Which compliance framework applies to your business? It depends on your sector, your contracts, and your customers.
There is no single US IT compliance checklist, and anyone selling you one is selling a template. Your obligations come from three directions at once: what sector you operate in (HIPAA for health data, GLBA and the FTC Safeguards Rule for financial data), what your contracts require (CMMC for the defense supply chain, SOC 2 for enterprise customers, PCI DSS for card payments), and which states your customers live in (CCPA and CPRA in California, plus a growing list of state privacy laws). This page maps every framework we cover, tells you in one line who each applies to, and links to the detailed page where one exists. If you already know your framework, jump straight to it. If you do not, the decision section below gets you there in a minute.

- Scope-ledMapped to your obligations
- 5 minP1 remote response
- One setControls mapped to every framework
- FreeInitial scoping call
Six things every framework asks for, whatever the acronym.
Know what data you hold and where it lives
Every data protection regime starts here: what personal, health, financial, or controlled data you process, why, where it is stored, who can reach it, and where the copies sit including backups. Most businesses cannot answer this on day one, and most findings trace back to that gap. A data inventory turns the question into an export.
Access control that survives an audit
Multi-factor authentication enforced rather than merely available, administrator accounts separated from daily accounts, joiner and leaver processes documented and followed, and dormant accounts removed. Assessors under every framework check this first because it is where breaches actually start.
Monitoring and the ability to detect an incident
Frameworks increasingly assume you will detect your own incidents rather than hear about them from a customer. That means logging that is retained, alerting that a human reviews, and an answer to the question of who noticed and when. HIPAA, the FTC Safeguards Rule, and NIST 800-171 all make this explicit.
A breach response you have rehearsed
HIPAA carries notification duties, every state has a breach notification statute, and cyber insurance policies impose their own reporting clocks. The difference between a controlled notification and a scramble is a written plan, named owners, and at least one rehearsal before the real event. We build and test the plan so the clock starts on a process rather than a panic.
Evidence, kept current, not assembled under deadline
Having controls and having proof of controls are different things, and assessments fail on the second one as often as the first. Policies, configurations, test results, training records, and restore evidence maintained continuously turn an auditor, insurer, or enterprise customer request into an export rather than a fortnight of archaeology.
People who know what the rules require of them
Awareness training, an acceptable use policy people have actually read, and clear ownership of compliance duties inside the business. HIPAA expects a named security official, the FTC Safeguards Rule expects a designated qualified individual, and SOC 2 auditors ask who owns each control.
Find your framework, grouped by who imposes it.
Government and defense contracting
Frameworks that arrive through federal contracts and flow down the supply chain. If you sell to the Department of Defense or to federal agencies, directly or through a prime, these pages are yours.
- CMMC compliance servicesThe DoD cybersecurity maturity model, built on NIST 800-171, flowing down to every contractor handling controlled unclassified information.
- FedRAMP readinessThe authorization path for cloud products sold to federal agencies, and the readiness work before the formal assessment.
Financial data rules
If your business handles consumer financial data, lending, dealerships, tax preparation, advisory, the FTC Safeguards Rule under GLBA reaches you, and it is broader than most owners expect.
State privacy laws
Consumer privacy rights imposed by states, led by California. Applicability turns on revenue and data volume thresholds, not on where your office is.
Assessment and audit
The engagements that establish where you actually stand, in writing, against the frameworks that apply to you.
The Microsoft compliance stack
Most US businesses already license part of the tooling their framework demands. These pages cover deploying it properly instead of buying something new.
- Microsoft PurviewData classification, DLP, and retention: the technical spine of HIPAA, GLBA, and privacy law obligations.
- Microsoft PrivaPrivacy risk management and subject rights requests, the operational side of CCPA and CPRA.
- Compliance ManagerFramework assessments and improvement actions tracked inside the tenant you already run.
- Microsoft SentinelThe logging and detection layer that satisfies the monitoring clauses in nearly every framework.
- Tenant security baselineThe hardened Microsoft 365 configuration that most framework controls assume as a starting point.
Resilience obligations
Every serious framework, and every cyber insurance policy, asks the same two questions: can you restore, and how fast.
Four reasons this works better than a policy pack.
We map obligations before we quote controls
The first conversation is about your sector, your contracts, and your customers, because that is what determines which regimes reach you. Scoping by company size alone is how providers sell a SOC 2 project to a business whose actual deadline is a CMMC assessment. You get the map in writing, including the regimes we think do not apply to you and why.
We implement, not just document
A policy that says MFA is enforced while the tenant says otherwise fails the audit and, worse, fails the breach. We are an IT and security provider first, so the controls get built in your actual environment: identity, endpoints, logging, backup, mail authentication. The documents describe a real state instead of an aspiration.
One control set, mapped to every framework you face
Most of our compliance clients answer to more than one regime at once: a sector rule, a contractual framework a customer imposed, and the insurer's questionnaire. We build the control set once and maintain a mapping to each framework, so a SOC 2 audit, an insurance renewal, and a customer security review all draw from the same living evidence.
We stand next to you at the review
Audits and assessor interactions go better with the people who built the controls in the room. We prepare the evidence pack, sit in the sessions where you want us, handle the technical questions, and turn findings into a remediation plan with owners and dates rather than a PDF that gets filed.
Frameworks we work with that do not have their own page yet.
HIPAA
The Security and Privacy Rules for covered entities and their business associates: risk analysis, safeguards, and breach notification.
SOC 2
The audit report enterprise customers demand from vendors: trust services criteria, evidenced over time by an independent CPA firm.
NIST Cybersecurity Framework
The maturity baseline boards and insurers reference, and a sensible structure for any security program.
NIST 800-171
The control set underneath CMMC, applying through DFARS clauses to contractors handling controlled unclassified information.
PCI DSS
Required by the card schemes for any business that stores, processes, or transmits cardholder data, whatever its size.
State privacy laws beyond California
Virginia, Colorado, Connecticut, Texas, and a growing list of states with their own consumer privacy statutes.
Cyber insurance questionnaires
Not a law, but the assessment most SMBs actually face first: MFA, EDR, backup, and logging as conditions of coverage.
FERPA
Student education records protection for schools and the vendors that serve them.
SOX IT general controls
Access, change, and operations controls for public companies and businesses preparing for a listing or acquisition.
The six situations that bring businesses here.
Healthcare providers and health-tech vendors
Clinics, practices, and the SaaS and billing vendors that serve them, all inside HIPAA through the covered entity or business associate route. The risk analysis is the starting point OCR asks for first, and most businesses have never done one properly.
Defense contractors facing CMMC
Machine shops, engineering firms, and software vendors with DFARS clauses in their contracts. Scoping where controlled unclassified information actually lives, then building the 800-171 controls around that enclave, is usually far cheaper than treating the whole company as in scope.
SaaS businesses selling upmarket
The deal is waiting on a security review. SOC 2 is the unlock, a privacy-law readiness answer is the follow-up question, and if federal agencies are on the roadmap, FedRAMP readiness is the one after that.
Financial businesses under the Safeguards Rule
Lenders, dealerships, mortgage and tax practices that discovered the FTC Safeguards Rule applies to them. The rule names specific controls, MFA, encryption, monitoring, a qualified individual, and the gap between the rule and a typical small office is real but closeable.
Retail and ecommerce taking card payments
The acquirer asks for PCI DSS evidence and the honest answer is nobody has looked. Scoping down what actually touches card data usually shrinks the problem dramatically before any control work starts.
Firms whose insurer or big customer is asking questions
Cyber insurance renewals and supplier security assessments impose more compliance work on US SMBs in practice than regulators do. The questionnaire is long, the deadline is short, and the answers have to be true.
Narrow it down by what you do and who your customers are.
By what you do
- Healthcare providers and their vendorsHIPAA applies to covered entities and, through business associate agreements, to the IT firms, billing companies, and SaaS vendors that touch protected health information. A signed BAA without the controls behind it is a liability, not a shield.
- Defense supply chainDFARS clauses in your contracts pull in NIST 800-171 today and CMMC assessment requirements as the program phases in. The obligation flows down from primes to subcontractors, and scoping where controlled unclassified information actually lives usually shrinks the problem.
- Financial services, broadly definedThe FTC Safeguards Rule under GLBA reaches lenders, auto dealerships, mortgage brokers, tax preparers, and advisors, not just banks. It requires a written program, a designated qualified individual, MFA, encryption, and monitoring.
- Anyone taking card paymentsPCI DSS applies through your acquirer whatever your size. Scoping down what actually touches card data usually shrinks the problem dramatically before any control work starts.
By who your customers are
- Selling to enterprisesEnterprise procurement asks for SOC 2 before regulators ask for anything. The report takes months because the controls must operate over a period before they can be audited, so start before the deal that needs it.
- Selling to federal agenciesCloud products sold to federal agencies need FedRAMP authorization, and the readiness work is most of the journey. Selling to the DoD brings CMMC instead of, or on top of, FedRAMP.
- Consumers in California and other privacy-law statesCCPA and CPRA applicability turns on revenue and data volume thresholds. If you meet them, subject requests, opt-outs, and vendor contract terms become operational duties, and other state laws add their own variations.
- Anyone renewing cyber insuranceThe questionnaire assumes MFA everywhere, EDR on endpoints, tested backup, and logging. Answers get verified at claim time, so the controls have to be real, not aspirational.
HIPAA, SOC 2, CMMC, CCPA and CPRA, and PCI DSS, side by side.
| Feature | HIPAA | SOC 2 | CMMC | CCPA / CPRA | PCI DSS |
|---|---|---|---|---|---|
What it is | Federal health data law | Independent audit framework | DoD contractor certification program | California consumer privacy law | Card industry security standard |
Generally applies to | Covered entities and business associates handling PHI | Vendors whose customers demand the report | Defense contractors and subcontractors handling CUI | Businesses meeting revenue or data thresholds with California consumers | Any business handling cardholder data |
Mandatory or voluntary | Law | Voluntary, required by contract in practice | Contractual, via DoD contract clauses | Law, where its thresholds apply | Contractual, via the card schemes and your acquirer |
Overseen or enforced by | HHS Office for Civil Rights | Independent CPA firms | The DoD, via authorized assessors | The California Privacy Protection Agency and attorney general | Card schemes, via acquirers and assessors |
Deadline style | Ongoing legal duty with breach notification clocks | Audit period, then annual renewal | Assessment before contract award, then maintenance | Ongoing duty with response windows for consumer requests | Annual validation plus quarterly requirements |
Typical trigger for a US business | Touching patient data, directly or as a vendor | An enterprise deal stalls on a security review | A DFARS clause appears in a contract or flow-down | Growth past the thresholds, or a customer asking | Your acquirer or payment provider requires evidence |
Consequence style, described without figures | Civil penalties, corrective action plans, reputational harm | Failed or qualified report, lost enterprise deals | Ineligibility for contracts, lost awards | Administrative fines per violation, private actions after breaches | Fines via the schemes, higher fees, loss of card acceptance |
What IT must show | Risk analysis, safeguards, access control, breach response | Controls operating over time across the trust criteria | The NIST 800-171 control set, evidenced and scored | Data inventory, request handling, reasonable security | Segmented card data, hardening, logging, testing |
Treating compliance as a document rather than a running state.
The pattern we see most is a business that bought a policy pack, passed one review, and changed nothing operationally. A year later the controls have drifted, the evidence is stale, and the next request lands as a crisis. Three habits prevent it.
- Map obligations once, properly. Most businesses are in scope of fewer regimes than they fear and more than they know. An hour of scoping against your sector, contracts, and customer base beats a year of guessing.
- Build controls once, map them to every framework that applies. MFA, logging, backup, joiner-leaver discipline, and breach response serve HIPAA, SOC 2, CMMC, and the Safeguards Rule simultaneously. Doing the work per-framework doubles the cost for no gain.
- Keep evidence continuously. The regimes that matter all assume you can show your state on demand. If proof takes two weeks to assemble, the controls may be fine but the review will not go well.
Four steps from unsure to evidenced.
- 1
Obligation mapping
Week 1
Sector, contracts, customers, card flows, and the states your customers live in. Out the other side comes a written map: which regimes apply, which do not and why, and which one has the nearest deadline. This is the step most businesses have never done and it changes everything after it.
- 2
Gap assessment against what applies
Weeks 1 to 3
Your actual environment, assessed against the frameworks from the map. Every finding is verified in the tenant, on the endpoint, or in the configuration rather than taken from an interview, and severity reflects your real exposure, not a generic score.
- 3
Remediation, worst first
Weeks 2 to 8, scope dependent
Close the gaps in risk order: identity and access first, then logging and backup, then the framework-specific items. Policies are written to describe the state we built, and staff get the training the regime expects.
- 4
Evidence and maintenance
Ongoing
The evidence pack goes live and stays current: control status, test results, training records, restore proofs, data inventories. Audits, insurance renewals, and customer reviews become exports. Continuous monitoring catches drift before the next review does.
The questions that decide what you actually need.
Where to go next.
Cybersecurity audit and compliance
The audit that starts most engagements: your current state, in writing, against the frameworks that apply to you.
Tenant security baseline
The hardened Microsoft 365 configuration most framework controls assume as a starting point.
Managed IT services
The operating model that keeps controls and evidence current after the project ends.
Tell us your sector and your customers, and we will tell you which frameworks actually apply.
A short call covering your sector, your contracts, your customer base, and any deadline already running. You get a written obligation map, including the regimes we believe do not apply to you and why. No charge for the scoping, and no program sold before the map exists.
Related Services
Explore more solutions that work great with this service