Map your regulatory requirements to the cybersecurity services you need.
Select your compliance requirement below to see which cybersecurity services are typically needed. These are industry-standard recommendations based on regulatory requirements and auditor expectations.
Any business that stores, processes, or transmits credit card data. This includes e-commerce sites, retail stores, SaaS platforms with billing, and payment processors.
External Penetration Testing
Required annually (Requirement 11.3). Must test all external-facing systems in the cardholder data environment.
Internal Penetration Testing
Required annually (Requirement 11.3). Must test internal segmentation controls and access to cardholder data.
Web Application Security Testing
Required for public-facing web applications (Requirement 6.6). Can be satisfied with a WAF or manual testing.
Vulnerability Scanning
Required quarterly by an Approved Scanning Vendor (ASV) for external scans (Requirement 11.2).
Compliance Audit
Annual assessment by a QSA (Qualified Security Assessor) for Level 1 merchants, or SAQ self-assessment for smaller merchants.
Healthcare providers, health plans, healthcare clearinghouses, and their business associates who handle protected health information (PHI). This includes hospitals, clinics, insurance companies, and SaaS vendors serving healthcare.
Risk Assessment
Required by the Security Rule (§164.308). Must identify risks to the confidentiality, integrity, and availability of ePHI.
Penetration Testing
Not explicitly mandated but strongly recommended by HHS as part of the risk assessment process. Expected during OCR audits.
Compliance Assessment
Evaluates administrative, physical, and technical safeguards against HIPAA requirements. No formal certification exists, but documented assessments are expected.
Incident Response Planning
The Breach Notification Rule requires you to notify affected individuals within 60 days. Having an IR plan and retainer ensures you can respond effectively.
vCISO
HIPAA requires a designated security official (§164.308). A vCISO can fulfill this role for organizations that cannot afford a full-time security executive.
All publicly traded companies in the United States. Section 404 specifically addresses internal controls over financial reporting, which increasingly includes IT controls.
IT General Controls (ITGC) Audit
Evaluates access controls, change management, computer operations, and program development for systems involved in financial reporting.
Penetration Testing
Not explicitly required but used to validate the effectiveness of access controls and network security protecting financial systems.
Cloud Security Assessment
If financial systems run in the cloud, SOX auditors need assurance that cloud configurations support control objectives.
vCISO
Provides strategic oversight to ensure IT security controls align with SOX compliance requirements and support audit readiness.
Any organization that processes personal data of EU/EEA residents, regardless of where the organization is located. Applies to most global SaaS companies, e-commerce businesses, and any company with European customers or employees.
Data Protection Impact Assessment (DPIA)
Required under Article 35 for high-risk processing activities. Identifies and mitigates privacy risks.
Penetration Testing
Article 32 requires "appropriate technical measures" and "regular testing, assessing and evaluating" the effectiveness of security measures.
Cloud Security Assessment
If personal data is stored in cloud environments, you must ensure appropriate security measures are in place (Article 32).
Incident Response
Article 33 requires breach notification to supervisory authorities within 72 hours. Having IR capabilities is essential.
Compliance Assessment
Regular evaluation of your data processing activities, privacy notices, consent mechanisms, and data subject rights processes.
Department of Defense contractors and subcontractors who handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). Required for DoD contract eligibility.
CMMC Readiness Assessment
Evaluates your current security posture against the 110+ practices required at your target CMMC level before the formal assessment.
Penetration Testing
Validates the effectiveness of your security controls and demonstrates they work as intended against real attack techniques.
Vulnerability Management
CMMC requires ongoing vulnerability scanning and remediation processes (multiple practices across several domains).
Incident Response Planning
The Incident Response (IR) domain requires documented IR capabilities, testing, and reporting to DoD.
vCISO
Provides the security leadership and program management needed to achieve and maintain CMMC certification, especially for small defense contractors.
Originally developed for critical infrastructure, now widely adopted as a voluntary framework by organizations of all sizes and industries. Often used as a baseline for building a security program or demonstrating due diligence.
Security Program Assessment
Maps your current capabilities to the five CSF functions (Identify, Protect, Detect, Respond, Recover) and identifies gaps.
Penetration Testing
Validates the effectiveness of your Protect and Detect functions with real-world attack simulation.
Incident Response Planning
The Respond function requires documented response processes, communications plans, and improvement based on lessons learned.
vCISO
Provides ongoing leadership to implement and mature your security program across all five CSF functions.
Cloud Security Assessment
Ensures your Protect function extends to cloud environments with appropriate technical safeguards.
Any organization seeking formal certification of their Information Security Management System (ISMS). Common for B2B companies, SaaS providers, and organizations that need to demonstrate security maturity to enterprise customers.
ISO 27001 Gap Assessment
Identifies gaps between your current ISMS and the requirements of Annex A controls before formal certification audit.
Penetration Testing
Annex A control A.18.2.1 requires independent review of information security. Pen testing is the most common way to satisfy this.
Internal Audit
Clause 9.2 requires regular internal audits of the ISMS. An external provider can perform this with greater independence.
Risk Assessment
Clause 6.1.2 requires a formal information security risk assessment process. This is foundational to the entire ISMS.
vCISO
Provides the management commitment and security leadership required by Clause 5, especially for organizations without dedicated security staff.
Important note: Compliance requirements vary based on your specific situation, scope of regulated data, and how your systems are architected. These recommendations represent common starting points. A qualified assessor can help you determine your exact requirements.