Think you're being hit by ransomware right now? Don't panic — start here →
Already a safemode IT client? Call our 24/7 Security Operations Center immediately: 512-761-7652, Option 1
COMPLIANCE RESOURCES

Compliance isn't just a big-company problem.

If you touch health records, credit cards, loan or financial data, or you're a Texas appraisal district, a specific framework probably already applies to you — whether or not anyone's told you. Here's each one in plain English, and who it actually applies to.

QUICK LOOKUP

Which one applies to me?

If you...This likely applies
Run any business at allNIST CSF 2.0 (voluntary baseline) and Texas's SB 2610 safe harbor
Handle health records (providers, plans, business associates)HIPAA Security Rule
Accept credit or debit card paymentsPCI-DSS 4.0.1
Extend credit, arrange financing, or otherwise qualify as a "financial institution" under FTC rules (incl. many auto dealers, mortgage brokers, tax preparers)FTC Safeguards Rule (GLBA)
Are a Texas appraisal district or connected government entityTexas Cybersecurity Framework / TAC 202
Are a broker-dealer, investment adviser, or other FINRA member firmFINRA Small Firm Cybersecurity Checklist
Sell cloud or SaaS services to a Texas state agency, public university, or community collegeTX-RAMP certification

NIST Cybersecurity Framework 2.0

Who it's for: Every business, of any size. It's voluntary and free, and increasingly the reference point other laws point back to — including Texas's own safe harbor law.

It organizes your security program into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. See the full breakdown on our Prepare for an Attack page.

HIPAA Security Rule

Who it's for: Healthcare providers, health plans, and any "business associate" that handles protected health information (PHI) on their behalf — including many IT and billing vendors.

The Security Rule requires administrative, physical, and technical safeguards around electronic PHI. A significant update to the rule has been proposed that would make protections like multi-factor authentication, encryption, and a current technology asset inventory explicit requirements rather than "addressable" suggestions — small practices should plan for stricter, more specific expectations rather than wait for final language.

FTC Safeguards Rule (Gramm-Leach-Bliley Act)

Who it's for: "Financial institutions" as the FTC defines them — a broader category than banks, and one that can include auto dealers who arrange financing, mortgage and loan brokers, tax preparation services, and others handling customer financial data.

Covered businesses must maintain a written information security program built around nine elements:

1
Designate a Qualified Individual to run the program.
2
Conduct a written risk assessment.
3
Design and implement safeguards (access control, encryption, MFA, and more).
4
Monitor and test effectiveness regularly.
5
Train staff, with regular refreshers.
6
Oversee service providers contractually.
7
Keep the program current as risks change.
8
Maintain a written incident response plan.
9
Report to leadership at least annually.

PCI-DSS 4.0.1

Who it's for: Any business that accepts, processes, transmits, or stores credit or debit card data — regardless of size. Version 4.0.1 is now fully in effect, with all previously future-dated requirements mandatory as of the 2025 enforcement deadline.

Twelve requirement families cover everything from network security to access control to logging. The single biggest lever most small businesses have is reducing scope: using a PCI-compliant payment processor (so card data never touches your own network) can shrink your obligations down to the simplest self-assessment questionnaire.

Texas Cybersecurity Framework / TAC 202

Who it's for: Texas appraisal districts and other governmental entities covered under Texas Administrative Code Title 1, Chapter 202. It sets baseline security control requirements modeled on recognized frameworks like NIST.

FINRA Cybersecurity Program Requirements

Who it's for: Broker-dealers, investment advisers, and other FINRA member firms — including small, independent offices, not just large brokerages.

FINRA publishes a free Small Firm Cybersecurity Checklist built around the same five NIST functions this site uses (Identify, Protect, Detect, Respond, Recover). It's a self-assessment tool, not a certification — but examiners routinely ask small firms to show something like it exists.

TX-RAMP (Texas Risk and Authorization Management Program)

Who it's for: Cloud and SaaS vendors — of any size — that want to sell to Texas state agencies, public universities, or community colleges. It's Texas's version of FedRAMP: a one-time, reusable security certification for cloud services, administered by the Texas Department of Information Resources (DIR).

Most small businesses will never need this. It matters if you're a software/MSP vendor bidding on Texas government or higher-ed contracts, or a small business buying software from a vendor who hasn't gotten certified yet (state customers legally can't use uncertified cloud products past their provisional window).

NOT SURE WHICH FRAMEWORK APPLIES TO YOU?

Get a free compliance gap conversation.

We'll help you figure out what actually applies to your business and where the real gaps are — no jargon, no pressure.