The most common finding in a first compliance audit is a policy that exists as a PDF and nothing else. Someone bought a template pack, changed the name in the header, and filed it. The quarterly access review it describes has never once happened. The problem is not a weak policy. It is that you wrote down a control and then proved, by omission, that you ignore it.
That gap is the actual work. The frameworks themselves are mostly reasonable. Getting a company to do what it wrote down is the hard part.
Which framework you are actually in
- HIPAA. Nobody issues HIPAA certificates, and a vendor calling itself "HIPAA certified" is selling a logo. You owe a documented risk analysis under
164.308(a)(1)(ii)(A), a risk management plan that follows from it, and signed business associate agreements with every vendor touching PHI. Including your MSP. Including your imaging archive. - SOC 2. An attestation from a CPA firm against the AICPA Trust Services Criteria. Security (the common criteria) is required; Availability, Confidentiality, Processing Integrity, and Privacy are opt-in. Pick only what customers ask for in writing. Every category is evidence you produce forever.
- ISO 27001. Certification of a management system, not a checklist. Annex A in the 2022 revision carries 93 controls, and your Statement of Applicability must justify every exclusion. Stage 1 reads your documents. Stage 2 checks whether you do them. Then a surveillance audit each year and recertification in year three.
- ISO 13485, FDA QMSR, and ISO 14971. For device clients. As of February 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference; the QMSR replaced the old Quality System Regulation and harmonizes with the standard. A 13485 certificate is not a substitute for it: the FDA kept its own definitions and record requirements on top, and it still inspects you itself. ISO 14971 sits underneath all of it, and it is the one most reliably treated as a binder instead of a process.
Type I versus Type II, and why Type I is usually wasted money
Type I says your controls were designed appropriately at a point in time. Type II says they operated effectively across a window, typically three to twelve months. The difference shows up in fieldwork. The auditor picks people who left during the window and asks for the deprovisioning ticket for each one. Auditors want evidence a control ran, not evidence it exists.
If the questionnaire blocking your deal says "SOC 2 Type II report required," Type I buys a few months of goodwill and nothing else. Buy it only when a named deal closes on it now and Type II is already scheduled. Otherwise skip it, open the observation window early, and spend the difference fixing controls you know are broken. The window opens when controls actually run, not when you sign the engagement letter.
What Drata, Vanta, and Secureframe do and do not do
They are genuinely useful, and we deploy them. They connect to Microsoft 365, Google Workspace, Okta, and AWS and watch continuously, so you find out MFA came off a privileged account in October, not during fieldwork in March.
What they do not do: write your policies (the generated templates are a starting point, and auditors can tell), set your risk appetite, define your system boundary, run vendor reviews, or judge whether an exception is acceptable. They will also show a mostly green dashboard while the few red items are exactly the ones that sink the audit.
What we ask before anyone writes a policy
Syncritech starts with the evidence question, not the document question. For every control you claim: what artifact proves it ran, who produces it, on what cadence. If the honest answer is "someone would have to remember," the control has already failed. Controls that can hang off a system already generating records (ticketing, MDM, identity) get wired that way. Security training counts when the platform emits a completion report with names and dates. Whatever is left gets a named owner and a recurring calendar entry, not a paragraph.
For device and imaging clients the same question covers what the quality system and IT stack share: retention, audit logging, archive access, BAAs. We hold our own Soteria Cloud Archive to that standard, because somebody else's auditor will eventually sample it. The compliance services page lists the frameworks we work in. Pick the one a paying customer has named, and leave the rest alone until someone asks.