Standard pages now say who decides your obligation, and what to ask them
On September 3, 2026, we added a short section to each published standard page under the compliance process: Who decides, and what to ask them. Every page already said to confirm your obligation in writing as step one. None said who to call or what to ask. That gap came up repeatedly when we read the pages as a first-time reader, so we closed it.
What changed
Each of the four published pages now names the party that sets that reader’s actual obligation, explains how to find them, and lists the questions to ask in writing:
- PCI DSS: the acquirer, how to identify it from a merchant statement or compliance-vendor email, and the level, form, assessor, evidence, and deadline questions to settle with them.
- CMMC: the contracting officer or the prime’s contracts contact, and the level, assessment type, CUI marking, flow-down, and POA&M questions.
- SOC 2: the customer’s security or vendor risk team rather than the salesperson who relayed the request, and the report type, categories, recency, alternatives, and delivery questions.
- HIPAA: there is no counterparty, so the list is aimed at the covered entities you serve, your vendors, anyone asking for “proof,” your insurer, and your own leadership.
Two pages also gained a first-decision picker at the top: HIPAA asks which kind of organization you are and returns your likely status (covered entity, business associate, or outside HIPAA); SOC 2 asks what a customer actually requested and returns what that request usually means.
Finally, several decision guides that were linked from these pages while still in draft are now unpublished until their copy is ready. Links to them have been removed from live pages and will return as each guide ships.
What to do now
- If you have not yet confirmed your obligation in writing, use the new list on your standard’s page as the script for that conversation.
- Keep the answers with your compliance records; they define your scope more concretely than the standard text does.
- Follow the standard you care about for the guides as they publish: HIPAA, PCI DSS, CMMC, or SOC 2.