Which IT Compliance Standards Actually Apply to Your Texas Business?
Most Texas SMBs are subject to 2-4 compliance frameworks but waste time on ones that don't apply. Answer five questions to build your shortlist.

Texas businesses with 50 to 500 employees typically fall under two to four compliance frameworks simultaneously. The problem isn’t awareness that compliance exists. It’s figuring out which of the 14-plus standards floating around actually apply to your specific business, so you can stop spending time on the ones that don’t.
This post walks through five scoping questions. Answer them honestly, and you’ll have a named shortlist of the frameworks your business needs to address. Skip the ones that don’t match, and focus your compliance budget where it counts.
The Baseline: What Every Texas Business Needs
Before getting into industry-specific standards, two obligations apply to nearly every business operating in Texas.
The Texas Data Privacy and Security Act (TDPSA) took effect July 1, 2024 and is now actively enforced. If your business processes personal data of Texas residents, including customer records and website visitor information (note: employee HR records are exempt under TDPSA), you’re subject to it. The first 100 enforcement actions from the Texas Attorney General’s office confirm that the state is not treating this as a paper requirement. Compliance requires documented data processing policies, consumer rights request handling, and reasonable security measures.
Cyber insurance carrier requirements function as a de facto compliance framework. Carriers now require MFA, endpoint detection and response, encrypted backups, security awareness training, and a documented incident response plan as conditions of coverage. If your business carries cyber insurance (and it should), you’re already subject to these controls. We’ve covered the full list of controls insurers verify in a previous post.
Those two apply to almost everyone. The next five questions determine what else goes on your list.
Five Questions That Build Your Compliance Shortlist
1. Do you accept credit or debit card payments?
If yes: PCI DSS v4.0.1 applies to your business.
Any organization that stores, processes, or transmits cardholder data must comply with PCI DSS. The March 2025 update (v4.0.1) added requirements that previously were best practices, including authenticated vulnerability scans, targeted risk analysis for each PCI requirement, and script management for payment pages. The specific level of assessment you need depends on your annual transaction volume, but even Level 4 merchants (under 20,000 e-commerce transactions annually) must complete a Self-Assessment Questionnaire and quarterly network scans. Our PCI DSS compliance guide for Texas SMBs breaks down the practical requirements by merchant level.
2. Does your business create, receive, store, or transmit protected health information?
If yes: HIPAA applies, and the 2026 Security Rule overhaul significantly expanded its requirements.
This applies to healthcare providers, health plans, and their business associates (anyone who handles PHI on their behalf, including IT providers, billing companies, and cloud hosting vendors). The 2026 HIPAA overhaul made MFA, encryption at rest, and annual penetration testing mandatory for the first time, and breach notification to HHS remains required within 60 days. If you’re a healthcare practice or a vendor that touches patient data, HIPAA compliance now requires a materially different security posture than it did two years ago.
3. Do you sell to the Department of Defense, directly or as a subcontractor to a prime contractor?
If yes: CMMC applies. The level you need depends on the type of information you handle.
If you handle Federal Contract Information (FCI) only: CMMC Level 1 requires 15 basic cybersecurity practices and allows annual self-assessment. Most SMBs that only handle FCI can achieve and maintain Level 1 at a significantly lower cost than Level 2.
If you handle Controlled Unclassified Information (CUI): CMMC Level 2 requires compliance with all 110 NIST 800-171 controls and a third-party assessment under Phase 2, which is now live. First-year compliance costs run $120,000 to $250,000 for most SMBs, dropping to $60,000 to $100,000 annually after initial certification.
Check your contract requirements and the type of information flowing through your systems to determine which level applies. If you’re a Texas defense contractor, neither level is optional and the timeline is firm. Our CMMC certification services cover the full path from gap assessment through certification at either level.
4. Are you a financial institution, or do you provide financial services or handle consumer financial data?
If yes: GLBA applies, and depending on your specific business, FINRA, SEC, and SOX rules may also apply.
The Gramm-Leach-Bliley Act requires financial institutions to protect customer financial information through written information security programs, risk assessments, and vendor management. “Financial institution” under GLBA is broader than you might expect: it covers insurance agencies, mortgage brokers, tax preparers, and any business significantly engaged in financial activities. If you’re also a registered broker-dealer or investment adviser, FINRA and SEC cybersecurity examination priorities add another layer. We’ve covered how these frameworks overlap for financial services firms in detail.
5. Do you sell to customers in California?
If yes: CCPA/CPRA may apply, but having California customers alone is not enough to trigger it. You must also meet at least one of the law’s thresholds.
The California Consumer Privacy Act (as amended by the CPRA) applies to businesses that have annual gross revenue over $25 million, buy or sell personal information of 100,000+ California residents, or derive 50% or more of revenue from selling or sharing California residents’ personal information. Texas companies with California customers frequently trigger the revenue threshold without realizing it, but smaller businesses that sell to a handful of California clients may not be subject to CCPA at all. Review all three thresholds against your actual numbers before adding this to your list. Enforcement runs through the California Privacy Protection Agency; a narrow private right of action applies to certain data security breaches. That combination makes this one worth scoping carefully if you do qualify.
Frameworks That Aren’t Laws but Still Matter
Three frameworks show up frequently in customer due diligence requests and enterprise vendor questionnaires, even though no government agency mandates them for most SMBs.
SOC 2 is an audit framework, not a regulation. But if your business sells to enterprise clients, you’ve probably been asked for a SOC 2 Type 2 report. The distinction between Type 1 (controls exist at a point in time) and Type 2 (controls operated effectively over 6-12 months) matters. Type 2 is what buyers actually want. If enterprise clients aren’t asking for it yet, you can skip it. Healthcare and financial services enterprise buyers typically require SOC 2 Type 2 for vendor onboarding, so if you sell into those verticals, treat it as a revenue requirement. If they are asking, it’s a revenue-enabling investment, not a compliance burden.
NIST Cybersecurity Framework (CSF 2.0) provides a structured approach to managing cybersecurity risk across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. No federal law mandates it for private businesses, but it serves as the foundation for CMMC, many state regulations, and most cyber insurance questionnaires. If you’re subject to multiple frameworks, aligning your security program to NIST CSF means you’re building a common foundation that maps to all of them.
CIS Controls v8 are implementation-level security guidance, not a certification. Think of them as the “how” behind NIST CSF. If your managed IT provider follows CIS Controls for your environment, you’re automatically satisfying large portions of HIPAA, PCI DSS, CMMC, and cyber insurance requirements at the technical level.
Standards You Can Probably Skip
If your scoping answers didn’t trigger these, you can deprioritize them:
- ISO 27001 is an international certification. Valuable if you sell to European or multinational enterprises that require it, but most Texas SMBs serving domestic customers don’t need it.
- FISMA applies to federal agencies and their contractors handling federal information systems. Unless you contract directly with civilian federal agencies (not DoD, which falls under CMMC), this doesn’t apply.
- SOX applies to publicly traded companies and those preparing for IPO. If you’re a private SMB, this isn’t on your list.
- ISO 42001 is the new AI management system standard. Relevant only if your business develops or deploys AI systems at a scale where customers or regulators expect a formal AI governance certification.
What to Do With Your Shortlist
Once you’ve identified your two to four applicable frameworks, the next step is a gap assessment: compare what controls you have today against what each framework requires. The overlap between frameworks means most SMBs discover they need roughly the same set of core controls (MFA, endpoint protection, encrypted backups, incident response planning, access reviews) mapped to multiple frameworks simultaneously.
The compliance budgeting guide we published earlier this year walks through what this costs for each tier. The short version: a business under two frameworks should budget $40,000 to $80,000 annually, and a business under three or more frameworks should budget $80,000 to $150,000 (based on Infonaligy engagement benchmarks). That investment covers both compliance and core cybersecurity controls, because the requirements overlap by 60% to 80%.
The most expensive outcome is guessing at your obligations, implementing controls against the wrong standards, and discovering the gap during an audit, a breach, or an insurance claim denial. Ten minutes of scoping now prevents that.
If your Texas business needs help mapping compliance obligations to a concrete plan, or if you want a second opinion on which frameworks actually apply to your operations, that’s a conversation we can have quickly.
Not Sure Which Standards Apply to You?
Our compliance team can scope your obligations and build a plan that covers every applicable framework without wasting budget on ones that don't.
Get a Free AssessmentServing Businesses Across Texas & Oklahoma