Skip to content

    Articles tagged: Compliance

    108 articles on Compliance from the Top Floor insights library.

    • 2026-08-25

      What Is a SOC 2 Observation Period, and How Long Should Yours Be?

      The observation period is the span of time a Type II opinion covers. Nothing in the attestation standard fixes its length, which is why it gets sold to you as a lever. What the window really is, what each length buys, and how to pick one you can defend to a buyer.

    • 2026-08-25

      What Does Outsourced Compliance Actually Cost?

      Most providers quote outsourced compliance after a discovery call, which makes the market almost impossible to compare. Here are our published tiers, what each one actually covers, the third-party lines no retainer includes, and how to compare quotes that hide the number.

    • 2026-08-25

      What Does ISO 27001 Certification Cost?

      For a 51 to 200 person company, we plan against four ISO 27001 lines: gap analysis, remediation, certification audit fees, and the recurring maintenance that outlives them all. Here are our planning bands, what sits inside each, and why size moves every line.

    • 2026-08-25

      How Long Does HITRUST Take?

      HITRUST publishes a duration for two of its three assessments and none for the third, and the Assessment Handbook fixes several clocks that no amount of readiness can shorten: a 90-day fieldwork cap, a 90-day control incubation period and a reserved QA block. Here is the calendar for each tier, sourced to HITRUST.

    • 2026-08-25

      What Does HITRUST Certification Cost?

      HITRUST certification is three separate bills: the MyCSF subscription and report credit paid to HITRUST, the authorised assessor's fee, and your own readiness and remediation effort. HITRUST publishes the structure of the first and, on every page we could fetch, no price. What each bill covers, and our own planning figures.

    • 2026-08-25

      How Long Does a Gap Assessment Take?

      Weeks, not months, for a single framework at a defined scope, and the framework is not what sets the clock. The depth of evidence the assessor examines is, and that is a decision made at scoping, usually without anyone noticing they made it.

    • 2026-08-25

      How Long Does Remediation Take After a Gap Assessment?

      Remediation is the widest band on every compliance timeline this site publishes, and the length of the gap list is a poor predictor of it. What predicts the calendar is the class of each gap, because a missing document closes in days and a control that has never operated closes only with time.

    • 2026-08-25

      How Long Does GDPR Readiness Take? The Clocks That Actually Set the Date

      GDPR has no certificate and no finish line, so the honest question is how long it takes to build a defined readiness file. No primary source publishes a project duration. What the Regulation does publish is a set of clocks, and those, plus the count of systems you hold, are what set the calendar.

    • 2026-08-25

      What Is a RoPA, and Does a Small Company Have to Keep One?

      A record of processing activities is the Article 30 register a supervisory authority can demand on request. The under-250 derogation is narrower than most content implies: any one of three conditions removes it, and a small company that pays staff has already met one of them.

    • 2026-08-25

      What Is a Lawful Basis Under GDPR, and Why Can You Not Change It Later?

      Every processing purpose needs one of the six Article 6 grounds before collection starts, and the EDPB's rule is that the choice cannot be swapped afterwards. Which basis fits which purpose, the three-step test behind legitimate interests, and the mistake of treating consent as the safe default.

    • 2026-08-25

      What Is an ISMS? The Thing ISO 27001 Actually Certifies

      An ISMS is the management system ISO/IEC 27001 specifies in clauses 4 to 10, scoped by you and certified as a whole. The controls in Annex A are a reference list, not the system, and the certificate covers the scope you wrote down, not the company.

    • 2026-08-25

      What Is an ISO 27001 Nonconformity? Major, Minor, and What Each Costs You

      A nonconformity is the non-fulfilment of a requirement. Whether it is major or minor turns on one test in ISO/IEC 17021-1, whether the management system can still achieve its intended results, and that grade decides what happens to the certificate.

    • 2026-08-25

      What Is a Risk Treatment Plan? The ISO 27001 Document Between the Risk Assessment and the SoA

      ISO/IEC 27001 clause 6.1.3 requires the organization to formulate a risk treatment plan and to obtain risk owners' approval of it and acceptance of the residual risk. The standard never lists the plan's columns; the signature is what the auditor checks.

    • 2026-08-25

      What Is a Compensating Control, and When Will an Assessor Accept One?

      A compensating control substitutes for a requirement you cannot meet as stated. The word doing the work is constraint, and the acceptance test differs by regime: PCI DSS wants a worksheet, HIPAA wants a documented reason, DoD wants a written variance, and SOC 2 has no worksheet at all.

    • 2026-08-25

      What Is a Management Assertion in a SOC 2 Report?

      The management assertion is the statement your auditor opines on. Without it there is no assertion-based examination: the attestation standard requires the auditor to withdraw if the party responsible for the system refuses to provide one. What it says, who signs it, and how it differs from the representation letter and the system description.

    • 2026-08-25

      How to Identify CUI in Your Environment: A Five-Step Procedure

      You do not decide what is CUI; the designating agency does. What you decide is where it landed. The procedure runs from the contract clause to the marking to the inbox to the file server, and it ends in three documents an assessor will ask for by name.

    • 2026-08-25

      What Is ePHI, Exactly? The Scoping Test Behind the Definition

      The regulation defines ePHI in one sentence that points at two other definitions, and the scoping decision hides in the pointer. Three nested tests decide whether a record is protected health information; one more decides whether the Security Rule reaches it.

    • 2026-08-25

      Does the EU AI Act Require a Conformity Assessment for Your System?

      Every high-risk AI system needs one, but for most of Annex III it is a self-assessment with no notified body. The notified body enters in two places only, and the deadline moved when the Digital Omnibus on AI took effect.

    • 2026-08-25

      Do You Need a Notified Body Under the CRA?

      Only if your product's core functionality is an important or critical category and, for class I, no harmonised standard covers the risks of that core functionality. The Commission's guidance turns both of those into tests you can run.

    • 2026-08-25

      How Long Does DORA Readiness Take?

      There is no grace period to plan against: DORA has applied since January 2025 and provides no transitional period. The honest timeline is set by the regulation's recurring clocks and by the workstreams with external lead times, and it differs for a new entrant, a laggard, a vendor and a group.

    • 2026-08-25

      How Long Does EU CRA Conformity Take?

      About fifteen months to the main obligations, weeks to the reporting duties, and a conformity route whose duration nobody can quote yet, because the product-specific standards are still in approval and the notified body listing is still marked once available. What you control, what you do not, and the sequence that survives both.

    • 2026-08-25

      How Long Does FDA Premarket Cybersecurity Review Take?

      FDA publishes its clocks: 90 FDA Days for a 510(k), 150 review days for a De Novo, 180 days from filing for a PMA, and 70 days for Pre-Submission feedback. The cybersecurity question is whether your submission stays on those clocks or falls off them, and the two places it falls off are screening and the Additional Information hold.

    • 2026-08-23

      How to Write an Incident Response Plan (NIST SP 800-61r3)

      The authoritative reference changed in April 2025, and most plans still teach the withdrawn model. Six questions a plan has to answer, what NIST puts in the policy instead, and the paragraph on containment authority that nearly every template omits.

    • 2026-08-23

      How Long Does ISO 42001 Certification Take?

      Four to nine months, and the audit is days of it. Stage 2 tests whether the AI management system operated rather than whether it was designed, which puts a floor under the calendar that no budget removes.

    • 2026-08-23

      How to Write an AI Acceptable Use Policy

      Six sections and two pages. ISACA's 2026 research puts formal AI policy adoption at 38 percent against 90 percent believing employees already use AI, which means most organizations are governing the tools after the fact rather than before.

    • 2026-08-23

      What Are the Trust Services Criteria?

      Five categories, 61 numbered criteria, 33 of them common to all five. The distinction between a category and a criterion is not pedantry: it is what decides how much your SOC 2 scope actually costs you in evidence.

    • 2026-08-23

      What Is a System Security Plan (SSP)?

      The SSP is not paperwork produced for an assessment. It is the document the assessment is conducted against, and 32 CFR 170.17 requires its name, date and version to be filed with your results.

    • 2026-08-23

      What Is a DPIA, and When Does GDPR Require One?

      The trigger is a property of the processing, not of your size. A twelve-person company doing large-scale profiling owes a DPIA; a thousand-person company running payroll does not.

    • 2026-08-23

      What Is a Risk Register, and What Makes One Worth Keeping?

      A risk register is a repository of risk information including the data understood about risks over time. NIST's notional template carries twelve fields, and the two that decide whether the thing works at all are the two most spreadsheets leave out.

    • 2026-08-23

      You Got an FDA Cybersecurity Deficiency Letter. Now What?

      180 calendar days, no extensions, and the submission is deleted if you miss it. What the three FDA hold types actually are, how to read a deficiency, and why the fast partial response is the one that costs a cycle.

    • 2026-08-23

      Does DORA Require Threat-Led Penetration Testing?

      Only if your competent authority tells you so. No financial entity opts into TLPT, and no vendor can tell you that you are in scope. What the designation actually turns on, and what to do while you wait to hear.

    • 2026-08-23

      India DPDP: What Is in Force Now, and What Lands in 2027

      Eighteen months. That is the gap the Indian government wrote into G.S.R. 843(E) between establishing the Data Protection Board and switching on a single obligation that binds your company. As of August 2026 none of them are on, and the ones everybody is preparing for arrive together on 13 May 2027.

    • 2026-08-23

      How Much Do Compliance Frameworks Actually Overlap?

      Overlap between two frameworks is two numbers, not one, and the two can differ by 79 percentage points on the same intersection. Measured from our own published mapping dataset, with the denominators named.

    • 2026-08-23

      Is CMMC Level 2 the Same as NIST 800-171?

      The regulation says the requirements are identical, in those words, and our own control crosswalk agrees control for control: both lenses reach the same 218 NIST 800-53 controls. Everything CMMC adds sits outside the standard, which is exactly where the cost is.

    • 2026-08-23

      Does GDPR Compliance Cover CCPA?

      The crosswalk says 85 percent of what GDPR reaches is already inside the California footprint, and only 23 percent the other way. Both numbers are misleading in a specific, checkable way. What the mapping can and cannot see about a rights statute.

    • 2026-08-23

      Boutique or Big Four: Who Should Do Your Security Consulting?

      Firm size is a proxy, and a weak one. You are choosing among five provider tiers, not two, and the variable that moves the outcome is whether the person who scoped your work is the person who does it.

    • 2026-08-23

      How Much Does a Cybersecurity Consultant Cost?

      Almost every hourly rate published for this question has no source behind it, and we went looking. Here is what can actually be verified, and how to price the proposal in front of you without a market rate.

    • 2026-08-23

      How Long Does SOC 2 Take, Start to Finish?

      Six to fifteen months from a standing start to a first Type II report. The number that actually fixes your date is not the length of the observation window you pick; it is how often your least frequent control runs, because a period report is tested by sampling.

    • 2026-08-23

      How Long Does a Penetration Test Take?

      The testing is days. The engagement is weeks. NIST's own methodology puts a whole phase before testing in which no testing happens, and that phase, plus the retest at the other end, is where your date actually goes.

    • 2026-08-23

      When Should You Start SOX Preparation Before an IPO?

      Your first annual report after listing contains no report on internal control over financial reporting at all. Instruction 1 to Item 308 of Regulation S-K says so, and once you accept it the start date stops being a rule of thumb and becomes arithmetic.

    • 2026-08-23

      Does SOX Apply to Private Companies?

      Two Sarbanes-Oxley provisions live in the federal criminal code and apply to whoever, not to issuers. A third protects the employees of a public company's contractors. The famous one, Section 404, does not apply to you, and that is the smallest part of the answer.

    • 2026-08-23

      What FDA Expects After Clearance: Postmarket Device Cybersecurity

      Most cybersecurity patches are device enhancements that need no report to FDA at all. The exception is the small subset addressing uncontrolled risk, where the enforcement discretion has four conditions and two of them are clocks.

    • 2026-08-23

      AOC or ROC: Which PCI Document Does Your Customer Actually Want?

      Your customer asks for your PCI report. Send the Attestation of Compliance, which the Council says is the document intended to be shared, and keep the Report on Compliance in house. Which one you must produce is decided by your acquirer, not by you and not by your assessor.

    • 2026-08-23

      The CCPA Cybersecurity Audit: Does It Apply to You, and When?

      California's cybersecurity audit rule took effect on January 1, 2026, with the first audit reports due April 1, 2028, 2029 or 2030 depending on revenue. Being a CCPA business is not enough to be caught by it, and the auditor independence rule disqualifies whoever built your program.

    • 2026-08-23

      How to Choose a SOC 2 Readiness Partner

      Three things you can verify about a SOC 2 partner before you sign, none of which is a testimonial: that your CPA firm is licensed and in peer review, that nobody sits on both sides of the readiness and opinion line, and that any arrangement between your partner, your platform and your auditor is on the table.

    • 2026-08-23

      42 CFR Part 2 vs HIPAA: What the Alignment Rule Changed

      Substance use disorder records carry a second federal confidentiality rule on top of HIPAA, and the compliance date for its overhaul passed on February 16, 2026. What actually changed, what deliberately did not, and how to tell whether it applies to you.

    • 2026-08-22

      How Much Does an Outsourced DPO Cost?

      Published benchmarks put outsourced DPO services at EUR 1,150 to EUR 2,900 a month against EUR 80,000 to EUR 150,000 a year in salary for an in-house appointment. We work through the sourced numbers, the scope drivers, and the threshold question most buyers skip: whether you owe a DPO at all.

    • 2026-08-22

      PCI Segmentation Testing: Who Needs It and How Often?

      If you use segmentation to shrink PCI scope, you have to prove it works: at least every 12 months under Requirement 11.4.5, and every six months for service providers under 11.4.6. A failed test can void the scope reduction your entire compliance budget assumes.

    • 2026-08-22

      How Much Does a HIPAA Risk Analysis Cost?

      Published ranges run from $0 to about $25,000, and the free federal tool is real. What actually drives the number, what the money buys that the free tool does not, and the enforcement record that sets the price of getting it wrong.

    • 2026-08-22

      HITRUST e1 vs i1 vs r2: Which One Do You Actually Need?

      HITRUST publishes the control counts: 43 for e1, 182 for i1, and a tailored set for r2, which is the only one valid for two years. The tier you need is the one your customer's contract names, and the cost sources disagree more than they admit.

    • 2026-08-22

      Do You Need HITRUST, or Is SOC 2 Enough for Healthcare?

      If a contract names HITRUST, SOC 2 will not substitute, because one is a scored certification and the other is an auditor's opinion. If no contract names it, the numbers say start with SOC 2 and documented HIPAA compliance.

    • 2026-08-22

      FDA Cybersecurity for Medical Devices: What Section 524B Requires

      Since March 2023, a cyber device submission without the Section 524B package is incomplete, and since October 2023 FDA has expected sponsors to be ready. The operative guidance changed again in February 2026, which most content on this topic has not caught up with.

    • 2026-08-22

      How Long Does ISO 27001 Certification Take?

      Six to nine months, and the audit is not what holds the clock. ISO/IEC 17021-1 requires your Stage 2 auditor to see the ISMS operating, so there is a floor no budget removes. Here is where the months actually go.

    • 2026-08-22

      Does Your MSP Need CMMC? External Service Provider Rules

      Your managed service provider almost certainly does not need its own CMMC certification, and neither does your cloud provider. Cloud carries a different obligation, and it lands on you: FedRAMP Moderate equivalency. What 32 CFR 170.19 and DFARS 252.204-7012 actually require of the vendors inside your boundary.

    • 2026-08-22

      NIST 800-171 Rev 2 or Rev 3: Which One You Actually Owe

      CMMC Level 2 is Revision 2, in the regulation's own words, and a DoD class deviation pins DFARS 7012 to Revision 2 until it is rescinded. Revision 3 is real, it is coming from a different direction, and rebuilding for it now is a mistake.

    • 2026-08-22

      CMMC Enclave or Full Scope: How to Decide

      The enclave decision is about people, not company size. If a minority of your staff touch CUI, a boundary pays. If most of them do, a boundary they cross daily will not survive an assessment. The asset categories, the crossover, and the hidden costs.

    • 2026-08-22

      How Long Does CMMC Level 2 Take?

      Six to eighteen months to assessment-ready, and nobody can currently tell you when an assessor will be available. The capacity arithmetic from DoD's own rule, why evidence maturity is the long pole, and what the suspension actually buys you.

    • 2026-08-22

      How to Choose a C3PAO, and When to Book One

      The regulation already guarantees more about a C3PAO than most buyers realize, which means the usual vetting questions are wasted. What 32 CFR 170.9 requires, what genuinely differs between assessors, and why most contractors should not book one right now.

    • 2026-08-22

      What Does PCI DSS Compliance Actually Cost?

      There is no published rate card for PCI, and the site that specialises in the question says so itself. What exists are seller-side ranges that disagree with each other by more than 2x on the same line item. The width is the finding.

    • 2026-08-22

      SAQ A Got Stricter by Getting Shorter

      The Council removed three requirements from SAQ A and added an eligibility criterion in their place. Iframe merchants now have to confirm something before they may use the questionnaire at all. Redirect merchants do not.

    • 2026-08-22

      How to Reduce Your PCI DSS Scope

      Four levers, in order of how much they remove: get card data out entirely, tokenize what you must keep, encrypt at the point of capture, and segment the remainder. The one that undoes all four is the back office nobody drew.

    • 2026-08-22

      How Long Does PCI DSS Compliance Take?

      One published assessor timeline puts a first Report on Compliance at three to six months from scoping to signed report, and annual renewals at six to ten weeks. If you self-assess there is no fieldwork clock at all, only a remediation clock.

    • 2026-08-22

      Big Four or Boutique for Audit Readiness: What You Are Paying For

      The 20-to-40-percent saving everyone quotes is a misread wage statistic, and we are a boutique refusing to use it. What actually separates the two proposals is the staffing pyramid, and there are three cases where the premium is the right purchase.

    • 2026-08-22

      Should You Switch Audit Firms? What Changing Auditors Really Costs

      Nothing stops you from changing auditors, which is exactly why companies do it for the wrong reason. The bill has three lines nobody puts in the quote: the reporting period, the system description, and a year of context.

    • 2026-08-22

      Auditor Walkthroughs: What They Ask, and How to Prepare Your Team

      A walkthrough follows one real transaction through your real systems using inquiry, observation, inspection and re-performance. Teams do not fail because their controls are weak; they fail because the person in the room does not perform the control.

    • 2026-08-22

      What Does ISO 42001 Certification Actually Cost?

      Published estimates for ISO 42001 run from a few thousand dollars to $650,000, and every one of them is defensible. Here is why they disagree, what the certification body actually charges, and how to place your own company on the range.

    • 2026-08-22

      Incident Response vs Disaster Recovery vs Business Continuity

      Incident response contains, disaster recovery restores, business continuity keeps the company trading. NIST's actual taxonomy has eight plan types, and the document most companies call a DR plan is not one under that definition.

    • 2026-08-22

      California's ADMT Rules: Does Your AI Make a Significant Decision?

      The trigger is not that you use AI. It is that a technology substantially replaces human decisionmaking about one of five listed outcomes, and compliance is required by January 1, 2027. The two-part test, the pre-use notice, and why most AI systems are out of scope.

    • 2026-08-21

      EU Representative vs DPO: Which Does a US Company Need?

      Two different GDPR appointments, two different triggers, and roughly two orders of magnitude between their published prices. Which one a US company owes, why the same firm cannot be both, and the case where you owe neither.

    • 2026-08-21

      ISO 27001 Stage 1 vs Stage 2: What Auditors Actually Check

      Stage 1 asks whether you have what you need. Stage 2 asks whether you are doing what you say. Here is what each auditor pulls, what a Stage 1 finding costs you, and why you cannot fail Stage 1 in the way people fear.

    • 2026-08-21

      NIST AI RMF vs ISO 42001: Which Do You Need?

      NIST AI RMF is a free voluntary US framework you align to; ISO 42001 is a certifiable international standard you get audited against. One question decides it: does anyone outside your company need proof?

    • 2026-08-21

      HITRUST Inheritance: What You Can Actually Reuse

      HITRUST says organisations can inherit as much as 70 to 85 percent of requirements from participating cloud providers. AWS attaches a conditional to that number which is where most of it goes. What inheritance moves, what it does not, and what HITRUST's public pages decline to explain.

    • 2026-08-20

      How Much Does GDPR Compliance Cost a US Company?

      The most-quoted GDPR cost figure is USD 1.7 million a year for a small business, and it is from 2018. We price the line items you can actually buy at published rates, work the arithmetic, and land somewhere very different.

    • 2026-08-20

      How to Write an ISO 27001 Statement of Applicability That Survives Audit

      The SoA is mandatory under clause 6.1.3 d and it is where most Stage 1 findings live. You do not have to implement all 93 Annex A controls; you do have to justify every inclusion and exclusion from your risk assessment.

    • 2026-08-20

      What Should a vCISO Deliver in the First 90 Days?

      Four artifacts by day 90: a real inventory, a risk assessment with a prioritized and costed roadmap, a first tranche of closed gaps, and a report you could hand an investor or an insurer. If all you have is policy templates, you bought documents.

    • 2026-08-19

      Data Privacy Framework vs SCCs: Which Transfer Mechanism Do You Need?

      DPF self-certification costs $260 a year at the smallest revenue tier and removes the SCC paperwork for covered transfers. Then the Supreme Court decided FTC commissioners can be fired at will, and the durability question got sharper.

    • 2026-08-19

      ISO 27001 Surveillance Audits: What Years 2 and 3 Actually Take

      The certificate runs three years, but your auditor comes back annually. Plan on about a third of your initial audit time for each surveillance visit and about two-thirds for recertification. Here is what they check and how certificates get suspended.

    • 2026-08-18

      Privacy Compliance Software vs a Consultant: What Do You Need?

      Consent tooling now publishes self-service tiers from EUR 7 a month, and it is genuinely good at what it does. It cannot decide which laws reach you, what your lawful bases are, or what goes in your Article 30 records. Buy the cheap tool, then buy hours.

    • 2026-08-18

      What Type of Penetration Test Do You Need?

      Match the test to your attack surface, not to a vendor's menu of nine test types. Most first-time buyers need one or two, and the scoping call should tell you which before anyone quotes a number.

    • 2026-08-18

      Do You Need an ISO 27001 Consultant, or Just a Platform?

      A platform automates evidence. It does not run your risk assessment, justify your Statement of Applicability, or perform your internal audit. Here is the split that decides the buy, plus the certification-body red flags nobody selling this mentions.

    • 2026-08-16

      Is Your Product Important Under the CRA? Annex III and the Conformity Routes

      Most products self-assess. Annex III class I products self-assess only if they apply harmonized standards in full, class II and critical products cannot. Which list you land on decides your budget and your timeline.

    • 2026-08-16

      Comply Once, Prove Many: Reusing Evidence Across Frameworks

      Most of the work for your second framework is already done, if you tagged the evidence the first time. Here is the mechanism, an honest account of the parts that never transfer, and what the overlap is really worth.

    • 2026-08-16

      When Does the New HIPAA Security Rule Take Effect?

      It has not taken effect, and as of August 2026 the Federal Register holds exactly one document for this rulemaking: the January 2025 proposal. Here is how to check that yourself, and what the current rule already requires while everyone waits.

    • 2026-08-16

      Is There Such a Thing as HIPAA Certification?

      No. There is no government-issued HIPAA certification, and a seal from a vendor proves nothing to an investigator. Here is what your customers will actually accept as proof, and what it costs you to produce it.

    • 2026-08-16

      Is Zoom HIPAA Compliant? Telehealth Rules Since the Waiver Ended

      Only on plans where the vendor signs a BAA. The COVID-era enforcement discretion expired on May 11, 2023 and the 90-day transition period closed at 11:59 pm on August 9, 2023, both stated in the HHS notice at 88 FR 22380.

    • 2026-08-16

      Which PCI SAQ Do You Need? A Decision Guide

      Your SAQ follows how card data touches your systems, not how big you are. The Council publishes several, each with its own eligibility criteria, and the boundary between the two most common ones is an engineering decision on your checkout page.

    • 2026-08-16

      What Is a PCI ASV Scan, and What Happens If You Fail One?

      An external scan by an Approved Scanning Vendor, tied to PCI DSS Requirement 11.3.2. A single finding can fail the whole scan, and failing is not the violation. Missing the quarter is.

    • 2026-08-16

      Do You Need a QSA, or Can You Self-Assess for PCI DSS?

      Most merchants can self-assess, and the entity that decides is your acquirer, not the Council and not a consultant. Get the answer in writing before you buy anything, including from us.

    • 2026-08-16

      CMMC Phase 2 Is Suspended: What Still Applies in 2026?

      The Department of War suspended CMMC Phases 2 through 4 on July 13, 2026. Almost nothing a defense contractor already owed went away with them. What paused, what did not, and what to do with the gap.

    • 2026-08-16

      What CMMC Level Do You Need? A Decision Tree by Data Type

      Your CMMC level is set by the information you handle, not by your contract size, your headcount, or your prime's certification. The decision rule, the three levels, and the edge cases that trip up small subcontractors.

    • 2026-08-16

      CMMC POA&M Rules: What You Can Defer, and for How Long

      The regulation is unusually specific: 80 percent to qualify, 1-point requirements only, six named exclusions, one 3-point exception, and 180 days to close. The practical translation is less generous than the headline.

    • 2026-08-16

      12 Questions to Ask a Compliance Consultant Before You Sign

      Twelve questions across staffing, scope, pricing, independence, and what happens when something fails. Each one with the answer you want and the answer that should end the meeting.

    • 2026-08-16

      7 Red Flags When Hiring a Security Consulting Firm

      Seven warning signs that reliably predict a bad engagement, and the mechanism behind each one. Any one of them is a reason to slow down. Two or more is a reason to walk.

    • 2026-08-16

      What Should a Security Consulting SOW Include?

      Seven things a statement of work has to pin down before anyone signs. If the SOW cannot say what you receive and who produces it, you are not buying an outcome, you are buying hours.

    • 2026-08-16

      Does Your SOC 2 Auditor's Brand Actually Matter?

      For most buyers, no. What a customer's security team checks is the CPA firm's license, the criteria and period covered, and whether the opinion is unmodified. Three exceptions where the logo genuinely counts.

    • 2026-08-16

      How to Choose a Penetration Testing Company

      Four evidence points, in order: named testers' credentials, the manual-to-automated balance, a sanitized sample report, and whether the SOW names the people. Price is the fifth criterion, not the first.

    • 2026-08-02

      You Bought Vanta or Drata. Do You Still Need a Consultant?

      Compliance automation genuinely wins at continuous monitoring, but it won't scope your Trust Services Criteria, write your system description, or answer the auditor. Here is a neutral breakdown of when a consultant still earns their fee, and when to keep your money.

    • 2026-08-02

      SOC 2 Year Two: Who Keeps Your Report Alive?

      Your second SOC 2 audit covers a full twelve-month window, and a control that lapsed in month three is a finding you cannot fix retroactively. Someone has to own the program between audits; here is what that job actually looks like and what it costs.

    • 2026-08-02

      Should You Hire a Compliance Manager or Outsource?

      A single compliance hire costs $200,000-plus fully loaded in year one and covers one of the five roles a working program needs. We run the full math on hiring versus outsourcing, then draw the honest line: three situations where in-house is clearly the right call.

    • 2026-08-01

      What Does a Compliance Program Actually Return?

      The business case for a compliance program comes down to three quantifiable lines: recovered enterprise pipeline, avoided breach losses, and audit labor saved. Here is the arithmetic, with a worked model you can populate with your own numbers.

    • 2026-07-31

      Who Owns Compliance When Nobody Owns Compliance?

      In most companies, compliance defaults to whoever answered the first security questionnaire, with no mandate, budget, or authority to run it. Here's the diagnosis, the RACI fix with a real escalation path, and when a fractional owner makes more sense.

    • 2026-07-29

      Build or Buy: Should You Run Compliance In-House?

      Both vendor camps push an all-or-nothing answer to the build-vs-buy compliance question, and both are wrong for most mid-market companies. Here is the five-axis framework we use, with worked scenarios for three org profiles and the hybrid split that usually wins.

    • 2026-07-26

      What Is Compliance Debt? A Self-Assessment

      Compliance debt is the accumulated gap between what your documentation claims and how your controls actually operate, and it compounds like technical debt. Run this 10-question scored self-assessment to find out how much you're carrying.

    • 2026-07-24

      Is a GRC Platform Enough, or Do You Need People Too?

      A platform can show that evidence was uploaded; it cannot judge whether that evidence survives auditor scrutiny. Here is the work that stays human (scoping, risk assessment, exception negotiation) and the tooling-to-people split that actually works.

    • 2026-03-28

      Why Top Floor: The Boutique GRC Advantage

      The compliance market is split between premium-priced Big Four firms, solo consultants who lack breadth, and automated platforms that miss nuance. Here is what makes a senior-practitioner boutique firm different, and why it matters for your audit outcome.

    • 2026-03-24

      Virtual CISO: When Your Organization Needs Fractional Security Leadership

      A full-time CISO at a small or midmarket company averages $415K in total compensation, but most mid-market organizations need strategic security leadership without the executive price tag. Here is how a virtual CISO works, what they deliver, and when the model makes sense.

    • 2026-02-21

      PCI DSS v4.0: The Complete Guide to Future-Dated Requirements

      PCI DSS v4.0 introduced dozens of new requirements, many labeled 'best practice until March 31, 2025,' after which they became mandatory. If your organization processes, stores, or transmits cardholder data, these future-dated requirements are now enforceable. Here is what changed and how to prepare.

    • 2026-02-05

      HIPAA Compliance Checklist for HealthTech Companies

      HIPAA violations can cost HealthTech companies millions in fines and destroy customer trust overnight. This practical checklist covers every safeguard category, BAA requirements, and breach notification rule you need to get right from day one.