The framework you need depends on your industry, the type of data you handle and who you do business with. Defense contractors and subcontractors handling Controlled Unclassified Information (CUI) need to comply with NIST SP 800-171 and CMMC. Healthcare organizations fall under HIPAA. Companies that process credit card transactions must meet PCI DSS requirements. Many organizations are subject to multiple frameworks, and our advisory approach identifies overlapping controls to help you avoid duplicating effort.