Services / 02 · Compliance groundwork
The evidence, not the certificate.
Most frameworks that apply to your business are self-assessed and self-attested. What they actually demand is a control that works and a document proving it worked on a date. That is engineering work, and it is the half your compliance consultant cannot do.
Lead line · HIPAA Security Rule
Every recent settlement turns on the same missing document.
The Office for Civil Rights runs a Risk Analysis Initiative that had reached its fourteenth enforcement action by June 2026. In February 2026 a small treatment centre settled a breach affecting 1,980 individuals for $103,000. The finding, over and over, is failure to conduct an accurate and thorough risk analysis under 45 CFR 164.308(a)(1)(ii)(A).
That figure matters more than any larger one, because it removes the only objection that ever gets raised: we are too small to be worth anyone’s time. The majority of healthcare practices nationwide are under ten employees, and they are the enforcement population, not an exemption from it.
What the engagement produces
- Security Risk Analysis under 45 CFR 164.308(a)(1)(ii)(A), documented and dated
- Risk management plan — findings ranked, owners named, dates attached
- Technical remediation: MFA, encryption at rest and in transit, access review, logging
- Asset inventory and a network diagram that matches reality
- Written policy set, workforce training records, sanction policy
- Business associate agreement review across your vendors
- Annual repeat, because a risk analysis from 2021 is an exhibit, not a defence
The part providers keep quiet
Second line · CTPAT MSC §4
Cyber criteria in CTPAT, and nobody technical is addressing them.
The 2019 revision of the CTPAT Minimum Security Criteria added cybersecurity as a full criteria section. Any business engaged in U.S. import or export — whether you operate a customs brokerage, freight forwarding operation, warehouse, or manufacturing facility with international shipments — falls under CTPAT validation requirements. Most are small operations, under ten employees.
The usual failure at validation is not a missing policy. It is the gap between a written security profile and operational reality: compliance points at IT, IT produces a screenshot of a console, and the reviewer wanted policy plus implementation plus test result plus remediation log. Closing that gap is the entire product.
MSC §4, as delivered work
- Gap assessment against Minimum Security Criteria §4, criterion by criterion
- Individual named logins, no shared accounts, role-based access
- MFA on privileged and remote access, and on the VPN
- Documented password standard and a written disciplinary process
- IT asset inventory, endpoint malware protection, documented patch cadence
- Network segmentation between office systems and operations
- Weekly backups with restore testing you can show evidence for
- Annually tested incident-response plan and phishing awareness records
- Evidence package assembled for the Annual Security Profile Review
Why this one fits here
Attached line · PCI DSS 4.0.1
Not a reason to call. A reason the security work pays for itself twice.
Version 4.0.1 is the only active version, and the 51 future-dated requirements stopped being optional on 31 March 2025. Most merchants are Level 4 and self-assess — no auditor is coming. But the controls are real engineering, and you are buying most of them anyway. Done in the right order, a defensible questionnaire falls out of security work you needed regardless.
Controls we implement
- Scope confirmation — which systems actually touch card data (12.5.2)
- MFA for all access into the cardholder data environment (8.4.2)
- Twelve-character passwords and the account policy behind them (8.3.6)
- Payment-page script inventory and integrity monitoring (6.4.3, 11.6.1)
- Automated daily log review (10.4.1.1) and authenticated internal scanning (11.3.1.2)
- Segmentation so the scope stops growing every time you add a laptop
Honest framing
Defense-adjacent · DFARS 252.204-7012
Read this before you buy a readiness engagement from anyone.
On 13 July 2026 the Department of War suspended Phase II of the CMMC rollout and froze the phases after it. Program managers may currently designate only Level 1 (Self) and Level 2 (Self); they are barred from designating Level 2 (C3PAO) or Level 3, and existing contracts carrying those requirements are being amended to remove them. A reform task force is reviewing the programme. The published regulation still contains the old Phase 2 date; it has not been amended and the memoranda control.
The arithmetic behind the pause is worth knowing: roughly 1,391 Level 2 certificates had been issued by May 2026, against the Department’s own estimate of 76,598–118,289 entities that would eventually need one. If anyone is currently selling you third-party certification preparation or telling you a certification deadline is bearing down on you, ask them for the memorandum.
What is still fully in force, and sellable
- NIST SP 800-171 Rev 2 gap assessment against the 110 requirements
- System Security Plan and Plan of Action & Milestones, written to be read by an assessor
- Basic and, where applicable, scored self-assessment support
- SPRS score posting and the annual affirmation process
- Level 1 annual self-assessment support — the surviving, still-designatable requirement
- A customer responsibility matrix covering the services we provide to you
The trap in hiring any IT provider
Limits
Where we draw the line.
- The Holm Team is not a certifying body, and for HIPAA no such thing exists
- Nobody can sell you a HIPAA certificate. There is no accrediting authority and no badge. Any provider offering one is either confused or counting on you being. What exists is a risk analysis you perform, a remediation programme you run, and evidence you can produce when OCR asks.
- The Holm Team does not perform CMMC certification assessments
- Assessment and remediation are separated by a conflict-of-interest firewall: whoever helps you implement cannot be the party who assesses you. We remain on the implementation side of that line. We hold no assessor credential and no third-party assessment organisation status.
- The Holm Team will not host your controlled unclassified information
- Running CUI on infrastructure we operate would make us a cloud service provider owing FedRAMP Moderate equivalency with an annual third-party audit. That is out of reach for an organization this size, and pretending otherwise would put your contract at risk.
- The Holm Team does not provide legal opinions
- Whether a specific disclosure is reportable, whether a clause flows down, whether a contract term binds you — that is your attorney's work. We produce the technical evidence they need and we say plainly when a question is outside our scope.
Next step
Find out what you can actually evidence today.
The IT Health & Risk Assessment establishes the baseline every one of these frameworks is measured against. A typical assessment runs 20–40 hours at $165/hr.
medical & dental · customs brokers & forwarders · card-taking retail · defense-adjacent suppliers