Derek Boczenowski

Derek Boczenowski

Derek Boczenowski, MBA, CISA, CISM, QSA, CMMC CCP, is a nationally recognized information security and compliance authority with over 20 years of experience across financial services, higher education, and government. As Chief Architect at Compass IT Compliance, he helps organizations identify security gaps and build practical, risk-based strategies to address them. Before joining Compass, Derek served as VP of Technology for a Massachusetts-based credit union with ~$700M in assets, giving him firsthand insight into the regulatory pressures financial institutions face daily. That perspective now informs his work with everyone from Fortune 500 companies to community banks. A sought-after speaker, Derek has presented at the Fiserv National Conference, the New York Bankers Association, and events nationwide. His expertise spans PCI DSS, SOC 2, CMMC, data privacy, and vendor risk management. He also writes extensively on emerging compliance issues and frequently presents through ISACA webinars.

Posts by Derek Boczenowski

CMMC & the False Claims Act: High Stakes for DoD Contractors

CMMC False Claims Act

Cybersecurity compliance for Defense Industrial Base (DIB) organizations has never been purely technical, but the stakes have now escalated into a very real legal and financial risk. With the Department of Defense’s final CMMC rule taking effect on November 10, 2025, and the Departmen …

Read Story

SOC 2 & ISO 27001 Together: How to Build One Unified Plan

Juggling SOC 2 and ISO 27001

For growing organizations, SOC 2 and ISO 27001 are no longer optional — they’ve become baseline expectations from customers, partners, and regulators. Both frameworks help you prove that you are serious about protecting sensitive data, but pursuing them separately can feel like runnin …

Read Story

The SOC for Cybersecurity Report: A Complete Guide

SOC for Cybersecurity

In a business environment where cyber threats are constant and trust is currency, organizations need a way to clearly demonstrate the strength of their cybersecurity programs. While many have turned to frameworks like SOC 2 for this purpose, there’s a growing recognition that these tr …

Read Story

PCI DSS 4.0 Password Requirements: A Guide to Compliance

PCI DSS v4.0 Password Requirements

As cyber threats evolve, ensuring the security of sensitive payment card data has become increasingly crucial for businesses across all industries. The Payment Card Industry Data Security Standard (PCI DSS) was introduced to provide a framework for safeguarding payment card data, incl …

Read Story

What to Look for When Choosing a SOC 2 Audit Firm

SOC 2 Proposals

Selecting a SOC 2 auditor can be challenging for many business leaders. This significant financial commitment demonstrates your dedication to data security to your business partners and customers. With numerous audit firms vying for your SOC 2 business, what criteria should you consid …

Read Story

What Is a SOC 2 Report and Who Needs One?

Who Needs a SOC 2?

In an era where data security and privacy are paramount, the SOC 2 report emerges as a critical tool for organizations that manage customer data. Tailored to ensure the safeguarding of information, a SOC 2 report not only enhances an organization's credibility but also solidifies its …

Read Story

Subscribe by email