PCI DSS, HIPAA and CPCSC readiness
Nobody wakes up wanting any of these. A payment processor imposes one, a health system’s contract imposes another, and a federal procurement process imposes the third. The framework is chosen for you; the only decisions left are scope, sequence and evidence.
The short version: three frameworks you do not choose
What they have in common is that somebody external decides when you are finished, and each has a different somebody. That is the fact to hold on to while reading the rest of this page, because it determines what readiness work can and cannot deliver.
The method is the same in all three cases: define the scope, assess control by control, build the evidence so it accumulates rather than being reconstructed, write the policy set, and sequence the remediation against the date somebody else set.
PCI DSS 4.x readiness
Scope is the whole game. The cardholder data environment is every system that stores, processes or transmits account data, plus everything connected to it or able to affect its security — and the second half is where organizations discover that a flat network has put the entire estate in scope. The most valuable early work is almost always scope reduction: tokenization, redirect or hosted payment flows, and segmentation that actually segments.
From there it is control-by-control gap work against the requirements that apply to your merchant or service provider level, evidence architecture, policy set and remediation planning, followed by preparation for validation.
Who validates
No. PCI DSS validation is performed by Qualified Security Assessors, and the work here is the readiness that comes before that assessment. The PCI Security Standards Council maintains the Qualified Security Assessor programme, alongside separate programmes for Approved Scanning Vendors and PCI Forensic Investigators. Those are distinct qualifications, held by distinct firms, and none of them is held here.
HIPAA Security Rule readiness
The Security Rule applies to covered entities and to business associates, and the second category catches more organizations than expect it — the software vendor, the analytics provider, the transcription service, the cloud platform handling electronic protected health information on somebody else’s behalf.
The general requirements at 45 CFR 164.306 are the place to start: covered entities and business associates must ensure the confidentiality, integrity and availability of all electronic protected health information they create, receive, maintain or transmit. The safeguards themselves sit in three sections — administrative at 164.308, physical at 164.310 and technical at 164.312 — with policies, procedures and documentation requirements at 164.316.
Readiness work maps your actual environment onto those safeguards, produces the risk analysis the administrative safeguards turn on, and writes the documentation that the rule requires you to keep. Clinics and small health organizations have a distinct set of practical problems, covered separately in security for clinics holding personal health information.
There is no HIPAA certificate
No. There is no body that issues a HIPAA certificate, and a vendor whose marketing implies one exists is selling something that does not. Enforcement sits with the regulator; what an organization can hold is evidence that it performed the risk analysis and implemented the safeguards, which is exactly what readiness work produces. Where a customer asks for HITRUST, we refer you to a HITRUST-authorized firm.
CPCSC readiness for Canadian defence suppliers
CPCSC is Canada’s cyber security programme for defence suppliers, run by Public Services and Procurement Canada with the Department of National Defence, the Standards Council of Canada, and the Canadian Centre for Cyber Security, which developed the underlying standard. The programme overview sets out how it works.
The standard is ITSP.10.171, adapted closely from the United States NIST Special Publications 800-171, on protecting controlled unclassified information in non-federal systems, and 800-172 on enhanced requirements. Suppliers already working to the American requirements will recognize most of it.
The three levels
| Level | How it is assessed | Controls |
|---|---|---|
| Level 1 | Annual self-assessment | 13 |
| Level 2 | External assessment led by one of the accredited certification bodies, plus an annual affirmation | 98 |
| Level 3 | Assessment conducted by National Defence, plus an annual affirmation | 200 |
The level is set by the contract rather than chosen. CPCSC Level 1 is an annual self-assessment against 13 controls, and the two higher levels involve external assessment and are still under development. Level 1 became available in April 2026; the official guidance states that from summer 2026 suppliers bidding on defence contracts may need to meet Level 1, that the self-assessment is required at contract award rather than during bidding, and that Levels 2 and 3 remain under development.
Why Level 1 is different
It is the one place in this entire page where no external issuer is involved at all. You assess yourself, you affirm it, and you keep the evidence. That makes readiness work unusually direct: the 13 controls are specific, the evidence expectations are published, and the gap between “we think we do this” and “we can show we do this” is the entire engagement.
What you receive, across all three
| Deliverable | What it is for |
|---|---|
| Scope definition | What is in, what is out, and what was done to make the boundary smaller |
| Gap assessment | Control by control: intent, practice and evidence, assessed separately |
| Evidence architecture | So records accumulate from the work rather than being reconstructed |
| Policy set | Sized to the organization, describing practices that are actually performed |
| Remediation plan | Sequenced against the date the contract or regulator set |
What the assembled evidence looks like to an outside reader is described in the evidence pack. Where testing is expected as part of the evidence, that is penetration testing, scoped and authorized separately.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Can anyone issue us a HIPAA certificate?
What you can produce, and what a customer should accept, is the risk analysis, the safeguard mapping and the documentation the rule requires.
Can you validate us for PCI DSS?
Where your level allows a self-assessment questionnaire rather than an on-site assessment, readiness work prepares that questionnaire and the evidence behind it, and says which questionnaire actually applies to your payment flows.
Does our US CMMC status count in Canada?
Public Services and Procurement Canada states that Canada may accept a contractor’s valid US CMMC status on a case-by-case basis, after confirming that the assessment covers the required scope. Canada also reserves the right to verify specific controls through the contract technical authority, so it is a question to settle with the contracting authority rather than to assume either way.
Which CPCSC level do we need?
If the contract does not say yet, the answer is to ask the contracting authority in writing and keep the reply. Guessing high is expensive and guessing low is worse.
How does this relate to privacy law?
These frameworks sit alongside privacy obligations rather than satisfying them; the Canadian instruments are covered in Canadian privacy readiness, and the customer-driven frameworks in SOC 2 and ISO 27001 readiness.
Start with the scope, because everything else scales with it
Say which framework your contract names and what the deadline is. The reply says what scoping and a gap assessment would cover and what you would receive — see also compliance and privacy.