Compliance guide
A practical cybersecurity compliance guide
Which framework applies to you, what each one asks for and where to start. This guide covers SOC 2, HIPAA, PCI DSS, CMMC, NIST CSF and ISO 27001 in plain language, with a checklist you can use to plan your first year.

Start here
What cybersecurity compliance means
Cybersecurity compliance means meeting a defined set of security requirements and being able to prove it. The requirements come from three places: laws and regulations (such as HIPAA), contracts (such as PCI DSS through your card processor, or CMMC through a Department of Defense contract) and frameworks you adopt voluntarily or because customers ask (such as SOC 2, ISO 27001 and NIST CSF).
Most frameworks ask for the same core controls in different words: know your assets and data, control who has access, protect systems, monitor for threats, respond to incidents and recover. The difference is scope, how strictly each control is defined and who checks your work.
That overlap is good news. A well-built security program can satisfy several frameworks at once, and evidence collected for one audit often supports the next.
The frameworks
The six frameworks most organizations run into
SOC 2
SOC 2 is an attestation developed by the AICPA and performed by an independent CPA firm. It reports on how a service organization protects customer data against the Trust Services Criteria: security, which is always in scope, plus availability, processing integrity, confidentiality and privacy where relevant.
- Who it’s for: SaaS companies, managed service providers, and professional firms that hold client data, such as accounting firms
- Why you’d pursue it: customers and prospects ask for the report during vendor reviews
- Type 1 reports on control design at a point in time; Type 2 reports on how controls operated over a review period, usually several months
- Learn more: SOC 2 readiness
HIPAA
The HIPAA Security Rule is a federal requirement for covered entities (healthcare providers, health plans and clearinghouses) and their business associates that create, receive, maintain or transmit electronic protected health information. It requires a risk analysis and administrative, physical and technical safeguards.
- Who it’s for: healthcare organizations and any vendor that handles ePHI on their behalf
- The most common gap: an outdated or missing security risk analysis
- There is no HIPAA certification; you demonstrate compliance through documentation, safeguards and ongoing risk management
- Learn more: HIPAA security risk assessment
PCI DSS
The Payment Card Industry Data Security Standard applies to any organization that stores, processes or transmits cardholder data, or that can affect the security of that data. Version 4.0.1 is current, and the requirements that were future-dated in version 4.0 became mandatory on March 31, 2025.
- Who it’s for: retailers, restaurants, e-commerce sites and service providers in the payment flow
- How you validate depends on transaction volume and your acquiring bank: a self-assessment questionnaire or an assessment by a Qualified Security Assessor
- Reducing the systems that touch card data, through segmentation or tokenization, reduces what you have to assess
- Learn more: PCI DSS compliance
CMMC
The Cybersecurity Maturity Model Certification program applies to Department of Defense contractors and subcontractors that handle Federal Contract Information or Controlled Unclassified Information. The acquisition rule took effect on November 10, 2025, which started a phased rollout of CMMC requirements into DoD contracts.
- Level 1: basic safeguarding of Federal Contract Information, with an annual self-assessment
- Level 2: the 110 security requirements of NIST SP 800-171 for Controlled Unclassified Information, assessed by self-assessment or a certified third-party assessor depending on the contract
- Level 3: additional requirements for the most sensitive programs, assessed by the government
- Learn more: CMMC and NIST 800-171
NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework that organizes security outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It isn’t a certification, but it’s widely used to measure maturity, report to boards and plan improvements, and many cyber insurers and public agencies reference it.
- Who it’s for: any organization that wants a common language for security, including public agencies
- How it’s used: score current maturity, set a target profile and close the gaps in order of risk
- Learn more: NIST CSF maturity assessment
ISO 27001
ISO/IEC 27001 is the international standard for an information security management system (ISMS). The current version is ISO/IEC 27001:2022, with 93 controls in Annex A. Certification comes from an accredited certification body, followed by surveillance audits and recertification on a three-year cycle.
- Who it’s for: organizations that sell internationally or to enterprises that require ISO certification
- What sets it apart: it certifies the management system, so leadership commitment, risk assessment and continual improvement matter as much as technical controls
- Learn more: ISO 27001 services
Choosing
How to choose which framework to start with
Start with what you’re required to do, then what your customers ask for, then what helps you manage risk. In practice, work through these questions in order.
- What does the law require? If you handle ePHI, HIPAA applies. If you accept cards, PCI DSS applies through your processor. Check state privacy and breach laws where you operate.
- What do your contracts require? DoD contracts bring CMMC. Enterprise customers may require a SOC 2 report or ISO 27001 certificate before they sign.
- What are prospects asking for? If security questionnaires are slowing deals, a SOC 2 report or ISO 27001 certificate can answer most of them at once.
- Where are you today? A NIST CSF maturity assessment gives you a baseline that maps to every other framework, so no effort is wasted.
- What can you sustain? Compliance is ongoing. Pick a scope you can maintain with your team, or with outside help, year after year.
Many organizations end up with more than one framework. A common path is a NIST CSF baseline first, then the certification or attestation customers require, with controls mapped once and reused across audits.
Checklist
A cybersecurity compliance checklist for your first year
These steps apply whichever framework you choose.
1. Define scope
List the data, systems, locations and third parties the framework covers.
2. Assess the gaps
Compare current controls to the framework and rank gaps by risk.
3. Assign ownership
Name an executive sponsor and an owner for each control area.
4. Write the policies
Document policies you actually follow, and have leadership approve them.
5. Fix the priorities
Close high-risk gaps first: MFA, backups, patching, logging and access.
6. Review vendors
Assess the third parties that hold your data or connect to your network.
7. Test your response
Run a tabletop exercise against your incident response plan.
8. Collect evidence
Keep records of reviews, tests and changes so audits go quickly.
E-books
Want a guide for your industry?
We’ve written downloadable compliance e-books for general audiences and for manufacturing, biotech and retail organizations. Each covers the regulations that matter most in that sector and practical first steps.
Request any of them through the form below and tell us which industry you’re in.

FAQ
Cybersecurity compliance questions
Related services
Related services
Talk to a compliance advisor
Get help choosing and planning your framework
Tell us your industry and what’s driving the work. An advisor will reply by email, and you can request our compliance e-books in the same message.
Prefer email? Write to [email protected] or call (858) 712-0040.
