The framework maze, decoded
Almost every security-framework conversation at a small organization starts the same way: someone heard they need "SOC 2 or ISO or one of those," nobody knows which, and the quotes they're getting range from confusing to terrifying.
Here's the secret that consultants under-advertise: the major frameworks are roughly 70% the same controls, packaged differently and proven differently. Patch your systems, control access, log what happens, plan for incidents, manage vendors, train people. The differences that matter are who's asking for it and what kind of proof they accept.
Pick by who's asking, not by what's popular
| Who's asking | What they usually want | What it really is |
|---|---|---|
| US customers, especially SaaS buyers | SOC 2 Type II | An auditor's attestation that controls you chose operated over a period. Not a checklist — you define the scope. |
| International or enterprise customers | ISO 27001 | Certification of your security management system — the process by which you manage risk, not a specific bar of security. |
| US DoD supply chain | CMMC (built on NIST SP 800-171) | A prescriptive checklist with assessment. Little room for interpretation; driven by contract clauses. |
| Cyber insurers | A questionnaire | MFA, backups, EDR, and email security. They're underwriting the same five moves everyone should make anyway. |
| Nobody specific (yet) | — | Use CIS Controls. Free, prescriptive, and prioritized into implementation groups sized for real budgets. |
And NIST CSF? It's the common language layered over all of this — a way to organize and talk about your program (Govern, Identify, Protect, Detect, Respond, Recover), not a certification you can hold. It's excellent for structuring leadership conversations and useless as a customer-facing badge.
Two truths that save money
First: compliant and secure are different properties. ISO certifies that you manage security systematically — you can be ISO-certified with weak controls, consistently managed. SOC 2 attests that the controls you picked operated as described — you picked them. Treat certification as a sales artifact and security as an operational outcome, and fund them with that honesty.
Second: don't pursue certification until someone with a checkbook asks for it. Certification is a recurring cost — annual audits, surveillance, evidence maintenance — not a one-time badge. Being ready (controls in place, evidence organized) costs a fraction of being certified, and readiness converts to certification in months when a deal actually demands it.
Build once, map many
The expensive mistake is treating each framework as a separate project. The cheap path:
- Implement against one prescriptive baseline. For most small organizations that should be CIS Controls Implementation Group 1 — 56 concrete safeguards, deliberately scoped to what a small team can run.
- Maintain one mapping from your controls to whatever frameworks people ask about. When the SOC 2 questionnaire or the ISO gap analysis arrives, you're translating, not rebuilding.
- Collect evidence as you operate. Auditors don't buy intent — a control without an artifact doesn't exist. Exports, tickets, dated screenshots, review sign-offs. If producing evidence requires a special project, the control isn't really running.
That last point deserves its own sentence: an audit is just someone else making your work visible. If the evidence only exists as a frantic pre-audit project, the audit isn't discovering your controls — it's discovering that your controls were invisible, even to you.
This is exactly what the gap assessment workbook does: all 56 CIS IG1 safeguards in plain language, pre-mapped to NIST CSF 2.0 and ISO 27001:2022, with notes on the realistic small-org implementation for each.
The trap to avoid
Don't let a framework set your priorities. Frameworks are comprehensive by design — they enumerate everything that could matter to anyone. Your risk register, not the framework index, decides what you fix first. A framework tells you the universe of controls; your actual risks, threats, and obligations tell you the order. Organizations that invert this spend a year on policy documents while their backups go untested.
Pick the framework the checkbook demands, build to CIS IG1 underneath it, keep one mapping, and let your risk register drive the sequence. That's the whole maze.
And if your checkbook situation is specific — a startup facing its first questionnaire, a US government contract, India's regulatory clocks, or an ISO certification ask — each one has its own page with the details that matter there.