Fortellar
Blog

The Modern Compliance Stack

HIPAA, SOC 2, NIST CSF, ISO 27001, and ISO 42001 Explained

If you've ever sat in a vendor review and heard someone casually drop "we're SOC 2 Type II certified, ISO 27001 aligned, and NIST CSF compliant" in the same breath (and nodded politely while discreetly Googling), this post is for you.

Compliance acronyms have a way of multiplying. And as organizations face increasing scrutiny around data security, privacy, and AI governance, the list of frameworks your vendors should know about keeps growing. The good news: once you understand what each framework actually covers and why it exists, the whole alphabet soup starts to make sense.

Let's break down the five frameworks showing up most in enterprise vendor conversations right now.

Why This Matters When You're Evaluating Vendors

Before we get into the frameworks themselves, it's worth naming why compliance credentials matter in the first place. They're not just checkboxes.

When a vendor holds a compliance certification or operates within a recognized framework, it tells you something real: that an independent third party (or a rigorous internal process) has verified that the vendor is doing what they say they're doing when it comes to protecting your data, your systems, and by extension, your customers.

That's not nothing. It's actually a lot.

“When a vendor holds a compliance credential, it tells you something real: that an independent third party has verified they are doing what they say they're doing.”

HIPAA: The Healthcare Data Standard

What it is: The Health Insurance Portability and Accountability Act. A US federal law, not a certification you earn but a standard you're required to comply with if you handle certain types of health information.

Who it applies to: Any organization that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity (like a hospital, health plan, or healthcare clearinghouse). This includes a wide range of software vendors, analytics providers, and technology companies.

What it covers: HIPAA has three main rules that matter in practice. The Privacy Rule governs how PHI can be used and disclosed. The Security Rule sets standards for safeguarding electronic PHI (ePHI). The Breach Notification Rule requires that affected parties are notified when a data breach occurs.

What to look for in vendors: Ask whether they will sign a Business Associate Agreement (BAA). This is a legal contract that formalizes each party's responsibilities for protecting PHI. If a vendor balks at signing one, that's a red flag. Also ask about their encryption practices, access controls, and breach response procedures.

The bottom line: If your organization touches healthcare data in any way, the vendors you work with need to be HIPAA-aware. There's no certification badge here, but there is legal exposure for everyone in the chain.

SOC 2: The Trust Standard for Technology Companies

What it is: A reporting framework developed by the American Institute of Certified Public Accountants (AICPA). SOC 2 evaluates how a service organization manages customer data based on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Who it applies to: Primarily SaaS companies, cloud providers, and any technology vendor that stores, processes, or transmits customer data.

What it covers: SOC 2 audits examine whether a vendor has the right controls in place around data security and operational risk. A Type I report is a point-in-time snapshot of controls design. A Type II report (the one you actually want to see) covers how those controls operated over a period of time, typically six to twelve months.

What to look for in vendors: Ask for the SOC 2 Type II report, not just confirmation that one exists. Look at the audit period, the scope (which Trust Services Criteria were included), and whether there were any exceptions noted by the auditor. Exceptions aren't automatically disqualifying, but they should come with explanations and remediation plans.

The bottom line: SOC 2 Type II is the baseline trust credential for most enterprise technology vendors. If a vendor can't provide one, ask why and factor that into your risk assessment.

NIST CSF: The Cybersecurity Roadmap

What it is: The National Institute of Standards and Technology (NIST) Cybersecurity Framework. Unlike HIPAA and SOC 2, it's not a compliance requirement or a certification. It's a voluntary framework organizations use to understand, manage, and reduce cybersecurity risk.

Who it applies to: Originally developed for critical infrastructure sectors, but now widely adopted across industries. If a vendor says they're "aligned with NIST CSF," it means they've used the framework to organize and assess their security program.

What it covers: The current version (CSF 2.0, released in 2024) is organized around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. These map to the full lifecycle of cybersecurity risk management, from understanding what assets you have and what threatens them to recovering quickly when something goes wrong.

What to look for in vendors: NIST CSF alignment is a signal of security program maturity. Ask vendors which Implementation Tier they operate at (these run from Partial to Adaptive) and how they use the framework to drive continuous improvement. Since there's no independent audit, the value is in the conversation: can they articulate their security posture clearly?

The bottom line: NIST CSF isn't a certification, but it's a serious framework used by serious organizations. Vendors who reference it meaningfully (not just name-drop it) tend to have well-structured security programs.

ISO 27001: The International Gold Standard for Information Security

What it is: An internationally recognized standard for Information Security Management Systems (ISMS), published by the International Organization for Standardization. This one comes with a real certification, issued by accredited third-party auditors.

Who it applies to: Organizations of any size, in any industry, anywhere in the world. ISO 27001 is particularly common in global enterprises and vendors operating across multiple countries, where it serves as a universally understood signal of security rigor.

What it covers: ISO 27001 requires organizations to establish, implement, maintain, and continually improve a comprehensive information security management system. This includes risk assessment, security controls across 93 areas (per the 2022 revision), and ongoing audits to maintain certification.

What to look for in vendors: Ask for a copy of their ISO 27001 certificate and verify it with the issuing certification body. Check the scope statement on the certificate carefully. Sometimes certifications cover only a specific product or office, not the whole company. Also ask about their last surveillance audit and when their next recertification is due.

The bottom line: ISO 27001 certification is one of the most rigorous and globally respected security credentials out there. For organizations operating internationally or in regulated industries, this one often isn't optional.

ISO 42001: The New Standard for AI Governance

What it is: Published in 2023, ISO 42001 is the world's first international standard for Artificial Intelligence Management Systems (AIMS). It provides a framework for organizations developing, providing, or using AI systems to manage risk, ensure responsible use, and build trust.

Who it applies to: Any organization building, deploying, or significantly relying on AI systems. As AI becomes embedded in more enterprise products, this standard is becoming increasingly relevant for vendor evaluation.

What it covers: ISO 42001 addresses AI-specific risks including bias, transparency, accountability, safety, and the ethical implications of automated decision-making. It requires organizations to document their AI objectives, assess associated risks, implement appropriate controls, and continuously monitor and improve their AI governance practices.

What to look for in vendors: This is early days for ISO 42001 certification, but it's worth asking AI-powered vendors whether they're familiar with the standard and working toward alignment or certification. Look for vendors who can speak to their model governance practices, how they handle bias and fairness, and what transparency they offer around AI-driven decisions that affect your data or workflows.

The bottom line: ISO 42001 is the framework to watch as AI governance becomes a boardroom-level concern. Vendors who are getting ahead of it now are signaling that they take responsible AI seriously — not just as a talking point, but as an operational commitment.

“ISO 42001 is the framework to watch as AI governance becomes a boardroom concern. Vendors getting ahead of it now are signaling an operational commitment to responsible AI.”

How These Frameworks Work Together

Here's the thing: these frameworks aren't competing. They're complementary. And a mature vendor will often hold or align with multiple standards because each one covers different ground.

Think of it this way:

  • HIPAA governs what health data you can handle and how.
  • SOC 2 verifies that your controls are actually working.
  • NIST CSF structures how you think about and manage cybersecurity risk.
  • ISO 27001 provides a system for managing information security across the organization.
  • ISO 42001 extends that rigor specifically to AI systems.

A vendor operating in healthcare, using AI in their product, and selling to enterprise customers globally might legitimately need to demonstrate alignment with all five. That's the modern compliance stack.

What This Means When You're Vetting Vendors

When you're in a vendor review, here's a practical starting point:

Ask for documentation, not just claims. Any vendor can say they're "SOC 2 compliant." Ask for the actual report.

Match the framework to your risk. If you're in healthcare, HIPAA and SOC 2 are table stakes. If you're enterprise with global operations, ISO 27001 matters. If you're deploying AI-powered tools, start asking about ISO 42001.

Look for continuous improvement, not just certification. The best vendors treat compliance as an ongoing discipline, not a checkbox they revisit every three years. Ask how they handle gaps, how they respond to incidents, and how their security program has evolved.

Understand scope. Certifications sometimes cover only part of a vendor's environment. Make sure what's certified includes the systems and services relevant to your use case.

The Bottom Line

Compliance frameworks exist for a reason: they create a shared language for security and trust in an environment where data is everywhere and risk is real. Understanding what each framework covers gives you a genuine advantage when evaluating vendors — not because you need to become a compliance expert, but because you know the right questions to ask.

And the vendors worth working with? They'll welcome those questions.

Interested in learning more about how Fortellar approaches security and compliance? Get in touch — we're happy to walk you through our practices in detail.

Governance, Risk & Compliance

Talk to the team that does the work.

Fortellar builds and runs security and compliance programs for regulated organizations. Bring us the gap you are trying to close.

Talk to Us