Stay ahead of security threats β€” get MOC1 insights delivered to your inbox.
Compliance Center

Compliance Resources

Comprehensive guides, frameworks, and tools to help your organization achieve and maintain compliance with industry regulations and security standards.

Partner Tool

Aegisoversight AI Assurance Tool

Leverage cutting-edge AI-powered compliance assurance with our partner Aegisoversight. Their automated AI Assurance platform provides continuous compliance monitoring, intelligent risk detection, and real-time regulatory alignment across all major frameworks.

Filter by Framework:

Regulatory Frameworks & Standards

Detailed information and official links to major compliance frameworks and security standards.

HIPAA
Healthcare

Health Insurance Portability and Accountability Act

Overview

U.S. federal law that establishes standards for protecting sensitive patient health information (PHI). Required for healthcare providers, health plans, and healthcare clearinghouses.

Key Requirements

  • Privacy Rule - Protects PHI and establishes patient rights
  • Security Rule - Physical, technical, and administrative safeguards
  • Breach Notification Rule - Reporting of data breaches
  • Business Associate Agreements (BAA) required
Scope

Healthcare providers, plans, and business associates in the United States

Penalties

Up to $1.5M per violation category per year

GDPR
Data Privacy

General Data Protection Regulation

Overview

Comprehensive data privacy regulation that applies to organizations processing personal data of EU residents, regardless of where the organization is located.

Key Requirements

  • Lawful basis for processing personal data
  • Data subject rights (access, erasure, portability)
  • Privacy by design and default
  • Data Protection Impact Assessments (DPIA)
  • Appointment of Data Protection Officer (DPO) when required
Scope

Any organization processing EU resident data

Penalties

Up to €20M or 4% of global annual revenue, whichever is higher

FISMA
Government

Federal Information Security Management Act

Overview

U.S. federal law requiring government agencies and contractors to secure information systems and protect government information.

Key Requirements

  • NIST SP 800-53 security controls implementation
  • Risk assessment and security authorization
  • Continuous monitoring and incident response
  • Annual security assessments and reporting
  • Supply chain risk management
Scope

Federal agencies and contractors handling federal information

Penalties

Contract termination, criminal penalties up to $100,000

SOC 2
Technology/SaaS

Service Organization Control 2

Overview

Auditing standard for service providers storing customer data, focusing on security, availability, processing integrity, confidentiality, and privacy.

Key Requirements

  • Trust Services Criteria (TSC) compliance
  • Risk assessment and mitigation procedures
  • Security policies and procedures documentation
  • Vendor management and due diligence
  • Incident response and change management
Scope

Service providers and SaaS companies

Penalties

Loss of business, reputational damage, contract violations

ISO 27001
International

Information Security Management System

Overview

International standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Key Requirements

  • Information security policies and objectives
  • Risk assessment and treatment methodology
  • 114 security controls across 14 domains
  • Management review and internal audits
  • Continual improvement processes
Scope

Organizations of all sizes seeking international security certification

Penalties

Certification loss, competitive disadvantage

PCI DSS
Financial/Retail

Payment Card Industry Data Security Standard

Overview

Security standard for organizations that handle credit card information, established by major credit card brands.

Key Requirements

  • Build and maintain secure networks and systems
  • Protect cardholder data with encryption
  • Maintain vulnerability management program
  • Implement strong access control measures
  • Regulary monitor and test networks
Scope

Any organization accepting, processing, storing, or transmitting credit card data

Penalties

Fines from $5,000 to $100,000 per month, card processing restrictions

FERPA
Education

Family Educational Rights and Privacy Act

Overview

U.S. federal law protecting the privacy of student education records. Applies to educational institutions receiving federal funding.

Key Requirements

  • Written consent for disclosure of education records
  • Student rights to inspect and review records
  • Procedure for amending incorrect records
  • Limitations on directory information disclosure
  • Annual notification to parents and students
Scope

Educational institutions receiving federal funding

Penalties

Loss of federal funding

SOX
Financial

Sarbanes-Oxley Act

Overview

U.S. federal law establishing auditing and financial regulations for public companies to protect investors from fraudulent accounting.

Key Requirements

  • Internal control assessment and reporting
  • IT general controls and application controls
  • Segregation of duties
  • Audit trail and change management
  • Executive certification of financial statements
Scope

Public companies and their auditors in the United States

Penalties

Up to $5M fines, 20 years imprisonment for executives

CCPA/CPRA
Data Privacy

California Consumer Privacy Act

Overview

California state law providing data privacy rights to California residents, including rights to know, delete, and opt-out of data sales.

Key Requirements

  • Consumer rights to access personal information
  • Right to delete personal information
  • Right to opt-out of data sales
  • Privacy notices and disclosures
  • Data breach notification requirements
Scope

Businesses meeting California thresholds for revenue or data volume

Penalties

Up to $7,500 per intentional violation

NIST CSF
Cybersecurity

NIST Cybersecurity Framework

Overview

Voluntary framework providing guidelines for managing cybersecurity risk, widely adopted across industries and sectors.

Key Requirements

  • Identify - Asset management and risk assessment
  • Protect - Access control and protective technology
  • Detect - Continuous monitoring and detection
  • Respond - Incident response and communications
  • Recover - Recovery planning and improvements
Scope

Organizations seeking comprehensive cybersecurity framework

Penalties

Not mandatory, but often contractually required

Compliance Resources & Tools

Download ready-to-use templates, checklists, and guides to streamline your compliance journey.

Checklist

Compliance Assessment Checklist

Comprehensive checklist covering all major regulatory requirements

Format: PDF

Templates

Security Policy Templates

Pre-built policy templates for HIPAA, SOC 2, and ISO 27001

Format: DOCX

Guide

Audit Preparation Guide

Step-by-step guide to preparing for compliance audits

Format: PDF

Framework

Risk Assessment Framework

Methodology and tools for conducting compliance risk assessments

Format: PDF

Playbook

Incident Response Playbook

Templates and procedures for compliance-related incidents

Format: PDF

Toolkit

Vendor Management Toolkit

Due diligence questionnaires and assessment tools

Format: ZIP

Need Compliance Support?

Our team of compliance experts can help you achieve and maintain regulatory compliance.

Compliance Assessment

Comprehensive gap analysis and compliance roadmap for your organization

Audit Preparation

Expert guidance and support to prepare for compliance audits

Ongoing Monitoring

Continuous compliance monitoring and reporting services

Ready to Achieve Compliance?

Contact our compliance team to discuss your regulatory requirements and learn how MOC1 Solutions can help you achieve and maintain compliance.