s90

Compliance

Find out which rules apply to you, and how you'll prove you meet them.

Pick your industry to see which rules usually apply, which apply only in certain situations, and which framework fits. Every quarter, a Compliance Posture Report for each framework shows the evidence without you having to ask.

A row of matching archive boxes with muted colored labels on an oak shelf, with one box taken down and opened on the table in front.

s90 runs the security controls that rules like SEC Regulation S-P, GLBA, the FTC Safeguards Rule, HIPAA and NIST SP 800-171 call for, keeps the documentation current, and sends a Compliance Posture Report for each framework every quarter showing the evidence. We work out which rules apply to you before anything is set up. The person in charge of compliance at your organization decides whether you're compliant.

What kind of organization are you?

For Financial Services

Your regulators expect proof. Which rules apply depends on what your firm does.

Your clients' financial information comes with rules attached: how it's protected, who can see it, and what happens if it's ever exposed.

Common for financial services firms

Add the ones that apply to your firm.

SEC Regulation S-P

Regulated

The SEC's rule for protecting your clients' personal information, including how you respond and notify clients when it's exposed (Regulation S-P, 17 CFR 248.30).

Applies if …

you're an SEC-registered adviser, broker-dealer, investment company or transfer agent.

What it asks for →

FINRA (broker-dealer rules)

Regulated

The rules FINRA member firms follow for business continuity and supervision (FINRA Rules 4370 and 3110).

Applies if …

you're a FINRA member firm.

What it asks for →

GLBA (client financial privacy)

Regulated

The federal law that requires financial institutions, including firms that prepare tax returns, to protect their customers' personal information (Gramm-Leach-Bliley Act).

Applies if …

you hold customers' nonpublic personal information as a financial institution.

What it asks for →

FTC Safeguards Rule

Regulated

The FTC's rule for how non-bank financial institutions, including tax preparers, must secure customer information (FTC Safeguards Rule, 16 CFR Part 314).

Applies if …

you're a non-bank financial institution, such as a mortgage lender.

What it asks for →

Already included in Complete IT

Nothing extra to add.

NIST CSF 2.0

Included

A widely used framework for managing cybersecurity, organized around six functions from governance to recovery (NIST Cybersecurity Framework 2.0).

Use it to …

show your examiner and insurer one recognized program.

What it asks for →

CIS Controls

Included

A prioritized list of security safeguards, with a starting set every team should have in place (CIS Critical Security Controls).

Use it to …

show insurers and clients a clear checklist of the safeguards you have in place.

What it asks for →

Bundle discounts available.

We provide the evidence. You decide.

01

We work out what applies

On a call, before anything is set up.

02

We run the controls

The safeguards each rule calls for, with documentation kept current.

03

You get proof every quarter

A Compliance Posture Report for each framework arrives without you asking, never more than three months old.

You decide

The person in charge of compliance at your organization decides whether you're compliant.

All frameworks

Regulated

Required by a law, regulator or contract. Added if it applies to you.

Included

A recognized framework you follow by choice. Already part of Complete IT and reported in your Technology Posture Report.

FrameworkWhat it isIndustries
SEC Regulation S-P
Regulated

The SEC's rule for protecting your clients' personal information, including how you respond and notify clients when it's exposed (Regulation S-P, 17 CFR 248.30).

FINRA (broker-dealer rules)
Regulated

The rules FINRA member firms follow for business continuity and supervision (FINRA Rules 4370 and 3110).

GLBA (client financial privacy)
Regulated

The federal law that requires financial institutions, including firms that prepare tax returns, to protect their customers' personal information (Gramm-Leach-Bliley Act).

FTC Safeguards Rule
Regulated

The FTC's rule for how non-bank financial institutions, including tax preparers, must secure customer information (FTC Safeguards Rule, 16 CFR Part 314).

IRS written security plan (WISP)
Regulated

The written information security plan the IRS expects every paid tax preparer to keep (IRS Publications 4557 and 5708).

NIST CSF 2.0
Included

A widely used framework for managing cybersecurity, organized around six functions from governance to recovery (NIST Cybersecurity Framework 2.0).

CIS Controls
Included

A prioritized list of security safeguards, with a starting set every team should have in place (CIS Critical Security Controls).

NIST SP 800-171
Regulated

The controls your defense contracts already require (NIST SP 800-171, DFARS 252.204-7012).

CMMC (defense contracts)
Regulated

The Department of Defense program that verifies contractors actually meet the security requirements in their contracts (Cybersecurity Maturity Model Certification, 32 CFR Part 170).

HIPAA (health information)
Regulated

The rules that protect the health information of the people you serve (HIPAA Security Rule).

PCI DSS (card payments)
Regulated

The card security standard your payment processor requires when you accept donations by card (PCI DSS).

CCPA
Regulated

California's privacy law, which requires reasonable security for personal information and applies to firms that meet its thresholds (California Consumer Privacy Act, as amended by the CPRA).

Low-rise office buildings with tile roofs among oaks and palms in the south Orange County foothills, with Saddleback Mountain in the morning haze beyond.

For Financial Services

If an examiner asked tomorrow, could your firm show the evidence?