The workspace supports three frameworks with one engine, so the way you work an item — status, notes, evidence — is identical across all of them. Here's how to pick.
SOC 2 (Trust Services Criteria)
What it is: An attestation report, issued by a CPA firm, that describes how your controls meet the AICPA Trust Services Criteria — security (required), plus optionally availability, confidentiality, processing integrity, and privacy.
Who needs it: Most B2B SaaS and service companies, because customers and prospects ask for it during procurement. It's the most common "can we see your SOC 2?" request.
Type I vs Type II: Type I is a point-in-time design assessment; Type II tests that controls operated effectively over a period (usually 3–12 months). Type II is what enterprise buyers want.
ISO 27001 (Annex A / ISMS)
What it is: An international certification that you run an Information Security Management System (ISMS) and have implemented the applicable Annex A controls, with a documented Statement of Applicability.
Who needs it: Companies selling internationally or into markets and enterprises that prefer the ISO standard over SOC 2. It emphasizes the management system — risk assessment, treatment, and continual improvement — as much as the individual controls.
HIPAA (Security & Privacy Rule)
What it is: A US regulation, not a certificate. If you create, receive, maintain, or transmit protected health information (PHI), you must implement the Security Rule's administrative, physical, and technical safeguards and meet Privacy Rule requirements.
Who needs it: Healthcare providers, health plans, and any business associate (vendors) that handle PHI. There's no "HIPAA certificate," but you must be able to demonstrate compliance — which is exactly what an evidence workspace produces.
Which should I work first?
| If… | Start with |
|---|---|
| Customers keep asking for a security report | SOC 2 |
| You sell internationally or a buyer named the standard | ISO 27001 |
| You touch patient / health data | HIPAA |
Tip: These frameworks overlap heavily — access control, encryption, logging, incident response, and vendor management appear in all three. Evidence you collect for one often satisfies the others, so working a second framework later is far less than double the work.
Working toward something outside these three — PCI DSS, NIST CSF, CMMC, FedRAMP — is a different exercise, and one intSignal handles as compliance program and audit-preparation services rather than in the workspace.
Ready? Head to Working the program.
