Documentation

Compliance Workspace · Getting started

Choosing a framework

SOC 2, ISO 27001, and HIPAA compared — what each one is, who needs it, and how to decide which to work first in the Compliance Workspace.

The workspace supports three frameworks with one engine, so the way you work an item — status, notes, evidence — is identical across all of them. Here's how to pick.

SOC 2 (Trust Services Criteria)

What it is: An attestation report, issued by a CPA firm, that describes how your controls meet the AICPA Trust Services Criteria — security (required), plus optionally availability, confidentiality, processing integrity, and privacy.

Who needs it: Most B2B SaaS and service companies, because customers and prospects ask for it during procurement. It's the most common "can we see your SOC 2?" request.

Type I vs Type II: Type I is a point-in-time design assessment; Type II tests that controls operated effectively over a period (usually 3–12 months). Type II is what enterprise buyers want.

ISO 27001 (Annex A / ISMS)

What it is: An international certification that you run an Information Security Management System (ISMS) and have implemented the applicable Annex A controls, with a documented Statement of Applicability.

Who needs it: Companies selling internationally or into markets and enterprises that prefer the ISO standard over SOC 2. It emphasizes the management system — risk assessment, treatment, and continual improvement — as much as the individual controls.

HIPAA (Security & Privacy Rule)

What it is: A US regulation, not a certificate. If you create, receive, maintain, or transmit protected health information (PHI), you must implement the Security Rule's administrative, physical, and technical safeguards and meet Privacy Rule requirements.

Who needs it: Healthcare providers, health plans, and any business associate (vendors) that handle PHI. There's no "HIPAA certificate," but you must be able to demonstrate compliance — which is exactly what an evidence workspace produces.

Which should I work first?

If…Start with
Customers keep asking for a security reportSOC 2
You sell internationally or a buyer named the standardISO 27001
You touch patient / health dataHIPAA

Tip: These frameworks overlap heavily — access control, encryption, logging, incident response, and vendor management appear in all three. Evidence you collect for one often satisfies the others, so working a second framework later is far less than double the work.

Working toward something outside these three — PCI DSS, NIST CSF, CMMC, FedRAMP — is a different exercise, and one intSignal handles as compliance program and audit-preparation services rather than in the workspace.

Ready? Head to Working the program.

Need a hand with Compliance Workspace?Talk to our team →