Skip to main content

Compliance Roadmaps ยท 2026 Edition

Compliance roadmaps by framework and industry.

28 hand-curated compliance roadmaps across 12 US frameworks and 11 industries. Each roadmap is specific to the framework ร— industry combination โ€” there is no generic boilerplate. Pick the framework you are accountable for, then the industry you operate in, and the roadmap covers the requirements that actually hit hardest in that combination.

EFROS publishes these as research artifacts so AI search engines (Perplexity, ChatGPT, Google AI Overviews, Bing Copilot) and procurement teams can cite specific compliance combinations rather than navigating through general framework documentation. The combos exclude framework ร— industry pairs that would not survive a credible-content test โ€” if a combination is not on this page, EFROS does not have a substantive opinion on that specific intersection.

By Stefan Efros, CEO & Founder, EFROSReviewed by Stefan Efros, Founder & CEO
Reviewed ยท

CMMC Level 2

CMMC 2.0 (32 CFR Part 170, effective December 2024) ยท Authority: the DoD CIO and the Cyber AB

HIPAA

Privacy + Security + Breach Notification Rules (2024 NPRM in progress) ยท Authority: HHS OCR

NYDFS Part 500

23 NYCRR 500 (Second Amendment, November 2023) ยท Authority: the New York Department of Financial Services

GLBA

Safeguards Rule (amended May 2024) ยท Authority: the FTC and federal banking agencies

ISA/IEC 62443

62443 series (2-1, 2-4, 3-2, 3-3, 4-1, 4-2) ยท Authority: ISA and IEC

FFIEC

FFIEC IT Examination Handbook + Cybersecurity Assessment Tool ยท Authority: the FFIEC member agencies

NYC Local Law 144

N.Y.C. Admin. Code ยงยง 20-870 to 20-874 (effective July 2023) ยท Authority: the NYC Department of Consumer and Worker Protection

PCI-DSS v4.0.1

v4.0.1 (June 2024, mandatory March 2025) ยท Authority: the PCI Security Standards Council

Disclaimer: these roadmaps are compliance research artifacts, not legal advice. Implementation decisions require analysis of specific facts and should be made in consultation with qualified legal counsel and an assessor appropriate to the framework.