Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Compliance

Compliance readiness

Compliance readiness for SOC 2, ISO/IEC 27001, the HIPAA Security Rule, PCI DSS, and CMMC.

Versions as of

  • SOC 22017 Trust Services Criteria (With Revised Points of Focus – 2022)
  • ISO/IEC 27001ISO/IEC 27001:2022, including Amendment 1:2024
  • HIPAA Security Rule45 CFR Part 164, Subpart C, as last substantively revised in 2013
  • PCI DSSPCI DSS v4.0.1
  • CMMCCMMC Program (32 CFR Part 170); Level 2 uses NIST SP 800-171 Rev 2

Readiness vs. formal assessment

Readiness and formal assessment are different jobs, done by different organizations. Knowing which is which helps you plan the work, budget for both, and avoid paying for a “certificate” the program doesn’t recognize.

Readiness

Getting ready: finding out where you stand and closing the gaps before anyone formally judges you.

  • Scoping: deciding which systems, people, and providers the formal assessment will cover
  • Gap assessment against the framework's current version
  • Remediation planning, with your team deciding and implementing
  • Evidence preparation and walkthrough rehearsal

Formal assessment

The official outcome: a report, a certificate, or an assessment result that your customers, acquirer, or contracting officer relies on.

  • Where a third party is required, performed only by an organization the program authorizes, such as a licensed CPA firm, an accredited certification body, a PCI SSC-listed QSA Company, or an authorized C3PAO. Some outcomes, such as a PCI DSS Self-Assessment Questionnaire or a CMMC self-assessment, are completed and signed by your own organization
  • Bound by independence rules that keep the people who designed your controls from judging them
  • Planned, scoped, and priced by the assessor you engage, where one is required
  • Not available for everything: there is no official HIPAA certification

Who performs the formal assessment

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

Who can issue what

Each framework has its own formal outcome and its own rules about who may issue it. Versions and program status were last checked on .

Who can issue each formal outcome, as of
FrameworkWhat it isFormal outcomeWho can issue itWhat Security Inspect does
SOC 2SOC 2 is an attestation report on a service organization's controls, issued by a licensed CPA firm after an examination and measured against the AICPA Trust Services Criteria. It isn't a certification.SOC 2 Type 1 or Type 2 report (an attestation report, not a certification)A licensed CPA firm, under AICPA attestation standardsSOC 2 readiness — preparation for an examination performed by an independent licensed CPA firm.
ISO/IEC 27001ISO/IEC 27001 is an international standard that sets requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).Certificate for your information security management systemA certification body, accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1 for accredited certificationISO/IEC 27001 readiness — preparation for certification by an independent accredited certification body.
HIPAA Security RuleThe HIPAA Security Rule (45 CFR Part 164, Subpart C) is a federal regulation that sets security standards for the electronic protected health information (ePHI) that covered entities and business associates create, receive, maintain, or transmit.None. There is no official HIPAA certification.Not applicable. HHS doesn't recognize private certifications; its Office for Civil Rights enforces the rule.HIPAA Security Rule readiness — risk analysis support, safeguards review, and remediation planning.
PCI DSSPCI DSS, the Payment Card Industry Data Security Standard, is a baseline of technical and operational requirements designed to protect payment account data. The PCI Security Standards Council (PCI SSC) maintains it, and it applies to entities that store, process, or transmit cardholder data or sensitive authentication data, or that could affect the security of the cardholder data environment.Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ), as your acquirer or the payment brands directA PCI SSC-listed QSA Company for a ROC; a listed ASV for external scans; your own organization for an SAQPCI DSS readiness — scoping support, gap assessment, and remediation planning before a QSA assessment or self-assessment.
CMMCCMMC, the Cybersecurity Maturity Model Certification program, is a Department of Defense program that verifies how contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).Self-assessment results in SPRS, or a Certificate of CMMC Status after a Level 2 certification assessmentYour own organization for Level 1 and Level 2 self-assessments; a C3PAO authorized by the Cyber AB for Level 2 certificationCMMC Level 1 and Level 2 readiness — preparation for self-assessment or a certification assessment by an authorized C3PAO.

Choose a framework

Each guide covers the current version, who needs it, who performs the formal assessment, what our readiness work includes and excludes, and published starting prices.

  • 2017 Trust Services Criteria (With Revised Points of Focus – 2022)

    SOC 2 readiness

    Get your controls, evidence, and system description ready for a SOC 2 examination by an independent, licensed CPA firm that you select and engage directly.

  • ISO/IEC 27001:2022, including Amendment 1:2024

    ISO/IEC 27001 readiness

    Design and tune an information security management system (ISMS) that's ready for a certification audit by an independent, accredited certification body.

  • 45 CFR Part 164, Subpart C, as last substantively revised in 2013

    HIPAA Security Rule readiness

    Risk analysis support, a safeguards review against the HIPAA Security Rule, and a remediation plan, with a clear line between the rule in force and changes HHS has only proposed.

  • PCI DSS v4.0.1

    PCI DSS readiness

    Scoping support, a gap assessment against PCI DSS v4.0.1, and a remediation plan before your assessment by a PCI SSC-listed QSA Company or your own Self-Assessment Questionnaire.

  • CMMC Program (32 CFR Part 170); Level 2 uses NIST SP 800-171 Rev 2

    CMMC readiness

    Readiness for CMMC Level 1 and Level 2 against FAR 52.204-21 and NIST SP 800-171 Rev 2, with support for self-assessments and for a certification assessment by an authorized C3PAO if you need one.

What we don't do

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

Is SOC 2 a certification? Who can issue what

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Not sure which framework applies to you?

Tell us who is asking for evidence and what they’ve asked for. We’ll help you work out which framework and formal outcome fit, and what readiness work would help.

What happens next

  1. Tell us which customers, contracts, or regulators are driving the request.
  2. Talk through the framework, scope, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.