Do this before selecting a framework
- Identify which law, contract, card-brand rule or customer request actually applies.
- Define the legal entity, data, systems, vendors and assessment boundary with qualified advisers.
- Reuse operational evidence where requirements overlap, but map each obligation separately.
- A NIST-aligned assessment, security product or SOC 2 report does not certify compliance with every regime.
Last updated: September 25, 2026
This guide helps an SMB organize compliance work; it cannot determine its legal obligations. GDPR, HIPAA, PCI DSS and SOC 2 have different sources, scope and evidence. SOC 2 is an examination and report for a service organization, not a law. A business may face none, one or several of these, plus state or sector requirements. Confirm applicability with counsel, an assessor, a qualified security adviser or the relevant contractual party before making claims to customers.
Scope the obligation, not the logo
| Regime | First scoping question | Primary source |
|---|---|---|
| GDPR | Does the organization process personal data in circumstances covered by the EU regulation, including its territorial rules? | EU GDPR text |
| HIPAA Security Rule | Is the entity a covered entity or business associate handling electronic protected health information? | HHS Security Rule summary |
| PCI DSS | Does the business store, process or transmit payment-account data, or otherwise fall into a payment program's validated scope? | PCI SSC v4.x resource hub |
| SOC 2 | Does a customer need an independent report on a service organization's controls and a defined system? | AICPA SOC 2 resources |
The HHS summary says its current Security Rule applies to covered entities and business associates, and that its overview is not a comprehensive compliance guide. The PCI SSC published v4.0.1; verify the current documentation, validation form and payment-program instructions rather than reusing an old checklist. Laws and standards can change, so record the source and review date for your scoped obligations.
Build one evidence system, then map it
Start with an inventory of systems and data, named control owners, access decisions, vendor relationships, incident contacts and recovery tests. Keep dated evidence: policy, configuration export, review result, exception and corrective action. A shared control such as MFA may support several requirements, but each regime may ask for different scope, wording, frequency or proof. Ask the responsible adviser to map that evidence to the applicable text. Do not label a control “HIPAA compliant” or “GDPR certified” because a vendor page uses those words.
| Common control | Operational evidence | Scoping risk |
|---|---|---|
| Access review | Named users, role approvals and revocation test | Did it cover the regulated system and vendor users? |
| Data inventory | Data flow, retention and supplier list | Was the regulated data actually included? |
| Incident response | Runbook, exercise and decision log | Are the applicable notice triggers and contacts known? |
| Recovery | Backup scope and restore result | Does it meet the real service and record obligation? |
Sequence the project
First, document the business requirement and boundary. Second, identify what evidence already exists and where controls are unknown or missing. Third, assign owners and close high-risk gaps. Fourth, have the adviser or assessor review the mapped evidence before making a claim. The NIST CSF 2.0 guide helps structure security outcomes but does not itself grant compliance status. Use the security checklist for routine ownership and the privacy-first guide to map personal data.
Avoid an expensive shortcut
A software subscription, generic template or automated score cannot decide whether a law applies, sign a payment attestation or issue a SOC 2 report. Define scope and required evidence before buying a “compliance” tool.
Sources checked September 25, 2026: EU GDPR, HHS HIPAA Security Rule, PCI SSC v4.x hub, and AICPA SOC 2 resources. This page is educational and not legal, audit or attestation advice.