Compliance guide

A practical cybersecurity compliance guide

Which framework applies to you, what each one asks for and where to start. This guide covers SOC 2, HIPAA, PCI DSS, CMMC, NIST CSF and ISO 27001 in plain language, with a checklist you can use to plan your first year.

  • Six major frameworks, side by side
  • How to choose where to start
  • A cybersecurity compliance checklist
Digital graphic of compliance documents and controls

Start here

What cybersecurity compliance means

Cybersecurity compliance means meeting a defined set of security requirements and being able to prove it. The requirements come from three places: laws and regulations (such as HIPAA), contracts (such as PCI DSS through your card processor, or CMMC through a Department of Defense contract) and frameworks you adopt voluntarily or because customers ask (such as SOC 2, ISO 27001 and NIST CSF).

Most frameworks ask for the same core controls in different words: know your assets and data, control who has access, protect systems, monitor for threats, respond to incidents and recover. The difference is scope, how strictly each control is defined and who checks your work.

That overlap is good news. A well-built security program can satisfy several frameworks at once, and evidence collected for one audit often supports the next.

The frameworks

The six frameworks most organizations run into

SOC 2

SOC 2 is an attestation developed by the AICPA and performed by an independent CPA firm. It reports on how a service organization protects customer data against the Trust Services Criteria: security, which is always in scope, plus availability, processing integrity, confidentiality and privacy where relevant.

  • Who it’s for: SaaS companies, managed service providers, and professional firms that hold client data, such as accounting firms
  • Why you’d pursue it: customers and prospects ask for the report during vendor reviews
  • Type 1 reports on control design at a point in time; Type 2 reports on how controls operated over a review period, usually several months
  • Learn more: SOC 2 readiness

HIPAA

The HIPAA Security Rule is a federal requirement for covered entities (healthcare providers, health plans and clearinghouses) and their business associates that create, receive, maintain or transmit electronic protected health information. It requires a risk analysis and administrative, physical and technical safeguards.

  • Who it’s for: healthcare organizations and any vendor that handles ePHI on their behalf
  • The most common gap: an outdated or missing security risk analysis
  • There is no HIPAA certification; you demonstrate compliance through documentation, safeguards and ongoing risk management
  • Learn more: HIPAA security risk assessment

PCI DSS

The Payment Card Industry Data Security Standard applies to any organization that stores, processes or transmits cardholder data, or that can affect the security of that data. Version 4.0.1 is current, and the requirements that were future-dated in version 4.0 became mandatory on March 31, 2025.

  • Who it’s for: retailers, restaurants, e-commerce sites and service providers in the payment flow
  • How you validate depends on transaction volume and your acquiring bank: a self-assessment questionnaire or an assessment by a Qualified Security Assessor
  • Reducing the systems that touch card data, through segmentation or tokenization, reduces what you have to assess
  • Learn more: PCI DSS compliance

CMMC

The Cybersecurity Maturity Model Certification program applies to Department of Defense contractors and subcontractors that handle Federal Contract Information or Controlled Unclassified Information. The acquisition rule took effect on November 10, 2025, which started a phased rollout of CMMC requirements into DoD contracts.

  • Level 1: basic safeguarding of Federal Contract Information, with an annual self-assessment
  • Level 2: the 110 security requirements of NIST SP 800-171 for Controlled Unclassified Information, assessed by self-assessment or a certified third-party assessor depending on the contract
  • Level 3: additional requirements for the most sensitive programs, assessed by the government
  • Learn more: CMMC and NIST 800-171

NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework that organizes security outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It isn’t a certification, but it’s widely used to measure maturity, report to boards and plan improvements, and many cyber insurers and public agencies reference it.

  • Who it’s for: any organization that wants a common language for security, including public agencies
  • How it’s used: score current maturity, set a target profile and close the gaps in order of risk
  • Learn more: NIST CSF maturity assessment

ISO 27001

ISO/IEC 27001 is the international standard for an information security management system (ISMS). The current version is ISO/IEC 27001:2022, with 93 controls in Annex A. Certification comes from an accredited certification body, followed by surveillance audits and recertification on a three-year cycle.

  • Who it’s for: organizations that sell internationally or to enterprises that require ISO certification
  • What sets it apart: it certifies the management system, so leadership commitment, risk assessment and continual improvement matter as much as technical controls
  • Learn more: ISO 27001 services

Choosing

How to choose which framework to start with

Start with what you’re required to do, then what your customers ask for, then what helps you manage risk. In practice, work through these questions in order.

  1. What does the law require? If you handle ePHI, HIPAA applies. If you accept cards, PCI DSS applies through your processor. Check state privacy and breach laws where you operate.
  2. What do your contracts require? DoD contracts bring CMMC. Enterprise customers may require a SOC 2 report or ISO 27001 certificate before they sign.
  3. What are prospects asking for? If security questionnaires are slowing deals, a SOC 2 report or ISO 27001 certificate can answer most of them at once.
  4. Where are you today? A NIST CSF maturity assessment gives you a baseline that maps to every other framework, so no effort is wasted.
  5. What can you sustain? Compliance is ongoing. Pick a scope you can maintain with your team, or with outside help, year after year.

Many organizations end up with more than one framework. A common path is a NIST CSF baseline first, then the certification or attestation customers require, with controls mapped once and reused across audits.

Checklist

A cybersecurity compliance checklist for your first year

These steps apply whichever framework you choose.

E-books

Want a guide for your industry?

We’ve written downloadable compliance e-books for general audiences and for manufacturing, biotech and retail organizations. Each covers the regulations that matter most in that sector and practical first steps.

Request any of them through the form below and tell us which industry you’re in.

  • General cybersecurity compliance for small businesses
  • Manufacturing cyber compliance
  • Biotech cyber compliance
  • Retail cyber compliance
Team reviewing findings around a conference table

FAQ

Cybersecurity compliance questions

SOC 2 is an attestation report from a CPA firm, common with US customers. ISO 27001 is a certification of your information security management system, common internationally. The controls overlap heavily, so many organizations build once and pursue both.

For most private organizations, no. It’s voluntary, but it’s widely used as a baseline for measuring maturity, and some public agencies, insurers and customers reference it.

It depends on your starting point, the framework and your scope. A gap assessment gives you a realistic timeline because it shows how many controls you already meet.

Cost is driven by scope (how many systems, locations and people are covered), the gaps you need to close, whether you need an external auditor or assessor, and how much of the ongoing work you handle internally. Narrowing scope is often the biggest lever.

Not on its own. Compliance proves you meet a minimum set of controls at a point in time. Pair it with testing, monitoring and incident response so the controls hold up against real attacks.

Talk to a compliance advisor

Get help choosing and planning your framework

Tell us your industry and what’s driving the work. An advisor will reply by email, and you can request our compliance e-books in the same message.

  • Advice on which framework to start with
  • E-books for manufacturing, biotech, retail and general audiences

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message