Cybersecurity Compliance: Frameworks, Requirements, and How to Get Started (2026 Guide)
.png)
.png)
Cybersecurity compliance is the process of aligning your organisation's security controls, policies, and processes with the requirements set by laws, regulations, and industry standards, and being able to demonstrate that alignment with evidence. It covers how you protect systems and data, how you detect and respond to incidents, and how you document all of it for auditors and regulators.
The financial stakes are measurable. According to IBM's Cost of a Data Breach Report 2025, the global average cost of a breach was USD 4.44 million, and regulatory penalties were a major driver of the USD 10.22 million average in the United States (IBM, 2025). In the EU, security failures can also trigger data protection enforcement. Article 32 of the GDPR requires appropriate technical and organisational measures, and infringements of core GDPR principles carry fines of up to EUR 20 million or 4% of annual global turnover, whichever is higher (Regulation (EU) 2016/679, Articles 32 and 83). GDPR's cybersecurity requirements sit alongside the frameworks in this guide rather than replacing them.
A cybersecurity governance risk and compliance model, usually shortened to GRC, is the operating structure that connects security decisions to business risk and regulatory duty. Compliance rarely fails because of missing tools. It fails because nobody owns the obligations, so GRC exists to assign that ownership. Our guide to governance, risk, and compliance (GRC) covers the model in full.
Governance defines who decides, who is accountable, and how security performance is reported to leadership. Effective cybersecurity governance sets policy, assigns roles, and gives the board visibility of cyber risk. NIST elevated this in 2024 by making Govern one of the six core functions of CSF 2.0 (NIST, 2024).
Risk management turns an abstract obligation into a prioritised work plan. A structured cybersecurity risk assessment identifies your critical assets, the threats to them, and the likelihood and impact of each scenario, so controls are applied where exposure is highest rather than where implementation is easiest.
Compliance is the evidence layer of GRC. Governance sets the rules, risk management prioritises the work, and compliance demonstrates to auditors, regulators, and customers that security, risk, and regulatory obligations stay aligned. Treating cybersecurity governance risk and compliance as one connected system prevents the common failure mode where policies exist on paper but no control maps back to them.
The most widely adopted cybersecurity compliance standards are NIST CSF 2.0, ISO 27001, SOC 2, and PCI DSS, with sector frameworks such as HITRUST and CMMC layered on where they apply. Most organisations answer to more than one of them at once. The table below compares the frameworks covered in this section.
The NIST CSF is a voluntary, risk-based framework published by the US National Institute of Standards and Technology. Version 2.0, released on 26 February 2024, organises outcomes into six functions, Govern, Identify, Protect, Detect, Respond, and Recover, across 22 categories and 106 subcategories (NIST, 2024). NIST cybersecurity framework compliance is not certified by an external body. Organisations self-assess against a target profile, which makes the CSF a common backbone for programs that must also satisfy other regimes.
ISO/IEC 27001:2022 is the international standard for building a certifiable information security management system (ISMS). Its Annex A lists 93 controls grouped into organisational, people, physical, and technological themes (ISO, 2022). Because ISO 27001 certification is issued by an accredited third party, it is the framework most often requested in enterprise procurement across Europe.
SOC 2 is an attestation report, not a certification, in which an independent auditor evaluates a service organisation's controls against the AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy. A Type I report assesses control design at a point in time, while a Type II report tests operating effectiveness over a period, which is why enterprise buyers usually ask for Type II.
PCI DSS applies to any entity that stores, processes, or transmits payment card data. The current version is v4.0.1, and all requirements, including those originally future-dated, became mandatory on 31 March 2025 (PCI SSC, 2024). The standard sets twelve requirement areas covering network security, access control, monitoring, and testing across the cardholder data environment.
Sector and regional frameworks add further obligations. CMMC 2.0 sets three maturity levels for US defence contractors, built on NIST SP 800-171 controls. HITRUST provides a certifiable framework that harmonises HIPAA with other standards for healthcare organisations. In the EU, NIS2 imposes risk management and incident reporting duties on essential and important entities, with a national transposition deadline of 17 October 2024 (Directive (EU) 2022/2555), and DORA has applied to financial entities since 17 January 2025 (Regulation (EU) 2022/2554).
The cybersecurity compliance requirements that recur across frameworks fall into five control families. The labels differ between standards, but an auditor working from NIST, ISO 27001, or HIPAA will test broadly the same things, which is why a single well-mapped control set can serve multiple regimes.
Administrative safeguards are the policies, risk assessments, and training that direct the program. Technical safeguards are the controls implemented in systems, such as firewalls, logging, and endpoint protection. Physical safeguards restrict access to facilities and hardware. This three-part structure comes from the HIPAA Security Rule (45 CFR Part 164, Subpart C) but describes the safeguard mix every framework expects. A documented cybersecurity policy is the administrative anchor auditors look for first.
Access control requirements centre on least privilege, unique user identification, and multi-factor authentication (MFA). PCI DSS v4.0.1, for example, requires MFA for all access into the cardholder data environment. Regular access reviews and prompt deprovisioning of leavers are the controls most often found deficient in audits.
Frameworks require sensitive data to be protected at rest and in transit, with documented key management. Under GDPR Article 32, encryption and pseudonymisation are named examples of appropriate technical measures for personal data (Regulation (EU) 2016/679). Data classification comes first, since you cannot apply the right protection level to data you have not identified.
Every major framework requires a tested cybersecurity incident response plan with defined roles, escalation paths, and reporting procedures. Deadlines are strict. The GDPR requires notification of personal data breaches to the supervisory authority within 72 hours of awareness where feasible (Article 33), and SEC rules require US public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality (SEC, 2023).
Frameworks increasingly hold you responsible for your suppliers' security. NIS2 makes supply chain security an explicit risk management measure, and PCI DSS requires monitoring of third-party service provider compliance. In practice this means due diligence before onboarding, contractual security clauses, and periodic reassessment of critical vendors.
On top of the horizontal frameworks, each regulated sector adds obligations of its own. The four sectors below account for most audit activity, and each pairs a legal mandate with a preferred framework.
Healthcare cybersecurity compliance in the US is anchored in the HIPAA Security Rule, which requires covered entities and business associates to protect electronic protected health information (ePHI) with administrative, physical, and technical safeguards. Many providers pursue HITRUST certification to demonstrate healthcare cybersecurity compliance to partners through a single assessment. In the EU, health data is a special category under GDPR Article 9, which raises the bar for processing and security.
SOX cybersecurity compliance stems from the Sarbanes-Oxley Act of 2002, whose Section 404 requires management to assess internal control over financial reporting. Because financial reporting now runs on IT systems, access controls, change management, and segregation of duties fall directly within SOX scope. The SEC's 2023 disclosure rules add incident reporting and annual disclosure of cyber risk management and governance, making SOX cybersecurity compliance and SEC readiness a joint exercise for listed companies (SEC, 2023). EU financial entities face the parallel DORA regime for ICT risk management and incident reporting.
US defence contractors must protect Federal Contract Information and Controlled Unclassified Information under CMMC 2.0, which assesses implementation of NIST SP 800-171 controls across three levels. The practical effect is that compliance is now a condition of bidding, not an after-award formality.
Any merchant or service provider handling card payments must validate against PCI DSS v4.0.1. The requirements that took effect on 31 March 2025 notably expanded controls for payment page scripts and anti-phishing mechanisms, which pulls e-commerce front ends squarely into scope (PCI SSC, 2024).
Maturity models measure how consistently your security practices operate, which is different from whether a control exists. Pairing a maturity view with your framework obligations shows not just what you comply with today but how durable that position is.
A cybersecurity maturity model rates your capabilities on a scale, typically from initial or ad hoc through managed and defined to optimised. CMMC is the best-known example of cybersecurity maturity model compliance being written directly into contracts, where a required maturity level determines eligibility.
Measurement starts with a structured cybersecurity maturity assessment that scores each control domain against the target level your regulators, customers, and contracts demand. The output is a heat map of domains where practice lags obligation, which becomes the prioritised remediation roadmap.
Reactive programs prepare for audits. Proactive programs monitor controls continuously, so audit evidence is a by-product of normal operations. Organisations that reach this stage treat cybersecurity maturity model compliance targets as annual objectives with owners and budgets, rather than as findings to close after each assessment.
Most compliance programs stall for the same four reasons. Recognising them early is cheaper than discovering them during an audit, and each has a known countermeasure.
A mid-size company can face ISO 27001, SOC 2, PCI DSS, and GDPR at once, each with its own audit cycle. The countermeasure is a common control framework, where each internal control is mapped once to every external requirement it satisfies, so one piece of evidence serves several audits.
You cannot secure or certify assets you cannot see. Unmanaged cloud services, shadow IT, and undocumented data flows are the usual gaps. IBM's 2025 research found that unsanctioned shadow AI alone added an average of USD 670,000 to breach costs, a sign of how quickly unmonitored tooling accumulates risk (IBM, 2025).
Compliance work competes with delivery work, and senior security and privacy skills remain scarce. Outsourcing defined roles, such as an external DPO or a fractional CISO, is often faster than recruiting, particularly for organisations that need audit-ready evidence within a fixed deadline.
The regulatory baseline keeps moving. Between 2024 and 2025 alone, NIST CSF 2.0 arrived, PCI DSS future-dated requirements became mandatory, NIS2 transposition took effect across EU member states, and DORA began applying to financial entities. Our guide to ISO 27001, NIS2, and DORA covers how the three interact, and a regulatory watch process with named owners is now a control in its own right.
A cybersecurity compliance program is built in five sequential steps. Each step produces a concrete artifact, an obligations register, a gap report, a control set, a training record, and a monitoring dashboard, that together form your audit evidence base.

Figure 1. The five steps of a cybersecurity compliance program and the evidence artefact each one produces.
List every regime that applies to you by jurisdiction, sector, data type, and contract. A UK SaaS company selling to EU hospitals, for example, may face UK GDPR, EU GDPR, NIS2, and customer demands for ISO 27001 simultaneously. Record each obligation and its owner in an obligations register.
Compare your current controls against each requirement to produce a prioritised gap report. A formal cybersecurity compliance audit or a data protection compliance audit gives you an independent baseline, which is more defensible with regulators and customers than self-assessment alone.
Close the gaps in priority order, starting with the controls that reduce the most risk per unit of effort, typically MFA, logging, backup, and access reviews. Document each control as you deploy it, since undocumented controls fail audits even when they work.
Frameworks from HIPAA to NIS2 require documented security awareness training. Make it role-specific. Developers need secure coding training, finance teams need payment fraud awareness, and everyone needs phishing recognition, with completion records retained as evidence.
Schedule internal audits, control testing, and management reviews on a recurring calendar. A structured cybersecurity audit checklist keeps internal reviews consistent between external assessments, and the findings feed the next cycle of the program.
Cybersecurity compliance and data protection compliance overlap but answer to different regulators and protect different things. Security frameworks protect systems and all the data in them. Data protection law protects people, through rules on lawful processing, individual rights, and transfers that no firewall can satisfy.
The overlap is security of processing. GDPR Article 32 and frameworks such as ISO 27001 both demand risk-appropriate technical measures, so the same encryption or access control serves both. The differences sit in scope. Only data protection law governs consent, retention, data subject rights, and international transfers, and only security frameworks specify control depth for the full IT estate.
A company can hold ISO 27001 certification and still breach the GDPR by processing data without a lawful basis. Equally, a privacy-compliant company with weak controls remains one incident away from a reportable breach. Integrated multi-regulatory compliance services address both dimensions in a single program, which is where mature organisations are converging.
DPO Consulting provides cybersecurity compliance services that combine security expertise with more than a decade of data protection practice across 800+ client organisations. The work spans four areas, each mapped to the frameworks in this guide.
Independent cybersecurity audit services establish where your controls stand against your obligations, producing a prioritised remediation plan rather than a generic findings list.
Consultants map your control set once across NIST CSF 2.0, ISO 27001, SOC 2, and applicable EU regimes such as NIS2 and DORA, so evidence collected for one assessment serves the others.
Structured risk assessments identify your highest-exposure assets and scenarios, and implementation support turns the resulting priorities into deployed, documented controls.
Retained support keeps the program running between audits, from regulatory watch and policy maintenance to board reporting, with outsourced DPO and CISO-as-a-service options for organisations that need the roles without the headcount.
Sustainable cybersecurity compliance comes from one control framework mapped to every obligation, owned by named people, and monitored continuously, so each audit draws on evidence you already have. Organisations that reach this state spend less on each assessment and materially reduce breach exposure, which IBM prices at USD 4.44 million on average globally (IBM, 2025).
If you are facing several frameworks at once, or preparing for a first certification, talk to a DPO Consulting expert. Request a consultation to scope a gap assessment, or explore our cybersecurity compliance services to see how framework alignment works in practice.
Cybersecurity compliance is the practice of meeting the security requirements defined by applicable laws, regulations, and industry standards, and maintaining documented evidence that your controls satisfy them.
The most common cybersecurity compliance standards are NIST CSF 2.0, ISO 27001, SOC 2, and PCI DSS. Sector rules add HIPAA for healthcare, SOX and DORA for finance, and CMMC for defence contracting, while the GDPR and NIS2 apply across sectors in the EU.
You know through assessment. Map your obligations, then commission a gap analysis or independent audit against each applicable framework. Certification (ISO 27001), attestation (SOC 2), or validated self-assessment (PCI DSS) then provides third-party confirmation.
The NIST Cybersecurity Framework is a voluntary, risk-based framework organising security outcomes into six functions, Govern, Identify, Protect, Detect, Respond, and Recover. NIST cybersecurity framework compliance is demonstrated through self-assessment against a target profile rather than formal certification (NIST, 2024).
Compliance proves you meet a defined external standard at a point in time. Security is the continuous practice of protecting systems and data against real threats. Compliance is necessary evidence of security, but passing an audit does not by itself make an organisation secure.
European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). EUR-Lex. https://eur-lex.europa.eu/eli/reg/2016/679/oj
European Parliament & Council of the European Union. (2022). Directive (EU) 2022/2555 (NIS 2 Directive). EUR-Lex. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
European Parliament & Council of the European Union. (2022). Regulation (EU) 2022/2554 (Digital Operational Resilience Act). EUR-Lex. https://eur-lex.europa.eu/eli/reg/2022/2554/oj
IBM. (2025). Cost of a Data Breach Report 2025. IBM Corporation. https://www.ibm.com/reports/data-breach
International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection. Information security management systems. Requirements. https://www.iso.org/standard/27001
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29
PCI Security Standards Council. (2024). Payment Card Industry Data Security Standard v4.0.1. https://www.pcisecuritystandards.org/document_library/
U.S. Department of Health and Human Services. (2024). The HIPAA Security Rule (45 CFR Part 164, Subpart C). https://www.hhs.gov/hipaa/for-professionals/security/index.html
U.S. Securities and Exchange Commission. (2023). Cybersecurity risk management, strategy, governance, and incident disclosure (Release No. 33-11216). https://www.sec.gov/rules/final/2023/33-11216.pdf