Browse standards by category, or use the applicability picker if you’re not sure where to start.
What applies to me?
CMMC
A practical introduction to CMMC, including who it applies to, what the three levels require, how assessments work, and where the phased rollout stands.
Applies to: Defense contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under DoD contracts.
HIPAA
A practical introduction to HIPAA, including who counts as a covered entity or business associate, what the rules require, and how compliance is actually demonstrated.
Applies to: Covered entities (health plans, healthcare clearinghouses, and providers that transmit health information electronically) and the business associates that handle protected health information for them.
PCI DSS
A practical introduction to PCI DSS, including who it applies to, what is in scope, how validation works, and what compliance takes.
Applies to: Entities that store, process, or transmit payment account data, or could affect the security of the cardholder data environment.
SOC 2
A practical introduction to SOC 2, including who asks for it, what a report contains, how Type 1 and Type 2 differ, and what an examination takes.
Applies to: Service organizations whose customers want independent assurance over controls for security, availability, processing integrity, confidentiality, or privacy.