A report from a CPA firm on how a company protects customer data. Customers ask for it before they sign; there is no certificate, only the report.
Checked by: A licensed CPA firm (independent certified public accountants) performhelp
How to use this section
If a customer, auditor, insurer or contract gave you a name, start with the eight below or search any page for it. If you only know your industry, open the family it belongs to. If you do not know which rules apply at all, start from your business type instead; the obligations index names the standards for you.
Start here
The standards people ask about most.
Eight names that come up in almost every contract, audit or customer questionnaire. Each explainer says what the standard is, who has to follow it, what you must write down, and who checks it.
The international standard for running information security as a managed system. An accredited registrar certifies it; consultants help you build it.
Checked by: An accredited certification body (registrar) operating under ISO/IEC 1US rules for protecting patient health information. There is no certification; the Office for Civil Rights checks your policies and records after a complaint or breach.
Checked by: Government enforcement only. OCR investigates complaints and breach reThe quality management standard most manufacturers and service firms are asked for by customers. A registrar audits it and issues a certificate every three years.
Checked by: Accredited certification body (registrar) accredited to ISO/IEC 17021-The card brands' security rules for anyone who takes card payments. Small merchants self-assess; larger ones use a qualified assessor.
Checked by: A PCI SSC qualified Qualified Security Assessor (QSA) company with cerThe Department of Defense's cybersecurity requirement for contractors that handle controlled information. Assessed by accredited third parties from late 2026.
Checked by: Level 1 and Level 2 (self): the organization's own assessment with senThe safety plans US employers must keep in writing, such as hazard communication and emergency action. Inspectors ask for the document and the training records.
Checked by: OSHA compliance safety and health officers, or State Plan inspectors (The European Union's data protection law. It applies to any business that handles EU residents' data, wherever the business sits.
Checked by: No mandatory assessor. Supervisory authorities (for example CNIL, theBy family
Every family, five examples each.
Grouped the way the market groups them. Open a family for its full list and who assesses it.
Need a hand implementing it?
Find a Consultant Who Does This Work
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Keep Your Written Policies in One Place
Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.