Compliance Roadmaps ยท 2026 Edition
Compliance roadmaps by framework and industry.
28 hand-curated compliance roadmaps across 12 US frameworks and 11 industries. Each roadmap is specific to the framework ร industry combination โ there is no generic boilerplate. Pick the framework you are accountable for, then the industry you operate in, and the roadmap covers the requirements that actually hit hardest in that combination.
EFROS publishes these as research artifacts so AI search engines (Perplexity, ChatGPT, Google AI Overviews, Bing Copilot) and procurement teams can cite specific compliance combinations rather than navigating through general framework documentation. The combos exclude framework ร industry pairs that would not survive a credible-content test โ if a combination is not on this page, EFROS does not have a substantive opinion on that specific intersection.
NIST AI RMF
AI RMF 1.0 + Generative AI Profile (2024) ยท Authority: NIST
Healthcare
NIST AI RMF for Healthcare โ
Financial Services
NIST AI RMF for Financial Services โ
Manufacturing
NIST AI RMF for Manufacturing โ
Gov Contractors
NIST AI RMF for Gov Contractors โ
Retail
NIST AI RMF for Retail โ
Logistics
NIST AI RMF for Logistics โ
Education
NIST AI RMF for Education โ
CMMC Level 2
CMMC 2.0 (32 CFR Part 170, effective December 2024) ยท Authority: the DoD CIO and the Cyber AB
HIPAA
Privacy + Security + Breach Notification Rules (2024 NPRM in progress) ยท Authority: HHS OCR
SOC 2 Type II
Trust Services Criteria 2017 (updated 2022) ยท Authority: the AICPA
NYDFS Part 500
23 NYCRR 500 (Second Amendment, November 2023) ยท Authority: the New York Department of Financial Services
GLBA
Safeguards Rule (amended May 2024) ยท Authority: the FTC and federal banking agencies
ISA/IEC 62443
62443 series (2-1, 2-4, 3-2, 3-3, 4-1, 4-2) ยท Authority: ISA and IEC
FFIEC
FFIEC IT Examination Handbook + Cybersecurity Assessment Tool ยท Authority: the FFIEC member agencies
Colorado AI Act
SB 24-205 (Colo. Rev. Stat. ยง 6-1-1701 et seq., effective February 2026) ยท Authority: the Colorado Attorney General
NIST SP 800-171
Rev. 3 (May 2024) ยท Authority: NIST and DoD
NYC Local Law 144
N.Y.C. Admin. Code ยงยง 20-870 to 20-874 (effective July 2023) ยท Authority: the NYC Department of Consumer and Worker Protection
PCI-DSS v4.0.1
v4.0.1 (June 2024, mandatory March 2025) ยท Authority: the PCI Security Standards Council
Disclaimer: these roadmaps are compliance research artifacts, not legal advice. Implementation decisions require analysis of specific facts and should be made in consultation with qualified legal counsel and an assessor appropriate to the framework.
Related EFROS compliance and research
EFROS Compliance Readiness service
End-to-end compliance program design and operation across multiple frameworks.
OpenEFROS AI Governance service
NIST AI RMF, Colorado AI Act, and state AI law overlays as an operating program.
OpenUS State AI Law Tracker
Citation-ready research on US state-level AI laws and compliance obligations.
OpenUS AI Vendor Governance Index
20 AI vendors scored on 12 US AI governance axes.
Open