Compliance done right is a business strategy. Compliance done wrong is a tax. I've watched organizations spend seven figures on ISO 27001 certifications that produced no security improvement - and I've watched others use the same framework to genuinely mature their security posture. The difference is not the framework. It is whether the leadership team decided compliance would be a real discipline or a documentation exercise.
The Frameworks I Work With Most
EU data protection. Applies to any organization processing EU residents' data. Fines up to 4% of global revenue.
International standard for information security management systems. Signals maturity to customers and partners.
US framework increasingly used globally. Practical, outcome-focused, works across sectors.
Mandatory for anyone handling payment card data. Prescriptive, technical, evolves regularly.
US trust services criteria. Required by most enterprise SaaS buyers. Type II is what actually matters.
EU directive expanding cybersecurity requirements across critical sectors. Personal accountability for directors.
First comprehensive AI regulation. High-risk AI system obligations from August 2, 2026.
EU financial services digital operational resilience. Applies to financial entities and their ICT third parties.
The Question I Always Ask First
Before I recommend a certification path or a compliance program, I ask a question that most consultants skip: why are you doing this? Because the answer determines everything else. If the answer is "we want to close enterprise deals faster," we design for that. If it's "we need to enter the EU market," we design for that. If it's "our board wants to see progress," we design for that. Each answer produces a different roadmap, even when the framework is the same.
The organizations that get compliance wrong are the ones that never asked this question - they just started with a framework and let it drive the outcome. That is how you get seven-figure certifications that produce no security improvement.
What Compliance Actually Requires
Every serious compliance program has three components that most organizations underestimate:
If you're rushing to gather evidence for audit two months out, you're doing it wrong. Evidence should be a byproduct of how you work.
Every control needs a named owner. Without that, controls exist on paper and fail in practice.
Audit findings that generate action items that don't get closed are worse than no audit at all. They document known failures.
The Regulatory Wave of 2026
The next 18 months will bring the largest wave of cybersecurity regulation most organizations have ever faced. The EU AI Act begins high-risk enforcement on August 2, 2026. NIS2 transposition is complete across the EU. DORA is now enforceable for financial entities. SEC cyber disclosure rules continue to evolve. US state privacy laws now cover most of the US population.
Organizations that treat these as separate compliance projects will drown. Organizations that build a unified control framework that maps to multiple regulations at once will have a durable advantage. That is the work I help executive teams design.