Compass IT Compliance Blog

Maintaining Targeted Risk Analysis (TRAs) for PCI DSS Compliance

Maintaining Targeted Risk Analysis (TRAs) for PCI DSS Compliance

Every organization that processes, stores, or transmits cardholder data is required to protect it. That much is well understood. What is less understood, and where many organizations quietly fall short, is how they justify specific risk-based decisions inside their compliance program. …

Read Story

How to Reduce CMMC Scope: A Practical Guide for Defense Contractors

How to Reduce Your CMMC Scope: A Practical Guide for Defense Contractors

For defense contractors preparing for Cybersecurity Maturity Model Certification (CMMC), scope is the single biggest lever you have over cost, timeline, and audit complexity. The smaller and more clearly defined your scope, the fewer systems your assessor has to evaluate, the fewer co …

Read Story

PCI Compliance for Small Business: A QSA's Field Guide to PCI DSS

PCI Compliance for Small Business: A QSA's Field Guide to PCI DSS

If you run a small business that accepts credit cards, the words "PCI compliance" probably land somewhere between mildly stressful and outright intimidating. I get it. I have spent years walking small merchants through the Payment Card Industry Data Security Standard (PCI DSS), and th …

Read Story

Canvas Breach: What It Means for Schools & FERPA Compliance

Canvas Breach What It Means for Schools & FERPA Compliance

When the Canvas login page was replaced with a ransom note on the morning of May 7, 2026, it did not look like a typical edtech outage. Students at Harvard, the University of Michigan, Duke, the University of Maryland, and thousands of other institutions opened their laptops in the mi …

Read Story

How to Become a vCISO: The Skills That Set Great Ones Apart

How to Become a vCISO The Skills That Set Great Ones Apart

At Compass IT Compliance, we run one of the more established virtual CISO practices in the country. That vantage point has given us a clear view of the capabilities that consistently define the strongest vCISOs working in the field today. The skills are not always the ones aspiring vC …

Read Story

CMMC Assessments in Higher Education: What Campus Leaders Are Saying

CMMC Assessments in Higher Education What Campus Leaders Are Saying

I just got back from the EDUCAUSE Cybersecurity and Privacy Professionals Conference in Anaheim last week, and I came home with a notebook full of conversations that I think a lot of provosts, CIOs, and CISOs need to hear. The hallway talk between sessions, the candid moments over cof …

Read Story

Subscribe by email