The Cyber Governance GroupSecurity · Risk · Compliance
[ Frameworks guide ]

The rules, in plain language.

Who each framework applies to, what it actually asks for, and how they overlap. You don't need to know any of this before calling us. It's here in case you want to.

  • HIPAA 45 CFR 164
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • NCUA Part 748 · ACET
  • FERPA 34 CFR 99
  • PA BPINA Breach notification
  • ITP-SEC023 Commonwealth of PA
  • ISO/IEC 27001 2022
  • SOC 2 Trust Services Criteria
01 — The frameworks

What applies to you, and why.

Highlighted cards are our core practice areas. Most organizations answer to two or three of these at once, which is why we assess each on its own terms and use the overlap so you never do the same work twice.

Healthcare · Federal regulation

HIPAA

45 CFR Part 164 · Security, Privacy & Breach Notification Rules

Requires safeguards for patient information, starting with an accurate, organization-wide risk analysis. Some safeguards are "required"; others are "addressable", meaning you implement them or document why an alternative is reasonable.

Applies to
Providers that bill electronically, health plans, clearinghouses, and their business associates
Payments · Industry standard

PCI DSS

Payment Card Industry Data Security Standard v4.0.1

Twelve requirement areas protecting cardholder data. Most small merchants validate annually through a self-assessment questionnaire (SAQ). Choosing the right one depends on how you take payments.

Applies to
Any business that stores, processes or transmits card data, through its acquirer agreement
All sectors · Voluntary framework

NIST CSF

NIST Cybersecurity Framework 2.0

Six functions (Govern, Identify, Protect, Detect, Respond, Recover) that give boards and staff a shared language. It's our default lens for local government and for board reporting.

Applies to
Anyone; widely used by public-sector and critical-infrastructure organizations
Credit unions · Federal regulation

NCUA

12 CFR Part 748 · ACET

Requires a written information security program, board oversight and member-notice procedures, plus reporting of cyber incidents to NCUA within 72 hours. Examiners review it during information security examinations.

Applies to
Federally insured credit unions
Education · Federal law

FERPA

20 U.S.C. § 1232g · 34 CFR Part 99

Protects student education records and limits disclosure. Ed-tech vendors typically get access under the "school official" exception, which makes data sharing agreements essential.

Applies to
Schools and districts receiving U.S. Department of Education funds
Pennsylvania · State law

PA BPINA

Breach of Personal Information Notification Act

Pennsylvania's breach notification law. Amendments in 2024 added Attorney General notice and credit-monitoring requirements in certain breaches.

Applies to
Organizations holding personal information of Pennsylvania residents, including public entities
Pennsylvania · Commonwealth policy

ITP-SEC023

Commonwealth IT policy on technical security assessments

Requires independent, third-party technical security assessments for agencies supporting critical functions, and for vendors that serve them.

Applies to
Commonwealth agencies and their vendors and contractors
Global · Certifiable standard

ISO 27001

ISO/IEC 27001:2022

An international standard for an information security management system, certified by an accredited body. Usually driven by customers who require certification.

Applies to
Voluntary; common for service providers selling to larger enterprises
Service providers · Attestation

SOC 2

AICPA Trust Services Criteria

A CPA firm's report on a service organization's controls. We provide readiness: getting your controls and evidence in shape before the auditor arrives.

Applies to
Voluntary; often requested of MSPs and software vendors
02 — The deadlines

Deadlines don't shrink with headcount.

The clocks start the moment something goes wrong. A good program knows them before it needs them.

60days

Outer limit to notify individuals after discovering a HIPAA breach.

45 CFR 164.404(b)
72hours

For a federally insured credit union to report a cyber incident to NCUA.

12 CFR 748.1(c)
36specs

HIPAA Security Rule implementation specifications, 22 of them "addressable" with documented decisions.

45 CFR 164, Subpart C, App. A
12months

Longest interval between reviews of each PCI DSS targeted risk analysis.

PCI DSS v4.0.1 · 12.3.1
03 — Pennsylvania insight
HIPAA compliance can satisfy Pennsylvania's breach law for the same incident. But Pennsylvania adds its own layers, and the details matter.

Pennsylvania's Breach of Personal Information Notification Act generally treats a HIPAA-covered organization that follows HIPAA's breach notification rules as compliant. But 2024 amendments added Attorney General notice and credit-monitoring requirements, and the state's HIV, mental-health and patient-record confidentiality laws can be stricter than HIPAA. Your incident response plan should account for all of it.

General information, not legal advice.

Not sure which apply to you?

That's the first thing we sort out, usually in a single conversation.