Service
IT compliance and risk management
Most compliance work is not exotic. It is access control, encryption, logging, backup retention and being able to prove all four were operating on the day somebody asks. The specialist part is knowing which framework applies, what it genuinely requires, and where the overlaps let one control satisfy three obligations.
Frameworks covered
8
including CMMC and Washington State law
Controls overlap heavily. Carrying three obligations rarely means three times the work.
In this service
The frameworks that apply in Pierce County
Two of these are specific to Washington State and are routinely missed by providers working from a national template.
| Framework | Who it applies to |
|---|---|
| HIPAARisk analysis, access logging, encryption, business associate agreements | Healthcare, dental, any business handling protected health information |
| CMMC 2.0 and NIST 800-171Controlled unclassified information handling, 110 controls, SPRS score | Defence suppliers, including businesses serving Joint Base Lewis McChord |
| PCI DSSNetwork segmentation, scanning, restricted cardholder data access | Anyone accepting card payments |
| FTC Safeguards RuleWritten information security plan, named qualified individual, vendor oversight | Accounting firms, tax preparers, some financial services |
| GLBACustomer data protection, incident response, board reporting | Credit unions, lenders, financial advisers |
| SOC 2Evidence over a period, independent audit, continuous control operation | Businesses whose own customers demand assurance |
| RCW 19.255Breach notification within statutory timeframes | Every Washington business holding personal information |
| My Health My Data ActConsent, disclosure limits, broader definition than HIPAA | Washington businesses handling consumer health data outside HIPAA |
General information about regulatory scope, not legal advice. Confirm your specific obligations with counsel or the relevant authority.
How the work runs
Phase 01
Gap assessment
Your current state measured against the specific framework that applies, control by control. The output is a findings register with an owner and an effort estimate against each gap, not a compliance score with no path attached.
Phase 02
Remediation
Technical controls first because they are fastest to close: identity, encryption, logging, backup retention, access review. Policy and procedure follow, written to match what actually happens rather than to satisfy a template.
Phase 03
Evidence
Compliance is demonstrated over a period, not on a day. Logging, review records and change history are configured so evidence accumulates as a by-product of normal operation instead of being assembled in a panic before an audit.
Phase 04
Audit support
When an auditor, an assessor or a client security questionnaire arrives, we produce the technical evidence and answer the technical questions. You are not left translating a control requirement into a screenshot request at short notice.
Four things people get wrong
Each of these costs money, and the first one costs the most because it feels like progress.
- Buying a compliant product does not make an organisation compliant. Frameworks assess how you operate, not what you purchased.
- A cloud provider being certified covers their infrastructure, not your configuration of it. The shared responsibility model puts most of the burden on you.
- Compliance is not the same as security. A business can satisfy a framework and still be exposed, and can be genuinely secure and still fail an audit on documentation.
- Most frameworks require evidence over time, so a control switched on the week before an assessment usually will not qualify.
Common questions
Answered before you ask.
Which framework actually applies to us?
It depends on the data you hold and who you contract with rather than on your sector alone. Handling protected health information brings HIPAA regardless of whether you consider yourself a healthcare business. Holding controlled unclassified information under a defence contract brings CMMC and NIST 800-171. Taking card payments brings PCI DSS. Many businesses in Pierce County carry two or three simultaneously, and the controls overlap heavily, which means the work is far less than the framework count suggests.
Can an IT provider make us compliant?
No provider can, and any who claims to should be treated carefully. Compliance covers business process, training, physical security, contracts and governance as well as technology. What an IT provider can do is close the technical controls, which is typically the largest single portion of a framework, and produce the evidence for that portion. The remainder needs an owner inside your business, and frameworks like the FTC Safeguards Rule explicitly require a named individual.
We supply Joint Base Lewis McChord. Where do we start?
Establish which level applies, because the requirements differ sharply. Handling only federal contract information sits at the lower level with a modest control set. Handling controlled unclassified information brings the full NIST 800-171 control set and a formal assessment. Start by confirming with your prime contractor or contracting officer which category your contract data falls into, because scoping this wrong in either direction is expensive.
How long does it take to close the gaps?
Technical controls typically move within one to three months. Policy, training and governance take longer because they need business input rather than configuration. Where a framework requires evidence over a period, the calendar sets the floor: a control operating for six months cannot be demonstrated in six weeks. Anyone promising a fast route to a framework requiring sustained evidence is describing paperwork rather than compliance.
Related
What sits alongside this.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Healthcare
HIPAA, EHR uptime, device segmentation
Accounting and CPA firms
FTC Safeguards, WISP, tax season uptime
What managed IT services cost in Tacoma
Per user pricing bands, what moves the number up, and how to read a quote.
Find out which controls you are already missing.
The assessment includes a gap review against the framework that applies to you, with a findings register you can act on with or without us.