Skip to content

Service

IT compliance and risk management

Most compliance work is not exotic. It is access control, encryption, logging, backup retention and being able to prove all four were operating on the day somebody asks. The specialist part is knowing which framework applies, what it genuinely requires, and where the overlaps let one control satisfy three obligations.

Frameworks covered

8

including CMMC and Washington State law

Controls overlap heavily. Carrying three obligations rarely means three times the work.

The frameworks that apply in Pierce County

Two of these are specific to Washington State and are routinely missed by providers working from a national template.

Compliance frameworks, who they apply to, and their core technical demands
FrameworkWho it applies to
HIPAARisk analysis, access logging, encryption, business associate agreementsHealthcare, dental, any business handling protected health information
CMMC 2.0 and NIST 800-171Controlled unclassified information handling, 110 controls, SPRS scoreDefence suppliers, including businesses serving Joint Base Lewis McChord
PCI DSSNetwork segmentation, scanning, restricted cardholder data accessAnyone accepting card payments
FTC Safeguards RuleWritten information security plan, named qualified individual, vendor oversightAccounting firms, tax preparers, some financial services
GLBACustomer data protection, incident response, board reportingCredit unions, lenders, financial advisers
SOC 2Evidence over a period, independent audit, continuous control operationBusinesses whose own customers demand assurance
RCW 19.255Breach notification within statutory timeframesEvery Washington business holding personal information
My Health My Data ActConsent, disclosure limits, broader definition than HIPAAWashington businesses handling consumer health data outside HIPAA

General information about regulatory scope, not legal advice. Confirm your specific obligations with counsel or the relevant authority.

How the work runs

  1. Phase 01

    Gap assessment

    Your current state measured against the specific framework that applies, control by control. The output is a findings register with an owner and an effort estimate against each gap, not a compliance score with no path attached.

  2. Phase 02

    Remediation

    Technical controls first because they are fastest to close: identity, encryption, logging, backup retention, access review. Policy and procedure follow, written to match what actually happens rather than to satisfy a template.

  3. Phase 03

    Evidence

    Compliance is demonstrated over a period, not on a day. Logging, review records and change history are configured so evidence accumulates as a by-product of normal operation instead of being assembled in a panic before an audit.

  4. Phase 04

    Audit support

    When an auditor, an assessor or a client security questionnaire arrives, we produce the technical evidence and answer the technical questions. You are not left translating a control requirement into a screenshot request at short notice.

Four things people get wrong

Each of these costs money, and the first one costs the most because it feels like progress.

  • Buying a compliant product does not make an organisation compliant. Frameworks assess how you operate, not what you purchased.
  • A cloud provider being certified covers their infrastructure, not your configuration of it. The shared responsibility model puts most of the burden on you.
  • Compliance is not the same as security. A business can satisfy a framework and still be exposed, and can be genuinely secure and still fail an audit on documentation.
  • Most frameworks require evidence over time, so a control switched on the week before an assessment usually will not qualify.

Common questions

Answered before you ask.

Which framework actually applies to us?

It depends on the data you hold and who you contract with rather than on your sector alone. Handling protected health information brings HIPAA regardless of whether you consider yourself a healthcare business. Holding controlled unclassified information under a defence contract brings CMMC and NIST 800-171. Taking card payments brings PCI DSS. Many businesses in Pierce County carry two or three simultaneously, and the controls overlap heavily, which means the work is far less than the framework count suggests.

Can an IT provider make us compliant?

No provider can, and any who claims to should be treated carefully. Compliance covers business process, training, physical security, contracts and governance as well as technology. What an IT provider can do is close the technical controls, which is typically the largest single portion of a framework, and produce the evidence for that portion. The remainder needs an owner inside your business, and frameworks like the FTC Safeguards Rule explicitly require a named individual.

We supply Joint Base Lewis McChord. Where do we start?

Establish which level applies, because the requirements differ sharply. Handling only federal contract information sits at the lower level with a modest control set. Handling controlled unclassified information brings the full NIST 800-171 control set and a formal assessment. Start by confirming with your prime contractor or contracting officer which category your contract data falls into, because scoping this wrong in either direction is expensive.

How long does it take to close the gaps?

Technical controls typically move within one to three months. Policy, training and governance take longer because they need business input rather than configuration. Where a framework requires evidence over a period, the calendar sets the floor: a control operating for six months cannot be demonstrated in six weeks. Anyone promising a fast route to a framework requiring sustained evidence is describing paperwork rather than compliance.

Find out which controls you are already missing.

The assessment includes a gap review against the framework that applies to you, with a findings register you can act on with or without us.

CallFree assessment