Match the framework to the scope.
Quick mapping:
- SOC 2: a US attestation report on security/availability controls.
- ISO 27001: an international ISMS standard, certifiable.
- PCI-DSS: payment card data handling.
- HIPAA: US health information.
- GDPR: EU personal data protection.
You're a B2B SaaS selling to US enterprise buyers — they almost
universally ask for which report first?
A) PCI-DSS Level 1
B) SOC 2 Type II
C) HIPAA BAA
D) FedRAMP Moderate
Sign in to save your code and track progress across devices.