← All Blogs

HIPAA vs CMMC vs SOC 2: Which Compliance Framework Does Your Business Actually Need?

Your trigger decides, not your industry. HIPAA applies when you touch protected health information, including as a vendor. CMMC applies when a Department of Defense contract sends you controlled unclassified information. SOC 2 applies when customers demand proof before they buy. They stack. Many firms need two or three at once.

Three compliance triggers: protected health information triggers HIPAA, controlled unclassified information triggers CMMC, customer demand triggers SOC 2
Three compliance triggers: protected health information triggers HIPAA, controlled unclassified information triggers CMMC, customer demand triggers SOC 2
Key takeaways
  • Three different triggers, not three options. Patient data triggers HIPAA, defense data triggers CMMC, customer demand triggers SOC 2.
  • HIPAA is federal law, CMMC is a contract term, and SOC 2 is a sales requirement with no regulator behind it.
  • HIPAA reaches vendors. A business associate, and any subcontractor it hires, is directly liable under the rule.
  • CMMC Level 2 covers 110 security requirements, needs a certification assessment every three years, and an affirmation every year.
  • The controls overlap heavily. The evidence does not, which is where most compliance budgets get wasted.

How did we compare HIPAA, CMMC and SOC 2?

By what triggers each one, not by which is strictest. These three are not competing standards you choose between, and treating them as a ranked list is the mistake this article exists to correct.

The table states all three triggers side by side. If more than one row applies to you, the answer is not to pick one.

Which compliance framework do you actually need?

Your trigger decides, not your industry. You need HIPAA when your business creates, receives, maintains, or transmits protected health information. You need CMMC when a Department of Defense contract pushes federal contract information or controlled unclassified information down to you. You need SOC 2 when your own customers refuse to buy until you hand them independent proof that your controls work. Those are three different questions with three different answers, so answer each one separately.

HIPAA, CMMC and SOC 2 compared by trigger, enforcer, verification and consequence
DimensionHIPAACMMCSOC 2
What triggers itTouching protected health information, including as a vendorA Department of Defense contract sending you controlled unclassified informationA customer's security questionnaire
Who enforces itHHS Office for Civil RightsThe Department of Defense, through the contractNobody; the market does
How it is verifiedNo certificate exists; investigated after a complaint or breachAssessed before award, and repeatedAn examination by a licensed CPA firm
What non-compliance costsCivil monetary penalties after the factNo valid status, no contractA lost deal

These frameworks are not alternatives. A healthcare software company that sells to hospitals and holds one defense subcontract needs all three at once. Each one is triggered by a different fact about your business: the data you hold, the contract you signed, and the customer you want. This guide is the decision. If you already know which framework applies and want the how, read our cybersecurity compliance guide next.

The money argues for getting this right early. IBM puts the global average cost of a data breach at $4.99 million in 2026, and one in four malicious breaches is now AI-enabled at an average of $6 million. Compliance work does not make you breach-proof. It does force the controls that shorten the damage, and it keeps a bad week from becoming a regulatory case or a cancelled contract.

Three compliance triggers: protected health information triggers HIPAA, controlled unclassified information triggers CMMC, customer demand triggers SOC 2
Three compliance triggers: protected health information triggers HIPAA, controlled unclassified information triggers CMMC, customer demand triggers SOC 2

Do you need HIPAA?

HIPAA applies the moment you handle protected health information on behalf of a covered entity, even if you are not a clinic, a hospital, or an insurer. The rule reaches vendors through the business associate definition, which covers anyone who creates, receives, maintains, or transmits protected health information for a regulated function, including a subcontractor hired by that business associate. That single clause pulls in managed IT providers, billing companies, cloud hosts, shredding firms, and the software vendors sitting behind them.

What HIPAA demands as evidence

HIPAA asks for documented process, not a certificate. You maintain a written risk analysis, you sign a business associate agreement with every vendor that touches the data, you set access control and audit logging, you encrypt what you can, and you keep an incident response plan you have actually tested. Breach timing is written into the rule, so you report on its clock, not yours. You must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, and a breach affecting 500 or more people goes to the Secretary at the same time as the individual notices.

What it costs you to ignore it

HIPAA penalties scale with how much you knew and whether you fixed it. The current inflation-adjusted civil money penalties run from $145 per violation at the lowest tier to $73,011 per violation, with a calendar-year cap of $2,190,294 for repeat violations of the same requirement. Willful neglect that you do not correct within 30 days starts at $73,011 per violation. Enforcement usually arrives after a complaint or a reported breach, so the trigger for an investigation is often the incident you were hoping nobody would notice. Healthcare buyers can compare vetted providers on our healthcare IT services page.

HIPAA civil money penalties run from 145 dollars per violation to 2,190,294 dollars in a calendar year
HIPAA civil money penalties run from 145 dollars per violation to 2,190,294 dollars in a calendar year

Do you need CMMC?

CMMC applies when a Department of Defense contract flows federal contract information or controlled unclassified information onto your systems. Your industry does not decide this. Your contract does. The requirement became contractual on November 10, 2025, when the DoD acquisition rule took effect, and the clause is checked before award rather than after an incident.

Your contract names the level you must hit, and there are three. Level 1 covers the 15 basic safeguarding requirements in FAR clause 52.204-21, the floor for federal contract information such as drawings, statements of work, and delivery schedules that are not public. Level 2 covers the 110 security requirements in NIST SP 800-171, the standard set for controlled unclassified information. Level 3 adds 24 selected requirements from NIST SP 800-172 for the most sensitive programs. NIST groups those requirements into 17 families, from access control to supply chain risk management.

CMMC Level 1 covers 15 requirements, Level 2 covers 110, and Level 3 adds 24 more
CMMC Level 1 covers 15 requirements, Level 2 covers 110, and Level 3 adds 24 more

What CMMC demands as evidence

CMMC demands a score, not a policy binder. Level 1 and some Level 2 work is self-assessed and posted to the government's Supplier Performance Risk System. Higher-risk Level 2 work needs a certified third-party assessment organization to assess you against all 110 requirements. DoD expects 8,350 medium and large entities to need that certified assessment at Level 2. Certification assessments at Level 2 and Level 3 must be completed every three years, with an affirmation filed annually, so the status you certify is a living claim, not a one-off.

What it costs you to ignore it

You do not get the contract. That is the whole penalty, and it is enough. DoD estimates 337,968 unique entities are affected, including prime contractors and subcontractors, and 229,818 of them, or 68 percent, are small entities. The rule phases in over three years and applies to every eligible contract from year four, around November 2028. DoD prices the contract clause alone at about $329 million in public cost over ten years, which is the reporting overhead, before any remediation. If you subcontract into defense work, see the vetted providers on our aerospace and defense IT page.

DoD estimates 337,968 entities are affected by CMMC and 68 percent of them are small entities
DoD estimates 337,968 entities are affected by CMMC and 68 percent of them are small entities

Do you need SOC 2?

SOC 2 applies when a customer's security review blocks your deal. No statute makes SOC 2 mandatory. It is an attestation engagement performed by a CPA firm under AICPA standards, which is why it is voluntary in law and near mandatory in practice for any B2B software, data, or managed services firm selling upmarket. The enforcement mechanism is a procurement team, not a regulator.

SOC 2 is scoped against the five AICPA trust services criteria categories: security, availability, processing integrity, confidentiality, and privacy. Security is in every SOC 2. You add the others only when your contract or your product needs them, so scope is a negotiation, not a given. Two report types exist. A Type 1 describes your controls at a point in time. A Type 2 tests whether they actually operated across a period, and the AICPA illustrative Type 2 report follows the SSAE-21 reporting requirements. Enterprise buyers ask for Type 2, because a snapshot proves nothing about Tuesday.

Why the security questionnaire keeps getting harder

Buyers tightened up because vendors became the attack path. Verizon found 48 percent of breaches involved a third party in its 2026 report, a 60 percent rise in a single year, and vulnerability exploitation is now the top initial access vector at 31 percent of breaches. Every enterprise security team read the same number. That is why the questionnaire you got last quarter is longer than the one you got two years ago, and why a Type 2 report now shortens a sales cycle more reliably than a case study.

48 percent of breaches involved a third party in the 2026 Verizon DBIR
48 percent of breaches involved a third party in the 2026 Verizon DBIR

How much do HIPAA, CMMC, and SOC 2 overlap?

The controls overlap heavily. The evidence does not, and that gap is where most compliance budgets get wasted. All three want the same technical core: access control, multi-factor authentication, encryption in transit and at rest, centralized logging, vulnerability management, an incident response plan, security awareness training, and vendor oversight. Build that core once and you have most of the work behind all three.

What differs is the proof each one accepts. HIPAA wants a current risk analysis, a signed business associate agreement for every vendor, and documented policies you can show an investigator. CMMC wants a numeric score against 110 named requirements posted in a government system and, at higher levels, confirmed by a licensed assessor. SOC 2 wants a CPA opinion covering a period of operation, evidenced by sampled tickets, screenshots, and logs. One control set, three evidence packages.

Buy the controls once. Budget for the evidence three times.

One control set but three evidence packages: a risk analysis for HIPAA, a score for CMMC, and a CPA opinion for SOC 2
One control set but three evidence packages: a risk analysis for HIPAA, a score for CMMC, and a CPA opinion for SOC 2

The practical consequence is scheduling. If you know two frameworks are coming, sequence the evidence work so a single logging change or access review serves all of them, and pick tooling that exports in more than one format. Firms that treat each framework as a separate project pay for the same control three times and still miss the deadline that mattered. You comply once. You prove it three ways.

Who audits you, how often, and what does it cost?

Each framework uses a different auditor on a different clock. Two of the three end in a third-party audit you can hand to a customer. HIPAA does not, and that surprises most first-time buyers.

Direct costs vary too much by scope for a single honest number, so budget by driver instead: the size of the environment you must protect, how much you already monitor, and how much remediation the first gap assessment finds. The one figure worth anchoring on is the downside. Ransomware appeared in 88 percent of breaches at small and medium businesses in Verizon's data, with a median ransom payment of $115,000. Compliance work is not insurance, but it forces the controls that keep that number from being your number.

Audit cadence: HIPAA has no certificate, CMMC requires certification every three years, SOC 2 is repeated annually
Audit cadence: HIPAA has no certificate, CMMC requires certification every three years, SOC 2 is repeated annually

Which five questions settle it?

Answer these five questions in order and you will know exactly which compliance framework applies to you.

Write the answers down with the contract or customer name beside each yes. That one page is the scope document every provider will ask for, and it is the difference between a fixed-price quote and an open-ended one.

What should you hand your MSP once you know the answer?

Hand your provider the trigger, the deadline, and the evidence format. Vague briefs like "help us get compliant" produce vague invoices. Specific briefs produce scoped work.

Compliance rarely arrives alone. Most firms are also deciding whether to keep the work in-house, which our managed IT vs in-house IT comparison covers, or to split it, which is what co-managed IT is for. Before you sign, run the checks in how to choose a managed service provider and price the retainer against the benchmarks in how much managed IT services cost. Being compliant and being secure are related, not identical, and a good provider will tell you where they diverge.

FAQ

Do I need SOC 2 if I am already HIPAA compliant?

Possibly, because they answer different audiences. HIPAA is federal law enforced by HHS after a complaint or breach, with penalties reaching $2,190,294 in a calendar year. SOC 2 is a voluntary CPA attestation your customers ask for. HIPAA compliance does not satisfy a buyer who wants a SOC 2 Type 2 report.

Does CMMC apply to subcontractors?

Yes. CMMC flows down whenever a subcontract sends federal contract information or controlled unclassified information to your systems. DoD estimates 337,968 unique entities are affected, including primes and subcontractors, and 229,818 of those are small entities. Your prime contractor will require your CMMC status before it awards the work.

What happens if you ignore HIPAA?

HHS Office for Civil Rights can impose civil money penalties from $145 per violation up to a $2,190,294 calendar-year cap, scaled by how much you knew and whether you corrected it. You must still notify affected individuals within 60 calendar days of discovery, which is usually how an investigation starts in the first place.

Is SOC 2 a certification?

No. SOC 2 is an attestation report issued by a CPA firm, not a certificate from a standards body. It covers the five trust services criteria categories, with security always in scope. A Type 1 describes controls at one point in time, while a Type 2 tests whether they operated over a period.

Which compliance framework should a small business start with?

Start with whichever one a contract or a customer already forces. If none applies yet, adopt the 15 basic safeguarding requirements in FAR 52.204-21 as a baseline. They cover access control, multi-factor authentication, patching, and backups, and they map cleanly onto the 110 requirements in NIST SP 800-171 later.

Sources

Know your framework? Find a provider who has done it before.

Best IT MSP is the independent, merit-ranked directory of managed IT and security providers across North America. Compare firms in your city by rating and verified data, filter for the compliance work you actually need, and shortlist three in minutes. Free to browse, and paid placement is always labelled.

Browse Vetted Providers

← All Blogs