HIPAA vs CMMC vs SOC 2: Which Compliance Framework Does Your Business Actually Need?
Your trigger decides, not your industry. HIPAA applies when you touch protected health information, including as a vendor. CMMC applies when a Department of Defense contract sends you controlled unclassified information. SOC 2 applies when customers demand proof before they buy. They stack. Many firms need two or three at once.

- Three different triggers, not three options. Patient data triggers HIPAA, defense data triggers CMMC, customer demand triggers SOC 2.
- HIPAA is federal law, CMMC is a contract term, and SOC 2 is a sales requirement with no regulator behind it.
- HIPAA reaches vendors. A business associate, and any subcontractor it hires, is directly liable under the rule.
- CMMC Level 2 covers 110 security requirements, needs a certification assessment every three years, and an affirmation every year.
- The controls overlap heavily. The evidence does not, which is where most compliance budgets get wasted.
How did we compare HIPAA, CMMC and SOC 2?
By what triggers each one, not by which is strictest. These three are not competing standards you choose between, and treating them as a ranked list is the mistake this article exists to correct.
- The dimensions. What sets each obligation running, who enforces it, how compliance is verified, and what happens if you do not have it.
- The evidence. Every requirement is cited to the instrument that creates it: the Federal Register for CMMC and the HIPAA penalty table, the Code of Federal Regulations for HIPAA definitions and notification duties, the AICPA for SOC 2, and NIST for SP 800-171.
- Not legal advice. This maps triggers so you can ask a better question. Where a contract or a regulator is involved, confirm your position with counsel.
- No vendor ranking. This compares approaches, not products. It names no vendors and recommends no supplier.
- Independence. Best IT MSP does not sell IT services or security services, and does not appear in its own rankings.
The table states all three triggers side by side. If more than one row applies to you, the answer is not to pick one.
Which compliance framework do you actually need?
Your trigger decides, not your industry. You need HIPAA when your business creates, receives, maintains, or transmits protected health information. You need CMMC when a Department of Defense contract pushes federal contract information or controlled unclassified information down to you. You need SOC 2 when your own customers refuse to buy until you hand them independent proof that your controls work. Those are three different questions with three different answers, so answer each one separately.
| Dimension | HIPAA | CMMC | SOC 2 |
|---|---|---|---|
| What triggers it | Touching protected health information, including as a vendor | A Department of Defense contract sending you controlled unclassified information | A customer's security questionnaire |
| Who enforces it | HHS Office for Civil Rights | The Department of Defense, through the contract | Nobody; the market does |
| How it is verified | No certificate exists; investigated after a complaint or breach | Assessed before award, and repeated | An examination by a licensed CPA firm |
| What non-compliance costs | Civil monetary penalties after the fact | No valid status, no contract | A lost deal |
These frameworks are not alternatives. A healthcare software company that sells to hospitals and holds one defense subcontract needs all three at once. Each one is triggered by a different fact about your business: the data you hold, the contract you signed, and the customer you want. This guide is the decision. If you already know which framework applies and want the how, read our cybersecurity compliance guide next.
- <strong>HIPAA.</strong> Triggered by protected health information. Federal law. Enforced by HHS Office for Civil Rights after a complaint or a breach.
- <strong>CMMC.</strong> Triggered by a DoD contract clause. Verified before award. No valid status, no contract.
- <strong>SOC 2.</strong> Triggered by a customer's security questionnaire. No regulator. The penalty is a lost deal.
The money argues for getting this right early. IBM puts the global average cost of a data breach at $4.99 million in 2026, and one in four malicious breaches is now AI-enabled at an average of $6 million. Compliance work does not make you breach-proof. It does force the controls that shorten the damage, and it keeps a bad week from becoming a regulatory case or a cancelled contract.

Do you need HIPAA?
HIPAA applies the moment you handle protected health information on behalf of a covered entity, even if you are not a clinic, a hospital, or an insurer. The rule reaches vendors through the business associate definition, which covers anyone who creates, receives, maintains, or transmits protected health information for a regulated function, including a subcontractor hired by that business associate. That single clause pulls in managed IT providers, billing companies, cloud hosts, shredding firms, and the software vendors sitting behind them.
What HIPAA demands as evidence
HIPAA asks for documented process, not a certificate. You maintain a written risk analysis, you sign a business associate agreement with every vendor that touches the data, you set access control and audit logging, you encrypt what you can, and you keep an incident response plan you have actually tested. Breach timing is written into the rule, so you report on its clock, not yours. You must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, and a breach affecting 500 or more people goes to the Secretary at the same time as the individual notices.
What it costs you to ignore it
HIPAA penalties scale with how much you knew and whether you fixed it. The current inflation-adjusted civil money penalties run from $145 per violation at the lowest tier to $73,011 per violation, with a calendar-year cap of $2,190,294 for repeat violations of the same requirement. Willful neglect that you do not correct within 30 days starts at $73,011 per violation. Enforcement usually arrives after a complaint or a reported breach, so the trigger for an investigation is often the incident you were hoping nobody would notice. Healthcare buyers can compare vetted providers on our healthcare IT services page.

Do you need CMMC?
CMMC applies when a Department of Defense contract flows federal contract information or controlled unclassified information onto your systems. Your industry does not decide this. Your contract does. The requirement became contractual on November 10, 2025, when the DoD acquisition rule took effect, and the clause is checked before award rather than after an incident.
Your contract names the level you must hit, and there are three. Level 1 covers the 15 basic safeguarding requirements in FAR clause 52.204-21, the floor for federal contract information such as drawings, statements of work, and delivery schedules that are not public. Level 2 covers the 110 security requirements in NIST SP 800-171, the standard set for controlled unclassified information. Level 3 adds 24 selected requirements from NIST SP 800-172 for the most sensitive programs. NIST groups those requirements into 17 families, from access control to supply chain risk management.

What CMMC demands as evidence
CMMC demands a score, not a policy binder. Level 1 and some Level 2 work is self-assessed and posted to the government's Supplier Performance Risk System. Higher-risk Level 2 work needs a certified third-party assessment organization to assess you against all 110 requirements. DoD expects 8,350 medium and large entities to need that certified assessment at Level 2. Certification assessments at Level 2 and Level 3 must be completed every three years, with an affirmation filed annually, so the status you certify is a living claim, not a one-off.
What it costs you to ignore it
You do not get the contract. That is the whole penalty, and it is enough. DoD estimates 337,968 unique entities are affected, including prime contractors and subcontractors, and 229,818 of them, or 68 percent, are small entities. The rule phases in over three years and applies to every eligible contract from year four, around November 2028. DoD prices the contract clause alone at about $329 million in public cost over ten years, which is the reporting overhead, before any remediation. If you subcontract into defense work, see the vetted providers on our aerospace and defense IT page.

Do you need SOC 2?
SOC 2 applies when a customer's security review blocks your deal. No statute makes SOC 2 mandatory. It is an attestation engagement performed by a CPA firm under AICPA standards, which is why it is voluntary in law and near mandatory in practice for any B2B software, data, or managed services firm selling upmarket. The enforcement mechanism is a procurement team, not a regulator.
SOC 2 is scoped against the five AICPA trust services criteria categories: security, availability, processing integrity, confidentiality, and privacy. Security is in every SOC 2. You add the others only when your contract or your product needs them, so scope is a negotiation, not a given. Two report types exist. A Type 1 describes your controls at a point in time. A Type 2 tests whether they actually operated across a period, and the AICPA illustrative Type 2 report follows the SSAE-21 reporting requirements. Enterprise buyers ask for Type 2, because a snapshot proves nothing about Tuesday.
Why the security questionnaire keeps getting harder
Buyers tightened up because vendors became the attack path. Verizon found 48 percent of breaches involved a third party in its 2026 report, a 60 percent rise in a single year, and vulnerability exploitation is now the top initial access vector at 31 percent of breaches. Every enterprise security team read the same number. That is why the questionnaire you got last quarter is longer than the one you got two years ago, and why a Type 2 report now shortens a sales cycle more reliably than a case study.

How much do HIPAA, CMMC, and SOC 2 overlap?
The controls overlap heavily. The evidence does not, and that gap is where most compliance budgets get wasted. All three want the same technical core: access control, multi-factor authentication, encryption in transit and at rest, centralized logging, vulnerability management, an incident response plan, security awareness training, and vendor oversight. Build that core once and you have most of the work behind all three.
What differs is the proof each one accepts. HIPAA wants a current risk analysis, a signed business associate agreement for every vendor, and documented policies you can show an investigator. CMMC wants a numeric score against 110 named requirements posted in a government system and, at higher levels, confirmed by a licensed assessor. SOC 2 wants a CPA opinion covering a period of operation, evidenced by sampled tickets, screenshots, and logs. One control set, three evidence packages.
Buy the controls once. Budget for the evidence three times.

The practical consequence is scheduling. If you know two frameworks are coming, sequence the evidence work so a single logging change or access review serves all of them, and pick tooling that exports in more than one format. Firms that treat each framework as a separate project pay for the same control three times and still miss the deadline that mattered. You comply once. You prove it three ways.
Who audits you, how often, and what does it cost?
Each framework uses a different auditor on a different clock. Two of the three end in a third-party audit you can hand to a customer. HIPAA does not, and that surprises most first-time buyers.
- <strong>HIPAA.</strong> No certificate exists and no auditor signs you off. HHS Office for Civil Rights investigates after a complaint or a reported breach. Your protection is a current risk analysis and the ability to show you acted on it. Penalty tiers run to $2,190,294 in a calendar year.
- <strong>CMMC.</strong> A certified third-party assessment organization runs the Level 2 and Level 3 assessment, repeated every three years, with an annual affirmation in between. Self-assessment is allowed only where the contract permits it.
- <strong>SOC 2.</strong> A licensed CPA firm performs the examination. Most companies repeat the Type 2 every 12 months, because customers reject a report with a stale period.
Direct costs vary too much by scope for a single honest number, so budget by driver instead: the size of the environment you must protect, how much you already monitor, and how much remediation the first gap assessment finds. The one figure worth anchoring on is the downside. Ransomware appeared in 88 percent of breaches at small and medium businesses in Verizon's data, with a median ransom payment of $115,000. Compliance work is not insurance, but it forces the controls that keep that number from being your number.

Which five questions settle it?
Answer these five questions in order and you will know exactly which compliance framework applies to you.
- <strong>Question 1.</strong> Does any system you own hold, move, or back up patient data for a provider, plan, or clearinghouse? If yes, you are a business associate and HIPAA applies. Subcontractors count too.
- <strong>Question 2.</strong> Does any contract or purchase order reference DFARS, FAR 52.204-21, or controlled unclassified information? If yes, CMMC applies at the level your contract names. The clause has been enforceable since November 10, 2025.
- <strong>Question 3.</strong> Has a prospect or customer sent you a security questionnaire, a vendor risk assessment, or a request for a SOC 2 report in the last 12 months? If yes, SOC 2 is now a revenue requirement.
- <strong>Question 4.</strong> Did you answer yes more than once? Then plan one control program with separate evidence tracks, and do not run three projects.
- <strong>Question 5.</strong> Did you answer no to all three? Then adopt a baseline anyway. Start with the 15 safeguarding requirements in FAR 52.204-21, which is a short, sensible floor for any small business.
Write the answers down with the contract or customer name beside each yes. That one page is the scope document every provider will ask for, and it is the difference between a fixed-price quote and an open-ended one.
What should you hand your MSP once you know the answer?
Hand your provider the trigger, the deadline, and the evidence format. Vague briefs like "help us get compliant" produce vague invoices. Specific briefs produce scoped work.
- <strong>Name the framework and the level.</strong> CMMC Level 2, HIPAA as a business associate, SOC 2 Type 2 on the security category only.
- <strong>Name the deadline.</strong> A contract award date, a renewal, or a customer's go-live.
- <strong>Name the scope.</strong> Which systems hold the regulated data, and which do not.
- <strong>Ask who signs.</strong> Confirm whether the provider will assess, remediate, monitor, or all three, and who supplies the evidence at audit time.
- <strong>Ask for references.</strong> A provider that has taken a client through your exact framework will say so in one sentence.
Compliance rarely arrives alone. Most firms are also deciding whether to keep the work in-house, which our managed IT vs in-house IT comparison covers, or to split it, which is what co-managed IT is for. Before you sign, run the checks in how to choose a managed service provider and price the retainer against the benchmarks in how much managed IT services cost. Being compliant and being secure are related, not identical, and a good provider will tell you where they diverge.
FAQ
Do I need SOC 2 if I am already HIPAA compliant?
Possibly, because they answer different audiences. HIPAA is federal law enforced by HHS after a complaint or breach, with penalties reaching $2,190,294 in a calendar year. SOC 2 is a voluntary CPA attestation your customers ask for. HIPAA compliance does not satisfy a buyer who wants a SOC 2 Type 2 report.
Does CMMC apply to subcontractors?
Yes. CMMC flows down whenever a subcontract sends federal contract information or controlled unclassified information to your systems. DoD estimates 337,968 unique entities are affected, including primes and subcontractors, and 229,818 of those are small entities. Your prime contractor will require your CMMC status before it awards the work.
What happens if you ignore HIPAA?
HHS Office for Civil Rights can impose civil money penalties from $145 per violation up to a $2,190,294 calendar-year cap, scaled by how much you knew and whether you corrected it. You must still notify affected individuals within 60 calendar days of discovery, which is usually how an investigation starts in the first place.
Is SOC 2 a certification?
No. SOC 2 is an attestation report issued by a CPA firm, not a certificate from a standards body. It covers the five trust services criteria categories, with security always in scope. A Type 1 describes controls at one point in time, while a Type 2 tests whether they operated over a period.
Which compliance framework should a small business start with?
Start with whichever one a contract or a customer already forces. If none applies yet, adopt the 15 basic safeguarding requirements in FAR 52.204-21 as a baseline. They cover access control, multi-factor authentication, patching, and backups, and they map cleanly onto the 110 requirements in NIST SP 800-171 later.
Sources
- U.S. GovInfo / Federal Register, DFARS Final Rule: Assessing Contractor Implementation of Cybersecurity Requirements, DFARS Case 2019-D041 (10 September 2025, effective 10 November 2025)
- U.S. GovInfo / Federal Register, Cybersecurity Maturity Model Certification (CMMC) Program Final Rule, 32 CFR Part 170 (15 October 2024)
- U.S. GovInfo / Federal Register, HHS Annual Civil Monetary Penalties Inflation Adjustment, 45 CFR 160.404 HIPAA penalty table (28 January 2026)
- Cornell Law School Legal Information Institute, 45 CFR 160.103, definition of business associate
- Cornell Law School Legal Information Institute, 45 CFR 164.404, HIPAA notification to individuals
- Cornell Law School Legal Information Institute, 45 CFR 164.408, HIPAA notification to the Secretary
- AICPA & CIMA, 2017 Trust Services Criteria (with revised points of focus, 2022)
- AICPA & CIMA, Illustrative Service Auditor's SOC 2 Type 2 Report (SSAE-21)
- Verizon, 2026 Data Breach Investigations Report (news release, May 2026)
- Verizon, 2025 Data Breach Investigations Report (news release, April 2025)
- IBM, Cost of a Data Breach Report 2026 (news release, 29 July 2026)
- NIST, SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (May 2024)
- Acquisition.gov, FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- AICPA & CIMA, SOC 2, SOC Suite of Services for service organizations
Best IT MSP is the independent, merit-ranked directory of managed IT and security providers across North America. Compare firms in your city by rating and verified data, filter for the compliance work you actually need, and shortlist three in minutes. Free to browse, and paid placement is always labelled.