Discussion about this post

User's avatar
Mark Kirstein's avatar

Thanks for the update. Requirements in the scope of SOC 2 for ALL businesses will simply fail. There's no way for some of the really small businesses to afford the implementation, audit and operations. Requiring CMMC would be significantly more burdensome, as it appears to be on a path to more rigorous standard and audit process (at least level 3), and there's 700,000 defense suppliers queueing up already. It's critical that regulations balance feasibility with objectives.

Expand full comment

No posts