TL;DR: What This Checklist Covers and Who It's For
A cybersecurity compliance requirements checklist maps specific technical and administrative controls to the frameworks your regulators, customers, or insurers require. This guide covers SOC 2, HIPAA, CMMC and NIST CSF for IT Directors at 50 to 500 employee companies. You get a cross-framework overlap map, tiered controls by company size, and rough cost per line item.
Most published checklists get one thing wrong. They treat every company the same. A 60-person SaaS startup preparing for SOC 2 Type I doesn't need the same control depth as a 400-person defence contractor pursuing CMMC Level 2. This article fixes that by tiering the checklist and showing which controls satisfy multiple frameworks at once.
According to IBM's 2024 Cost of a Data Breach Report, organisations with fewer than 500 employees saw average breach costs of $3.31 million. Compliance work isn't paperwork. It's the operational floor that keeps that number from becoming your number.
Why One Flat Checklist Fails Most Mid-Market Companies
Compliance readiness isn't linear. It scales with headcount, data sensitivity, and customer contracts.
I break clients into three tiers. Tier 1 is 50 to 100 employees, typically pursuing SOC 2 Type I or basic HIPAA Security Rule coverage. Tier 2 is 100 to 250 employees, usually chasing SOC 2 Type II plus a second framework. Tier 3 is 250 to 500 employees, often facing CMMC Level 2 or multi-framework audits.
Tier 3 reality check. CMMC Level 2 requires 110 practices drawn from NIST SP 800-171. That's a multi-quarter engineering programme, not a checklist weekend. The DoD finalised the CMMC rule in October 2024 with phased contract enforcement rolling through 2025 and beyond.
Practitioner note. Most companies overestimate their readiness. They also underestimate how many controls overlap between frameworks. That second point is where the money is.
The Cross-Framework Overlap Map
Here's the single highest-ROI insight in compliance work. One well-implemented control often satisfies four frameworks simultaneously. You do the engineering once. You produce the evidence four times.
MFA is the cleanest example. Deploy it on all admin and remote access, and you've satisfied SOC 2 CC6.1, HIPAA §164.312(d), CMMC AC.L2-3.5.3, and NIST CSF PR.AC-7. Same control. Four evidence packets.
Encryption at rest lines up the same way: SOC 2 CC6.7, HIPAA §164.312(a)(2)(iv), CMMC SC.L2-3.13.16. Audit logging hits SOC 2 CC7.2, HIPAA §164.312(b), and CMMC AU.L2-3.3.1.
For log management, mid-market teams usually land on Microsoft Sentinel (roughly $2.46 per GB ingestion on pay-as-you-go per current Azure pricing) or Splunk Cloud. Sentinel wins on price for shops already inside the Microsoft 365 E5 stack. Splunk wins on ecosystem depth if you've got a large SOC team who lives in it.
Document the control once. Point each framework's evidence packet at the same artefact. That's the trick.
The Core Checklist: 10 Controls Tiered by Size and Cost
Here's the working list. Each control shows frameworks satisfied, tier applicability, rough cost, and recommended tools.
1. MFA on all admin and remote access. All tiers. Okta Workforce Identity or Microsoft Entra ID P1 at around $6 per user per month. Satisfies SOC 2 CC6.1, HIPAA §164.312(d), CMMC AC.L2-3.5.3, NIST CSF PR.AC-7. If you skip everything else, don't skip this. Read our MFA best practices guide for deployment sequencing.
2. Endpoint Detection and Response (EDR). All tiers. SentinelOne Singularity Core runs roughly $6 to $8 per endpoint per month at mid-market volumes; CrowdStrike Falcon Go sits around $8.99. SentinelOne wins for teams that want autonomous rollback. CrowdStrike wins for teams that want the biggest threat intel feed. Satisfies SOC 2 CC7, HIPAA §164.308(a)(1), CMMC SI.L2-3.14.1.
3. Encryption at rest and in transit. All tiers. BitLocker and FileVault are free at the OS layer. Tier 3 data classification projects with vendor tooling typically run $5,000 to $15,000 in year one.
4. Vulnerability scanning, quarterly minimum. Tier 2 and up. Tenable Nessus Professional around $4,000 per year for a single scanner. Rapid7 InsightVM around $1.93 per asset per month. Satisfies NIST CSF ID.RA-1 and SOC 2 CC7.1.
5. Annual penetration test. Tier 2 and up. External network pen tests from qualified firms typically run $15,000 to $40,000 depending on scope. Our penetration testing cost guide breaks down what's inside those numbers.
6. Incident Response Plan, documented and tested. All tiers. Internal drafting time is 40 to 80 hours. Facilitated tabletop exercises run $5,000 to $12,000. Satisfies SOC 2 CC7.3 through CC7.5, HIPAA §164.308(a)(6), CMMC IR.L2-3.6.1.
7. Audit log retention. All tiers. 90 days hot, 12 months archived is the working floor for most auditors. Costs scale with log volume via Sentinel or Splunk.
8. Access control policy plus least-privilege review. All tiers. Internal labour. Semi-annual access reviews with sign-off. Satisfies SOC 2 CC6.2 and CC6.3, HIPAA §164.312(a)(1).
9. Backup and tested recovery, 3-2-1 minimum. All tiers. Veeam Data Platform Essentials starts around $1,400 per year for small environments. Satisfies SOC 2 A1.2 and HIPAA §164.308(a)(7). Untested backups are a common failure mode. When ransomware hits, teams that never ran a full restore drill are the ones that pay.
10. Security awareness training plus phishing simulation. All tiers. KnowBe4 runs roughly $20 to $30 per user per year. Satisfies SOC 2 CC1.4, HIPAA §164.308(a)(5), CMMC AT.L2-3.2.1.
Compliance Gap Scoring: How to Prioritise
Flat checklists don't help an IT Director with three months and a $50,000 budget. A scoring model does.
Score each control on two axes. Risk Exposure runs 1 to 5 based on data sensitivity and attack surface. Audit Impact runs 1 to 5 based on how likely the control is to be tested by your specific auditor. Multiply them.
Controls scoring 20 to 25 get fixed before the audit. Controls scoring 10 to 19 get documented compensating controls plus a remediation date. Controls under 10 go on next quarter's plan.
Worked example. A HIPAA-covered entity missing audit logging: ePHI exposure of 5, times an HHS OCR audit protocol priority item at 5, equals 25. Fix immediately. A SaaS company missing a formal vendor risk management policy: 3 times 4 equals 12. Draft the lightweight version this sprint, full programme next quarter.
Auditors are human. A credible remediation roadmap with owner names and dates often converts a Type I "finding" into an "observation." That distinction matters when the report gets shared with your enterprise customers.
When Do These Requirements Actually Become Mandatory?
Enforcement triggers vary by framework. Knowing which one applies to you decides everything.
HIPAA. Applies the moment you're a covered entity or business associate touching ePHI. No revenue threshold. No headcount minimum. OCR investigations get triggered by breach notifications and patient complaints. If you're evaluating providers, our guide on SOC 2 readiness covers the adjacent trust-services criteria.
SOC 2. Never legally mandatory. It becomes de facto mandatory the moment an enterprise customer or cyber insurer requires the report. Type I can be produced in 60 to 120 days. Type II requires a minimum six-month observation window. See our SOC 2 certification cost breakdown for realistic budgets.
CMMC. DoD contractors handling CUI need CMMC Level 2 certification before contract award. The final rule was published in the Federal Register in October 2024 with phased enforcement in contract solicitations from 2025.
NIST CSF 2.0. Released February 2024. Not a regulation on its own, but it maps to the FTC Safeguards Rule (in force since June 2023 for non-banking financial institutions) and multiple state data protection laws.
Cyber insurance. Most carriers now require MFA on all remote access and email, EDR on every endpoint, and a tested backup as underwriting minimums. Miss one, and a claim can be denied. Our cyber insurance requirements piece covers the current carrier questionnaire in detail.
A 90-Day Compliance Sprint
If an audit is on the calendar, here's the sequence that consistently reduces findings.
Weeks 1 and 2. Run a gap assessment against your target framework. Use the NIST CSF 2.0 Organisational Profile as the baseline. It's free, and it maps cleanly to SOC 2, HIPAA and CMMC.
Weeks 3 and 4. Deploy MFA if it isn't already universal. Highest impact, lowest cost. Okta or Entra ID, live in days.
Weeks 5 and 6. Confirm EDR coverage across every endpoint. Zero unmanaged laptops. Export the coverage report as audit evidence.
Weeks 7 and 8. Verify backup integrity. Run a full test restore. Document the 3-2-1 configuration. Veeam restore reports get accepted as SOC 2 evidence when signed and dated.
Weeks 9 and 10. Draft or update the Incident Response Plan. Assign named roles. Book a tabletop exercise. Compliance tooling like Vanta or Drata can accelerate evidence collection here, and we've written about the trade-offs in our compliance automation software review.
Weeks 11 and 12. Organise evidence artefacts. Assign a control owner to each checklist line. Brief leadership on open findings and remediation timelines.
What this sprint won't do. It won't get you to SOC 2 Type II. That needs six months of operating history. It will get you to Type I readiness and materially reduce findings.
The Practitioner Reality
We regularly see companies with 14 different security tools spending $28,000 a month on licences, where three of those tools do essentially the same job. Consolidating to six well-chosen tools at under half the cost is often the first thing we do in a readiness engagement. Vendors love selling overlap. Auditors don't care how many logos you own. They care whether the control operates.
The other pattern we see constantly. A previous MSP told the client they were "compliant" for two years without producing a single piece of audit evidence. Compliant without evidence is just a word. Auditors want artefacts with timestamps, owners and review cadences.
If you're within 90 days of a SOC 2 or HIPAA audit and don't know where you stand, book a free 30-minute audit with Mike. We'll map your current controls against your target framework and tell you exactly what's missing.
FAQ
What is a cybersecurity compliance checklist? A structured list of technical and administrative controls mapped to specific regulatory frameworks (SOC 2, HIPAA, CMMC, NIST CSF) that a company must implement and document to pass an audit or meet contractual requirements.
Which compliance framework applies to my company? HIPAA if you handle patient health data. CMMC if you hold DoD contracts touching CUI. SOC 2 if enterprise customers or insurers require the report. NIST CSF as a baseline for most US mid-market companies.
How long does it take to become SOC 2 compliant? Type I typically runs 60 to 120 days from gap assessment to report. Type II requires a minimum six-month audit period plus 4 to 8 weeks of auditor fieldwork.
What tools do I need for a basic compliance stack? At minimum: MFA (Okta or Entra ID), EDR (SentinelOne or CrowdStrike), log management (Microsoft Sentinel or Splunk), backup (Veeam), and security awareness training (KnowBe4).
How much does a mid-market compliance programme cost? A realistic year-one baseline for a 100-person company runs $50,000 to $150,000, including tooling, a SOC 2 audit fee ($20,000 to $50,000), and implementation labour.
What happens if I fail a compliance audit? Consequences vary by framework. HIPAA civil penalties range from roughly $100 to $50,000 per violation with annual caps. SOC 2 failure produces a qualified report that gets shared with your customers. CMMC failure means no DoD contract award.
{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{"@type":"Question","name":"What is a cybersecurity compliance checklist?","acceptedAnswer":{"@type":"Answer","text":"A structured list of technical and administrative controls mapped to specific regulatory frameworks (SOC 2, HIPAA, CMMC, NIST CSF) that a company must implement and document to pass an audit or meet contractual requirements."}},
{"@type":"Question","name":"Which compliance framework applies to my company?","acceptedAnswer":{"@type":"Answer","text":"HIPAA if you handle patient health data. CMMC if you hold DoD contracts touching CUI. SOC 2 if enterprise customers or insurers require the report. NIST CSF as a baseline for most US mid-market companies."}},
{"@type":"Question","name":"How long does it take to become SOC 2 compliant?","acceptedAnswer":{"@type":"Answer","text":"Type I typically runs 60 to 120 days from gap assessment to report. Type II requires a minimum six-month audit period plus 4 to 8 weeks of auditor fieldwork."}},
{"@type":"Question","name":"What tools do I need for a basic compliance stack?","acceptedAnswer":{"@type":"Answer","text":"At minimum: MFA (Okta or Entra ID), EDR (SentinelOne or CrowdStrike), log management (Microsoft Sentinel or Splunk), backup (Veeam), and security awareness training (KnowBe4)."}},
{"@type":"Question","name":"How much does a mid-market compliance programme cost?","acceptedAnswer":{"@type":"Answer","text":"A realistic year-one baseline for a 100-person company runs $50,000 to $150,000, including tooling, a SOC 2 audit fee ($20,000 to $50,000), and implementation labour."}},
{"@type":"Question","name":"What happens if I fail a compliance audit?","acceptedAnswer":{"@type":"Answer","text":"HIPAA civil penalties range from roughly $100 to $50,000 per violation with annual caps. SOC 2 failure produces a qualified report that gets shared with customers. CMMC failure means no DoD contract award."}}
]
}
Know exactly where your security stands.
Get your free security assessment →Know exactly where your security stands.
Most IT directors are one audit away from a nasty surprise. We remove the guesswork.
- A full assessment of your environment, mapped to SOC 2 and HIPAA.
- A prioritised remediation plan you can act on, whether you hire us or not.
- Managed protection across endpoints, data, and incident response.
- Fixed monthly pricing, so there are no per-incident surprises.
The assessment is free, and the plan is yours to keep.