A year later the controls have drifted, the evidence is stale, and the next request lands as a crisis. Three habits prevent it.

  • Map obligations once, properly. Most businesses are in scope of fewer regimes than they fear and more than they know. An hour of scoping against your sector, contracts, and customer base beats a year of guessing.
  • Build controls once, map them to every framework that applies. MFA, logging, backup, joiner-leaver discipline, and breach response serve HIPAA, SOC 2, CMMC, and the Safeguards Rule simultaneously. Doing the work per-framework doubles the cost for no gain.
  • Keep evidence continuously. The regimes that matter all assume you can show your state on demand. If proof takes two weeks to assemble, the controls may be fine but the review will not go well.
Get your obligations mapped
How a compliance engagement runs

Four steps from unsure to evidenced.

  1. 1

    Obligation mapping

    Week 1

    Sector, contracts, customers, card flows, and the states your customers live in. Out the other side comes a written map: which regimes apply, which do not and why, and which one has the nearest deadline. This is the step most businesses have never done and it changes everything after it.

  2. 2

    Gap assessment against what applies

    Weeks 1 to 3

    Your actual environment, assessed against the frameworks from the map. Every finding is verified in the tenant, on the endpoint, or in the configuration rather than taken from an interview, and severity reflects your real exposure, not a generic score.

  3. 3

    Remediation, worst first

    Weeks 2 to 8, scope dependent

    Close the gaps in risk order: identity and access first, then logging and backup, then the framework-specific items. Policies are written to describe the state we built, and staff get the training the regime expects.

  4. 4

    Evidence and maintenance

    Ongoing

    The evidence pack goes live and stays current: control status, test results, training records, restore proofs, data inventories. Audits, insurance renewals, and customer reviews become exports. Continuous monitoring catches drift before the next review does.

US compliance FAQ

The questions that decide what you actually need.

If you create, receive, maintain, or transmit protected health information on behalf of a covered entity, you are a business associate, and HIPAA applies to you directly, not just through your contract. That is the case for billing companies, IT providers, cloud vendors, and many SaaS products serving healthcare. The practical consequences are a signed business associate agreement, a documented risk analysis, the Security Rule safeguards implemented for real, and breach notification duties with clocks attached. Size does not exempt you; enforcement actions have reached very small organizations. The scoping call establishes whether you actually touch PHI, because plenty of vendors assume they do when a small architecture change would take them out of scope entirely.

Both attest that your security program works; they come from different traditions. SOC 2 is an audit report issued by a CPA firm against the trust services criteria, and it is what US enterprise procurement teams ask for by default. ISO 27001 is an international certification of a management system, and it carries more weight with multinational and European customers. If your customer base is primarily US enterprises, SOC 2 first. If you sell globally, some companies eventually hold both, because the underlying controls overlap heavily and the second one costs much less once the first exists. The honest starting question is: what have the customers who stalled deals actually asked for?

Treat it as real now. The obligations underneath CMMC are not new: DFARS clauses have required NIST 800-171 implementation and self-assessment scores for years, and false claims about compliance status carry legal risk today. CMMC adds third-party assessment requirements that are phasing into contracts, which is why primes are pressing subcontractors: they cannot win or renew work with a supply chain that will not assess cleanly. The sensible move is to scope where controlled unclassified information actually lives, shrink that footprint, implement 800-171 in the enclave, and get your score honest. Waiting until an assessment date is in a contract is how the work becomes a crisis.

They can. The law reaches businesses that collect personal information from California residents and meet its thresholds, which turn on revenue and on the volume of personal information processed, not on where the business is incorporated. An ecommerce company in Texas with a national customer base can be squarely in scope. And California is no longer alone: Virginia, Colorado, Connecticut, Texas, and a growing list of states have their own statutes with similar shapes and different details. The practical approach is one privacy program built on a real data inventory, with per-state deltas handled as a mapping layer, rather than a separate scramble per statute.

The questionnaire gets verified at exactly the wrong moment: after an incident, during the claim. Misstatements on the application are grounds for a carrier to deny coverage or rescind the policy, which converts an insurable event into an uninsured one. The right sequence is to treat the questionnaire as a gap list: implement MFA, EDR, tested backup, and logging first, then answer truthfully, and often the premium improves as a result. Where a control genuinely cannot be in place by renewal, insurers generally respond better to a dated remediation plan than to a discovered false answer. We prepare both the controls and the honest answers.

It depends on the regime, and we deliberately describe consequences in kind rather than quoting figures, because figures change and the category of exposure is what should drive your decisions. HIPAA violations bring civil penalties and corrective action plans from HHS OCR. Privacy law violations bring administrative fines per violation and, after breaches, private lawsuits. CMMC failures cost you contract eligibility, which for a defense supplier is the business itself. PCI failures arrive as fines passed through your acquirer and ultimately loss of card acceptance. And across all of them sits the commercial penalty: failed due diligence, lost enterprise deals, denied insurance claims, and strained banking relationships, which for most SMBs bite earlier and harder than any regulator does.

Yes, and it should, because running separate programs per framework doubles cost and creates contradictions. The structure that works is one control set, one evidence system, and one owner, with a per-framework mapping that records which controls satisfy which requirements and any deltas. The controls themselves, identity, logging, backup, breach response, training, barely differ between regimes, so most of the program is genuinely shared. The mapping layer is where the differences live, and keeping it explicit is what lets one audit serve several reviewers without anyone being told something untrue.

Scoping and gap assessment typically fit inside the first three weeks, and the critical remediation items usually close within the first two months for an SMB estate. Beyond that it depends on the finish line: readiness for an insurance renewal is measured in weeks, a SOC 2 report is measured in months because the controls must operate over a period before they can be audited, and CMMC timing depends on when assessments reach your contracts. Two honest cautions: any provider quoting one timeline before seeing your environment is guessing, and compliance is not a project that ends. The regimes that matter all assume a maintained state, which is why the evidence and monitoring step is ongoing rather than final.

More than most businesses use, and less than a vendor pitch implies. The platform carries real compliance tooling: Purview for classification, DLP, and retention, Priva for subject rights requests, Compliance Manager for framework tracking, Sentinel for logging and detection, and Entra for the access controls every framework demands. Deployed properly, that covers a large share of the technical controls in HIPAA, the Safeguards Rule, and 800-171. What it does not do is scope your obligations, write policies that match reality, train your people, run your risk analysis, or attend your audit. The honest framing: Microsoft sells the instruments; the program is still yours to run, and that is the part we deliver.
Related pages

Where to go next.

Cybersecurity audit and compliance

The audit that starts most engagements: your current state, in writing, against the frameworks that apply to you.

Learn more

Tenant security baseline

The hardened Microsoft 365 configuration most framework controls assume as a starting point.

Learn more

Managed IT services

The operating model that keeps controls and evidence current after the project ends.

Learn more
Compliance scoping

Tell us your sector and your customers, and we will tell you which frameworks actually apply.

A short call covering your sector, your contracts, your customer base, and any deadline already running. You get a written obligation map, including the regimes we believe do not apply to you and why. No charge for the scoping, and no program sold before the map exists.

Get a compliance scopeStart with the audit

Related Services

Explore more solutions that work great with this service

Compliance Manager

Regulatory compliance assessment tools

Learn more

Microsoft Purview

Data governance and compliance solutions

Learn more

Tenant Security Baseline

Documented controls mapped to CIS

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA