Close side panel

For over 40 years, we have helped thousands of businesses with their IT solutions for lasting success. We provide personalized IT solutions tailored to your diverse business needs.

Contacts

(952) 715-3600

619-853-3744

323-435-1318

916-352-8792

1-800-381-9383

505-219-1694

(918) 508-2228

501-329-1238

504-502-1550

312-284-3219

616-727-8260

740-638-0883

301-867-7128

757-982-8986

973-604-0655

701-354-2979

1-800-830-0112

913-382-2823

561-693-1382

Top Cybersecurity Standards and Frameworks

Shield with padlock on binary code background.

Table of Contents

What a cybersecurity framework is, and what it is not

A cybersecurity framework is a structured set of practices for managing cyber risk. It tells you what to do and roughly in what order, so you are not guessing which control matters most.

What a framework is not is a certification, and the distinction matters commercially. Some frameworks are voluntary guidance you adopt because it is sensible. Others are legal obligations that apply to your industry whether you like them or not. A third group are certifications that a customer or regulator can require you to hold and prove. Confusing the three is how businesses end up claiming compliance they do not have, which is worse than claiming nothing.

Blue quotation mark on black background.

Think your IT is in good shape?

Take the free 3-minute readiness quiz

What changed recently

Three things have moved in the past two years that most guidance on this topic has not caught up with.

NIST CSF 2.0 arrived in February 2024, the first major revision since 2014. It added a sixth Function, Govern, alongside Identify, Protect, Detect, Respond and Recover. Govern covers the organizational side: who is accountable, how risk decisions get made, how supply chain risk is managed. It also formally broadened the framework beyond critical infrastructure to organizations of every size. If you read that CSF is for power plants, you are reading pre-2024 material.

NIST SP 800-61 Revision 3 landed in April 2025, restructuring incident response guidance around those same CSF 2.0 Functions and superseding the four-phase lifecycle.

CMMC became contractually real on 10 November 2025, when the DFARS rule took effect and Phase 1 of a three-year rollout began.

The frameworks worth knowing

NIST Cybersecurity Framework 2.0

The most widely adopted voluntary framework in the United States, and the usual starting point for a business that has no regulatory obligation forcing a particular choice.

Six Functions: Govern, Identify, Protect, Detect, Respond, Recover. It is deliberately outcome-based rather than prescriptive, which makes it adaptable but also means it will not hand you a checklist. Free, published by NIST.

CIS Critical Security Controls v8.1

Eighteen controls, ordered by priority, grouped into three Implementation Groups so a small business can start with IG1 and grow into the rest. Where CSF tells you what outcomes to aim for, CIS tells you what to do on Tuesday morning. For most SMBs it is the more actionable of the two, and the two map to each other cleanly.

ISO/IEC 27001

An international standard for an information security management system, and one you can be formally certified against by an accredited body. That certification is the reason it comes up: enterprise customers and international partners often ask for it contractually. The current version is the 2022 revision. Achieving it is a substantial program of work, not a configuration exercise.

HIPAA Security Rule

A legal obligation for covered entities and their business associates, not a voluntary framework. It requires administrative, physical and technical safeguards for electronic protected health information.

Worth being precise here, because a lot of published material currently is not. HHS issued a notice of proposed rulemaking on 27 December 2024 proposing significant strengthening of the Security Rule. That proposal is not final. The existing Security Rule remains in force. Content asserting that HIPAA now mandates multi-factor authentication is describing a proposal, not current law. Healthcare organizations should prepare for the direction of travel while complying with what is actually in effect.

PCI DSS

Required contractually by the payment card brands for any business that stores, processes or transmits cardholder data. Not a government regulation, but enforceable through your merchant agreement, and the fastest route to reducing scope is usually to stop handling card data directly.

CMMC

The Department of Defense program verifying that contractors protect controlled unclassified information. The DFARS rule took effect on 10 November 2025, starting a three-year phase-in, and CMMC requirements now appear in solicitations.

Level 1 covers basic safeguarding with annual self-assessment. Level 2 aligns to NIST SP 800-171 and, for most contracts, requires assessment by an accredited third party. Level 3 adds requirements for the highest-priority programs. If you are anywhere in the defense supply chain, this stopped being theoretical.

SOC 2

An attestation report produced by an independent CPA firm, commonly requested by enterprise buyers of software and services. Not a certification and not a government standard, but frequently the thing standing between a vendor and a large contract.

How to choose

Work through it in this order.

First, what is compulsory? Healthcare means HIPAA. Card payments mean PCI DSS. Defense contracting means CMMC. These are not choices.

Second, what do your customers demand? Enterprise buyers may require ISO 27001 or a SOC 2 report regardless of what regulators say. That is a sales requirement, and it belongs in the sales budget.

Third, what does your insurer expect? Cyber insurance applications increasingly ask about specific controls, and answers are treated as warranties. This is one of the more common places businesses discover a gap.

Finally, what improves your actual security? If nothing above binds you, start with CIS Controls IG1 and use CSF 2.0 to organize the conversation with leadership. That combination gives you a prioritized list of work and a language for reporting progress.

Most SMBs end up with one compulsory framework and one voluntary one, and that is a reasonable place to be. Adopting four frameworks properly is harder than adopting one, and a framework adopted badly is documentation rather than security.

Which framework fits which situation

A rough guide, and the reason most businesses need fewer frameworks than they fear.

A 30-person professional services firm with no regulatory obligation. CIS Controls Implementation Group 1, organized and reported through CSF 2.0. Nothing else is required, and doing those two properly puts you ahead of most of your peers.

A medical practice. HIPAA Security Rule is compulsory. CIS Controls give you the practical implementation detail the rule does not, since HIPAA tells you to be secure without telling you how.

A manufacturer selling into the defense supply chain. CMMC, at the level your contracts specify, built on NIST SP 800-171. Start early, because Level 2 third-party assessment is not a short process.

A software company selling to enterprises. SOC 2 first, because your buyers will ask for the report. ISO 27001 if you sell internationally or a specific contract demands it.

Anyone taking card payments. PCI DSS, and the first question worth asking is how to reduce scope by not handling card data directly.

What adoption actually involves

Choosing is the easy part, and it is where most articles stop.

Assess honestly. Compare what you do now against the framework and write down the gaps without softening them. A flattering assessment produces a plan that fixes nothing.

Prioritize by risk, not by effort. The temptation is to close the easy gaps first so the chart looks better. The gaps worth closing first are the ones an attacker would use.

Assign ownership with names. Controls owned by “IT” are owned by nobody.

Produce evidence as you go. The difference between being compliant and proving you are compliant is documentation, and reconstructing a year of it retrospectively is far harder than capturing it as you work.

Reassess on a schedule. Environments change, staff change, and controls decay quietly. A framework adopted once and never revisited describes a business that no longer exists.

Frequently asked questions

Which framework should a small business start with?

CIS Controls Implementation Group 1, unless a regulator or a customer has already decided for you. It is prioritized, practical, and achievable for a business without a security team.

Is NIST CSF a certification?

No. It is voluntary guidance, and there is no body that certifies you against it. You can say you align to it. You cannot be certified in it.

Does following a framework make us compliant?

Not automatically. Frameworks and regulations overlap but are not the same thing. CIS Controls will improve your HIPAA position substantially without being HIPAA compliance in itself.

How long does ISO 27001 certification take?

For most small and mid-sized organizations, a year is a realistic planning assumption from start to certificate, and it is a management-system program rather than a technical project.

Do we need more than one framework?

Most businesses end up with one compulsory obligation and one voluntary framework for structure. Adopting four properly is harder than adopting one, and a framework adopted badly is documentation rather than security.

Does CMMC apply to us if we are a subcontractor?

Frequently yes. Requirements flow down through the supply chain, so if controlled unclassified information reaches you, the obligation typically does too. Check your contracts rather than assuming.

A note on what we can and cannot claim

Corporate Technologies helps clients meet their own obligations under these frameworks. That is a different statement from Corporate Technologies holding a given certification, and any provider who blurs the two is worth a follow-up question. If a control matters to your compliance position, ask specifically who holds what, and get it in writing.

Where a managed provider helps

Frameworks fail in implementation, not selection. The gap is rarely knowing that MFA is required. It is enforcing it across every account, keeping it enforced as people join and leave, and being able to demonstrate it a year later to an auditor or an insurer.

We map your obligations, implement and enforce the controls, and produce the evidence when someone asks for it. Contact us or call 1-866-363-4628.

This page is general guidance and not legal, regulatory or insurance advice. Standards, rules and reporting obligations change, and the requirements that apply to your business depend on your sector, your contracts and your location. Corporate Technologies helps clients meet their own obligations and does not represent that it holds any particular certification unless stated. Confirm current requirements with your legal, compliance and insurance advisers.

Mark Stevens

Mark Stevens writes about managed IT, cybersecurity and technology operations for Corporate Technologies. He is the founder of The Syndicate and spent more than 25 years in marketing, sales and product development, including a decade at Atlas where he led the business through a 100x growth period. He works with the Corporate Technologies engineering team to turn day-to-day support and security work into practical guidance for small business owners. Technical claims in security and compliance articles are reviewed by a Corporate Technologies engineer before publication. Mark is based in Edina, Minnesota.

You might also like

  • All Posts
  • Backup
  • Business IT 101
  • Cloud Computing
  • Compliance
  • Data Storage
  • IT Solutions
  • Managed IT in Idaho
  • Managed IT in NJ
  • Managed IT Minnesota
  • Managed Services
  • MSP Comparisons
  • Onsite support
  • Resources
  • Security
  • Technology
  • Training
    •   Back
    • Whitepapers
    • Press Releases
    • Case Studies
    • Coffee Break Reads
    • Checklists

  • This field is for validation purposes and should be left unchanged.
  • Get Your Instant IT Support Estimate

  • Responsive Range Slider with Min and Max
    0
    Min: 0 Max: 200
  • 0
    Min: 0 Max: 200
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Back to top

Downloading...

Please wait while the PDF downloads