These are not alternatives you pick between. HIPAA is a law that applies if you handle patient health information. PCI DSS is a contract with the card brands that applies if you take cards. The FTC Safeguards Rule is a law covering more businesses than people expect. SOC 2 is not a law at all — it is a voluntary audit you buy because customers ask for it. Most small businesses are subject to at least one without knowing.
“Are we SOC 2 compliant?” is one of the most commonly asked and least useful questions in small business technology. It treats these frameworks as a ladder you climb, when they are separate obligations arriving from separate directions.
Here is what each compliance framework actually is, who it reaches, and what it costs you to deal with.

HIPAA: a law, if you are a covered entity
HIPAA applies to healthcare providers, health plans and healthcare clearinghouses, plus the business associates who handle protected health information on their behalf.
That last category is wider than people assume. A billing company, an IT provider with access to patient records, a transcription service, a shredding company — all business associates, all needing a signed business associate agreement.
What HIPAA asks for is a security risk analysis, administrative, physical and technical safeguards, workforce training, and breach notification. Encryption is addressable rather than mandatory, which does not mean optional: you implement it or you document a reasoned alternative.
Enforcement is by the HHS Office for Civil Rights, usually triggered by a complaint or a reported breach rather than a routine audit.
PCI DSS: not a law, but not optional either
This is the one people misunderstand most. PCI DSS is not legislation. It is a standard set by the card brands and imposed on you through your merchant agreement.
That distinction matters for what happens when you fail. There is no regulator to fine you. Instead your acquirer can raise your rates, impose penalties, or ultimately stop you taking cards — which for most businesses is worse than a fine.
The good news for small merchants is that scope is mostly about architecture. If you never touch card data — the customer enters it into a hosted payment page or an iframe served by your processor — your obligations shrink dramatically, usually to a short self-assessment questionnaire.
If card numbers pass through your server, or worse are stored on it, you have taken on an enormous amount of work. The single best PCI decision a small business can make is to arrange things so card data never reaches their own systems.
The FTC Safeguards Rule: broader than the name suggests
This one catches businesses that do not think of themselves as financial institutions.
The Safeguards Rule covers a wide definition that explicitly includes tax preparation firms, and also reaches mortgage brokers, auto dealers arranging financing, collection agencies, investment advisers and others.
It requires a written information security programme with nine elements: a designated Qualified Individual, a written risk assessment, specific safeguards including multi-factor authentication and encryption, monitoring and testing, staff training, oversight of service providers, programme updates, an incident response plan, and an annual report to leadership.
If you prepare returns for compensation, this applies to you and it is not advisory. Our page for accounting and tax firms goes through what it means in practice.
SOC 2: a product you buy, not a rule you follow
SOC 2 is different in kind from everything above. No law requires it. It is an attestation report produced by an independent CPA firm saying that your controls meet criteria you largely define yourself.
You get one because a customer asks for it. That is the entire reason it exists in the market, and it is a perfectly good one — without it, enterprise procurement will often not proceed.
Two types matter. A Type I report says your controls were designed appropriately at a point in time. A Type II says they operated effectively over a period, usually three to twelve months. Customers who know what they are asking for want Type II.
It is not cheap. Between the auditor, the tooling and the internal time, a small company should expect a meaningful five-figure outlay for the first year, and it recurs annually.
The honest advice: do not pursue SOC 2 speculatively. Pursue it when a named deal requires it and the deal is worth more than the report.
CMMC: only if you are in the defense supply chain
CMMC applies to Department of Defense contractors and flows down through contracts to subcontractors. Level 1 covers basic protection of federal contract information; Level 2 aligns with NIST SP 800-171 for controlled unclassified information.
If you are not in that supply chain it does not touch you. If you are, it arrives as a contract requirement rather than a choice. See our CMMC explainer for what Level 2 actually asks of a small shop.
State privacy laws: the one everybody forgets
While businesses worry about SOC 2, the obligation most likely to actually apply to them is a state consumer privacy law.
California, Virginia, Colorado, Connecticut, Utah, Texas and a lengthening list of others have their own statutes with their own thresholds, often based on revenue or the number of consumers whose data you handle.
They are real laws with real regulators, they apply to ordinary domestic businesses, and almost nobody asks about them because no customer sends a questionnaire.
What they have in common
Here is the practical relief. Strip away the acronyms and the same foundation sits under all of them.
Know what data you hold, where it lives, who can reach it, and how long you keep it. Every framework starts here and most businesses have never written it down.
Control access. Multi-factor authentication, least privilege, and removing accounts when people leave. This appears in every one of them.
Encrypt it, in transit and at rest.
Have an incident plan, because all of them have notification duties with deadlines you cannot meet by improvising.
Oversee your vendors, with agreements and some evidence you checked.
Train your people, because the control that fails is almost always a human one.
Do those six properly and you are most of the way through any framework that later turns out to apply. That is a far better use of a small budget than certifying against something nobody has asked you for.
How to work out which compliance framework applies
Answer these honestly and you will have your list.
Do you handle health information for a provider or plan? Do you take card payments, and does card data touch your systems? Do you prepare tax returns or arrange financing? Has a customer asked for a SOC 2 report in writing? Do you hold federal contract information? How many consumers’ data do you process, and in which states?
Most small businesses find one or two apply and the rest do not. The failure mode is not usually missing a framework — it is spending money on the wrong one because it had the most familiar name.

Frequently asked questions
Is SOC 2 required by law?
No. SOC 2 is entirely voluntary. It is an attestation report produced by an independent CPA firm, and businesses obtain one because customers — usually enterprise buyers — ask for it during procurement. There is no regulator enforcing it and no penalty for not having one, other than losing deals that require it.
Is PCI DSS a law?
No, though it can feel like one. PCI DSS is a standard set by the card brands and imposed on you through your merchant agreement. The consequences of failing it are contractual: higher rates, penalties passed down by your acquirer, or losing the ability to take cards. For most businesses that last one is worse than any fine would be.
I am a small business. Am I too small for any of this?
Almost certainly not. HIPAA has no size exemption. PCI applies to any merchant taking cards. The FTC Safeguards Rule covers sole practitioners preparing tax returns. What size affects is proportionality — what is expected of a five-person firm is not what is expected of a hospital — but nothing exempts you outright.
Which one should I do first?
Whichever one legally applies, ahead of any that is voluntary. A tax practice should address the FTC Safeguards Rule before thinking about SOC 2. A clinic should address HIPAA. If nothing mandatory applies, do the six common foundations — data inventory, access control, encryption, incident plan, vendor oversight, training — because they serve every framework you might later need.
How much does SOC 2 cost a small company?
Expect a meaningful five-figure outlay in year one once you count the auditor, the compliance tooling and your own team’s time, and expect it to recur annually. That is why it is worth pursuing only when a specific deal requires it and that deal is worth more than the report. Speculative SOC 2 is one of the more common ways small companies waste a security budget.
Does my hosting provider make me compliant?
No provider can make you compliant, and be careful of any that implies otherwise. A provider supplies infrastructure that meets certain technical requirements, and documentation you can point at in your own programme. The risk assessment, the training, the incident plan and the accountable person remain yours. What you should expect from a provider is straight answers about where data sits, what encryption applies and how backups work.
What about state privacy laws?
These are the ones most American small businesses actually fall under, and the ones nobody asks about because no customer sends a questionnaire. California, Virginia, Colorado, Connecticut, Utah, Texas and others each have thresholds based on revenue or the number of consumers whose data you process. Worth checking against your own numbers, because a purely domestic business can easily be in scope.
The mistakes that waste the most money
Almost every compliance framework budget that gets wasted is wasted in one of five ways, and none of them are exotic.
Buying an audit nobody asked for. SOC 2 is the clearest example. It is not a law and nothing obliges you to hold one. It exists because enterprise buyers demand evidence, and the correct trigger is a buyer asking for it in a deal you want. Commissioning a Type II report speculatively, before a single prospect has raised it, spends real money and twelve months of evidence collection on a document that may sit unread. If a deal is genuinely blocked, ask the buyer whether a completed security questionnaire and a remediation timeline will unblock it — very often it will.
Assuming your vendor’s compliance is your compliance. This is the most expensive misunderstanding on the list. Your hosting provider being certified does not make you certified. Cloud infrastructure operates a shared responsibility model: the provider secures the infrastructure, and you remain responsible for what you build on it, who you grant access to, and how you configure it. A HIPAA-eligible platform with no business associate agreement signed and no access controls configured leaves you exactly as exposed as you were before.
Confusing a document with a control. Writing an access control policy is not the same as revoking the account of the contractor who left in March. Auditors sample evidence, and every framework on this page cares about what actually happened rather than what the binder says should happen. A short policy you genuinely follow beats a long one you do not, and it is cheaper to maintain.
Scoping too widely. Scope is the single biggest driver of cost in any assessment. Every system that touches regulated data is in scope, and every system that does not can be excluded if you can demonstrate the separation. Segmenting card data onto a hosted payment page rather than passing it through your own servers is the classic example, and it can move a business from a lengthy PCI assessment to a short self-assessment questionnaire. Do the scoping work before you buy anything.
Treating it as a project with an end. Every framework here assumes continuous operation. A SOC 2 Type II report covers a review period rather than a moment, HIPAA expects risk analysis to be ongoing, and PCI DSS requires quarterly and annual activities. Budgeting for a one-time push and nothing afterwards produces a lapse at the first renewal, which is more expensive than maintaining it would have been.
Your first ninety days
If you have identified which compliance framework applies and you are starting from nothing, this sequence front-loads the work that every framework counts and defers the work that only some do.
Weeks one and two: inventory. List every system holding regulated data, every person with access to each, and every vendor that processes it on your behalf. This single document feeds every framework on this page, and producing it almost always surfaces something unwelcome — an old database, a shared login, a former employee with live access. Fixing what the inventory finds is often the largest single risk reduction available to a small business, and it costs nothing but attention.
Weeks three and four: access. Remove accounts that should not exist, replace shared logins with named ones, enforce multi-factor authentication everywhere it is supported, and write down who approves new access. Auditors ask for this first and attackers exploit its absence first, which is a useful coincidence.
Weeks five and six: vendors. Collect the agreements. Business associate agreements for anything touching protected health information, data processing terms for personal data, and attestations of compliance from anyone in your card flow. Reputable providers publish these and will sign them without negotiation. A vendor that cannot produce one is telling you something.
Weeks seven and eight: the written risk analysis. What could go wrong, how likely is it, what would it cost, and what are you doing about it. HIPAA requires this explicitly and every other framework assumes it. It does not need to be long. It needs to exist, be dated, and be revisited.
Weeks nine and ten: incident response. One named owner, a written sequence, contact details for your legal counsel and your insurer, and the notification deadlines that apply to you. Then walk through a plausible scenario with the people named in it. The rehearsal is where you discover that the person responsible for notifying customers does not have the customer list.
Weeks eleven and twelve: evidence and the gap list. Decide how you will prove, in twelve months, that any of this happened. Where the logs live, who reviews them, how long they are retained. Then write the honest list of what you have not done and when you will. A dated gap list with owners is a materially better position than an unexamined assumption that you are fine, both with an auditor and with a buyer.
Only after those twelve weeks is it worth asking whether you need a formal audit — and by then you will have a much better idea of which compliance framework your customers actually care about.
Sources
Each of these frameworks publishes its own authoritative guidance, and in every case it is clearer than the summaries written about it. Start here before paying anyone to interpret them for you.
- HIPAA for Professionals — U.S. Department of Health and Human Services.
- FTC Safeguards Rule: What Your Business Needs to Know — Federal Trade Commission.
- PCI DSS standards and supporting documents — PCI Security Standards Council.