Compliance Mapping

Map your regulatory requirements to the cybersecurity services you need.

Select your compliance requirement below to see which cybersecurity services are typically needed. These are industry-standard recommendations based on regulatory requirements and auditor expectations.

PCI DSS

Payment Card Industry Data Security Standard

Any business that stores, processes, or transmits credit card data. This includes e-commerce sites, retail stores, SaaS platforms with billing, and payment processors.

Recommended Services

External Penetration Testing

Required annually (Requirement 11.3). Must test all external-facing systems in the cardholder data environment.

Internal Penetration Testing

Required annually (Requirement 11.3). Must test internal segmentation controls and access to cardholder data.

Web Application Security Testing

Required for public-facing web applications (Requirement 6.6). Can be satisfied with a WAF or manual testing.

Vulnerability Scanning

Required quarterly by an Approved Scanning Vendor (ASV) for external scans (Requirement 11.2).

Compliance Audit

Annual assessment by a QSA (Qualified Security Assessor) for Level 1 merchants, or SAQ self-assessment for smaller merchants.

HIPAA

Health Insurance Portability and Accountability Act

Healthcare providers, health plans, healthcare clearinghouses, and their business associates who handle protected health information (PHI). This includes hospitals, clinics, insurance companies, and SaaS vendors serving healthcare.

Recommended Services

Risk Assessment

Required by the Security Rule (§164.308). Must identify risks to the confidentiality, integrity, and availability of ePHI.

Penetration Testing

Not explicitly mandated but strongly recommended by HHS as part of the risk assessment process. Expected during OCR audits.

Compliance Assessment

Evaluates administrative, physical, and technical safeguards against HIPAA requirements. No formal certification exists, but documented assessments are expected.

Incident Response Planning

The Breach Notification Rule requires you to notify affected individuals within 60 days. Having an IR plan and retainer ensures you can respond effectively.

vCISO

HIPAA requires a designated security official (§164.308). A vCISO can fulfill this role for organizations that cannot afford a full-time security executive.

SOX

Sarbanes-Oxley Act

All publicly traded companies in the United States. Section 404 specifically addresses internal controls over financial reporting, which increasingly includes IT controls.

Recommended Services

IT General Controls (ITGC) Audit

Evaluates access controls, change management, computer operations, and program development for systems involved in financial reporting.

Penetration Testing

Not explicitly required but used to validate the effectiveness of access controls and network security protecting financial systems.

Cloud Security Assessment

If financial systems run in the cloud, SOX auditors need assurance that cloud configurations support control objectives.

vCISO

Provides strategic oversight to ensure IT security controls align with SOX compliance requirements and support audit readiness.

GDPR

General Data Protection Regulation

Any organization that processes personal data of EU/EEA residents, regardless of where the organization is located. Applies to most global SaaS companies, e-commerce businesses, and any company with European customers or employees.

Recommended Services

Data Protection Impact Assessment (DPIA)

Required under Article 35 for high-risk processing activities. Identifies and mitigates privacy risks.

Penetration Testing

Article 32 requires "appropriate technical measures" and "regular testing, assessing and evaluating" the effectiveness of security measures.

Cloud Security Assessment

If personal data is stored in cloud environments, you must ensure appropriate security measures are in place (Article 32).

Incident Response

Article 33 requires breach notification to supervisory authorities within 72 hours. Having IR capabilities is essential.

Compliance Assessment

Regular evaluation of your data processing activities, privacy notices, consent mechanisms, and data subject rights processes.

CMMC

Cybersecurity Maturity Model Certification

Department of Defense contractors and subcontractors who handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). Required for DoD contract eligibility.

Recommended Services

CMMC Readiness Assessment

Evaluates your current security posture against the 110+ practices required at your target CMMC level before the formal assessment.

Penetration Testing

Validates the effectiveness of your security controls and demonstrates they work as intended against real attack techniques.

Vulnerability Management

CMMC requires ongoing vulnerability scanning and remediation processes (multiple practices across several domains).

Incident Response Planning

The Incident Response (IR) domain requires documented IR capabilities, testing, and reporting to DoD.

vCISO

Provides the security leadership and program management needed to achieve and maintain CMMC certification, especially for small defense contractors.

NIST CSF

NIST Cybersecurity Framework

Originally developed for critical infrastructure, now widely adopted as a voluntary framework by organizations of all sizes and industries. Often used as a baseline for building a security program or demonstrating due diligence.

Recommended Services

Security Program Assessment

Maps your current capabilities to the five CSF functions (Identify, Protect, Detect, Respond, Recover) and identifies gaps.

Penetration Testing

Validates the effectiveness of your Protect and Detect functions with real-world attack simulation.

Incident Response Planning

The Respond function requires documented response processes, communications plans, and improvement based on lessons learned.

vCISO

Provides ongoing leadership to implement and mature your security program across all five CSF functions.

Cloud Security Assessment

Ensures your Protect function extends to cloud environments with appropriate technical safeguards.

ISO 27001

International Organization for Standardization 27001

Any organization seeking formal certification of their Information Security Management System (ISMS). Common for B2B companies, SaaS providers, and organizations that need to demonstrate security maturity to enterprise customers.

Recommended Services

ISO 27001 Gap Assessment

Identifies gaps between your current ISMS and the requirements of Annex A controls before formal certification audit.

Penetration Testing

Annex A control A.18.2.1 requires independent review of information security. Pen testing is the most common way to satisfy this.

Internal Audit

Clause 9.2 requires regular internal audits of the ISMS. An external provider can perform this with greater independence.

Risk Assessment

Clause 6.1.2 requires a formal information security risk assessment process. This is foundational to the entire ISMS.

vCISO

Provides the management commitment and security leadership required by Clause 5, especially for organizations without dedicated security staff.

Important note: Compliance requirements vary based on your specific situation, scope of regulated data, and how your systems are architected. These recommendations represent common starting points. A qualified assessor can help you determine your exact requirements.

BreachBench | Find the Right Cybersecurity Provider