Compliance & Frameworks

SOC 2, PCI DSS, ISO 27001, NIST, HIPAA, HITRUST, GDPR, CCPA, and AI security — proof that follows from a risk program that works.

Compliance that follows risk management

Proof for customers and auditors — built on a risk program that works.

We build one risk-based control set and map it to every framework and regulation you’re accountable to. You get the report or certification you need, and controls that actually reduce risk. Pursue one today; add the next without starting over.

SOC 2

SOC 2 Type I & Type II

The AICPA Trust Services Criteria report your customers ask for when they trust you with their data.

  • Trust Services Criteria scoping (Security, Availability, Confidentiality, Processing Integrity, Privacy)
  • System description and control matrix
  • Type I readiness, then Type II operating-period support
  • CPA firm coordination through fieldwork

Best for: SaaS, cloud, and service providers selling to enterprises

PCI DSS

PCI DSS v4.0.1

The payment card industry’s data security standard for anyone who stores, processes, or transmits cardholder data.

  • Cardholder data environment scoping and scope reduction
  • SAQ selection and completion, or ROC readiness
  • Targeted risk analyses and customized approach support
  • Segmentation and quarterly scan coordination

Best for: merchants, payment processors, and service providers

ISO 27001

ISO/IEC 27001:2022

The international standard for an Information Security Management System (ISMS) — certifiable and recognized worldwide.

  • ISMS scope, context, and leadership commitments
  • Risk treatment plan and Statement of Applicability
  • Annex A control implementation
  • Internal audit and management review ahead of certification

Best for: organizations with international customers or partners

NIST

NIST CSF 2.0, SP 800-53 & SP 800-171

The U.S. government’s security frameworks — a flexible foundation for any program and a requirement for many federal contracts.

  • CSF 2.0 current and target profiles (Govern, Identify, Protect, Detect, Respond, Recover)
  • 800-53 control baselines for federal and regulated workloads
  • 800-171 System Security Plan and POA&M for CUI
  • Maturity scoring leadership can track over time

Best for: federal contractors, critical infrastructure, and anyone wanting a strong baseline

HIPAA

HIPAA Security Rule

Administrative, physical, and technical safeguards for electronic protected health information (ePHI).

  • HIPAA security risk analysis, as the rule requires
  • Safeguard implementation and documentation
  • Business Associate Agreement review
  • Breach response and workforce training programs

Best for: covered entities, business associates, and health tech

HITRUST

HITRUST CSF — e1, i1 & r2

A certifiable framework that harmonizes HIPAA, NIST, ISO, PCI, and more — increasingly required across healthcare.

  • Choosing the right assessment: e1, i1, or risk-based r2
  • Readiness assessment and scoping in MyCSF
  • Policy, procedure, and implementation maturity guidance
  • Validated assessment services delivered with the independence HITRUST requires

Best for: healthcare organizations and their technology vendors

GDPR

EU & UK GDPR

Europe’s data protection regulation, applying to any organization that offers services to, or monitors, people in the EU or UK.

  • Data mapping and Records of Processing Activities (Article 30)
  • Lawful basis, privacy notices, and consent management
  • Data Protection Impact Assessments (Article 35)
  • Processor agreements and international transfer safeguards
  • Security of processing (Article 32) and 72-hour breach readiness

Best for: companies with European customers, users, or employees. Data privacy details →

CCPA / CPRA

California Consumer Privacy Act (as amended by CPRA)

California’s privacy law, now with CPPA regulations covering risk assessments, automated decision-making, and cybersecurity audits.

  • Consumer rights: know, delete, correct, and opt out of sale or sharing
  • Risk assessments required for covered processing from January 1, 2026
  • Automated decision-making technology (ADMT) requirements from January 1, 2027
  • Annual cybersecurity audit readiness — first certifications due April 1, 2028–2030 by revenue
  • Service-provider contracts and U.S. state-law harmonization

Best for: businesses handling personal information of California residents. Data privacy details →

AI Security

Agentic AI Security & Governance

Security and governance for the AI models and autonomous agents that now read your data and act inside your systems.

  • AI inventory, risk assessment, and acceptable-use policy
  • Threat modeling against the OWASP Top 10 for Agentic Applications (2026)
  • AI management system aligned to ISO/IEC 42001 and the NIST AI RMF
  • EU AI Act readiness, including Article 50 transparency obligations
  • HITRUST AI security assessment readiness

Best for: organizations building or deploying AI agents, copilots, and LLM features. AI security details →

Unified control framework

Why mapping once saves you a year later.

The same core disciplines — access control, change management, logging, vulnerability management, vendor risk, incident response, training — show up in every framework above. We implement each discipline once, document it in a way every auditor can follow, and keep a crosswalk that shows which requirement each control satisfies.

The result: when a new customer asks for ISO after you’ve finished SOC 2, you’re closing a short list of gaps rather than starting a new program.

Disciplines we map across frameworks

  • Governance, policy, and risk management
  • Identity and access management
  • Asset, configuration, and change management
  • Logging, monitoring, and incident response
  • Vulnerability and patch management
  • Vendor and third-party risk
  • Business continuity and disaster recovery
  • Security awareness and onboarding

Juggling more than one framework?

Tell us which ones are on your plate and we’ll show you how much overlap you can take advantage of.