All services
Compliance

Compliance

Comprehensive support to comply with HIPAA, CMMC, NIST 800-171, NYSDFS, PCI, SEC, and FTC Safeguards

Compliance, without the panic

Compliance work usually arrives as a deadline someone else set: a customer's questionnaire, a regulator's certification date, a contract you cannot sign without it. It rarely arrives with a budget or a spare person to own it.

We do that work for smaller businesses. Not as a one-off audit that leaves you with a spreadsheet of findings and no way through them, but as ongoing support: figuring out where you actually stand, building a realistic path from there, and staying with you as the rules change.

Benefits

  • A defensible roadmap rather than a perfect score
  • Evidence of continuous improvement and accountability
  • Separation of oversight from execution
  • Someone who has been through examinations with customers before

Features

The goal is not a perfect score. It is documented, deliberate improvement you can defend.

  • Expert-led evaluation of every in-scope control, assessed with risk in a single effort
  • Remediation support at a pace your team can absorb
  • The documentation auditors and examiners actually ask to see
  • A senior advisor who owns the roadmap and prepares your annual certification
  • Cyber-AB Registered Provider Organization, with Registered Practitioners on the team
  • Virtual HIPAA Security Officer, where you need that job done

HIPAA and HITECH

If you handle patient data, HIPAA is what your partners and your regulator will ask about, and most of it has nothing to do with technology.

We help healthcare providers translate the security rule into operational reality: annual HIPAA risk assessments, the policies and documentation behind them, workforce training, and support for the business associate agreements your partners require. Where you need the security official’s job done, we can serve as your virtual HIPAA Security Officer, doing the risk analysis, the policies, and the training records while the designation stays with you.

Read More About Healthcare

CMMC and NIST 800-171

Whether you are in the DOD supply chain or not, vendors and customers increasingly require you to demonstrate your focus on cybersecurity.

OrbitalFire is a Cyber-AB Registered Provider Organization, one of the first firms designated an RPO for CMMC, and our team includes Registered Practitioners authorized to advise on the standard.

Cyber AB Registered Practitioner Organization

We prepare smaller manufacturers for CMMC by assessing where your cybersecurity stands today and building a path toward certification: NIST 800-171 assessment, gap remediation, and a readiness plan mapped to the controls you will be measured against.

We can also coordinate with your region’s MEP center on grant opportunities, and advocate for you in the conversations with primes and customers where compliance timelines get negotiated.

When and if it is time for a CMMC audit, we will support you along the way, and can even recommend auditors for you to consider.

Read More About Manufacturing

NYSDFS Part 500

Part 500 requires that a qualified individual oversee and implement your cybersecurity work and report annually to your board. That role can be filled internally or by an external firm, and OrbitalFire fills it for a number of covered entities.

For smaller NYSDFS-regulated organizations, the difficulty is rarely the controls themselves. It is documenting decisions, defining scope, and explaining compensating controls in a way that holds up under review. “If it isn’t documented, it wasn’t done” is how New York state examiners approach this.

Where MFA cannot be deployed everywhere Section 500.12 requires it, Part 500 allows a compensating control instead, on three conditions: it is reasonably equivalent or more secure, your qualified individual approves it in writing, and it is reviewed at least annually. Organizations lose that argument on the second and third, not the first.

We help you confirm where you stand, navigate MFA requirements and compensating controls, prepare for annual certification with documentation that reflects reality, and keep everything aligned as your business changes. We have been through examinations with customers and know what examiners look for. The earlier we are involved, the better that goes.

Read More About Financial Services

PCI, SEC, and FTC Safeguards

We assess and support these rules as well. If your obligation is not listed here, it is worth a conversation. The underlying work is usually the same, and the controls overlap more than the acronyms suggest.

See All Services

What the work actually looks like

  • Compliance assessment

    Expert-led evaluation of every in-scope control, with control-by-control scoring and detailed, risk-based recommendations. Compliance and risk assessed together in a single effort rather than as two separate engagements.

  • Remediation support

    Closing the gaps the assessment finds, in priority order, at a pace your team can absorb.

  • Documentation

    Written Information Security Plans, cybersecurity policies, and incident response plans. The deliverables auditors and examiners actually ask to see.

  • Ongoing oversight

    Through our vCISO service, a senior advisor who owns the roadmap, prepares your annual certification, and answers the questions as they come up.

Separating oversight from execution also satisfies the separation-of-duty requirements several of these rules impose.

  • Do we have to be 100% compliant?

    Not on day one, and that is rarely what is being asked of you. Regulators and customers look for continuous improvement, accountability, and documentation: evidence that you know your risks and are working through them deliberately. A roadmap you can defend is worth more than a score you cannot explain, and it is far more achievable for a smaller business than chasing every control at once.

  • Which rules actually apply to my business?

    Usually it is decided by three things: your industry, your customers, and your contracts. Handling patient data brings HIPAA. A contract in the defense supply chain brings CMMC and NIST SP 800-171. Operating under New York financial regulation brings NYSDFS Part 500. Taking card payments brings PCI DSS. Most smaller businesses are surprised to find more than one applies, and we can help you identify which, if any, apply.

  • Do you perform the certification audit?

    No, and that is deliberate. A CMMC certification is issued by an accredited third party and a SOC 2 report comes from an independent CPA firm. We prepare you for both, support you through the audit itself, and can recommend auditors for you to consider. Keeping preparation separate from assessment is what makes the preparation credible.

  • We already have someone handling IT. Do you replace them?

    No. We work alongside whoever handles your IT rather than in place of them. Cybersecurity and IT are different disciplines with different training and different accountability, and several of these rules expect oversight to be separate from execution. We set the baseline, assess, and recommend.

  • How long does compliance work take?

    It depends on where you are starting and what the deadline is, which an assessment establishes in the first few weeks. What we can say is that the work is sequenced rather than simultaneous: gaps are closed in priority order, at a pace your team can absorb, and the roadmap is built so you can show progress at any point along it rather than only at the end.

  • Could we do the risk assessment ourselves with a template?

    You can, and for a very small business with a simple setup it beats doing nothing. Two things smaller businesses find once they go through it themselves. A template cannot tell you which questions apply to you, and that is where most of the work is. And a regulator, auditor, or insurer gives less weight to an assessment you graded yourself. If you are doing the assessment to show someone, who did it matters.

  • How long does it take to get compliant from a standing start?

    For most smaller businesses, three to nine months. The Assessment takes a few weeks. Closing what it finds depends on how you prioritize it in your business, and that usually sets the pace. We will tell you at the start which deadlines you can realistically hit.

Tell us about your business.

A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.

Not ready to talk? Check your readiness in five minutes and see where to start.