IT Compliance Services in Utah

Compliance frameworks such as HIPAA (health data), PCI DSS (card payments), SOC 2 (service provider reports) and NIST 800-171 (data from government contracts) list what a business has to protect. WITS turns those requirements into technical controls, written policies and the evidence an auditor, insurer or customer asks to see.

We support Utah medical and dental practices, retailers and restaurants, financial firms and government contractors from our Lehi office. Call 385-242-2514 to schedule an on-site assessment.

What IT Compliance Work Involves

A compliance framework is a written list of requirements. It says what has to be true, for example that access to sensitive data is limited to the people who need it and that activity on those systems is logged. It rarely says which setting to change on your firewall, your Microsoft 365 account or your card terminals.

IT compliance work closes that gap in three parts. Technical controls are the configurations and tools that meet each requirement. Documentation is the policies, procedures, network diagrams and asset lists that describe how your systems work. Evidence is the logs, screenshots, configuration exports and training records that show the controls are in place and still working.

Which framework applies depends on the data you handle and the contracts you sign, not on your headcount. Some businesses answer to more than one.

Which Framework Applies to Your Business

These are the frameworks WITS supports.

HIPAA

HIPAA, the Health Insurance Portability and Accountability Act, covers health plans, health care clearinghouses and health care providers that conduct certain transactions electronically, such as submitting claims. It also covers their business associates, the outside companies that handle patient data for them, such as billing companies and IT vendors. The Security Rule requires administrative, physical and technical safeguards for electronic protected health information, meaning patient health data that is stored or sent electronically. A risk analysis comes first.

WITS implements and documents the technical safeguards: access control, encryption, audit logging, backups and patching. Read the HIPAA IT compliance checklist, or see IT for healthcare practices and dental practices.

PCI DSS

PCI DSS, the Payment Card Industry Data Security Standard, covers any business that stores, processes or transmits cardholder data. The PCI Security Standards Council publishes the standard. The card brands and your acquirer, the bank or processor behind your card payments, decide what proof you submit. PCI DSS v4.0.1 is the current version. Requirements that v4.0 gave a later start date became mandatory on March 31, 2025.

WITS finds which of your systems touch card data and works to reduce that scope. It then implements network segmentation, firewall rules, access control, logging and patching, and gives guidance on the self-assessment questionnaire (SAQ). Read the PCI DSS compliance checklist, or see IT for retail and restaurants.

SOC 2

SOC 2, short for System and Organization Controls 2, is a reporting framework from the American Institute of Certified Public Accountants (AICPA) for service providers. A licensed CPA firm examines your controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality and privacy) and issues a report. A Type 1 report covers the design of controls at a point in time. A Type 2 report also tests how they operated over a period of time. It is a report, not a certificate. A customer asking for a SOC 2 report is a common reason to pursue it.

WITS sets up the technical controls and gathers the supporting evidence so the CPA firm has something to test. Firms that hold client data can also see IT for financial firms.

NIST SP 800-171 and CMMC

Covers contractors and subcontractors that handle controlled unclassified information (CUI), meaning sensitive government information that is not classified. NIST SP 800-171, from the National Institute of Standards and Technology, lists the security requirements for protecting CUI on non-federal systems. Revision 2 has 110 requirements in 14 families. NIST published Revision 3 in May 2024, so we check which revision your contract cites before scoping anything.

CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense program that verifies contractors meet those requirements. Level 1 covers federal contract information, which is non-public information you receive or create under a federal contract. Level 2 covers CUI and uses the NIST SP 800-171 Revision 2 requirements, as set by the CMMC rule (32 CFR Part 170, in the Code of Federal Regulations). Level 3 adds requirements from NIST SP 800-172. Your contract states which level applies and how it is assessed.

WITS maps the requirements to your environment and implements the technical controls. It also helps prepare two documents. The system security plan describes your systems and how each requirement is met. The plan of action lists the open gaps and when you will close them. See IT for manufacturers and construction firms.

Access control, logging, patching and backups appear in most of these frameworks, so work done for one often supports another.

How an IT Compliance Engagement Runs

Steps 1 to 5 apply to every engagement, whichever framework applies. Step 6 is part of WITS Inner Circle.

1

On-Site Assessment

A WITS engineer visits your office and reviews your network, servers, cloud accounts and devices, along with the data and contracts behind your requirements. The assessment is a $200 flat fee, credited toward the project if you proceed.

2

Gap Analysis

We compare what we found with the framework you need to meet and list each gap, ranked by risk and effort. You receive it as a written report.

3

Remediation

We fix the technical gaps: access control, multi-factor authentication, encryption, patching, endpoint protection, logging, network segmentation and backups.

4

Policies and Documentation

We write or update the policies, procedures, network diagrams and asset lists the framework calls for, so they match how your systems actually run.

5

Evidence Collection

We gather logs, configuration exports, screenshots and training records into one organized set, so you can answer a request for proof without searching for it.

6

Quarterly Review

This step is part of WITS Inner Circle. Each quarter we review changes to your systems, staff and vendors and check that your controls still work.

What WITS Does and Does Not Do

What WITS does

  • Assess your systems on site and report the gaps in writing.
  • Configure the technical safeguards a framework requires, such as multi-factor authentication, encryption and patching.
  • Write or update the policies and network diagrams your framework calls for.
  • Organize logs, configuration exports and training records so you can answer an assessor's request.
  • On WITS Inner Circle, review your controls each quarter.

What WITS does not do

  • Act as your auditor, your attorney or a certification body.
  • Certify a business as HIPAA compliant.
  • Perform SOC 2 audits or CMMC assessments.
  • Guarantee that you will pass an audit or assessment.

Who assesses each framework

  • HIPAA: there is no official certification. The Office for Civil Rights at the U.S. Department of Health and Human Services (HHS) enforces the rules.
  • SOC 2: an independent CPA firm performs the examination and writes the report.
  • PCI DSS: your acquirer sets how you prove compliance. Depending on your merchant level, that is a self-assessment questionnaire (SAQ) or a Report on Compliance, the full assessment report, from a Qualified Security Assessor (QSA) or another assessor the card brands allow. Quarterly external scans by an Approved Scanning Vendor (ASV) may also apply. Ask your acquirer which applies to you.
  • CMMC: Level 1 is a self-assessment. Level 2 is a self-assessment or an assessment by a CMMC Third-Party Assessment Organization (C3PAO), as your contract states. Level 3 is assessed by the government itself, through the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC).

How This Fits With WITS Plans

Compliance work can run as a project or as part of a managed plan. Without a plan, we scope the work after the on-site assessment, and the $200 is credited toward it.

WITS Inner Circle is $125 per user per month, with a 5 user minimum, month-to-month. It includes CCIE-designed security architecture, annual penetration testing, email threat protection, security awareness training, dark web monitoring, an incident response plan and a quarterly compliance review. It also includes support for HIPAA, NIST 800-171, PCI DSS and SOC 2. WITS Command is our managed IT plan at $85 per user per month, also with a 5 user minimum and month-to-month terms.

Compare the plans on the pricing page. You can also read about managed cybersecurity and backup and disaster recovery, since backups come up in several frameworks.

IT Compliance Support in Salt Lake City and Along the Wasatch Front

WITS is based in Lehi and supports businesses in Salt Lake City, Sandy, Draper, Provo, Orem, Ogden and the rest of the Wasatch Front. The assessment happens at your office. Much of the remediation and monitoring is done remotely. See the full list on our business IT in Utah page.

IT Compliance FAQ

Common questions about IT compliance for Utah businesses

No. The U.S. Department of Health and Human Services (HHS) does not certify people, products or businesses as HIPAA compliant, and it does not recognize private HIPAA certifications. A company can assess your safeguards and give you a report, but a certificate from a private firm does not stop HHS from finding a violation. Treat any vendor that sells a HIPAA certificate with caution.

A licensed CPA (certified public accountant) firm that is independent of your company. SOC 2 is an examination under standards from the American Institute of Certified Public Accountants, and the CPA firm writes the report. WITS is not a CPA firm. We set up the technical controls and gather the evidence, and the CPA firm tests them.

It depends, and we do not give a timeline before the assessment. The main factors are how many systems and locations are in scope, how many gaps the assessment finds, how much documentation already exists and how fast your staff can approve changes.

If an outside assessor is involved, such as a CPA firm for SOC 2 or a third-party assessor for CMMC Level 2, the assessor's schedule matters too. A SOC 2 Type 2 report also covers a period of time in which the controls have to be operating.

PCI DSS is intended for all entities that store, process or transmit cardholder data, so an online store is not exempt. If a PCI DSS validated third party handles all card entry, and you never store, process or transmit card data on your own systems, your scope is smaller. A shorter self-assessment questionnaire (SAQ A) may then apply.

Even then, the SAQ A criteria ask you to confirm that your site is not susceptible to script attacks that could affect your e-commerce system. Your acquirer confirms which questionnaire you complete.

No. NIST SP 800-171 is the publication that lists the security requirements for protecting controlled unclassified information. CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense program that verifies contractors meet requirements. CMMC Level 2 follows NIST SP 800-171, so the technical work overlaps. Your contract states which CMMC level applies and how it is assessed, and WITS does not perform CMMC assessments.

No. Auditors, assessors and regulators decide the outcome, not WITS. What we control is the quality of the technical work, the documents and the evidence you bring to them.

Have another question? We're here to help.

Contact Us

This page is general information, not legal advice. Your obligations depend on your facts and your contracts, and your business remains responsible for its own compliance. Ask a qualified attorney what a specific regulation requires of you.

Schedule a Consultation

Let's discuss how we can support your business with reliable managed IT services.

Contact Support

Prefer to book directly?

Assessment only, not the service itself. The fee is applied toward your project.

A payment processing fee is added at checkout.