Cybersecurity Services
Compliance & Risk Management Services
PCI DSS, HIPAA, SOC 2, ISO 27001, NIST and CMMC all moved in the last eighteen months. iFlock’s certified experts translate the standard that applies to you into a practical plan, then work alongside your team until you can prove you meet it — not just claim it.
Schedule a consultationSee which frameworks applyWhy compliance keeps moving
Compliance used to be an annual event. It isn’t anymore. Four of the frameworks small and mid-sized businesses get asked about most have changed since the start of 2025, and the direction of travel is the same in all of them: continuous evidence instead of a once-a-year snapshot.
The standards themselves changed
PCI DSS v4.x ended its grace period. Of the 64 new requirements introduced in version 4.0, 51 were future-dated and became mandatory on 31 March 2025 — they are no longer “best practice,” they are assessed. Our PCI compliance team can tell you which of them touch your environment.Source: PCI Security Standards Council
ISO 27001:2013 certificates stopped being valid after 31 October 2025. The 2022 revision, with its restructured Annex A, is the only current version — if your certificate predates the transition, you are starting a fresh cycle, not renewing one.
CMMC entered live DoD contracts on 10 November 2025 under the 48 CFR final rule. If you sit anywhere in the defense supply chain, the requirement now arrives through the contract clause rather than as guidance, and it has to be maintained and annually affirmed for the life of that contract.Source: 48 CFR CMMC final rule, published 10 September 2025
HIPAA is next. The proposed Security Rule overhaul — the first since 2013 — would make multi-factor authentication, encryption of ePHI at rest and in transit, an annually reviewed asset inventory, six-monthly vulnerability scans and annual penetration testing explicit requirements. The final rule is now targeted for 2027, which makes the next eighteen months the cheap time to prepare.Source: HHS Notice of Proposed Rulemaking, 6 January 2025; 2026 Unified Agenda
Auditors want evidence, not intentions
A policy document proves you wrote a policy. What an assessor asks for is the log, the ticket, the scan result and the sign-off that show the control actually ran. Most failed assessments we see are not security failures — they are evidence failures. That is the gap our audit readiness work is built to close, and why we pair it with continuous vulnerability management rather than a point-in-time scan.
Your insurer is auditing you too
Cyber liability carriers now underwrite on controls. MFA everywhere, endpoint detection and response, tested backups, logging and a real incident response plan are table stakes on the application form — and an inaccurate answer is the kind of thing that gets a claim contested later. We help you answer the questionnaire honestly, and fix what the honest answer exposes.
Compliance is the floor, not the ceiling
Meeting a standard proves you cleared a baseline on a given day. Real attackers do not care about your certificate. So we build the compliance programme and the actual security at the same time — penetration testing, remediation and monitoring included — so the effort protects the business as well as the certification.
Schedule a consultation
PCI DSS v4.x requirements that stopped being optional on 31 March 2025PCI Security Standards Council
of breaches now start with an exploited vulnerability — the top initial access vectorVerizon 2026 Data Breach Investigations Report
since the HIPAA Security Rule was last meaningfully updated; the overhaul is targeted for 2027HHS / 2026 Unified Agenda
frameworks handled under one programme, by one team that knows your environmentiFlock Security Consulting
What we cover
Frameworks we help you meet
Not sure which of these apply to your business? That is the first thing we work out together.
PCI DSS v4.x
If you store, process or transmit card data, this one is not optional — and all 64 of the version 4 requirements are now in force. We scope your cardholder data environment, close the gaps and get you to the right validation path. PCI compliance and testing →
HIPAA
For covered entities and their business associates. We build the risk analysis, safeguards and documentation the Security Rule already requires — and get you ahead of the MFA, encryption and testing requirements in the proposed update.
SOC 2
The report your enterprise customers ask for before they will sign. We define the scope and trust services criteria, build the controls and prepare the evidence so the auditor’s fieldwork is short.
ISO 27001:2022
The international standard for an information security management system. Since 2013-version certificates expired on 31 October 2025, the 2022 revision is the only route — we build the ISMS, the risk treatment plan and the Statement of Applicability.
NIST & CMMC
For federal and defense supply chain work. NIST SP 800-171 controls, a scored self-assessment, a POA&M and the evidence to support the annual affirmation CMMC now requires under contract.
Cyber insurance readiness
Carriers underwrite on controls now. We map your environment against what the application form actually asks — MFA, EDR, tested backups, logging, incident response — so your answers are accurate and your premium reflects reality.
How we work
What a compliance and risk engagement looks like
Risk assessment
We identify, measure and rank the risks specific to your business, your data and your industry. Every framework is built on this, so it comes first.
Gap analysis
We compare where you are today against the standard you have to meet, and hand you a prioritised roadmap rather than a list of 400 findings.
Remediation
We help your team actually close the gaps — policy, configuration and control work — instead of documenting them and walking away.
Audit readiness
We assemble the evidence, rehearse the questions and prepare your people so the assessment goes smoothly the first time. More on audit readiness →
Ongoing compliance
Continuous monitoring, scheduled scans and annual attestation support, so the next cycle is maintenance instead of another scramble.
Common questions
Compliance and risk management FAQs
Which compliance frameworks does my business actually need?
It depends on what data you handle and who you sell to. Card data means PCI DSS. Protected health information means HIPAA. Enterprise customers usually ask for SOC 2, international ones for ISO 27001, and defense contracts now carry CMMC. Most businesses need one or two, not all of them — working that out is the first conversation we have.
Is iFlock a PCI Qualified Security Assessor?
No. We prepare you for assessment and work alongside your QSA — or recommend one — rather than issuing your Report on Compliance ourselves. That separation is deliberate: it keeps the readiness work honest.
How long does it take to become audit-ready?
It depends on your starting point and the framework, which is why we begin with a gap analysis rather than a quote. That assessment gives you a realistic timeline and a prioritised roadmap before you commit to anything.
Does being compliant mean we are secure?
No. Compliance proves you cleared a baseline on a given day. That is why we pair every compliance programme with real security work — vulnerability management, penetration testing and remediation — so the controls hold up between assessments.
Can you help us qualify for cyber insurance?
Yes. We map your environment against what carriers ask for, tell you honestly where you fall short, and help you close those gaps — which is what gets a claim paid, not just a policy issued.
Do you work with small and mid-sized businesses?
That is most of our work. We are a boutique firm, so you get senior practitioners who learn your environment rather than a rotating cast of junior analysts working from a checklist.
Let’s map your path to compliance
Book a no-obligation consultation and we will help you identify which frameworks apply to your business, where you stand against them today, and what it will realistically take to get there.
Schedule a consultation