Compliance
Security and compliance guides
These guides explain security and compliance topics in plain language: SOC 2 reports, the HIPAA Security Rule, PCI DSS, ISO/IEC 27001, CMMC and NIST SP 800-171, penetration testing, risk assessment, vCISO leadership and incident response planning.
Each guide answers its question first, then goes into detail. It lists the primary sources it relies on, such as AICPA criteria, the Code of Federal Regulations, PCI Security Standards Council documents and NIST publications, and shows the date those sources were checked. The glossary defines the terms the guides use.
Start here
Good first reads if you're preparing for SOC 2, the HIPAA Security Rule, PCI DSS or a penetration test. Each also appears under its subject below.
Guides by subject
Each subject links to the page on this site that covers it. Every guide lists its primary sources and the date they were checked.
Showing all 20 guides in 8 subjects.
Compliance
SOC 2 readiness checklist: how to prepare for your report
A practical SOC 2 readiness checklist: set your system boundary, pick Trust Services Criteria, close control gaps, collect evidence and choose a CPA firm.
Compliance
SOC 2 Type 1 vs Type 2: which report do you need?
SOC 2 Type 1 vs Type 2: what each report covers, how the Type 2 review period works, and how to decide which one your customers actually need first.
Compliance
SOC 2 Trust Services Criteria explained, CC1 to CC9
The SOC 2 Trust Services Criteria explained: the five categories, the CC1 to CC9 common criteria, points of focus, and how to choose what goes in scope.
HIPAA Security Rule
HIPAA Security Rule readiness overviewCompliance
HIPAA security risk analysis: what the rule requires
What the HIPAA Security Rule requires in a risk analysis, how to scope ePHI, rate risks, document decisions and keep it current, with NIST and HHS resources.
Compliance
HIPAA Security Rule checklist: every standard, explained
A HIPAA Security Rule checklist built from 45 CFR 164.308 to 164.316: every standard and implementation specification, marked required or addressable.
Compliance
HIPAA for SaaS companies: when you're a business associate
When a SaaS or health tech company becomes a HIPAA business associate, what the Security Rule and a BAA cover, and how SOC 2 fits alongside HIPAA work.
Compliance
Proposed HIPAA Security Rule changes: status and impact
The proposed HIPAA Security Rule update explained: its current status, what HHS proposed in January 2025, what applies today, and how to plan sensibly.
PCI DSS
PCI DSS readiness overviewCompliance
Which PCI DSS SAQ do you need? SAQ types and scope
Which PCI DSS Self-Assessment Questionnaire fits your payment setup: SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC and D, who decides, and how scope drives it.
Compliance
PCI DSS v4.0.1 explained: versions and 2025 requirements
PCI DSS v4.0.1 explained: how it differs from v4.0, the requirements that took effect March 31, 2025, and what the 2026 request for comments means.
Compliance
PCI DSS 6.4.3 and 11.6.1: payment page script security
PCI DSS requirements 6.4.3 and 11.6.1 in plain terms: payment page script inventory, authorization and integrity, tamper detection, and SAQ A eligibility.
ISO/IEC 27001
ISO/IEC 27001 readiness overviewReadiness
The ISO/IEC 27001 certification process, step by step
The ISO/IEC 27001 certification process, step by step: ISMS scope, risk assessment, Statement of Applicability, stage 1 and 2 audits, and surveillance.
CMMC and NIST SP 800-171
CMMC readiness overviewCompliance
CMMC Level 2 and NIST SP 800-171: readiness basics
CMMC Level 2 readiness basics: NIST SP 800-171 Rev. 2's 110 requirements, FCI vs CUI, SSPs and POA&Ms, SPRS scores and the DFARS clauses behind them.
Comparing frameworks and formal outcomes
Compliance frameworks comparedCompliance
ISO 27001 vs SOC 2: differences and which to pursue
ISO 27001 vs SOC 2: certificate vs attestation report, who issues each, how scope and upkeep differ, and how to decide which to pursue first or do both.
Compliance
Is SOC 2 a certification? Who can issue what
There's no SOC 2 or HIPAA certification. Here's who can issue SOC 2 reports, ISO 27001 certificates, PCI DSS reports and CMMC results, and how to check.
Penetration testing and vulnerability scanning
Penetration testing service overviewTesting
Penetration testing types and how often to test
Penetration test types and cadence: web app, API, external and internal network tests, and what PCI DSS, SOC 2, HIPAA and ISO 27001 say about frequency.
Testing
Penetration testing vs vulnerability scanning
Vulnerability scanning vs penetration testing: what each finds, how often each runs, where PCI DSS requires ASV scans, and how the two work together.
Testing
How to scope a penetration test you can act on
How to scope a penetration test you can act on: the question to answer, written authorization, targets and exclusions, rules of engagement and retest.
Security leadership, risk and incident readiness
All security servicesGovernance
What a vCISO does, and when to hire a full-time CISO
What a virtual or fractional CISO does, what stays with your leadership, and the signs it is time to hire a full-time CISO, framed by NIST CSF 2.0 Govern.
Readiness
Incident response plan guide: write it, then test it
What an incident response plan should include, aligned to NIST SP 800-61 Rev. 3, and how to test it with a tabletop exercise before you ever need it.
Governance
How to do a cybersecurity risk assessment
How to do a cybersecurity risk assessment: the four NIST SP 800-30 steps, writing and ranking risks in a risk register, and a roadmap with named owners.
Glossary
Short, precise definitions, including who is authorized to issue each formal outcome. A few terms people often ask about:
- Readiness assessment
- A review of how prepared an organization is for a specific audit, assessment, or certification, and what it should fix first.
- Attestation
- A formal written conclusion from an independent party about whether a subject, such as a system description or a set of controls, meets defined criteria.
- Certified Third-Party Assessment Organization (C3PAO)
- An organization authorized by the Cyber AB, the CMMC Accreditation Body, to conduct CMMC Level 2 certification assessments.
- Compensating control
- In PCI DSS, an alternative control an organization may use when a legitimate, documented technical or business constraint prevents it from meeting a requirement as written.
Tools
Help choosing a service, understanding cost, or finding a page.
Tool
Service finder
Answer a few questions about your situation to see which services fit.
Tool
Pricing estimator
See how starting prices and scope factors fit together before you ask for a proposal.
Tool
Site search
Search services, compliance guides, glossary terms, and articles in one place.
How these resources are written
We review dated technical and compliance content at least every six months.
Each article lists the primary sources it relies on, so you can check the original.
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Have a question these resources don't answer?
Every engagement begins with a written scope and proposal.