The email usually arrives from a customer, not a regulator. A larger client sends over a security questionnaire before renewing your contract. Forty questions, most of them written by someone who assumed you have a security team. Somebody has to answer it, and the answers have to be true.
That is how most small and mid sized businesses meet compliance for the first time. Not through an audit, but through a customer, an insurer, or a contract clause. And by then the deadline is short.
Compliance is not one thing
People use the word as though there were a single standard to meet. There is not. What applies to you depends on what data you hold, who you sell to, and how you take payment. A veterinary clinic, a machine shop with defense work, and a car dealership have almost nothing in common in terms of obligations, even though all three will be told they need to “be compliant.”
The frameworks that actually reach businesses our size, roughly in order of how often we see them:
- HIPAA if you handle protected health information, including as a business associate rather than a provider.
- The FTC Safeguards Rule if you extend credit, arrange financing, or otherwise meet the definition of a financial institution. This catches far more businesses than people expect.
- PCI DSS if you take card payments, which is nearly everyone, though the burden varies enormously with how you process them.
- CMMC and NIST SP 800-171 if you are anywhere in the defense supply chain, including as a subcontractor two tiers down.
- SOC 2 if your customers demand it. This one is not a law. It is a market requirement, which in practice can be just as binding.
Two examples worth understanding
The FTC Safeguards Rule
If you finance or lease, you are covered. Auto dealerships are the clearest case, but the definition of a financial institution under this rule is broad, and plenty of businesses are covered without realizing it.
The rule requires a written information security program with specific named elements. Among them: you must designate a qualified individual to run the program, produce a written risk assessment, implement access controls, encryption and multi factor authentication, either continuously monitor your systems or run annual penetration testing plus vulnerability assessments every six months, train your staff, oversee the security of your service providers, maintain a written incident response plan, and have that qualified individual report in writing to your leadership at least annually. Breaches affecting 500 or more consumers must be reported to the FTC within thirty days. The FTC publishes plain language guidance for dealers that is worth reading directly.
Note the shape of that list. Most of it is not technology. It is documentation, ownership, and process. A dealership can have excellent security and still be out of compliance because nobody wrote any of it down or named a person responsible.
CMMC
If you do defense work, the timeline stopped being theoretical. The acquisition rule was published in the Federal Register in September 2025, and CMMC requirements began appearing in Department of Defense contracts in November 2025, phasing in across roughly four years. Level 2, which applies when you handle controlled unclassified information, means implementing all 110 controls in NIST SP 800-171, and depending on the contract it may require assessment by an accredited third party rather than a self assessment.
The practical problem for a small manufacturer is that 110 controls is a real project, certification is not instant, and the requirement lands when a contract lands. Starting after you see the clause is starting late.
The gap between doing it and proving it
This is where most businesses actually fail, and it is worth sitting with.
You almost certainly have a firewall. Can you produce its configuration and change history? You run backups. When were they last restore tested, and where is the record of that test? Your staff had security training. Who completed it, on what date, and what were the phishing simulation results? You patch systems. What is your defined timeline for critical patches, and can you show compliance against it last quarter?
Auditors, assessors, insurers and enterprise customers do not accept “yes we do that.” They accept evidence. A business with average controls and excellent documentation will clear a questionnaire that a business with strong controls and no records will fail.
How we approach it
Our process is deliberately unglamorous, because compliance work rewards being systematic more than being clever.
- Define the requirement. Establish which framework actually applies to you and at what level. A surprising amount of wasted effort comes from businesses chasing a standard they were never subject to.
- Map the environment. Compare what you have against what the requirement asks for, and find the missing controls and the missing documentation. These are two different lists.
- Prioritize the gaps. Not every gap carries equal risk. Some are quick, some are expensive, and some matter more than others. Sequence accordingly.
- Remediate and document. Deploy the technical controls, which for most frameworks means MFA, endpoint protection, backup, logging, patching and device management. Then write the policies and organize the evidence so it can be handed to an assessor.
- Maintain the controls. Environments drift. People leave, systems change, exceptions get made and never reversed. Ongoing monitoring is what keeps you compliant between assessments rather than compliant on one day of the year.
We also help with the questionnaires themselves, and with reviewing the security posture of your own vendors, which is an obligation under several of these frameworks and one that gets skipped constantly.
What we do not do
We do not certify anyone. Certification is the job of auditors and accredited assessors, and any IT provider telling you they can both build your controls and certify them is describing a conflict of interest. What we do is get your environment and your documentation into the state where an assessment goes smoothly, and then keep it there.
We also are not attorneys. Which framework applies to your business, and how its requirements are interpreted for your situation, is a question worth putting to counsel. This article is general information, not legal advice.
If you are starting from nothing
Begin with a gap analysis against the one framework you are most clearly subject to. It is a finite piece of work, it produces a concrete list, and it turns an intimidating topic into a project plan with an end date.
If a customer questionnaire is already sitting in your inbox, send it over. We can tell you which answers you can support today and which ones need work before you sign your name to them.
