Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Industries

Security and compliance requirements by industry

Security and compliance requirements depend on what you sell, who you sell to, and the data you hold. For five sectors, here's what typically comes up, which services and frameworks relate, and what to have ready before a first conversation.

Who we work with

U.S. SaaS, professional-services, healthcare, e-commerce, and defense-supply-chain organizations with roughly 25 to 1,000 employees.

SaaS and technology

For software and technology companies, security requirements usually arrive through sales: enterprise customers want evidence that your product, and the company behind it, is run securely before they sign or renew.

Typical requirements

  • Security questionnaires and due-diligence reviews from prospective and existing customers.
  • A SOC 2 report. SOC 2 is an attestation report, not a certification, and only a licensed CPA firm can issue one.
  • ISO/IEC 27001 certification of your information security management system, issued by an independent certification body.
  • Recent penetration test results for the application, its APIs, and the cloud environment it runs in.
  • Contract terms on security incidents, subprocessors, and data handling that your team then has to operate day to day.
  • Obligations that flow down from your customers, such as HIPAA business associate terms, or PCI DSS if your product handles card data.

Relevant services

Frameworks and rules

  • SOC 2 (AICPA Trust Services Criteria)
  • ISO/IEC 27001:2022
  • NIST CSF 2.0
  • CIS Controls v8.1

What to prepare

  1. A short description of the product, the infrastructure it runs on, and the cloud services and subprocessors it depends on.
  2. Recent customer questionnaires, especially the questions you found hard to answer.
  3. Any policies you already have, even drafts.
  4. How access, code changes, and logging actually work today, and who approves what.
  5. The dates driving the work, such as a customer deadline or a renewal.

Data safety: Don't include credentials, API keys, or customer data in an inquiry.

Healthcare

If you're a healthcare provider, a health plan, or a vendor that handles electronic protected health information (ePHI) for one, the HIPAA Security Rule sets the baseline for how you protect it.

Typical requirements

  • Administrative, physical, and technical safeguards for ePHI under the HIPAA Security Rule (45 CFR Part 164, Subpart C).
  • An accurate and thorough risk analysis, kept current as systems and vendors change, and risk management that acts on it.
  • Business associate agreements with vendors that create, receive, maintain, or transmit ePHI on your behalf.
  • Security incident procedures and contingency planning, including data backup and disaster recovery.
  • A periodic evaluation of how well your safeguards and policies meet the rule.
  • No official HIPAA certification exists. HHS doesn't recognize private certifications, so readiness means meeting the rule and being able to show how.
  • HHS proposed changes to the Security Rule in January 2025. As of 2026-09-26, they haven't been finalized, so they aren't law.

Relevant services

Frameworks and rules

  • HIPAA Security Rule (45 CFR Part 164, Subpart C)
  • NIST CSF 2.0

What to prepare

  1. An inventory of the systems, devices, and vendors that touch ePHI, even if it's incomplete.
  2. Your most recent risk analysis and the date it was done, if you have one.
  3. Your current business associate agreements, or a list of the vendors that handle ePHI.
  4. Your security policies and procedures, and who your designated security official is.

Data safety: Don't include patient information or any ePHI in an inquiry.

Payments and e-commerce

If you store, process, or transmit payment card data, or your systems can affect its security, PCI DSS applies. Your acquirer or the payment brands decide how you validate compliance.

Typical requirements

  • PCI DSS v4.0.1, the only active version as of 2026-09-26. Every requirement, including those once future-dated, has applied since March 31, 2025.
  • Validation as your acquirer or the payment brands direct: a Self-Assessment Questionnaire (SAQ) that your organization completes, or a Report on Compliance (ROC) by a PCI SSC-listed QSA Company, each with an Attestation of Compliance.
  • A clearly defined scope: the cardholder data environment and every system, person, and service provider that can affect it. Segmentation can reduce scope, but it has to be tested.
  • External vulnerability scans by a PCI SSC Approved Scanning Vendor (ASV) where required. ASV scanning is a separate PCI SSC program.
  • Internal and external penetration testing, including tests of segmentation controls if you rely on them.
  • For online checkouts, control over the scripts that run on payment pages. Which requirements apply depends on your SAQ type and how the payment page is built; PCI SSC updated SAQ A for e-commerce merchants in January 2025.
  • Oversight of the service providers that handle card data for you or could affect its security, including their compliance status.

Relevant services

Frameworks and rules

  • PCI DSS v4.0.1

What to prepare

  1. Every way you accept payments (online, in person, by phone) and the processors, gateways, and service providers involved.
  2. A data-flow or network diagram showing where card data travels, even a rough one.
  3. How your acquirer asks you to validate (which SAQ, or a ROC), if you know.
  4. Your most recent SAQ or Attestation of Compliance, and recent ASV scan reports.
  5. Attestations of Compliance from the service providers that handle card data for you.

Data safety: Never include card numbers or any other cardholder data in an inquiry.

Defense supply chain

Defense contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must protect it under their contracts, and CMMC is how the Department verifies that protection.

Note:

CMMC program update — September 26, 2026: CMMC implementation remains paused in Phase 1 following the suspension of Phase II on July 13, 2026. Phase I self-assessment requirements remain in force. During the suspension, procurement requirements may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC).

Typical requirements

  • FAR 52.204-21 sets 15 basic safeguarding requirements for FCI. CMMC Level 1 covers them and is self-assessed every year.
  • DFARS 252.204-7012 requires contractors that handle covered defense information to implement NIST SP 800-171 and to report cyber incidents to the Department.
  • CMMC Level 2 covers the 110 requirements of NIST SP 800-171 Rev 2. It's either self-assessed or, where a contract calls for it, assessed by an authorized C3PAO.
  • Assessment results are entered in SPRS, and a senior official at your own organization affirms them.
  • Requirements flow down: prime contractors pass FCI and CUI obligations to their subcontractors.
  • CMMC ecosystem members, such as C3PAOs, their assessors and CMMC professionals, who consulted to prepare an organization for any CMMC assessment within the previous three years may not take part in its Level 2 certification assessment (32 CFR 170.8(b)(17)(ii)(G)).

Relevant services

Frameworks and rules

  • CMMC (32 CFR Part 170)
  • NIST SP 800-171 Rev 2
  • FAR 52.204-21
  • DFARS 252.204-7012

What to prepare

  1. The FAR and DFARS clauses in your contracts, and any CMMC level named in solicitations you're pursuing.
  2. What you handle (FCI, CUI, or both) and where it's stored, processed, and sent.
  3. Your system security plan (SSP) and plan of action and milestones (POA&M), if you have them.
  4. Your current SPRS entry and when it was submitted, if you have one.

Data safety: Don't include CUI or any other controlled defense information in an inquiry.

Professional services

Law, accounting, consulting, and other advisory firms hold some of their clients' most sensitive information, and clients and insurers expect you to show how it's protected.

Typical requirements

  • Security questionnaires and outside guidelines from corporate clients, sometimes as a condition of keeping the work.
  • Confidentiality duties from professional rules and client contracts. Which rules apply to your firm is a question for your own counsel.
  • Cyber insurance applications and renewals that ask about controls such as multi-factor authentication, backups, and incident-response planning.
  • State data-security and notification laws, which differ from state to state.
  • Due diligence on the cloud tools that hold client files, such as document management, practice management, email, and file sharing.

Relevant services

Frameworks and rules

  • NIST CSF 2.0
  • CIS Controls v8.1

What to prepare

  1. Recent client questionnaires or outside guidelines you've been asked to meet.
  2. Your latest cyber insurance application or renewal questions.
  3. A list of the systems and cloud services that hold client files.
  4. Any existing security policies, such as acceptable use, access control, or incident response.

Data safety: Don't include client files or confidential client details in an inquiry.

Service boundaries

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Read who can issue which formal outcome

Talk through your sector's requirements

Tell us your sector and what prompted the question: a customer review, a contract clause, an insurer, or an upcoming assessment.

What happens next

  1. Send a short note through the contact form. Leave out regulated data such as card numbers, patient information, or CUI.
  2. Every engagement begins with a written scope and proposal.