Cybersecurity Compliance Requirements by Industry in 2026

Last updated: 09/17/2026
Compliance
Cybersecurity Compliance Requirements by Industry in 2026

Your industry sets some of your cybersecurity compliance requirements. Your customers and your insurance carrier set the rest, and they usually get there first. Here is the map for manufacturers, distributors, professional services firms, property managers, creative agencies, and engineering firms, plus the nine controls that satisfy almost all of it at once.

Cybersecurity compliance requirements vary by industry because three sources create them. Federal or state law, customer contracts, and insurance carriers. Manufacturing answers to CMMC and NIST 800-171. Professional services firms answer to SOC 2 and the FTC Safeguards Rule.

Almost nobody arrives at cybersecurity compliance through a regulator. No agency calls. Work usually starts because a customer sent over a security questionnaire, or an insurance renewal came back with conditions attached, or a prime contractor added a clause to a purchase order that nobody in the building recognized. The law is in there somewhere. It rarely sets the calendar.

Order of operations matters here. Search for the rules that govern your industry and you'll find a short list you'll feel reasonably covered by, then read the security language in your three largest customer contracts and you'll usually find a longer one that nobody has scoped. Both lists are real. They just arrive at different speeds, and the contract list arrives faster.

So this is a map of both, organized around the industries we work in rather than the ones that make for easy headlines.

Cybersecurity Compliance Requirements by Industry, at a Glance

Requirements sort into three groups. Rules that apply by law, rules that arrive through a contract, and frameworks companies adopt on their own so they can answer the first two categories without running three separate projects on three separate budgets.

Group three confuses people, because adopting a framework voluntarily feels entirely optional right up until the moment a customer asks for the report and the renewal stalls behind it. ISO 27001 and SOC 2 are voluntary in the sense that no agency will fine you for skipping them. They're mandatory in the sense that a deal dies without one. So which pressure is actually on your calendar? Same deadline either way.

Cybersecurity compliance requirements by industry, showing what applies by law, what arrives by contract, and what companies commonly adopt

One honest exclusion. If you're a healthcare provider, HIPAA drives your entire program and this map won't get you there. Same goes for banks and credit unions, where federal examiners set the agenda. Everything below assumes you're outside those two worlds.

If you'd rather come at this from the framework side than the industry side, we've covered which standards apply to you in a separate piece.

Manufacturing and the Defense Supply Chain

Sell anything to a federal agency and FAR 52.204-21 already applies. It carries 15 basic safeguarding requirements. Nobody sends a notice.

Work that touches Controlled Unclassified Information under a Defense Department contract goes much further. DFARS 252.204-7012 pulls in all 110 requirements of NIST SP 800-171 and adds a 72-hour cyber incident reporting obligation. Controlled Unclassified Information, or CUI, is information the government owns or controls that isn't classified but isn't public either. Drawings, specifications, test data. The kind of file that lands in a shared folder because somebody on the shop floor needed it, and then stays there for four years while the project it belonged to closes out and the people who knew about it move on.

Then 2026 got complicated.

On July 13, 2026, the Pentagon suspended Phase II of the CMMC program, pausing the requirement that contractors handling CUI obtain an independent third-party assessment by November 10, 2026. A reform task force was stood up to review the program, and industry responses were collected through August 14. Plenty of suppliers read the headline and stopped work. The news moved quickly.

It was the wrong read. What got suspended was a verification mechanism, not an obligation. DFARS 7012 still applies. NIST SP 800-171 still applies, all 110 requirements of it. Phase 1 self-assessments still apply. And your score still goes into SPRS, the Supplier Performance Risk System, where a senior company official affirms it annually under their own name.

Consider what that affirmation means. When a government assessor is no longer verifying the number, the number you posted yourself becomes the record. Self-attestation carries False Claims Act exposure in a way a third-party certificate never did. The pressure didn't go away. It moved onto a signature.

Manufacturers in this position usually end up running two things in parallel, and it helps to know why. The contract obligation is 800-171. The program you actually want is broader than that, which is where the practical difference between NIST 800-171 and the NIST CSF starts to matter for anyone planning past the next contract cycle.

Distribution and Logistics Has No Regulator, and That's the Problem

Four buildings, a factory, a warehouse, an office tower and a studio, each connected by a dotted line to one central security shield

No agency writes cybersecurity rules for distributors. There's no CMMC for warehousing. Which sounds like good news for about a week, until the requirements show up anyway through channels that are harder to plan around.

They arrive three ways. A customer sends a security addendum as a condition of renewal, and it reads like it was written for a software company. CTPAT minimum security criteria include information technology controls that plenty of members treat as a paperwork exercise until an audit says otherwise, and any payment portal you run brings PCI DSS along with it whether or not anybody in operations knew that was part of the deal.

Controls are rarely the problem. Ownership is the harder question. A 300-person distributor with two IT staff gets a 90-question security questionnaire from its largest account, and it lands in sales, who forward it to IT, who forward it to the MSP, who answer what they can see and guess at the rest. Who owned that answer? Guessing is where the trouble starts, because a wrong answer on a customer questionnaire is a contractual representation.

Professional Services and the Rule Most Firms Don't Know Applies

Two requirements dominate here. SOC 2 Type II, which enterprise clients ask for before they'll sign, and the FTC Safeguards Rule, which quietly covers more firms than anyone expects.

The Safeguards Rule uses a definition of financial institution that reaches well past banks. The FTC's own guidance lists tax preparation firms, collection agencies, credit counselors, mortgage brokers, investment advisors that aren't required to register with the SEC, and finders, meaning companies that bring buyers and sellers together. A 60-person accounting practice is covered. Few of them know it.

Being covered means a written information security program, a named Qualified Individual who reports to your board, and multi-factor authentication for any individual accessing any information system. Any individual. Any system. That reach is deliberate. There's a narrow exception if your Qualified Individual approves an equivalent control in writing, and that approval has to exist as a document before anyone asks for it.

SOC 2 sits in a different category. It isn't a law. It's an opinion from a CPA firm about whether your controls operated the way you said they did over a period of time. Firms usually start one because a client asked. Then a second client asks, and a third, and the report starts paying for itself. If you're weighing that report against a certification, we've compared SOC 2 against ISO 27001 in detail.

Real Estate and Property Management

Property managers get pulled in two ways, and neither one feels like cybersecurity at the time.

Start with the rent portal. The moment residents pay by card, PCI DSS applies to that flow, and the version in effect leaves no room to defer. The Payment Card Industry Security Standards Council confirmed that 51 of the 64 new requirements in v4.0 became effective on March 31, 2025. Every assessment since then runs against the full standard. No future-dated column left. Our PCI DSS 4.0.1 requirements breakdown walks the specifics.

State privacy law is the other one, and it catches people because it follows the resident, not the company. Where they live decides it. A property manager headquartered in Texas with buildings in three other states inherits the obligations of all of them. As of 2026, 20 state consumer privacy laws are in effect with 24 enacted, and Indiana, Kentucky, and Rhode Island all went live on January 1. Rhode Island's threshold is 35,000 consumers, the lowest in the country. For a portfolio of any real size, that's a few thousand units.

Media, Entertainment, and Creative Agencies

Content security runs on its own system here, and it's almost entirely contractual. No regulator involved.

The Trusted Partner Network is owned and managed by the Motion Picture Association, and studios and streamers write TPN participation into vendor agreements. Assessment is against the MPA Content Security Best Practices, which cover 48 security topics in the Common Guidelines plus six more in the Application and Cloud Security Guidelines. Post houses, visual effects vendors, editorial facilities, and increasingly the agencies handling unreleased campaign assets all sit inside that perimeter.

Something structural changes how you plan for it. A TPN assessment produces no pass or fail grade, no certificate, and no rating. Nothing to frame. It produces an assessment of how your facility conforms to the best practices, and where it doesn't, you remediate and furnish evidence, which is genuinely different from an audit you either pass or repeat, and it rewards a program that stays maintained rather than a sprint the week before an assessor arrives.

Engineering and Architecture

This one rarely comes through a regulator at all. It comes through the prime.

Think of a firm doing structural work on an aerospace facility, or systems design for a defense installation. It ends up holding technical data that falls under ITAR or the export control rules that govern what can be shared with a foreign national, and holding CUI that triggers the same DFARS clause a machine shop deals with. The flow-down language arrives in the project agreement, often after the proposal has already been priced. Design firms read contracts closely for scope and liability. The security exhibit gets skimmed.

The Nine Controls Every Framework Asks For

A checklist clipboard beside a padlock, a key and a magnifying glass, representing the controls every compliance framework shares

Frameworks overlap far more than their page counts suggest, and NIST maintains the proof. Its CSF 2.0 Informative References map the framework's subcategories to ISO/IEC 27001, SP 800-53, SP 800-171, and the CIS Controls, which means a control you build for one standard can be claimed against several others without anyone doing the work twice.

Nine controls carry the weight.

  • Multi-factor authentication everywhere, not just on email. VPN, remote desktop, cloud admin accounts, the payroll system somebody stood up in 2019.
  • An asset inventory that reflects reality. Every framework asks for one, almost nobody's is current, and you can't protect a laptop you don't know exists.
  • Logging, kept long enough to matter. A year is roughly where the requirements land.
  • Access reviews on a schedule. Quarterly is the common cadence, and the finding is always the same, which is that people who changed roles kept the access from the old one.
  • Encryption at rest and in transit. IBM's 2026 research found only 37% of breached organizations encrypted sensitive data in both states.
  • Patching you can prove happened, which is a different project from patching.
  • A written incident response plan somebody has actually tested. DFARS gives you 72 hours to report. Reading the plan for the first time inside that window goes badly.
  • Vendor review. Your obligations don't stop at your own firewall.
  • Security awareness training, documented, with completion records.

Build those nine well and you've covered a large share of 800-171, most of the SOC 2 common criteria, the operational core of ISO 27001, and nearly everything the FTC Safeguards Rule asks for. Order matters less than overlap. The second framework costs a fraction of the first, and that inverts the advice companies usually get, which is to pick one standard and worry about the rest later.

What the Frameworks Cost in Time

Budget questions usually come in as dollars. Time is the better unit. The calendar is what breaks deals.

Time to first attestation, signing authority, and renewal cycle for seven compliance frameworks

Signing authority and renewal cycles in that table come from the standards themselves. A CMMC Level 2 certification runs three years with annual affirmations under 32 CFR 170.17, and every accredited ISO 27001 certificate anywhere follows the same three-year cycle with surveillance audits in between. The first column works differently. Those ranges are what readiness work tends to take rather than a published figure, and remediation is the variable that moves them. We've published what ISO 27001 costs and takes for a mid-market company if you want a worked example.

The Requirement Almost Everyone Misses Is Evidence

Two different things. A control that exists, and a control you can prove existed on a given Tuesday in March. The first is an IT project. The second is a compliance program, and it's where first-time audits come apart.

You recognize the pattern once you've watched it happen. A firm rolls out MFA across the company in the spring. The assessor arrives in the fall and asks for evidence that MFA was enforced continuously across that whole period, for every account, including the three service accounts somebody excepted in April for a printer integration and never put back. Could you produce that record today? The control was real. The record wasn't.

Insurance carriers pushed this shift harder than regulators did. Screenshots, not promises. Written attestations stopped being enough some time ago, and renewals now arrive with requests for exported sign-in logs and configuration evidence drawn from the systems you said were covered. Heading into a renewal, what carriers now ask for is worth reading before you fill in the application, because a misstatement there is grounds to deny a claim later.

Evidence collection is also the piece most worth automating, and whether to build or buy that tooling depends mostly on how many systems you're pulling from. One cloud and Microsoft 365, and you probably own the tools already. Fifteen SaaS platforms, and a dedicated one starts earning its price.

Where to Start This Quarter

Pull three documents. Your largest customer contract, your cyber insurance application from last renewal, and any federal or defense purchase order sitting in the system. Read the security language. That's your actual requirement set, and it's usually more demanding and a good deal more urgent than the regulatory list you'd assemble by searching your own industry, because it comes with dates attached.

Then map what you find against the nine controls above. Gaps that show up in more than one column are the ones to fund first.

Find Out Which Requirements Reach Your Business

Consilien is a security-first managed IT and advisory firm working with companies of 20 to 1000 users nationwide, mostly in manufacturing, distribution, professional services, real estate, media and creative, and engineering, and compliance readiness is a standalone offering here rather than something folded into a managed IT agreement, because the work is genuinely different. Gap assessment, remediation planning, control ownership, and the evidence discipline that keeps a program defensible between audits.

If a contract or an audit date is already on the calendar, CMMC readiness work and the equivalent for SOC 2, ISO 27001, and PCI all start the same way, with a gap assessment against what you're actually being asked to prove.

Questions Companies Ask Before an Audit

We've never had a regulator contact us. Does any of this actually apply?
Probably, though not through the door you're watching. Federal and state rules apply whether or not anyone tells you, and the FTC Safeguards Rule in particular covers firms that never thought of themselves as financial institutions. The trigger is usually commercial. A customer questionnaire, an insurance renewal, or a purchase order clause reaches you long before an agency does.
Our biggest customer sent a 40-page security questionnaire. Is that a compliance requirement?
Yes, and a binding one. Your answers become contractual representations, which means a wrong answer carries more risk than an honest gap. Answer what you can verify, say plainly where you're short, and give a remediation date. Buyers deal with partial answers constantly. What ends relationships is finding out an answer wasn't true.
Did the CMMC suspension let defense suppliers off the hook?
No. The suspension paused third-party verification, not the underlying requirements. DFARS 252.204-7012, the 110 requirements in NIST SP 800-171, Phase 1 self-assessments, and annual SPRS affirmations are all still in force. If anything the exposure concentrated, because a self-reported score signed by a senior official is now the primary record, and that signature carries False Claims Act risk.
Should we do SOC 2 or ISO 27001 first, if a customer is asking and we might need both?
Follow the customer. A request from a US enterprise buyer almost certainly means SOC 2, and handing them an ISO certificate will not close the item. International buyers and European counterparties usually want ISO 27001. The control work underneath is largely shared, so whichever comes second is much cheaper than the first.
How small is too small for this to matter?
Under about 20 users, with no federal contracts, no card payments, and no enterprise customers, a structured compliance program is probably premature. Get MFA, backups, and endpoint protection right, and revisit when the first questionnaire arrives. The trigger isn't headcount. It's who you sell to.
Can our existing IT provider handle compliance, or is that a separate thing?
Ask them who owns each control and who signs the affirmation. Managed IT keeps systems running and implements controls. Compliance readiness scopes which requirements apply, assigns ownership, and maintains the evidence trail an assessor asks for, which is a different discipline with different deliverables and usually a different person accountable for the outcome. Plenty of providers do both. Very few do both under the same agreement, and it's fair to ask which one you're buying.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.