PCI DSS, HIPAA and CPCSC readiness

Nobody wakes up wanting any of these. A payment processor imposes one, a health system’s contract imposes another, and a federal procurement process imposes the third. The framework is chosen for you; the only decisions left are scope, sequence and evidence.

The short version: three frameworks you do not choose

What they have in common is that somebody external decides when you are finished, and each has a different somebody. That is the fact to hold on to while reading the rest of this page, because it determines what readiness work can and cannot deliver.

The method is the same in all three cases: define the scope, assess control by control, build the evidence so it accumulates rather than being reconstructed, write the policy set, and sequence the remediation against the date somebody else set.

PCI DSS 4.x readiness

Scope is the whole game. The cardholder data environment is every system that stores, processes or transmits account data, plus everything connected to it or able to affect its security — and the second half is where organizations discover that a flat network has put the entire estate in scope. The most valuable early work is almost always scope reduction: tokenization, redirect or hosted payment flows, and segmentation that actually segments.

From there it is control-by-control gap work against the requirements that apply to your merchant or service provider level, evidence architecture, policy set and remediation planning, followed by preparation for validation.

Who validates

No. PCI DSS validation is performed by Qualified Security Assessors, and the work here is the readiness that comes before that assessment. The PCI Security Standards Council maintains the Qualified Security Assessor programme, alongside separate programmes for Approved Scanning Vendors and PCI Forensic Investigators. Those are distinct qualifications, held by distinct firms, and none of them is held here.

HIPAA Security Rule readiness

The Security Rule applies to covered entities and to business associates, and the second category catches more organizations than expect it — the software vendor, the analytics provider, the transcription service, the cloud platform handling electronic protected health information on somebody else’s behalf.

The general requirements at 45 CFR 164.306 are the place to start: covered entities and business associates must ensure the confidentiality, integrity and availability of all electronic protected health information they create, receive, maintain or transmit. The safeguards themselves sit in three sections — administrative at 164.308, physical at 164.310 and technical at 164.312 — with policies, procedures and documentation requirements at 164.316.

Readiness work maps your actual environment onto those safeguards, produces the risk analysis the administrative safeguards turn on, and writes the documentation that the rule requires you to keep. Clinics and small health organizations have a distinct set of practical problems, covered separately in security for clinics holding personal health information.

There is no HIPAA certificate

No. There is no body that issues a HIPAA certificate, and a vendor whose marketing implies one exists is selling something that does not. Enforcement sits with the regulator; what an organization can hold is evidence that it performed the risk analysis and implemented the safeguards, which is exactly what readiness work produces. Where a customer asks for HITRUST, we refer you to a HITRUST-authorized firm.

CPCSC readiness for Canadian defence suppliers

CPCSC is Canada’s cyber security programme for defence suppliers, run by Public Services and Procurement Canada with the Department of National Defence, the Standards Council of Canada, and the Canadian Centre for Cyber Security, which developed the underlying standard. The programme overview sets out how it works.

The standard is ITSP.10.171, adapted closely from the United States NIST Special Publications 800-171, on protecting controlled unclassified information in non-federal systems, and 800-172 on enhanced requirements. Suppliers already working to the American requirements will recognize most of it.

The three levels

LevelHow it is assessedControls
Level 1Annual self-assessment13
Level 2External assessment led by one of the accredited certification bodies, plus an annual affirmation98
Level 3Assessment conducted by National Defence, plus an annual affirmation200

The level is set by the contract rather than chosen. CPCSC Level 1 is an annual self-assessment against 13 controls, and the two higher levels involve external assessment and are still under development. Level 1 became available in April 2026; the official guidance states that from summer 2026 suppliers bidding on defence contracts may need to meet Level 1, that the self-assessment is required at contract award rather than during bidding, and that Levels 2 and 3 remain under development.

Why Level 1 is different

It is the one place in this entire page where no external issuer is involved at all. You assess yourself, you affirm it, and you keep the evidence. That makes readiness work unusually direct: the 13 controls are specific, the evidence expectations are published, and the gap between “we think we do this” and “we can show we do this” is the entire engagement.

What you receive, across all three

DeliverableWhat it is for
Scope definitionWhat is in, what is out, and what was done to make the boundary smaller
Gap assessmentControl by control: intent, practice and evidence, assessed separately
Evidence architectureSo records accumulate from the work rather than being reconstructed
Policy setSized to the organization, describing practices that are actually performed
Remediation planSequenced against the date the contract or regulator set

What the assembled evidence looks like to an outside reader is described in the evidence pack. Where testing is expected as part of the evidence, that is penetration testing, scoped and authorized separately.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Can anyone issue us a HIPAA certificate?

What you can produce, and what a customer should accept, is the risk analysis, the safeguard mapping and the documentation the rule requires.

Can you validate us for PCI DSS?

Where your level allows a self-assessment questionnaire rather than an on-site assessment, readiness work prepares that questionnaire and the evidence behind it, and says which questionnaire actually applies to your payment flows.

Does our US CMMC status count in Canada?

Public Services and Procurement Canada states that Canada may accept a contractor’s valid US CMMC status on a case-by-case basis, after confirming that the assessment covers the required scope. Canada also reserves the right to verify specific controls through the contract technical authority, so it is a question to settle with the contracting authority rather than to assume either way.

Which CPCSC level do we need?

If the contract does not say yet, the answer is to ask the contracting authority in writing and keep the reply. Guessing high is expensive and guessing low is worse.

How does this relate to privacy law?

These frameworks sit alongside privacy obligations rather than satisfying them; the Canadian instruments are covered in Canadian privacy readiness, and the customer-driven frameworks in SOC 2 and ISO 27001 readiness.

Start with the scope, because everything else scales with it

Say which framework your contract names and what the deadline is. The reply says what scoping and a gap assessment would cover and what you would receive — see also compliance and privacy.

Discuss a scope