NIST, SOC 2, HIPAA, CMMC: Which Framework Applies to Your Business?

Published On
September 14, 2026
Share this post
https://www.emrynetworks.com/post/which-compliance-framework-applies-to-your-business

Frameworks reach you in three ways: by law, by contract, or by choice. How a framework applies decides whether you have any control over it.

Most people approach the question the wrong way. A customer sends a security questionnaire asking whether you're SOC 2 compliant, and you start researching SOC 2, instead of first checking what you were already required to do.

The order matters. If someone requests a framework, you can usually negotiate it. If the law requires a framework, you have to follow it, even if no customer ever brings it up.

So the real question isn't a feature comparison. It's how each framework applies to your business.

Frameworks reach you three different ways

Every compliance rule for a small or midsize business comes through one of three doors, and which door it is tells you how much control you have.

By law. HIPAA if you handle protected health information. State security and breach-notification statutes based on where your customers live. Nobody has to ask you for these, and you can't decline them. There's no certificate, no expiry date, and no vendor who can hand you one.

By contract. SOC 2, ISO 27001, HITRUST, CMMC, and PCI DSS (the one people overlook) come into play when you sign agreements, like the merchant agreement you accept when you take card payments. These are negotiable in scope and timing right up until you sign.

By choice. NIST's Cybersecurity Framework is optional. No one requires it, and no auditor certifies you for it. Its value is helping you organize your security work so you can manage the requirements from the other two categories.

If you don't know how a framework applies to you, you can't tell whether you're meeting a real requirement or just following someone's preference.

The seven frameworks, and what actually triggers each

These are the seven frameworks Emry Networks works with. Start with the trigger column.

The seven frameworks, and what triggers each

FrameworkWhat triggers itHow it arrivesWhat you end up holding
HIPAAYou're a healthcare provider, plan or clearinghouse, or a vendor handling PHI for one.By lawNo certificate. A defensible risk analysis, documented decisions, and evidence.
PCI DSSYou accept card payments. Any volume.By contract, via your merchant agreementA self-assessment questionnaire or a formal assessment, depending on volume and channel.
SOC 2A customer asks, usually during procurement.By contractAn auditor's report on design and operation over a period. Not a certificate.
ISO 27001Enterprise or international customers, often in procurement.By contractA genuine certificate with a real expiry, issued by an accredited body.
CMMCA clause in a Department of War contract or subcontract.By contract, imposed by regulationA self-assessment at Level 1 or 2 today; third-party certification is currently suspended.
HITRUSTA health plan or large healthcare partner requires it.By contractA certification that maps across HIPAA and other frameworks.
NIST CSFNothing. You adopt it.By choiceAn organizing structure. No audit, no certificate, no expiry.

Four of these have changed recently, so the details matter.

CMMC: the one that changed in July

If you hold a Department of War contract or subcontract, this is the fastest-moving item on the list, and most of what's written about it online is now out of date.

The acquisition rule at 48 CFR was published on 10 September 2025 and took effect on 10 November 2025, starting Phase 1. Since then, most new contracts have required at least CMMC Level 1 or Level 2 self-assessment at the time of award. Phase 2 was scheduled to make third-party certification through a C3PAO mandatory from 10 November 2026.

On 13 July 2026, the Department of War suspended Phase 2 with immediate effect and also paused Phases 3 and 4. It set up a 60-day reform task force to recommend ways to make the program less burdensome for small and non-traditional contractors, and asked for industry feedback, with responses due by mid-August 2026.

Here's the part that gets misreported. Nothing was repealed. Phase 1 self-assessment requirements at Levels 1 and 2 are unchanged and still apply at award. The underlying obligations under DFARS 252.204-7012 and NIST SP 800-171 to safeguard controlled unclassified information are untouched. What was suspended is the third-party certification step, not the duty to implement the controls.

A contractor who reads the suspension as permission to stop is taking a risk, because the review isn't finished. Someone who was preparing for a Level 2 assessment in November now has extra time. Those are two different responses, and only one holds up if the task force decides to restart Phase 2.

There are two NISTs, and people constantly conflate them

When you're asked whether you follow NIST, clarify which one they mean, because each applies differently.

The Cybersecurity Framework (CSF 2.0)

The Cybersecurity Framework is voluntary, and there's no certification for it. Version 2.0 added a sixth core function, Govern, alongside Identify, Protect, Detect, Respond, and Recover. That change puts leadership accountability, policy, and risk strategy at the center rather than treating governance as an afterthought. For an SMB juggling different obligations, the CSF is useful for organizing all of them in one place.

Special Publication 800-171

SP 800-171 is not optional if it applies to you. It sets the rules for protecting controlled unclassified information in non-federal systems, and it becomes mandatory through the DFARS clause in your contract. It's the technical foundation for CMMC Level 2. If you handle federal CUI, this requirement comes from your contract and still applies, even after July.

PCI DSS applies to almost every practice, and almost nobody mentions it

Any dental office, law firm, or medical practice that accepts card payments has to follow PCI DSS. The requirement comes from the merchant agreement, not a law, which is why it rarely comes up in compliance conversations and almost never shows up in security questionnaires.

The new requirements in PCI DSS v4.0 became mandatory on 31 March 2025. In 2026 they're strict pass-or-fail items, not best practices. Two of them tend to surprise small merchants who assumed the self-assessment would be easy: Requirement 6.4.3, which covers managing scripts on payment pages, and Requirement 11.6.1, which covers tamper detection on those pages.

Under v4.0.1, merchants who want to use SAQ A have to confirm their site isn't vulnerable to script-based attacks. If your online booking or payment site was built years ago and hasn't been updated, you can't assume it's safe. The person who manages the site, not the one who processes payments, is the one who can answer that.

ISO 27001: the transition window already closed

ISO 27001 is the one framework here that produces a real certificate from an accredited body, with an expiry date and surveillance audits in between. That makes it valuable in enterprise procurement and unforgiving about deadlines.

The transition from the 2013 edition to the 2022 edition ended on 31 October 2025. Certificates that didn't transition were withdrawn or allowed to expire rather than run their normal three-year term. Miss the deadline and you don't pick up where you left off. You're treated as a new client and have to go through a full initial certification audit.

If ISO 27001 appears in your sales materials, take a moment this week to check the edition and expiry date on your actual certificate rather than trusting the year you remember passing.

Nobody has one framework

The question of which framework applies assumes there's one answer. For most regulated SMBs, it's almost never just one.

A three-clinic dental group handles PHI, so HIPAA applies by law. It takes card payments, so PCI DSS applies by contract. It may face a certification demand from a payer, which brings HITRUST. That's three, and none of them cancels the others.

The good news is that the control sets have far more in common than the framework names suggest. Multi-factor authentication, access reviews, asset inventories, encryption at rest and in transit, logging with a set retention period, tested backups, vendor management, and a documented risk assessment show up in every framework. What changes is the wording, the type of evidence needed, and who reviews it.

Stop asking which framework

The real question isn't which framework to pick. It's the smallest set of controls that covers all your obligations, with evidence you can create once and reuse everywhere.

So build your controls to cover the union of your obligations, map each one to every framework it satisfies, and generate evidence as you go. That's an operating model, not a paperwork exercise. We explain the difference in our guide to standard IT vs. defensible IT.

How to establish your actual scope

Six questions, in this order. Most SMBs can work through them in an afternoon, and the answers define your scope.

  1. What data do you hold? Patient information brings HIPAA. Cardholder data brings PCI DSS. Controlled unclassified information brings NIST SP 800-171 and probably CMMC. Personal data on residents of particular states brings state law.
  2. Who are your customers, and what have they requested? SOC 2 and ISO 27001 usually arrive this way. If no one has asked, you may not need one yet. Getting one anyway is more a sales decision than a compliance need.
  3. What did you already sign? Read the security exhibits in your existing customer contracts and your merchant agreement. Obligations you agreed to two years ago are still obligations, and this is where most surprises hide.
  4. Do you take card payments, and how? Terminal only, online, or both. The answer changes which self-assessment questionnaire you're eligible for.
  5. Do you touch federal contracts, directly or as a subcontractor? Check for the DFARS clause. Being two tiers down a supply chain doesn't remove it.
  6. Where do your customers live? State security and breach-notification requirements follow the individual, not your office.

Write down your answers. That list, not a framework name, defines your compliance scope. It's also the document to hand anyone trying to sell you a compliance program.

Where this becomes someone's job

Emry Networks works across all seven (HIPAA, SOC 2, ISO 27001, NIST, PCI DSS, CMMC, and HITRUST), and the first engagement is deliberately about scope rather than certification. Regulatory Discovery scans the live environment and cross-references it against the frameworks that genuinely apply to you, producing a plain-English Risk Status Report naming each gap between what your documentation claims and what your systems are doing. Security Hardening then deploys the managed stack, and Continuous Management holds the posture with monitoring, staff training, backup verification, and recurring compliance drift checks. The detail is on our IT compliance page.

Scope comes first because buying a framework you don't need is a common and costly mistake, and missing one you do need is worse. A three-clinic healthcare group came to us after a surprise HIPAA audit. They hadn't done a formal risk assessment in two years and were sharing credentials in clinical systems. We found and fixed eighteen gaps, making them audit-ready in 90 days. The real work wasn't picking a framework. It was figuring out what was actually in place.

If you want to see how the phases fit together before talking to anyone, how it works lays out the sequence.

Find out which frameworks already have a claim on you

Before you commit to a framework, discuss your compliance scope. We map what your data, your contracts, and your customers already require.

Discuss your compliance scope

Frequently asked questions

Which compliance framework applies to a small business?

It depends on three things: the data you hold, the contracts you've signed, and where your customers are. Frameworks arrive by law, by contract, or by choice. HIPAA and state security statutes apply by law if you handle the relevant data, and no customer has to request them. SOC 2, ISO 27001, HITRUST, CMMC and PCI DSS apply by contract, whether that's a customer agreement, a government clause, or a merchant agreement. NIST's Cybersecurity Framework applies only if you adopt it. Most regulated small businesses carry two to four at once.

What is the difference between SOC 2 and ISO 27001?

SOC 2 is an attestation and ISO 27001 is a certification, and the distinction is practical rather than semantic. A SOC 2 Type 2 engagement produces an auditor's report describing how your controls were designed and whether they operated across a defined observation period, including any exceptions found. There is no SOC 2 certificate. ISO 27001 produces an actual certificate from an accredited certification body, with an expiry date and surveillance audits between cycles. SOC 2 is more common in United States technology procurement; ISO 27001 travels better internationally. Both usually arrive because a customer asked.

Is CMMC still required in 2026?

Partly. Phase 1 of the CMMC rollout began on 10 November 2025 and remains in force, meaning most new Department of War contracts require at least a Level 1 or Level 2 self-assessment at award. On 13 July 2026, the department suspended Phase 2, the step that would have made third-party C3PAO certification mandatory from 10 November 2026, and froze the later phases, launching a 60-day review focused on the burden on small contractors. Crucially, the underlying obligations under DFARS 252.204-7012 and NIST SP 800-171 were not changed. The certification step is paused; the requirement to protect controlled unclassified information is not.

Does PCI DSS apply if we only take a few card payments?

Yes. PCI DSS applies to any organization that accepts, processes, stores, or transmits cardholder data, with no minimum volume. What volume and channel change is how you demonstrate compliance: which self-assessment questionnaire you're eligible for, or whether a formal assessment is needed. The requirements introduced in version 4.0 became mandatory on 31 March 2025, including controls on payment page scripts and tamper detection, and eligibility for the simplest questionnaire now requires confirming your site isn't susceptible to script-based attacks. Small merchants running online booking or payments are the ones most likely to have missed this.

Do we need NIST if we already follow HIPAA?

You don't need to add anything, but the two do different jobs and pair well. HIPAA tells you what outcomes are required and leaves substantial latitude on method. Much of the Security Rule is written as addressable specifications, meaning you choose an approach and document why. NIST's Cybersecurity Framework gives you a structure for organizing that work, and version 2.0 added a Govern function covering leadership accountability and risk strategy. Many practices use the CSF as the organizing layer and map their HIPAA obligations onto it, which also makes it easier to absorb a second framework later without rebuilding.

If we carry several frameworks, do we have to do the work several times?

No, and organizations that do are usually being sold to rather than advised. The control sets overlap heavily: multi-factor authentication, access reviews, asset inventory, encryption at rest and in transit, logging with a defined retention period, tested backups, vendor management, and a documented risk assessment appear across all of them. What differs is the vocabulary, the evidence format, and who reviews it. The efficient approach is to build to the union of your obligations, map each control to every framework it satisfies, and generate evidence as a byproduct of operating rather than assembling it separately for each audit.

Sources

  • CMMC acquisition rule at 48 CFR: published in the Federal Register 10 September 2025, effective 10 November 2025; Phase 1 requires CMMC Level 1 or Level 2 self-assessment at award for most new contracts.
  • Department of War suspension of CMMC Phase II, 13 July 2026: third-party C3PAO certification requirement scheduled for 10 November 2026 suspended with immediate effect; Phases 3 and 4 frozen; 60-day reform task force convened with a remit covering impact on small and non-traditional contractors; industry request for information issued with responses due mid-August 2026. Reported via law firm client alerts (Morgan Lewis, Wiley, BDO, Schellman) and Federal News Network. Obligations under DFARS 252.204-7012 and NIST SP 800-171 unchanged.
  • PCI Security Standards Council, PCI DSS v4.0 and v4.0.1: future-dated requirements mandatory from 31 March 2025, including Requirement 6.4.3 (management of payment page scripts) and Requirement 11.6.1 (payment page tamper detection); v4.0.1 SAQ A eligibility requires the merchant to confirm the site is not susceptible to script-based attacks.
  • ISO/IEC 27001:2022 transition: transition period from the 2013 edition closed 31 October 2025; non-transitioned certificates withdrawn or expired rather than running a standard three-year term; organizations that missed the deadline are treated as new clients requiring a full initial certification audit.
  • NIST Cybersecurity Framework 2.0: adds Govern as a sixth core function alongside Identify, Protect, Detect, Respond and Recover.
  • NIST Special Publication 800-171 and DFARS 252.204-7012: controls for protecting controlled unclassified information in non-federal systems, binding through the contract clause and forming the technical basis of CMMC Level 2.
  • AICPA: SOC 2 Type 2 reports address suitability of design and operating effectiveness across a defined observation period; there is no SOC 2 certificate.

Exact figures above are attributed to the named primary sources. Any other number in this article is presented as reasoning or as an explicit estimate and should not be read as a measured value.

Share this post
https://www.emrynetworks.com/post/which-compliance-framework-applies-to-your-business

Ready to strengthen your compliance?

Get hands-on assessment and guidance from our compliance experts.