Compliance isn't just a big-company problem.
If you touch health records, credit cards, loan or financial data, or you're a Texas appraisal district, a specific framework probably already applies to you — whether or not anyone's told you. Here's each one in plain English, and who it actually applies to.
Which one applies to me?
| If you... | This likely applies |
|---|---|
| Run any business at all | NIST CSF 2.0 (voluntary baseline) and Texas's SB 2610 safe harbor |
| Handle health records (providers, plans, business associates) | HIPAA Security Rule |
| Accept credit or debit card payments | PCI-DSS 4.0.1 |
| Extend credit, arrange financing, or otherwise qualify as a "financial institution" under FTC rules (incl. many auto dealers, mortgage brokers, tax preparers) | FTC Safeguards Rule (GLBA) |
| Are a Texas appraisal district or connected government entity | Texas Cybersecurity Framework / TAC 202 |
| Are a broker-dealer, investment adviser, or other FINRA member firm | FINRA Small Firm Cybersecurity Checklist |
| Sell cloud or SaaS services to a Texas state agency, public university, or community college | TX-RAMP certification |
NIST Cybersecurity Framework 2.0
Who it's for: Every business, of any size. It's voluntary and free, and increasingly the reference point other laws point back to — including Texas's own safe harbor law.
It organizes your security program into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. See the full breakdown on our Prepare for an Attack page.
HIPAA Security Rule
Who it's for: Healthcare providers, health plans, and any "business associate" that handles protected health information (PHI) on their behalf — including many IT and billing vendors.
The Security Rule requires administrative, physical, and technical safeguards around electronic PHI. A significant update to the rule has been proposed that would make protections like multi-factor authentication, encryption, and a current technology asset inventory explicit requirements rather than "addressable" suggestions — small practices should plan for stricter, more specific expectations rather than wait for final language.
FTC Safeguards Rule (Gramm-Leach-Bliley Act)
Who it's for: "Financial institutions" as the FTC defines them — a broader category than banks, and one that can include auto dealers who arrange financing, mortgage and loan brokers, tax preparation services, and others handling customer financial data.
Covered businesses must maintain a written information security program built around nine elements:
PCI-DSS 4.0.1
Who it's for: Any business that accepts, processes, transmits, or stores credit or debit card data — regardless of size. Version 4.0.1 is now fully in effect, with all previously future-dated requirements mandatory as of the 2025 enforcement deadline.
Twelve requirement families cover everything from network security to access control to logging. The single biggest lever most small businesses have is reducing scope: using a PCI-compliant payment processor (so card data never touches your own network) can shrink your obligations down to the simplest self-assessment questionnaire.
Texas Cybersecurity Framework / TAC 202
Who it's for: Texas appraisal districts and other governmental entities covered under Texas Administrative Code Title 1, Chapter 202. It sets baseline security control requirements modeled on recognized frameworks like NIST.
FINRA Cybersecurity Program Requirements
Who it's for: Broker-dealers, investment advisers, and other FINRA member firms — including small, independent offices, not just large brokerages.
FINRA publishes a free Small Firm Cybersecurity Checklist built around the same five NIST functions this site uses (Identify, Protect, Detect, Respond, Recover). It's a self-assessment tool, not a certification — but examiners routinely ask small firms to show something like it exists.
TX-RAMP (Texas Risk and Authorization Management Program)
Who it's for: Cloud and SaaS vendors — of any size — that want to sell to Texas state agencies, public universities, or community colleges. It's Texas's version of FedRAMP: a one-time, reusable security certification for cloud services, administered by the Texas Department of Information Resources (DIR).
Most small businesses will never need this. It matters if you're a software/MSP vendor bidding on Texas government or higher-ed contracts, or a small business buying software from a vendor who hasn't gotten certified yet (state customers legally can't use uncertified cloud products past their provisional window).
Get a free compliance gap conversation.
We'll help you figure out what actually applies to your business and where the real gaps are — no jargon, no pressure.