- | Home
- | Solutions
- | Compliance & Risk
Compliance & Risk Management
Compliance and Risk Management Services That Keep You Audit-Ready
Regulatory requirements are not a paperwork exercise. They decide which contracts you can bid on, which clients you can serve, and what happens after an incident. CompassMSP turns regulatory pressure into a clear plan: know your gaps, fix them in priority order, produce the evidence, and defend it.-
CMMC
-
-
NIST CSF
-
-
HITRUST
-
-
PCI DSS
-
-
FINRA
-
-
NIST SP 800-171
-
-
HIPAA
-
-
SOC 2
-
-
GDPR
-
-
NYDFS Part 500
-
-
CMMC
-
-
NIST CSF
-
-
HITRUST
-
-
PCI DSS
-
-
FINRA
-
-
NIST SP 800-171
-
-
HIPAA
-
-
SOC 2
-
-
GDPR
-
-
NYDFS Part 500
-
First principle
Compliance Is Not Security, and Confusing the Two Is Expensive
Compliance proves you met a standard on a given day. Security is whether you can withstand an attack tomorrow. Organizations get hurt when they treat the certificate as the goal.
Compass builds compliance on top of working security controls, which means the evidence is a byproduct of operations rather than a project. When the tools that run your environment are the same tools that generate your audit artifacts, evidence collection stops being a quarterly scramble.
That is the practical difference between a compliance consultant and a compliance partner who also runs your systems. A consultant tells you what to fix. Compass fixes it, then proves it stayed fixed.
Regulatory bulletin Verified 10 September 2026
Where the Rules Stand Right Now
Phase 2 Paused CMMC: Phase 2 Is Suspended. Phase 1 Remains Active.
On July 13, 2026, the Department announced the suspension of the November 10, 2026 CMMC Phase 2 transition. The official announcement confirms that Phase 1 self-assessment requirements remain in place. The pause should not be treated as permission to stop meeting applicable contract security requirements.
Status at a Glance
| Requirement | Current Status |
|---|---|
| November 2026 Phase 2 transition | Suspended |
| Phase 1 self-assessments | Remain active where applicable |
| SPRS reporting and annual affirmations | Required under applicable clauses |
| DFARS 252.204-7012 safeguarding and incident reporting | Applicable obligations continue |
| NIST SP 800-171 security requirements | Continue where contractually required |
| C3PAO Level 2 certification assessments | Still available |
| Requirements in an existing award | Review the award and applicable modifications |
Supporting sources: DFARS 252.204-7021 and DFARS 252.204-7012 .
What About Contracts You Already Hold?
An announcement does not establish that a requirement has been removed from your specific award. Review the incorporated clauses, modifications, and written contracting direction before changing your compliance plan. Where incorporated, DFARS 252.204-7021 requires the specified CMMC status and associated affirmations throughout contract performance.
Can You Still Pursue Certification?
Yes. The Cyber AB confirms that certification assessments remain operational , alongside training, professional exams, practitioner services, and DIBCAC assessments of C3PAOs. Whether to proceed now depends on your customer requirements, existing commitments, readiness, and business priorities.
What Happens Next?
The announced reform process includes a 60-day review. That review period does not establish a guaranteed publication date, replacement deadline, or final policy outcome. Evaluate published changes and their applicability to your contracts before adjusting your plan.
Proposed Changes HIPAA Security Rule: Current Requirements Still Apply
HHS has proposed significant changes to the HIPAA Security Rule, including more specific requirements for encryption, multi-factor authentication, network segmentation, vulnerability management, and compliance reviews. The HHS proposal fact sheet explains the proposed safeguards.
What Should Your Organization Do Now?
Start with the requirements already applicable to your organization. The existing HIPAA Security Rule requires risk analysis and appropriate administrative, physical, and technical safeguards.
- Keep your security risk analysis current as systems and operations change.
- Document identified risks, remediation priorities, and responsible owners.
- Evaluate encryption, MFA, access controls, and recovery capabilities against your risks.
- Use the proposed changes to inform planning while tracking finalized requirements separately.
Addressable safeguards under the current rule require evaluation and documentation; they are not simply optional. The proposal would make several safeguards more explicit and prescriptive.
This bulletin reflects the sources reviewed on the date shown. Follow The Fine Print for more compliance and risk insights.
Risk-First Financial IT
How Compass Compliance Engagements Work
We start with your requirements, assess the gaps, and build a prioritized plan with clear owners and milestones. From implementing controls to preparing evidence, each step moves your organization toward assessment readiness and ongoing improvement.-
STEP 01
Scope
Determine which frameworks apply, which systems and data fall within scope, and where the boundaries sit. Scope errors are the most expensive mistake in compliance, and they are made in week one.
-
STEP 02
Assess
Measure your current controls against the applicable framework and produce a documented gap analysis with each finding ranked by risk and remediation effort.
-
STEP 03
Prioritize
Sequence remediation by risk and by deadline, so budget goes to what moves the needle on both audit outcome and actual exposure.
-
STEP 04
Remediate
Implement the technical and administrative controls. Because Compass manages the environment, remediation is executed rather than recommended.
-
STEP 05
Document
Produce policies, procedures, system security plans, and the evidence trail auditors and regulators expect.
-
STEP 06
Sustain
Monitor control effectiveness continuously, maintain evidence, and prepare for the next assessment cycle. Compliance decays without maintenance.
Built to Make Tech Work for You
| Framework | What Compass Delivers Practical Support for Your Requirements | Who It Applies To |
|---|---|---|
| CMMC and NIST SP 800-171 | Scoping, gap assessment against applicable requirements, enclave design, System Security Plan and Plan of Action and Milestones development, SPRS scoring support, and assessment preparation. CMMC Readiness → | Defense contractors and suppliers subject to applicable contract requirements. |
| HIPAA and HITRUST | Security risk assessments, safeguard implementation, business associate agreement management, workforce training, breach response planning, and HITRUST certification support. HIPAA + HITRUST → | HIPAA-covered healthcare organizations and business associates, plus organizations pursuing HITRUST certification. |
| SOC 2 | Readiness assessment, control design, evidence automation, and coordination with your independent auditor. | Service organizations whose customers require independent assurance over security and other applicable trust services criteria. |
| PCI DSS | Cardholder data environment scoping, segmentation, control implementation, and assessment support. | Merchants and service providers that store, process, or transmit payment card data, or can affect its security. |
| NIST Cybersecurity Framework | Program-level assessment and roadmapping to organize security priorities and coordinate controls where multiple frameworks overlap. | Any organization seeking a structured approach to managing cybersecurity risk. |
| FINRA and NYDFS Part 500 | Control alignment, governance documentation, and support for applicable compliance reporting and certification requirements. | FINRA member firms and financial services or insurance organizations covered by NYDFS Part 500, as applicable. |
| GDPR | Data mapping, processing documentation, and technical safeguards to support your privacy and data protection program. | Organizations whose personal data processing falls within GDPR’s scope. |
Where multiple frameworks apply, Compass maps overlapping controls so shared implementations and evidence can support several requirements, while addressing the obligations specific to each framework.
Beyond the checklist
Risk Management Beyond the Checklist
Risk Assessments
Identify what would genuinely damage the organization: data loss, downtime, regulatory penalty, contract loss, and reputational harm, sized and ranked rather than listed.
Vendor & Third-party Risk
Verizon found third-party involvement in 48% of breaches in 2026, a 60% year-over-year increase. Your vendors' security is your exposure, and most frameworks expect you to manage it.
Incident Response Planning
Documented, tested procedures with defined roles and notification obligations, because most frameworks require the plan, and every regulator asks whether you followed it.
Policy & Governance
Written policies that reflect what actually happens, rather than a template nobody follows, which auditors detect immediately.
Executive Reporting
Risk posture translated into business terms for boards, insurers, and leadership.
Remediation Tracking
Turn findings into measurable progress with clear owners, deadlines, and verification that fixes address the underlying risk.
Data residency
A 100% U.S.-Based Security Operations Center
Compass operates no offshore security operations center and does not subcontract analysis, escalation, or response to an overseas provider.
For most buyers, that is a preference. For contractors handling controlled unclassified information or ITAR-controlled technical data, it is a documented requirement. Knowing exactly who can access your environment and where those people sit is a question that appears on security questionnaires, in DFARS flow-down reviews, and in audit findings. A blended global delivery model does not answer it cleanly.
Security telemetry, forensic artifacts, and chain-of-custody documentation stay inside a U.S.-only handling chain from first signal to final report.
Bring the Receipts
Compliance Backed by Real Security Operations
Compass connects compliance support with security operations, turning monitoring records, incident findings, and documented improvements into evidence your organization can use. Add vCISO advisory to connect that operational insight to governance, risk decisions, and board reporting.
The Apex Security Platform
Monitoring records, detection history, and incident documentation.
Complete Security
Forensic timelines with chain of custody, which is what regulators and cyber insurers ask for after an incident.
Managed IT
Patching records, access reviews, backup verification, and configuration baselines.
vCISO & Security Advisory
The governance layer, presented to your board.
Inherited Compliance Risk
Find the Gaps Before They Become Yours
CompassMSP evaluates the target’s controls, documentation, and regulatory obligations so your team can price remediation, address material findings, and plan the integration with better evidence.
- Standardize systems and vendors
- Retire duplicated tools and technical debt
- Sequence changes around business continuity
Turn Compliance Into Confidence.
Organizations maintain a state of continuous readiness across regulated engagements, ensuring evidence is organized and defensible whenever auditors arrive. Gartner
We streamline the path to compliance, reducing preparation time by eliminating the last-minute scramble for documentation and evidence. Forrester
Proactive gap management allows our clients to identify vulnerabilities early, resulting in significantly fewer corrections during formal assessments. PWC
The Compass Approach to Compliance & Risk Management
We don't guess; we verify. We conduct a comprehensive review of your current controls, policies, and overall risk posture to establish a clear, data-driven starting point for your compliance program.
We map your environment against regulatory standards to identify specific vulnerabilities, control gaps, and areas of misalignment. This proactive analysis ensures you understand your true exposure before an auditor does.
We deliver clear, prioritized action plans designed to close gaps efficiently. Our focus is on practical security that fits your business, avoiding the common trap of "overengineering" solutions that slow down operations.
We transform scattered records into a defensible system of record. Policies, procedures, and evidence are centralized, maintained, and kept up-to-date, ensuring you are always prepared for an assessment.
We turn your workforce into your first line of defense. Our training programs ensure employees understand expectations and reduce human risk through informed, security-conscious behavior.
Featured Healthcare Compliance Guide
The Complete Guide to Compliance for Healthcare SMBs
HIPAA sets the regulatory baseline for protecting PHI and ePHI. HITRUST gives healthcare organizations a certifiable framework for proving those safeguards work. This guide breaks down where the two overlap, where they differ, and how healthcare leaders can use both to build a more defensible compliance program without creating extra operational drag.
CUSTOMER SUCCESS STORY
Burke Aerospace Clears the Runway for CMMC Readiness and Manufacturing Uptime
This success story highlights how a premier aerospace manufacturer eliminated production downtime and achieved audit-ready CMMC compliance. By transitioning from an unresponsive legacy provider to a strategic IT partnership, Burke Aerospace turned infrastructure instability into a secure foundation for Industry 4.0 growth.
Organizations maintain a state of continuous readiness across regulated engagements, ensuring evidence is organized and defensible whenever auditors arrive. Gartner
We streamline the path to compliance, reducing preparation time by eliminating the last-minute scramble for documentation and evidence. Forrester
Proactive gap management allows our clients to identify vulnerabilities early, resulting in significantly fewer corrections during formal assessments. PWC
Secure AI Governance
Make AI Useful Without Letting Risk Get Ahead of You
The issue is not whether employees will use AI. The issue is whether the organization has the visibility, access controls, data safeguards, and usage rules to manage it responsibly. CompassMSP helps leaders bring structure to AI adoption before sensitive data, loose permissions, and unapproved tools create bigger problems. We start with an AI Readiness Roadmap to understand where risk exists today, then help build the guardrails, governance, and oversight needed to use AI with confidence.
-
01 MAP AI Readiness Map
See Where AI Risk Already Exists
Where are we exposed today?
Get a clear view of current AI use, shadow AI, data exposure, Microsoft 365 and Copilot readiness, identity gaps, audit logging, and policy gaps before adoption expands.
-
02 STABILIZE AI SAFE START
Create A Safe Path Forward
Can we use AI safely at all?
Address priority gaps, set acceptable use rules, define pilot guardrails, document known risk, and get a safe-to-proceed recommendation in 2 to 3 weeks.
-
03 GOVERN AI Governance Buildout
Prove Responsible AI Use
Can we prove AI is being used responsibly?
Build formal ownership, approval workflows, data handling rules, compliance alignment, reporting structure, and governance that leaders can defend.
-
01 OPERATE AI OPERATIONS
Keep AI Controlled As It Grows
How do we keep AI controlled as adoption grows?
Use recurring reviews, risk reporting, policy updates, control tuning, and automation oversight to keep AI visible, useful, and accountable.
INCIDENT RESPONSE
Experiencing a Cybersecurity Incident?
A cybersecurity incident brings urgent questions: What was affected? Was sensitive data exposed? What needs to be reported? CompassMSP helps investigate the incident, coordinate containment, and document findings to support informed decisions.
We work alongside your IT team, legal counsel, and cyber insurance carrier to preserve evidence, establish timelines, and support notification planning. Findings guide recovery and control improvements, helping your organization address the incident and strengthen its compliance program.
Available to existing clients and new organizations through a separate retainer-based engagement.
Industries we serve
Industries With the Heaviest Regulatory Load
Regulatory pressure is no longer limited to the defense sector. Whether you are protecting patient data under HIPAA, financial assets under NYDFS 500, or client trust under SOC 2, the cost of non-compliance is too high to ignore.
CompassMSP goes beyond basic support to deliver technology programs tailored to the specific regulations you are subject to. We understand the operational nuance of high-stakes environments (from healthcare and finance to legal and manufacturing) and design defensible security strategies that satisfy auditors without slowing down your business.
Healthcare
HIPAA-compliant infrastructure ensuring 24/7 patient data availability.
Finance
Secure infrastructure built for NYDFS and SEC audits.
Legal
Protect client confidentiality and critical billable hours.
Insurance
Secure policyholder data aligned with NAIC mandates.
Manufacturing
Secure production lines by bridging IT and OT.
Construction & Engineering
Secure field-to-office connectivity for complex project schedules.
Education
Safeguard student data and hybrid learning environments.
Nonprofit
Protect donor data while maximizing mission-critical resources.
Professional Services
Protect intellectual property to maintain client trust.
Logistics & Transportation
Secure supply chains to keep fleets moving.
Retail & Franchise
PCI-ready networks supporting rapid multi-location growth.
Local & State Government
Resilient infrastructure built to safeguard citizen records.
Why Organizations Trust Compass for Compliance Readiness
Compliance does not need to feel overwhelming. Compass provides structure, guidance, and accountability.
Compliance anchored in real cybersecurity controls, not paperwork alone.
CMMC is more than a documentation exercise; it is a validation of your actual security maturity. We build your compliance program on a foundation of technical excellence, ensuring that your 110 NIST 800-171 controls are fully implemented, functional, and verifiable. By aligning your CMMC requirements with day-to-day security operations, we ensure that your posture is defensible during a third-party assessment and resilient against evolving threats. We move beyond "checkbox compliance" to deliver a security environment that protects your intellectual property and your Department of Defense (DoD) contracts.
Hands-on guidance from vCISO and security advisors who understand audits and assessors.
Navigating the complexities of CMMC requires more than just IT support; it requires executive-level advisory and specialized compliance knowledge. Our vCISOs and security advisors act as your internal advocates, providing the practical judgment needed to translate dense regulatory language into actionable business milestones. As an RPO, our team is authorized to guide you through readiness using practices aligned with assessor expectations, significantly reducing the risk of failed audits or corrective action delays. We provide the high-level oversight necessary to manage your System Security Plan (SSP) and Plan of Action & Milestones (POA&M) with total confidence.
Programs designed to support contracts without slowing the business down.
We recognize that defense manufacturers must maintain production velocity while meeting strict security mandates. Our approach focuses on "right-sizing" your compliance scope, using techniques like enclave definition and CUI data flow mapping to isolate sensitive information. This strategy prevents the over-engineering of your entire IT environment, allowing your shop floor to remain efficient while your defense-related systems meet Level 2 requirements. We build compliance programs that fit the unique workflow of your industry, ensuring that security supports your people instead of slowing them down.
One partner responsible for alignment, follow-through, and outcomes.
Fragmented ownership is one of the leading causes of CMMC assessment failure. CompassMSP eliminates this risk by serving as your single integrated partner across IT, cybersecurity, and compliance. We take full responsibility for the alignment of technical controls, policy documentation, and employee training, ensuring no gaps exist between your IT operations and your audit evidence. From the initial gap analysis to the final pre-assessment validation, you have one partner accountable for the success of your certification journey and the protection of your manufacturing legacy.
FEATURED RESOURCES
Make Sense of Compliance.
Explore practical insights on regulatory changes, audit readiness, and risk management to help your team prioritize what matters and move forward with confidence.
Compliance & Risk Events Logistics & Transportation Local & State Governments 2 min read
ACM Aerospace Alley - October 29, 2026
Join CompassMSP at the ACM Aerospace Alley Tradeshow to explore cybersecurity solutions for aerospace manufacturers and enhance compliance readiness.
Compliance & Risk Events Logistics & Transportation Local & State Governments 2 min read
CS5 EAST - October 22-23, 2026
Join CompassMSP at CS5 East 2026 to learn about CMMC compliance for defense contractors. Visit Booth #16 for insights on cybersecurity and contract readiness.
Compliance & Risk Healthcare Articles 4 min read
The HIPAA Security Rule Delay Gives Small Healthcare Teams More Time. Here Is How to Use It.
This article highlights what the proposed HIPAA Security Rule update will cover and how to focus on "no-regret" moves in the meantime.FAQs
Clarity on Compliance & Risk Management Services
Executives, compliance officers, and IT leaders ask these questions most often when evaluating compliance support.
What are IT compliance services?
IT compliance services help organizations address the security, governance, and documentation requirements of applicable regulations, contracts, and industry standards. CompassMSP provides scoping, gap assessments, prioritized remediation, control implementation, policy development, evidence collection, and assessment support. Services include CMMC readiness, HIPAA and HITRUST support, and alignment with frameworks such as the NIST Cybersecurity Framework. Engagements can also address NIST SP 800-171, SOC 2, PCI DSS, GDPR, FINRA, and NYDFS Part 500 requirements.
What is the difference between compliance and security?
Compliance means meeting applicable requirements and maintaining evidence that demonstrates how those requirements are addressed. Security is the ongoing work of protecting systems, detecting threats, responding to incidents, and recovering operations. An audit evaluates a defined scope and does not guarantee protection against future attacks. Compass connects compliance support with cybersecurity operations, helping produce evidence through the controls and systems that protect your environment.
What is the current status of CMMC requirements?
On July 13, 2026, the Department announced the suspension of the November 10, 2026 CMMC Phase 2 transition. The official announcement confirms that Phase 1 self-assessment requirements remain in place.
Applicable contract obligations still matter. DFARS 252.204-7012 establishes safeguarding and incident-reporting requirements, while applicable CMMC clauses address assessment status, reporting, and affirmations. Compass’s CMMC readiness services help align your controls and documentation with the requirements relevant to your contracts.
Does the suspension remove CMMC requirements from contracts we already hold?
Do not assume the announcement automatically changes an existing award. Review the clauses, modifications, and written direction applicable to each contract. Where incorporated, DFARS 252.204-7021 requires contractors to maintain the specified CMMC status and associated affirmations. Compass can help organize the technical scope and supporting evidence through a CMMC readiness engagement.
Can we still get CMMC certified during the suspension?
Yes. The Cyber AB’s statement on the Phase 2 suspension confirms that C3PAO Level 2 certification assessments and other assessment, training, and practitioner services remain operational. Certification may support customer requirements and demonstrate independently assessed control implementation. Compass helps prepare your environment and evidence through CMMC readiness support; an authorized C3PAO performs the certification assessment.
Should we stop CMMC work because Phase 2 is suspended?
No. Continue addressing the security requirements that apply to your contracts and the information you handle. The pause does not remove applicable DFARS safeguarding obligations or Phase 1 self-assessment requirements. Prioritize accurate documentation, implemented controls, and evidence that supports your submissions. Compass’s CMMC readiness services help identify which work remains necessary and how to sequence it.
When will the CMMC picture become clear again?
The Cyber AB’s July 2026 announcement describes a 60-day program review, but that does not establish a guaranteed publication date or replacement implementation schedule. Review recommendations should not be treated as changes to your contract. Compass helps organizations assess published developments against their existing obligations, while The Fine Print provides ongoing coverage of compliance and cybersecurity changes.
Is the new HIPAA Security Rule in effect?
HHS continues to identify the Security Rule changes as a proposal and states that the current HIPAA Security Rule remains in effect during rulemaking. Proposed safeguards should not be presented as finalized requirements or assigned a firm compliance deadline.
The existing rule already requires risk analysis and appropriate administrative, physical, and technical safeguards. Compass’s HIPAA and HITRUST services help evaluate current obligations and prioritize security improvements while preparing for potential changes.
How long does compliance readiness take?
Timelines depend on the framework, assessment scope, existing controls, and the evidence already available. An initial assessment may take several weeks, while remediation and evidence collection can take months or longer. Technical changes, policy approvals, and external assessment scheduling also affect the timeline. Compass establishes milestones through its readiness assessment process, with responsibilities and dependencies defined before committing to a completion date.
What does a compliance gap assessment include?
A gap assessment compares your current controls and evidence with applicable requirements. It identifies missing or incomplete controls, documents findings, and establishes remediation priorities, owners, and estimated effort. For CMMC engagements, scoping includes identifying where federal contract information or controlled unclassified information is stored, processed, or transmitted. The result is a practical work plan that connects requirements to implementation and evidence.
Can CompassMSP help if we already failed an audit or received findings?
Yes. Compass helps translate findings into a prioritized remediation plan, address control gaps, improve documentation, and prepare evidence for reassessment. When Compass also manages your IT environment, its operating teams can implement agreed technical changes. In co-managed environments, Compass coordinates with your internal team so responsibilities, completion criteria, and supporting records remain clear.
Do we need a vCISO for compliance?
Not every organization needs a vCISO, but compliance work benefits from clear security leadership and accountability. Compass vCISO advisory provides separately scoped support for governance, risk prioritization, security strategy, and board reporting. A vCISO helps leadership evaluate remediation priorities and risk acceptance decisions; your organization retains responsibility for approving those decisions and meeting its obligations.
How does CompassMSP produce audit evidence?
Evidence comes from the services and controls operating within your agreed scope. Cybersecurity services provide monitoring and incident records, while Managed IT can provide patching records, backup checks, and configuration documentation. Complete Security adds deeper investigative findings and forensic records. Compass organizes relevant evidence around assessment requirements, as outlined in our guide to security and compliance deliverables.
Does CompassMSP perform the audit or certification itself?
Compass provides readiness, implementation, documentation, and assessment support. Formal assessment responsibilities depend on the program: authorized C3PAOs conduct CMMC Level 2 certification assessments, independent CPA firms perform SOC 2 examinations, and HITRUST certification involves an authorized external assessor and HITRUST’s review process. These programs have specific independence and qualification requirements. Compass’s HIPAA and HITRUST support helps prepare your organization for the applicable assessment process.
Where are the analysts who monitor our environment located?
CompassMSP’s security operations center is 100% U.S.-based, including detection, triage, investigation, and containment. Compass’s managed IT service desk and engineering teams operate a blended U.S. and Philippine follow-the-sun model.
SOC location alone does not establish personnel citizenship, data residency, or export-control compliance. Where those requirements apply, they must be addressed explicitly in service scope, access permissions, and contractual terms. Compass’s security advisors help connect those requirements to your security program.
Can you manage compliance for our vendors and third parties?
Compass supports third-party risk management through vendor inventories, risk classification, security questionnaire reviews, contractual security requirements, and ongoing oversight. The depth of review depends on each vendor’s access, the information it handles, and its importance to your operations. AICPA guidance on SOC engagements highlights the importance of vendor management controls. Compass vCISO advisory helps leadership evaluate vendor risks and prioritize follow-up actions.
Turn Regulatory Pressure Into a Plan That Drives Progress.
Ready to secure your future? Here is what happens next:
- Discovery
We schedule a brief call to understand your pain points. - Assessment
We review your current infrastructure and security posture. - Roadmap
We present a right-sized plan to modernize and secure your business.