Quick Answer: Cybersecurity Compliance
Cybersecurity compliance means meeting regulatory and contractual security requirements that apply to your organization. The four most common frameworks are HIPAA (healthcare PHI), SOC 2 (SaaS service organizations), PCI DSS (payment card data), and ISO 27001 (international InfoSec management). NIST CSF is voluntary but widely adopted as a baseline. Audit costs range from $15K for a HIPAA gap assessment to $200K+ for a PCI DSS Level 1 audit.
Who Needs Which Framework
| Framework | Who Needs It | Audit / Assessment |
|---|---|---|
| HIPAA | Healthcare providers, health plans, clearinghouses, and their business associates | Self-assessment or third-party audit; no formal certification |
| SOC 2 | SaaS, cloud, and service organizations that handle customer data | Type I (point-in-time) or Type II (3–12 month period) |
| PCI DSS | Any merchant or service provider processing payment cards | SAQ (Level 4) to on-site audit (Level 1) |
| ISO 27001 | Any organization wanting internationally recognized ISMS | Stage 1 + Stage 2 certification audit; 3-year cycle with surveillance |
| NIST CSF | Any US organization; voluntary but widely adopted as baseline | Self-assessment; no formal audit |
| GDPR / UK GDPR | Any organization handling EU/UK personal data | Self-assessment; ICO and EU DPAs enforce |
| CCPA / CPRA | Any business meeting thresholds for California consumers | Self-assessment; California AG enforces |
HIPAA Compliance (Healthcare)
HIPAA applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. The Security Rule requires administrative, physical, and technical safeguards for protected health information (PHI).
Key requirements:
- Risk analysis and risk management
- Workforce security training
- Access controls with unique user IDs and audit logging
- Encryption of PHI at rest and in transit
- Incident response and breach notification procedures
- Business associate agreements with all vendors handling PHI
Penalties range from $137 per violation (unknowing) to $68,928 per violation (willful neglect), with annual caps up to $2.07 million for repeated violations. The 2009 HITECH Act expanded these. Criminal penalties can include imprisonment for false claims.
SOC 2 Compliance (SaaS and Service Organizations)
SOC 2 is the most common compliance framework requested by enterprise SaaS buyers. Service organizations publish a SOC 2 attestation report to demonstrate they have controls in place to protect customer data.
SOC 2 Type I vs Type II
- SOC 2 Type I: Audits the design of controls at a point in time. Faster to obtain (4–6 weeks), but less comprehensive.
- SOC 2 Type II: Audits both the design and operating effectiveness of controls over a period (typically 3–12 months). Most enterprise buyers require Type II.
Five Trust Services Criteria (TSC) categories: Security (mandatory), Availability, Confidentiality, Processing Integrity, and Privacy. Most SOC 2 reports include only Security plus 1–2 additional TSCs.
PCI DSS Compliance (Payment Cards)
The Payment Card Industry Data Security Standard applies to any merchant or service provider that processes, stores, or transmits cardholder data. PCI DSS v4.0 went into full effect in March 2025, with v3.2.1 retired in March 2024.
PCI DSS Compliance Levels (Merchant)
- Level 1: Over 6M transactions/year — annual on-site audit by a Qualified Security Assessor (QSA).
- Level 2: 1M–6M transactions/year — annual SAQ plus quarterly network scans.
- Level 3: 20K–1M e-commerce transactions/year — annual SAQ plus quarterly scans.
- Level 4: Under 20K e-commerce or any other channel — annual SAQ plus quarterly scans.
Non-compliance penalties: card brand fines ranging from $5,000 to $100,000/month, plus increased transaction fees and potential loss of merchant account.
ISO 27001 Compliance (International)
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It is widely required by enterprise customers in Europe and globally, particularly for vendors selling into multinational corporations.
Key requirements:
- Risk assessment methodology and risk treatment plan
- Statement of Applicability (SoA) for 93 Annex A controls
- Internal audit program and management review
- Continuous improvement through corrective actions
- 3-year certification cycle with annual surveillance audits
Implementation is rigorous — typically 6–12 months for first-time certification — and certification is granted by accredited certification bodies (BSI, TÜV, LRQA, DNV).
NIST Cybersecurity Framework (Baseline)
The NIST Cybersecurity Framework is voluntary but widely adopted across US organizations as a baseline. It organizes security into five functions:





