NOC LIVE · 24/7/365 ⬢ MICROSOFT PARTNER · MPN 3318934 📍 NASHVILLE TN · NATIONWIDE SERVICE ⚡ EST. 2003 · 23+ YEARS NOC LIVE · 24/7/365 ⬢ MICROSOFT PARTNER · MPN 3318934 📍 NASHVILLE TN · NATIONWIDE SERVICE ⚡ EST. 2003 · 23+ YEARS
Service 08 of 09

IT Compliance.

HIPAA, PCI-DSS, CMMC, SOC 2, FTC Safeguards. Policy documentation, risk assessments, gap analysis, evidence collection.

IT compliance services at Maverick cover the major frameworks SMBs face: HIPAA, PCI-DSS, CMMC (L1/L2), SOC 2, FTC Safeguards Rule, and state privacy laws. We are not your auditor or QSA — that's a deliberate separation. Instead we deliver the technical controls, policy documentation, evidence collection, and remediation work your auditor will require. We have walked clients through CMMC L1 and L2 assessments, multiple SOC 2 audits, and HIPAA investigations.

How compliance actually works (the part nobody tells you)

Compliance is not a binary state. You are never "HIPAA-compliant" in a permanent sense — you are HIPAA-compliant today, based on the controls you have in place today, validated by evidence you can produce today. Frameworks operate on a continuous attestation model. The question is not "did we pass once?" — it's "can we prove we still meet the standard right now?"

That's where most SMBs fail. They scramble before an audit, get certified, then drift over the next 6 months as projects pile up, employees turn over, and controls quietly degrade.

Maverick's approach: build the controls correctly, document everything as you go, and run quarterly internal reviews so the next external audit is a formality rather than a fire drill.

The frameworks we work with

HIPAA / HITECH

Healthcare. Security Rule + Privacy Rule + Breach Notification Rule. We deliver the technical safeguards (access control, audit logs, encryption, transmission security), administrative safeguards (policies, training, risk assessment), and physical safeguards required. BAAs in place with every vendor we operate. Annual HIPAA risk assessment included.

PCI-DSS

Anyone processing, storing, or transmitting payment card data. We help define the cardholder data environment (CDE), segment it from the rest of the network, implement the technical controls, and prepare documentation for your SAQ or QSA audit.

CMMC

Defense contractors. We have taken clients through both Level 1 and Level 2 assessments. SSP development, POA&M management, gap analysis against NIST 800-171's 110 controls, evidence preparation.

SOC 2

Service organizations claiming Trust Services Criteria. We support SOC 2 Type I and Type II audits, working alongside your auditor to deliver controls and continuous evidence collection.

FTC Safeguards Rule

Financial institutions including auto dealers, mortgage brokers, tax preparers, and accountants under the expanded 2023 definition. Designated Qualified Individual, risk assessment, WISP, MFA, encryption, vendor management, incident response plan.

State privacy laws

Tennessee Information Protection Act, California CCPA/CPRA, New York SHIELD, and the growing patchwork of state laws.

What's Included

  • Initial gap analysis against your applicable framework(s)
  • Risk assessment documented per framework requirements
  • Policy library — written, reviewed, signed off, version-controlled
  • Technical control implementation — MFA, encryption, EDR, logging
  • Evidence collection — automated where possible
  • Security awareness training with completion tracking
  • Vendor risk management — third-party due diligence, BAAs, DPAs
  • Incident response plan — written, tested, framework-aligned
  • Quarterly internal reviews to catch drift
  • Audit liaison support — we handle the auditor's questions
  • POA&M tracking for CMMC and other framework remediation
  • Annual recertification support

Our Tech Stack for IT Compliance

We are vendor-aligned with the platforms our engineers actually trust in production. Here is what powers this service line:

Microsoft Purview
DLP + Compliance Manager
Drata / Vanta
Continuous compliance
KnowBe4
Training + tracking
Apptega / Compliancy Group
Framework management
Auvik / Liongard
Configuration drift
IT Glue / Hudu
Documentation library

When You Need This

Compliance work is mandatory when:

  • You handle protected health information (HIPAA)
  • You take credit cards (PCI-DSS)
  • You're a defense contractor or sub-contractor (CMMC)
  • Customers are asking for a SOC 2 report
  • You're a financial institution under the broadened FTC Safeguards definition
  • You operate in any state with comprehensive privacy law
  • Your insurance carrier is requiring specific controls at renewal

Common Questions About IT Compliance

Are you a HIPAA-certified MSP?

There is no government-issued "HIPAA certification" for MSPs — anyone claiming one is misrepresenting their credentials. What matters is whether the MSP signs a BAA with you, implements the required Security Rule safeguards, conducts annual risk assessments, and documents everything. Maverick does all of those.

How long does CMMC Level 2 prep take?

For a typical defense contractor starting from a moderate security baseline, CMMC L2 prep runs 6 to 12 months. That includes scoping CUI, building the SSP, implementing the 110 NIST 800-171 controls, training staff, collecting evidence, and remediating gaps via the POA&M.

What is the difference between SOC 2 Type I and Type II?

Type I evaluates whether your controls are properly designed at a single point in time. Type II evaluates whether those controls actually operated effectively over a period (typically 6 to 12 months). Type II is the report most enterprise customers want to see.

Does the FTC Safeguards Rule apply to small auto dealers and tax preparers?

Yes. The 2023 amendments expanded the rule to cover "financial institutions" much more broadly — including auto dealers, mortgage brokers, retail installment plan providers, tax preparation firms, collection agencies, and other non-bank financial businesses. Enforcement has been active.

Can Maverick be our compliance auditor?

No, and we are explicit about that separation. We implement the controls and documentation; an independent auditor or QSA evaluates them. The same firm cannot both build the system and certify it. We work alongside auditors and refer to qualified firms when clients need one.

Ready to talk about IT Compliance? Call 615-274-9555 or download the free assessment form. We respond in five business days with a written report — no obligation.