Skip to content
StrikeCyberStrikeCyber
Research topic

Compliance

SOC 2, HIPAA, PCI DSS, CMMC, NIST CSF and FedRAMP: how security testing maps to US compliance obligations.

SOC 2 and Penetration Testing: What Auditors Actually Expect

No SOC 2 criterion says penetration testing. Several say you must identify vulnerabilities and evaluate whether controls operate effectively, which auditors read the obvious way.

PCI DSS Penetration Testing Requirements Explained

PCI DSS is unusually specific about testing, which makes it easier to satisfy and easier to fail. Here is what requirement 11.4 actually asks for.

HIPAA Security Rule and Penetration Testing

HIPAA does not name penetration testing. It requires an accurate and thorough risk analysis and periodic technical evaluation, and OCR has been consistent about what inadequate looks like.

Cyber Security for Financial Services in the USA

Financial services carries the most developed regulatory expectations of any US sector and some of the most motivated adversaries. The gap between compliance and resilience is where incidents happen.

ISO 27001 and Penetration Testing: What Auditors Expect

ISO 27001 does not mandate penetration testing by name. It requires you to manage technical vulnerabilities and verify controls work, which in practice amounts to the same thing.

Cyber Security for Healthcare in the USA

Healthcare combines the most sensitive data, systems that cannot go offline, and an attacker population that understands both. That combination is why the sector is targeted.

NIST Cybersecurity Framework 2.0 Explained

CSF 2.0 added a sixth function and dropped the critical infrastructure framing. The change that matters most is that governance is now something you have to evidence.

Cyber Security for Federal, State and Local Government

Government environments carry legacy nobody can retire, adversaries with time and funding, and citizen data that cannot be reissued. The combination is difficult and the obligations are specific.

CMMC Level 2: What Defense Contractors Need to Know

CMMC did not create new requirements. It created verification of requirements defense contractors have carried since 2017, which is why so many are behind.

FedRAMP Penetration Testing Requirements

FedRAMP is the most prescriptive testing regime most cloud providers will encounter. It names the attack vectors you must cover, which removes the usual scoping arguments.

NYDFS Part 500: Penetration Testing and the Amended Rules

Part 500 is among the most specific US cybersecurity regulations, it carries personal certification by a senior officer, and the amendments raised the bar again.

SEC Cyber Disclosure Rules: What Boards Need to Know

Four business days from determining materiality, not from discovery. The clock starts on a judgment call, which is why the judgment process needs to exist beforehand.

Supply Chain and Third-Party Risk in the USA

A completed questionnaire tells you what a vendor says about their controls. It does not tell you what they could reach inside your environment, which is the question.

FAQ

Compliance: FAQs

What does StrikeCyber cover under Compliance?

This topic collects our research, field notes and guidance on compliance, written by our operators from real offensive security engagements.

Is StrikeCyber research specific to the United States?

Yes. Our research is grounded in the US threat and compliance landscape, including SOC 2, HIPAA, PCI DSS, CMMC, NIST CSF and FedRAMP and local sector risks, while drawing on global attacker tradecraft.

How can I get help with compliance?

Beyond the research, our operators deliver offensive security engagements across the United States. Scope a free consultation to discuss your environment.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation