These are the frameworks WITS supports.
HIPAA
HIPAA, the Health Insurance Portability and Accountability Act, covers health plans, health care clearinghouses and health care providers that conduct certain transactions electronically, such as submitting claims. It also covers their business associates, the outside companies that handle patient data for them, such as billing companies and IT vendors. The Security Rule requires administrative, physical and technical safeguards for electronic protected health information, meaning patient health data that is stored or sent electronically. A risk analysis comes first.
WITS implements and documents the technical safeguards: access control, encryption, audit logging, backups and patching. Read the HIPAA IT compliance checklist, or see IT for healthcare practices and dental practices.
PCI DSS
PCI DSS, the Payment Card Industry Data Security Standard, covers any business that stores, processes or transmits cardholder data. The PCI Security Standards Council publishes the standard. The card brands and your acquirer, the bank or processor behind your card payments, decide what proof you submit. PCI DSS v4.0.1 is the current version. Requirements that v4.0 gave a later start date became mandatory on March 31, 2025.
WITS finds which of your systems touch card data and works to reduce that scope. It then implements network segmentation, firewall rules, access control, logging and patching, and gives guidance on the self-assessment questionnaire (SAQ). Read the PCI DSS compliance checklist, or see IT for retail and restaurants.
SOC 2
SOC 2, short for System and Organization Controls 2, is a reporting framework from the American Institute of Certified Public Accountants (AICPA) for service providers. A licensed CPA firm examines your controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality and privacy) and issues a report. A Type 1 report covers the design of controls at a point in time. A Type 2 report also tests how they operated over a period of time. It is a report, not a certificate. A customer asking for a SOC 2 report is a common reason to pursue it.
WITS sets up the technical controls and gathers the supporting evidence so the CPA firm has something to test. Firms that hold client data can also see IT for financial firms.
NIST SP 800-171 and CMMC
Covers contractors and subcontractors that handle controlled unclassified information (CUI), meaning sensitive government information that is not classified. NIST SP 800-171, from the National Institute of Standards and Technology, lists the security requirements for protecting CUI on non-federal systems. Revision 2 has 110 requirements in 14 families. NIST published Revision 3 in May 2024, so we check which revision your contract cites before scoping anything.
CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense program that verifies contractors meet those requirements. Level 1 covers federal contract information, which is non-public information you receive or create under a federal contract. Level 2 covers CUI and uses the NIST SP 800-171 Revision 2 requirements, as set by the CMMC rule (32 CFR Part 170, in the Code of Federal Regulations). Level 3 adds requirements from NIST SP 800-172. Your contract states which level applies and how it is assessed.
WITS maps the requirements to your environment and implements the technical controls. It also helps prepare two documents. The system security plan describes your systems and how each requirement is met. The plan of action lists the open gaps and when you will close them. See IT for manufacturers and construction firms.
Access control, logging, patching and backups appear in most of these frameworks, so work done for one often supports another.