Guide · September 2026
Which compliance framework do I need?
Nine times out of ten, the answer is whoever is asking. Match your trigger to the framework below, then open the directory that covers it.
The trigger map
| If this is your situation | The framework | |
|---|---|---|
| An enterprise customer asked for your security report | SOC 2 — attestation of your controls by a licensed CPA firm | Directory → |
| You store, process, or transmit cardholder data | PCI DSS — the card brands' security standard, validated by a QSA or self-assessment | Directory → |
| You handle protected health information | HIPAA — safeguards for PHI; applies to covered entities and business associates | Directory → |
| A bank or partner asked about your financial-reporting controls | SOC 1 (SSAE 18) — attestation over controls relevant to financial reporting | Directory → |
| You hold (or want) defense contracts | CMMC — cybersecurity maturity required across the defense industrial base | Directory → |
| International customers want an ISO certificate | ISO 27001 — certification of your information security management system | Directory → |
| Buyers ask how you govern your AI systems | ISO 42001 / NIST AI RMF — AI management system certification and risk framework | Directory → |
| You run nonclinical safety studies for regulators | GLP — Good Laboratory Practice for labs supporting regulatory submissions | Directory → |
| You want a security program, but no one named a certificate | NIST CSF — the Cybersecurity Framework for building and measuring a program | Directory → |
Three things buyers get wrong
- "Compliance" is not one thing. SOC 2, PCI DSS, and ISO 27001 answer different questions for different audiences. Starting the wrong one burns months.
- An attestation is not a certification. SOC 2 is an attestation report issued by a licensed CPA firm — there is no "SOC 2 certificate." ISO 27001 is a certification issued by an accredited body. PCI DSS is a validation, usually via a qualified assessor. Using the wrong word in front of a customer is a credibility problem.
- Nobody can sell you the outcome itself. Providers get you ready and assess you; the auditor, assessor, or regulator decides. Anyone promising a guaranteed certificate is selling something that doesn't exist.
Still torn between two?
Read SOC 2 vs ISO 27001 vs PCI DSS, compared — the three frameworks buyers confuse most, side by side.
Know your framework? Get quotes
Matched providers for your framework, scoped to your size and timeline. Free, no obligation.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.