Compliance posture · for regulated SMBs

Compliance is now a buying-decision issue.

Frame your SOC around the audits your customers, prime contractors, and regulators already ask for — not around a generic NIST checklist.

Audit-ready baseline
Day 14
Frameworks covered
4 / 4
Log retention
Every tier

stwp.compliance / covered frameworks

Live SOC
  • CMMC

    Cybersecurity Maturity Model Certification — Level 1 vs Level 2 readiness for defense subcontractors

  • PCI DSS 4.0

    Payment Card Industry Data Security Standard — version 4.0

  • HIPAA

    Health Insurance Portability & Accountability Act

  • State privacy

    State consumer privacy laws — CA, CO, CT, VA

Why this page exists

Compliance stopped being a checkbox. Now it’s table stakes.

When a healthcare practice bids on hospital contracts, when a defense sub primes a tier-1, when a law firm pitches enterprise clients, when a financial advisor stores non-public personal information — the buyer (or the regulator) asks for the same artifact: proof that someone was watching. That’s the SOC's job.

Framework · 1 of 4

CMMC

Cybersecurity Maturity Model Certification — Level 1 vs Level 2 readiness for defense subcontractors

What the framework requires

What the auditor or the buyer asks for.
  • Level 1 (the floor): 17 practices across 6 domains, an annual self-assessment, and the safeguards needed to handle Federal Contract Information (FCI).
  • Level 2 (the bar primes care about): all 110 practices mapped to NIST SP 800-171 rev. 2 across 14 control families, applied to Controlled Unclassified Information (CUI), and assessed every three years by a C3PAO.
  • The gap most primes fail at L2: maturity evidence — practices are documented but there is no attestation that the controls are actually operating day to day. That is what a C3PAO samples for.

How Straitwatch produces the audit artifacts

Detection logs, incident records, access evidence, response timelines.
  • Detection logs → AU family (L2)

    Every alert captured with timestamp, source, analyst disposition, and outcome — the AU-2 / AU-3 trail mapped 1:1 to what a C3PAO samples at the L2 assessment.

  • Incident records → IR / RA family (L2)

    Containment, eradication, and lessons-learned entries per incident; root-cause evidence shipped as the running record the assessor reads, not assembled on the eve of the assessment.

  • Access evidence → AC family (L1 + L2)

    Periodic access reviews, joiner/mover/leaver events, and privileged-account changes captured continuously and surfaced to the C3PAO on demand — the maturity evidence L2 demands and L1 still needs.

  • Response timelines → RA / IR evidence (L2)

    Detection-to-containment timelines with the named analyst attached — closes the L2 maturity-evidence gap by proving controls are running, not just documented.

Framework · 2 of 4

PCI DSS 4.0

Payment Card Industry Data Security Standard — version 4.0

What the framework requires

What the auditor or the buyer asks for.
  • Requirements 1–12 covered: network segmentation, access control (Req 7/8), monitoring (Req 10), vulnerability management (Req 11), security policy (Req 12).
  • v4.0 emphasis on continuous monitoring rather than point-in-time attestation — log review, detection coverage, and incident-response cadence all year round.
  • Reasonable evidence for the acquiring bank or QSAC: not screenshots, but artifacts the assessor can sample.

How Straitwatch produces the audit artifacts

Detection logs, incident records, access evidence, response timelines.
  • Detection logs → Req 10 (logging & monitoring)

    Continuous logging of all in-scope system components with daily review — Req 10's continuous-monitoring bar met, not sampled quarterly.

  • Access evidence → Req 7 & Req 8

    Per-account access reviews, privileged-account inventories, and authentication-failure trends shipped in cadence with the assessor's review window.

  • Incident records → Req 12.10 incident response

    When Req 12.10.1 fires, the plan executes with named roles, decision logs, and a post-incident review already in the SOC's records.

  • Response timelines → Req 12.10.5 evidence

    Alerts-to-response timelines with alert severity, triage time, containment time, and resolution — the "lessons learned" Req 12.10.5 calls for.

Framework · 3 of 4

HIPAA

Health Insurance Portability & Accountability Act

What the framework requires

What the auditor or the buyer asks for.
  • HIPAA Security Rule technical safeguards at §164.312 — access control, audit controls, integrity, person-or-entity authentication, transmission security.
  • HIPAA Privacy Rule adherence: minimum necessary, business associate agreements, breach notification within statutory windows.
  • Documentation that an OCR investigator or business associate reviewer can read — not a vendor brochure.

How Straitwatch produces the audit artifacts

Detection logs, incident records, access evidence, response timelines.
  • Access logs → §164.312(a)

    Per-user, per-resource access events flow into the SOC's log store and are searchable on demand by PHI-adjacent systems.

  • Audit controls → §164.312(b)

    Every privileged action and every ePHI-touching service event is recorded; immutable retention makes the §164.312(b) audit-control claim provable.

  • Incident records → breach notification rule

    When an incident touches ePHI, the record — scope, containment, notification decision — is already written, ready for the §164.404 disclosure clock.

  • Response timelines → OCR inquiry response

    Detection-to-containment timelines with hand-off timestamps, formatted as the chronology an OCR investigator will ask for first.

Framework · 4 of 4

State privacy

State consumer privacy laws — CA, CO, CT, VA

What the framework requires

What the auditor or the buyer asks for.
  • Consumer rights workflows: access requests, deletion, opt-out of sale / sharing — across the California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), and Virginia (VCDPA) regimes.
  • Reasonable security safeguards with documented due-diligence; breach-notification clocks that differ state by state.
  • Attorney general inquiry responses — especially when a security incident drives a regulator's attention.

How Straitwatch produces the audit artifacts

Detection logs, incident records, access evidence, response timelines.
  • Access evidence → reasonable safeguards due-diligence

    Proof that the safeguards the statute calls for were running when an incident happened — not a post-hoc policy relic.

  • Response timelines → breach-notification clock

    Detection-to-confirmation timelines that anchor the state-specific notification deadlines, written before the AG's office asks.

  • Detection logs → reasonable-security evidence

    The detection records, retention posture, and response cadence attributable to the period the AG is scrutinising.

  • Incident records → AG inquiry response

    When the AG writes, the SOC already has the dated, named, attributable record of what happened, who responded, and what changed.

Tier coverage matrix

Which Straitwatch tier covers which framework.

The four frameworks your auditors and prime contractors ask about, mapped against the three tiers Straitwatch ships. Pick the tier that matches the framework set you have to answer for.

EssentialsCoverage at this tier
PCI DSS 4.0 — Req 10 monitoring + Req 12.10 IR
Annual posture report
HIPAA — §164.312 safeguards + breach notification
Annual posture report
CMMC L1 vs L2 — NIST 800-171 maturity evidence
State privacy — CA / CO / CT / VA
On request
ProCoverage at this tier
Most chosen
PCI DSS 4.0 — Req 10 monitoring + Req 12.10 IR
Quarterly evidence pull
HIPAA — §164.312 safeguards + breach notification
Quarterly evidence pull
CMMC L1 vs L2 — NIST 800-171 maturity evidence
State privacy — CA / CO / CT / VA
On request
DefenseCoverage at this tier
PCI DSS 4.0 — Req 10 monitoring + Req 12.10 IR
Continuous monitoring + audit artifacts
HIPAA — §164.312 safeguards + breach notification
Quarterly + on-demand breach pack
CMMC L1 vs L2 — NIST 800-171 maturity evidence
Audit-ready artifacts + named engagement lead
State privacy — CA / CO / CT / VA
On request + dedicated engagement lead
Frame your SOC around the audits you actually face

Bring us the framework list. We’ll show you what artifacts you’d already have.

CMMC, HIPAA, PCI DSS 4.0, or state privacy — name the compliance work your customers, prime contractors, or auditors are asking for now. We map Straitwatch against that list and tell you which tier already produces the artifact and which one closes the gap.