Compass IT Compliance Blog

Mercedes-Benz Dealer ISO 27001 & TISAX Certification Deadline 2026

Mercedes-Benz Dealer ISO 27001 & TISAX Certification Deadline 2026

If you lead IT, security, or compliance at a Mercedes-Benz dealership, you have probably already seen the note buried in your dealer communications: Mercedes-Benz now expects its dealer network to stand up a qualified information security program, backed by ISO 27001, TISAX Level 2 ce …

Read Story

SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means

SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means

A question has been coming up recently among people who work with e-commerce merchants, and it can be a real head-scratcher the first time you hit it. A small merchant qualifies for SAQ A and notices that Requirements 6.4.3 and 11.6.1 are simply gone from the form. A larger merchant w …

Read Story

“We Don’t Use AI” Is a Claim, Not a Control

“We Don’t Use AI” Is a Claim, Not a Control

A question we hear often from clients sounds simple on its face: Our company says it doesn’t use AI, and our acceptable use policy says the same. How do we actually prove our employees aren’t using it? It is a fair question, and the honest answer is uncomfortable. A written policy sta …

Read Story

How to Define Your Cardholder Data Environment (CDE) Under PCI DSS

How to Define Your Cardholder Data Environment (CDE) Under PCI DSS

Before an organization can implement Payment Card Industry Data Security Standard (PCI DSS) controls, it must answer a foundational question: what is in scope? The answer lies in the definition of the Cardholder Data Environment (CDE). Get it wrong, and everything built on top of it i …

Read Story

Plan of Action and Milestones (POA&M): A CMMC Level 2 Essential

Plan of Action and Milestones POA&M - A CMMC Level 2 Essential

Every CMMC Level 2 compliance program involves two documents that work in tandem: the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M). The SSP describes how practices are implemented. The POA&M documents what is not yet implemented and what the organiz …

Read Story

Your CMMC SSP Is Not Just a Checkbox: How to Build One That Works

Your CMMC SSP Is Not Just a Checkbox How to Build One That Works

The System Security Plan (SSP) is the cornerstone document of any CMMC Level 2 compliance program. Yet it is also one of the most underdeveloped artifacts assessors encounter. Organizations preparing for a C3PAO assessment frequently arrive with an SSP that describes their environment …

Read Story

Subscribe by email