Compliance Frameworks Compared: HIPAA, SOC 2, CMMC, PCI DSS, and NIST CSF
Last updated
Five frameworks, three kinds of obligation
Clients say "we need to be compliant" as if it were one thing. Of the five frameworks a small-business MSP actually meets, one is federal law, two are contract terms, and two are voluntary – and "compliant" ranges from a self-signed checklist to a year-long third-party assessment. Compliance as a service covers selling and delivering the retainer; this is the comparison behind choosing which framework to build it on.
HIPAA
Who: covered entities – providers, health plans, clearinghouses – and every business associate handling protected health information for them.
Obligation: federal law, enforced by HHS Office for Civil Rights. Penalties top out above $2M per violation category per year as of 2026.
What compliant means: there is no HIPAA certification. Compliance is self-attested and evidenced – a documented risk analysis, policies, training, signed business associate agreements, and proof the safeguards exist. Nobody checks until something goes wrong; then OCR's first request is the risk analysis.
Typical cost and timeline: a small-practice risk analysis $2K–20K, a tailored policy set $2K–5K, a compliance platform $100–500 per practice per month; three to six months to documented compliance, refreshed annually.
For your shop: you are a business associate with direct liability. You sign a BAA with every covered-entity client, and your own stack must be HIPAA-fit.
SOC 2
Who: any company whose customers ask for it – B2B SaaS, professional services, anyone selling into enterprises.
Obligation: voluntary attestation that becomes contractually required the day a large customer's procurement team asks. No regulator, no law.
What compliant means: an independent CPA firm audits the client's controls against the AICPA Trust Services Criteria and issues a report. Type I covers control design at a point in time; Type II covers operation over a three-to-twelve-month window. There is no pass or fail – only a report with or without exceptions, shared under NDA.
Typical cost and timeline: audit $10K–30K plus readiness work and evidence-automation tooling of $5K–20K a year; a first Type II takes six to twelve months, then annually.
For your shop: in the client's report you are a subservice organization. The auditor either carves you out – noting the client relies on its MSP for certain controls – or includes you, and your controls get tested too. An MSP holding its own SOC 2 Type II answers evidence requests with one attachment instead of a week of screenshots.
CMMC
Who: Department of Defense contractors and subcontractors handling federal contract information or controlled unclassified information.
Obligation: contractual. The DFARS clause has been in new DoD solicitations since November 2025, phasing in through 2028; no level, no contract.
What compliant means: Level 1 is an annual self-assessment against 15 basic safeguarding requirements, affirmed in SPRS. Level 2 is the 110 controls of NIST SP 800-171; most contracts require a certified third-party assessor, with certification valid three years and annual affirmations between.
Typical cost and timeline: Level 1, a few thousand dollars. Level 2 implementation $50K–150K for a small contractor, the assessment $30K–60K, twelve to eighteen months end to end.
For your shop: you are an external service provider. Touch CUI or the systems holding it and you are inside the client's assessment scope, expected to meet Level 2 yourself and to document which controls you own in a shared responsibility matrix. You cannot sell CMMC to one client and stay out of scope.
PCI DSS
Who: anyone that stores, processes, or transmits payment card data – retail, hospitality, medical front desks.
Obligation: contractual, imposed by the card brands through the merchant's acquiring bank. Not a law. Non-compliance means acquirer fines and liability for fraud losses after a breach.
What compliant means: nearly every SMB client is a Level 4 merchant completing an annual self-assessment questionnaire plus, for most questionnaire types, quarterly external scans from an approved scanning vendor. Version 4.0.1 has been fully mandatory since April 2025.
Typical cost and timeline: with hosted payment pages and encrypted terminals, under $1K–3K a year including scans.
For your shop: the job is scope reduction. Keep card data off the client's network – validated terminals, tokenized payments, a segmented VLAN for what must remain – and the questionnaire shrinks from hundreds of questions to a few dozen. Manage in-scope systems and PCI treats you as a third-party service provider whose responsibilities the client must document in writing.
NIST CSF
Who: everyone and no one. Version 2.0 (2024) is the vocabulary regulators, insurers, and boards use for security programs.
Obligation: voluntary. Nobody is certified against it.
What compliant means: there is no compliant. An organization profiles itself across six functions – Govern, Identify, Protect, Detect, Respond, Recover – producing a current state and a target state.
Typical cost and timeline: a current-profile assessment for a small business $5K–15K over a few weeks.
For your shop: write assessment reports in NIST CSF language, because the client's insurer, lawyer, and future auditor all speak it. It is not a niche.
Where the controls overlap
Strip the paperwork and all five ask for the same technical core: an inventory of assets and accounts, MFA and least privilege, patching and vulnerability management, endpoint protection, logging, tested backups, security awareness training, incident response, and vendor management. CIS Controls Implementation Group 1 – 56 safeguards – covers that core and publishes mappings to each framework, so a client at IG1 is most of the way through any of them.
What differs is everything around the core. Scope: which data triggers the obligation. Governance: HIPAA wants a risk analysis and BAAs, SOC 2 wants policies and change evidence, CMMC wants a control-by-control system security plan. Verification: self-attestation for HIPAA, CMMC Level 1, and small PCI merchants; independent assessment for SOC 2 and CMMC Level 2. Build one technical baseline and one evidence habit, then layer framework-specific paperwork on top – never five separate programs.
Pick one, not all five
Claiming all five marks you as a generalist, and buyers can tell. HIPAA points at practices that exist in every metro, buy on trust, and rarely leave. SOC 2 points at growing B2B firms that pay well and expect you to hold a report yourself. CMMC points at defense manufacturing clusters where engagements are large, slow, and require your own certification first. PCI is an adjacent obligation for hospitality and retail clients, not a specialty; NIST CSF is what you assess against when a client has no regulator. Match the pick to the businesses within an hour's drive and to your appetite for auditing your own shop – see choosing a niche – and take three clients through a full cycle before adding a second framework.
Bottom line
HIPAA is law with self-attested compliance and a BAA on your desk. SOC 2 is a customer-driven audit that makes you a subservice organization. CMMC is a contract gate that pulls your own shop into scope. PCI is a card-brand contract you win by keeping card data away from anything you manage. NIST CSF is shared vocabulary, not a credential. The technical controls overlap almost entirely, so the real choice is which paperwork, which verifier, and which clients you want for the next decade. Choose one.