Compass IT Compliance Blog

CMMC Scoping Guide: How to Define Your Level 2 Assessment Boundary

CMMC Scoping Guide How to Define Your Level 2 Assessment Boundary

One of the most consequential (and most misunderstood) steps in preparing for CMMC compliance is defining the scope of your assessment boundary. Scope too broadly and you’re burdening your organization with unnecessary controls and cost. Scope too narrowly and you risk leaving Control …

Read Story

Does SOC 2 Reduce Security Questionnaires, or Just Change Them?

Does SOC 2 Reduce Security Questionnaires, or Just Change Them?

Every B2B vendor chasing enterprise deals eventually asks the same thing. We are pouring real money and real calendar time into a SOC 2 Type 2 report, so will it actually reduce the security questionnaires we get buried under, or will buyers just keep sending them anyway?

Read Story

Third Party Administrator (TPA) Risks: IT Security & Compliance Guide

Third Party Administrator (TPA) Risks IT Security & Compliance Guide

If your organization handles sensitive data and outsources any operational work, there is a good chance a Third Party Administrator (TPA) is somewhere in your environment. Maybe they process claims for your self-funded health plan. Maybe they handle 401(k) recordkeeping. Maybe they ar …

Read Story

What Are Buyers Actually Looking for in Your SOC 2 Type 2 Report?

What Are Buyers Actually Looking for in Your SOC 2 Type 2 Report

You spent six months getting ready for your SOC 2 Type 2 audit. You collected the evidence. You sat through the walkthroughs. You finally got the report, a polished sixtypage document with an unqualified opinion stamped on the front. Then you sent it to your first enterprise prospect. …

Read Story

Maintaining Targeted Risk Analysis (TRAs) for PCI DSS Compliance

Maintaining Targeted Risk Analysis (TRAs) for PCI DSS Compliance

Every organization that processes, stores, or transmits cardholder data is required to protect it. That much is well understood. What is less understood, and where many organizations quietly fall short, is how they justify specific risk-based decisions inside their compliance program. …

Read Story

How to Reduce CMMC Scope: A Practical Guide for Defense Contractors

How to Reduce Your CMMC Scope: A Practical Guide for Defense Contractors

For defense contractors preparing for Cybersecurity Maturity Model Certification (CMMC), scope is the single biggest lever you have over cost, timeline, and audit complexity. The smaller and more clearly defined your scope, the fewer systems your assessor has to evaluate, the fewer co …

Read Story

Subscribe by email