Blog

Compliance

Regulations, frameworks and audits, explained in plain English.

All posts120PCI DSS25Vulnerability Management35Security Posture25Compliance35
2026
Compliance
Data Retention Policies: Keeping What You Need and Nothing More
How to build a data retention policy: set a schedule, meet GDPR, PCI DSS and HIPAA rules, handle legal holds, backups and logs, and prove deletion.
March 10, 2026 · 9 min readRead →
Compliance
Answering Vendor Security Questionnaires Without Losing Your Mind
How to answer vendor security questionnaires faster: use standard formats, build an answer library, share SOC 2 and ISO reports, and answer precisely.
January 13, 2026 · 8 min readRead →
2025
Compliance
HITRUST Certification: Is It Worth the Effort?
Is HITRUST certification worth the effort? Compare the e1, i1 and r2 assessments, see what drives the work, and learn when SOC 2 or ISO 27001 is enough.
November 18, 2025 · 8 min readRead →
Compliance
Writing Security Policies Auditors Will Accept
How to write security policies auditors will accept: structure, ownership, review cycles, control mapping, acknowledgment evidence and an exceptions process.
October 21, 2025 · 8 min readRead →
Compliance
PCI DSS vs. SOC 2 vs. ISO 27001: Which Framework Do You Need?
PCI DSS vs. SOC 2 vs. ISO 27001: who requires each, what you get, how they overlap, and which order to pursue them in based on your customers and your data.
September 16, 2025 · 8 min readRead →
Compliance
FedRAMP 20x: What's Changing for Cloud Providers
FedRAMP 20x aims to replace narrative paperwork with automated validation and faster authorizations. Here's what cloud providers know so far and what to do now.
April 22, 2025 · 7 min readRead →
Compliance
Navigating the Patchwork of U.S. State Privacy Laws
U.S. state privacy laws now cover about 19 states. See 2025–2026 effective dates, how the laws differ, and how to build one program to the strictest rules.
February 4, 2025 · 8 min readRead →
Compliance
The Proposed HIPAA Security Rule Overhaul: What Healthcare Should Expect
HHS proposed the biggest HIPAA Security Rule update in over a decade: mandatory encryption, MFA, asset inventories and annual audits. Comments close March 7.
January 21, 2025 · 8 min readRead →
Compliance
The EU Cyber Resilience Act and Products With Digital Elements
The EU Cyber Resilience Act sets security rules for products with digital elements. Key dates, product classes, Annex I requirements, SBOMs and reporting.
January 7, 2025 · 9 min readRead →
2024
Compliance
DORA: Operational Resilience Requirements for EU Financial Entities
DORA applies from January 17, 2025. Learn its five pillars, the oversight of critical ICT providers, which RTS and ITS are final, and a readiness checklist.
December 3, 2024 · 9 min readRead →
Compliance
CMMC 2.0 Final Rule: What Defense Contractors Need to Know
The CMMC 2.0 final rule takes effect December 16, 2024. Learn the three levels, assessment types, POA&M limits, annual affirmations and the phased rollout.
November 5, 2024 · 9 min readRead →
Compliance
Continuous Compliance: Moving Beyond the Annual Audit Scramble
Continuous compliance replaces the annual audit scramble with automated evidence collection, continuous control monitoring and policy-as-code. Here's how.
October 1, 2024 · 8 min readRead →
Compliance
The EU AI Act: What Security Teams Need to Know
The EU AI Act entered into force on August 1, 2024. What security teams need to know: risk tiers, Article 15 cybersecurity, logging, deadlines and fines.
September 17, 2024 · 9 min readRead →
Compliance
NIS2 Directive: Who's in Scope and What's Required
The NIS2 Directive covers medium and large firms in 18 sectors. Learn who is in scope, essential vs. important entities, Article 21 measures and fines.
June 4, 2024 · 8 min readRead →
Compliance
CIRCIA: Upcoming Incident Reporting Rules for Critical Infrastructure
CISA's proposed CIRCIA rule would have critical infrastructure entities report substantial cyber incidents within 72 hours. Who's covered and what to expect.
April 30, 2024 · 8 min readRead →
Compliance
ISO 27001:2022 Transition: What Changed and the October 2025 Deadline
The ISO 27001:2022 transition deadline is October 31, 2025. See what changed in the clauses and Annex A, and how to plan a smooth move off the 2013 version.
April 23, 2024 · 8 min readRead →
Compliance
NIST CSF 2.0: What the New 'Govern' Function Means for You
NIST CSF 2.0 adds a sixth function, Govern. Learn what the Govern function covers, why NIST added it, and how smaller teams can put it into practice.
March 12, 2024 · 9 min readRead →
Compliance
NYDFS Part 500 Amendments: Key Deadlines and Requirements
The NYDFS Part 500 amendments phase in new cybersecurity requirements through November 2025. Here are the key deadlines, Class A rules and what's due next.
February 13, 2024 · 9 min readRead →
2023
Compliance
FTC Safeguards Rule: New Breach Reporting for Non-Bank Financial Institutions
The amended FTC Safeguards Rule requires non-bank financial institutions to report breaches affecting 500 or more consumers within 30 days, from May 13, 2024.
November 21, 2023 · 8 min readRead →
Compliance
The SEC's Cyber Disclosure Rules: What Public Companies Must Report and When
The SEC cybersecurity disclosure rules require an 8-K within four business days of finding an incident material, plus new 10-K disclosures. Key dates inside.
August 15, 2023 · 9 min readRead →
Compliance
Control Mapping: Satisfying Multiple Frameworks With One Control Set
Control mapping lets one control set satisfy SOC 2, ISO 27001, PCI DSS and NIST CSF. How to build a common control framework, reuse evidence and avoid gaps.
May 2, 2023 · 9 min readRead →
Compliance
What Cyber Insurers Now Require Before They'll Write a Policy
The cyber insurance requirements underwriters now expect, from MFA and EDR to tested backups and patching, and how to answer applications accurately.
April 25, 2023 · 8 min readRead →
2022
Compliance
GDPR's 72-Hour Breach Notification Rule in Practice
How the GDPR 72-hour breach notification rule works in practice: when the clock starts, what to report, when to tell individuals, and a workable response plan.
November 15, 2022 · 9 min readRead →
Compliance
SOC 2 Type I vs. Type II: Which Do You Need?
SOC 2 Type I vs. Type II explained: what each report tests, how long it takes, when a Type I is enough, and how to pick the right report for your customers.
August 30, 2022 · 8 min readRead →
Compliance
Compliance Isn't Security: Why Passing an Audit Doesn't Mean You're Safe
Compliance vs. security: why passing a SOC 2, ISO 27001 or PCI DSS audit doesn't mean you're secure, and how to treat compliance as a floor, not a ceiling.
June 28, 2022 · 6 min readRead →
2020
Compliance
NIST SP 800-53 Rev. 5: What's New in the Control Catalog
NIST SP 800-53 Rev. 5 brings outcome-based controls, integrated privacy, a new supply chain family and separate baselines. See what changed and what to do next.
December 8, 2020 · 8 min readRead →
Compliance
CPRA Passed: What California's New Privacy Law Changes
California voters approved the CPRA (Prop 24). See what changes from the CCPA, the 2022 and 2023 dates, and the new security, audit and breach liability rules.
November 17, 2020 · 9 min readRead →
Compliance
The DFARS Interim Rule: SPRS Scores and the NIST 800-171 Assessment Methodology
The DFARS interim rule takes effect November 30, 2020. Learn how SPRS scores work, how to calculate your NIST 800-171 score and how the SSP and POA&M affect it.
October 13, 2020 · 9 min readRead →
Compliance
PCI Compliance When Your Staff Work From Home
PCI compliance doesn't pause when staff work from home. See which PCI DSS 3.2.1 requirements apply to remote workers and how to keep card data off home devices.
August 18, 2020 · 9 min readRead →
Compliance
Schrems II and the End of Privacy Shield: What Security Teams Should Do Now
Schrems II struck down the EU-US Privacy Shield. Learn what the ruling means for SCCs and the data transfer steps your security team should take right now.
July 28, 2020 · 8 min readRead →
Compliance
HIPAA Security Risk Analysis: A Step-by-Step Guide
A step-by-step guide to the HIPAA security risk analysis: scope all ePHI, find threats and vulnerabilities, rate each risk, document it and act on the results.
June 23, 2020 · 7 min readRead →
Compliance
SOC 2 Readiness: How to Prepare for Your First Audit
SOC 2 readiness for your first audit: scope the system, pick Trust Services Criteria, run a gap assessment, gather evidence and plan the Type II window.
May 19, 2020 · 8 min readRead →
Compliance
NYDFS Part 500 Annual Certification: How to Prepare
How to prepare for your NYDFS Part 500 annual certification: who signs, what records to keep, and a checklist of controls to verify before February 15.
March 10, 2020 · 8 min readRead →
Compliance
CMMC 1.0 Is Here: What the New Model Means for Defense Contractors
CMMC 1.0 was released January 31, 2020. What defense contractors need to know: the five levels, third-party certification, FCI vs. CUI and how to prepare now.
February 18, 2020 · 8 min readRead →
Compliance
CCPA Is Now in Effect: What Security Teams Need to Do
The CCPA took effect January 1, 2020. What security teams must do now: map personal data, verify consumer requests and meet the law's reasonable security duty.
January 14, 2020 · 9 min readRead →