Compliance Frameworks

SOC 2, PCI DSS, ISO 27001, NIST, HIPAA, and HITRUST — built on one unified control set.

One control set, many frameworks

We meet you at the framework you’re being asked for.

Behind the scenes we build a single, unified control set and map it to each framework you’re accountable to. Pursue one today; add the next without starting over.

SOC 2

SOC 2 Type I & Type II

The AICPA Trust Services Criteria report your customers ask for when they trust you with their data.

  • Trust Services Criteria scoping (Security, Availability, Confidentiality, Processing Integrity, Privacy)
  • System description and control matrix
  • Type I readiness, then Type II operating-period support
  • CPA firm coordination through fieldwork

Best for: SaaS, cloud, and service providers selling to enterprises

PCI DSS

PCI DSS v4.0.1

The payment card industry’s data security standard for anyone who stores, processes, or transmits cardholder data.

  • Cardholder data environment scoping and scope reduction
  • SAQ selection and completion, or ROC readiness
  • Targeted risk analyses and customized approach support
  • Segmentation and quarterly scan coordination

Best for: merchants, payment processors, and service providers

ISO 27001

ISO/IEC 27001:2022

The international standard for an Information Security Management System (ISMS) — certifiable and recognized worldwide.

  • ISMS scope, context, and leadership commitments
  • Risk treatment plan and Statement of Applicability
  • Annex A control implementation
  • Internal audit and management review ahead of certification

Best for: organizations with international customers or partners

NIST

NIST CSF 2.0, SP 800-53 & SP 800-171

The U.S. government’s security frameworks — a flexible foundation for any program and a requirement for many federal contracts.

  • CSF 2.0 current and target profiles (Govern, Identify, Protect, Detect, Respond, Recover)
  • 800-53 control baselines for federal and regulated workloads
  • 800-171 System Security Plan and POA&M for CUI
  • Maturity scoring leadership can track over time

Best for: federal contractors, critical infrastructure, and anyone wanting a strong baseline

HIPAA

HIPAA Security Rule

Administrative, physical, and technical safeguards for electronic protected health information (ePHI).

  • HIPAA security risk analysis, as the rule requires
  • Safeguard implementation and documentation
  • Business Associate Agreement review
  • Breach response and workforce training programs

Best for: covered entities, business associates, and health tech

HITRUST

HITRUST CSF — e1, i1 & r2

A certifiable framework that harmonizes HIPAA, NIST, ISO, PCI, and more — increasingly required across healthcare.

  • Choosing the right assessment: e1, i1, or risk-based r2
  • Readiness assessment and scoping in MyCSF
  • Policy, procedure, and implementation maturity guidance
  • Validated assessment services delivered with the independence HITRUST requires

Best for: healthcare organizations and their technology vendors

Unified control framework

Why mapping once saves you a year later.

The same core disciplines — access control, change management, logging, vulnerability management, vendor risk, incident response, training — show up in every framework above. We implement each discipline once, document it in a way every auditor can follow, and keep a crosswalk that shows which requirement each control satisfies.

The result: when a new customer asks for ISO after you’ve finished SOC 2, you’re closing a short list of gaps rather than starting a new program.

Disciplines we map across frameworks

  • Governance, policy, and risk management
  • Identity and access management
  • Asset, configuration, and change management
  • Logging, monitoring, and incident response
  • Vulnerability and patch management
  • Vendor and third-party risk
  • Business continuity and disaster recovery
  • Security awareness and onboarding

Juggling more than one framework?

Tell us which ones are on your plate and we’ll show you how much overlap you can take advantage of.