Reference

What these frameworks actually ask for

379 controls across 6 frameworks, each with a plain-language explanation of what it means in practice. Written for someone who has just been asked for a SOC 2 report and is not sure what one is.

SOC 2

38 controls · 2017 TSC (rev. 2022)

The report enterprise customers most often ask for before they will sign. It shows an independent auditor checked how you protect their data.

HIPAA

47 controls · Security Rule, 45 CFR Part 164 Subpart C

The rules for protecting health information. There is no certificate to earn - HIPAA is enforced by audit and by what happens after a breach, so what matters is being able to show what you do and why.

GDPR

28 controls · Regulation (EU) 2016/679

The rules for handling personal information about people in Europe. There is no certificate to earn and no auditor to satisfy - what GDPR asks is that you can explain what you hold, why, and what you would do if it leaked.

CMMC

110 controls · Level 2, 32 CFR Part 170 (NIST SP 800-171 Rev. 2)

The standard the US Department of Defense holds its suppliers to when they handle Controlled Unclassified Information. Level 2 is all 110 practices. Certification comes from an assessment by an accredited third-party assessor - a C3PAO - so Virtosic can get you ready for one and can never grant it. Whether your contract wants that assessment or a self-assessment you file yourself is set by the clause in the contract, and the phase-in has moved before: read the clause rather than assuming. Either way the 110 practices are the same.

ISO 27001

93 controls · ISO/IEC 27001:2022, Annex A

The international standard for running information security as a managed system, and the certificate overseas and enterprise customers most often ask a small supplier for. It is issued by an accredited certification body after that body audits you, so Virtosic can get you ready for the audit and can never grant the certificate itself. Annex A is a reference set you select from rather than a list you must complete: a control can be left out where your Statement of Applicability records why, which makes an honest exclusion here a real answer rather than a way of avoiding the work.

PCI-DSS

63 controls · v4.0.1

The security standard the card brands hold you to if you take card payments, enforced through your acquiring bank rather than a regulator. How you validate depends on how you take payments and how many transactions you process: most small merchants complete a Self-Assessment Questionnaire rather than being audited by a Qualified Security Assessor, and which questionnaire applies depends on your setup, which your acquirer confirms. One limit is worth knowing before you start. Virtosic cannot determine your scope. Scope here follows the cardholder data environment - everywhere card data is stored, processed or transmitted, plus anything connected to it - and Virtosic does not observe how card data actually flows through your business. You draw that boundary; Virtosic works honestly inside it.

Reading a list of controls is not the hard part

Working out which ones apply to you, what evidence counts, and what to do first is. Virtosic does that continuously, and the Foundation plan is free with no card and no time limit.

See what it costs