Valtik Studios

Compliance frameworks

Every major compliance framework that matters to US mid-market businesses in 2026. Complete readiness guides, implementation timelines, budget frameworks, and enforcement patterns. Written by people who audit against these frameworks for a living.

PCI DSS 4.0

Complete Compliance Guide

Critical

PCI DSS 4.0 is mandatory as of March 31, 2025. 64 new sub-requirements. Customized Approach option. Payment page script integrity (6.4.3 + 11.6.1) is the #1 audit failure in 2026.

Who
Merchants, payment processors, SaaS touching card data
Deadline
March 31, 2025 (hard cutoff passed)
Jurisdiction
Federal (via card brands)
Read Time
32 min

ISO 27001 vs SOC 2

Which wins deals, when you need both

Universal

B2B sales cycle requires one or the other. Which you pick depends on who your buyers are. SOC 2 Type II wins US enterprise deals. ISO 27001 wins EU + regulated international.

Who
B2B SaaS, professional services, mid-market enterprises
Deadline
Deal-driven
Jurisdiction
International (ISO) / US (SOC 2)
Read Time
12 min

SOC 2 Type II

12-Month Readiness Timeline

Most Common

Week-by-week 12-month timeline for first SOC 2 Type II. Compliance platform comparison (Vanta/Drata/Secureframe). Auditor selection with pricing. Top 10 exception patterns.

Who
B2B SaaS, fintech, healthcare tech
Deadline
Deal-driven
Jurisdiction
US
Read Time
28 min

HIPAA Security Rule

2025 NPRM Complete Guide

Major Update

HHS rewrote the Security Rule in Jan 2025 NPRM. Annual pentest now mandatory. 14-category gap analysis. 180-day implementation plan. Budget $400K-$1.5M year one for mid-market.

Who
Covered entities + business associates in healthcare
Deadline
180 days after Final Rule (Q1 2026 expected)
Jurisdiction
Federal
Read Time
30 min

HIPAA Pentest Mandate

What the 2025 Rule Actually Requires

Technical

Deep dive into the specific pentest + vulnerability scan requirements the NPRM adds to the Security Rule. What the tester needs, what the scope covers, what the documentation looks like.

Who
Healthcare operators needing pentest scope + cadence
Deadline
Annual (post-Final Rule)
Jurisdiction
Federal
Read Time
18 min

CMMC 2.0 Level 2

Complete Readiness Guide

DoD Mandatory

110 controls across 14 families. C3PAO third-party assessment. 12-month readiness timeline. Budget $300K-$1.5M year one. The scoping trap is the single most consequential decision.

Who
Defense Industrial Base (DIB) contractors handling CUI
Deadline
Phased 2024-2028
Jurisdiction
Federal
Read Time
30 min

CMMC 2.0 Overview

Introduction for DIB Contractors

Primer

Introduction to the CMMC program. Three levels. CUI definition. Who needs what level. How it differs from NIST 800-171 self-attestation.

Who
Prime + subcontractors in DoD supply chain
Deadline
Active
Jurisdiction
Federal
Read Time
20 min

NYDFS 23 NYCRR 500

Complete Implementation Guide

State Enforcement

Section-by-section walkthrough of 500.1 through 500.18. Second Amendment changes. 2024-2026 enforcement pattern with real settlements. DFS examination procedure.

Who
Financial services licensed in New York
Deadline
Second Amendment phased through Nov 2025
Jurisdiction
New York State
Read Time
28 min

NYDFS Part 500 Overview

The Amendments That Just Changed Everything

Update Summary

What changed in the Second Amendment. Penalties + enforcement actions. Quick readiness gap analysis.

Who
NY-licensed banks, insurers, financial firms
Deadline
Active
Jurisdiction
New York State
Read Time
16 min

EU NIS2 Directive

Impact on US Companies

International

NIS2 applies to US companies serving EU customers. Penalties up to 2% of global turnover. Personal liability for senior management. 24-hour incident reporting.

Who
US companies serving EU customers above threshold
Deadline
Active since October 2024
Jurisdiction
EU (extraterritorial)
Read Time
14 min

SEC 4-Day Breach Disclosure

The Rule That Rewrote Corporate Disclosure

Public Company

4 business days to disclose material cybersecurity incidents. Reshaped IR posture. Ransomware groups now reference the rule in negotiations. Enforcement actions against misdisclosure.

Who
US public companies
Deadline
Effective December 2023
Jurisdiction
Federal (SEC)
Read Time
15 min

Texas SB 2610 Safe Harbor

Breach Defense via Framework Adoption

State

Affirmative defense against civil lawsuits for Texas businesses implementing a recognized cybersecurity framework. Shifts breach defense economics. Framework adoption becomes quantifiable legal defense.

Who
Texas businesses
Deadline
Effective September 2025
Jurisdiction
Texas State
Read Time
12 min

US State Privacy Laws

20-State Compliance Matrix

State Patchwork

20 states now have comprehensive privacy laws. No federal floor. Different scopes, definitions, opt-out requirements. Matrix of what applies where.

Who
Any US consumer-facing business
Deadline
Varies by state
Jurisdiction
State (US)
Read Time
17 min

Vendor Security Audit

SaaS Checklist for Procurement

Procurement

What to actually dig into beyond the questionnaire ceremony. Evidence requests, direct verification, third-party risk intelligence, historical incident review.

Who
Buyers evaluating vendor security posture
Deadline
Per-vendor
Jurisdiction
Internal
Read Time
15 min

Third-Party Risk Management

Complete Program Guide

Program

Your security posture is your weakest vendor. Five-phase lifecycle. Four-level classification. Due diligence by risk tier. Contract provisions. Monitoring. The 10 program failures.

Who
Security leaders building TPRM programs
Deadline
Continuous
Jurisdiction
Internal
Read Time
28 min

Not sure which framework applies to you?

We run compliance readiness engagements for mid-market businesses across every framework on this page. If you're staring at a vendor questionnaire or a customer requirement and not sure where to start, a 30-minute call clears it up.