---
title: "Compliance Roadmaps by Framework and Industry | EFROS"
description: "Programmatic compliance roadmaps for US frameworks (NIST AI RMF, CMMC, HIPAA, SOC 2, NYDFS, GLBA, PCI-DSS, Colorado SB 26-189, NYC LL144) across healthcare, financial services, manufacturing, gov contractors, retail, logistics, SaaS, education, and more."
canonical: https://efros.com/compliance/
---

- [Home](https://efros.com/)
- /Compliance

Compliance Roadmaps · 2026 Edition

# Compliance roadmaps by framework and industry.

28 hand-curated compliance roadmaps across 12 US frameworks and 11 industries. Each roadmap is specific to the framework × industry combination. No generic boilerplate. Pick the framework you are accountable for, then the industry you operate in, and the roadmap covers the requirements that hit hardest in that combination.

EFROS publishes these as research artifacts so AI search engines (Perplexity, ChatGPT, Google AI Overviews, Bing Copilot) and procurement teams can cite specific compliance combinations instead of navigating general framework documentation. The combos exclude framework × industry pairs that would not survive a credible-content test. If a combination is not on this page, EFROS does not have a substantive opinion on that specific intersection.

By [Stefan Efros](https://www.linkedin.com/in/stefanefros-cyberdefense/), CEO & Founder, EFROS

Updated · May 23, 2026

## NIST AI RMF

AI RMF 1.0 + Generative AI Profile (2024) · Authority: NIST
- [HealthcareNIST AI RMF for Healthcare →](https://efros.com/compliance/nist-ai-rmf-for-healthcare/)
- [Financial ServicesNIST AI RMF for Financial Services →](https://efros.com/compliance/nist-ai-rmf-for-financial-services/)
- [ManufacturingNIST AI RMF for Manufacturing →](https://efros.com/compliance/nist-ai-rmf-for-manufacturing/)
- [Gov ContractorsNIST AI RMF for Gov Contractors →](https://efros.com/compliance/nist-ai-rmf-for-gov-contractor/)
- [RetailNIST AI RMF for Retail →](https://efros.com/compliance/nist-ai-rmf-for-retail/)
- [LogisticsNIST AI RMF for Logistics →](https://efros.com/compliance/nist-ai-rmf-for-logistics/)
- [EducationNIST AI RMF for Education →](https://efros.com/compliance/nist-ai-rmf-for-education/)

## CMMC Level 2

CMMC 2.0 (32 CFR Part 170, effective December 2024) · Authority: the DoD CIO and the Cyber AB
- [ManufacturingCMMC Level 2 for Manufacturing →](https://efros.com/compliance/cmmc-level-2-for-manufacturing/)
- [Gov ContractorsCMMC Level 2 for Gov Contractors →](https://efros.com/compliance/cmmc-level-2-for-gov-contractor/)

## HIPAA

Privacy + Security + Breach Notification Rules (2024 NPRM in progress) · Authority: HHS OCR
- [HealthcareHIPAA for Healthcare →](https://efros.com/compliance/hipaa-for-healthcare/)

## SOC 2 Type II

Trust Services Criteria 2017 (updated 2022) · Authority: the AICPA
- [SaaSSOC 2 Type II for SaaS →](https://efros.com/compliance/soc-2-type-ii-for-saas/)
- [Financial ServicesSOC 2 Type II for Financial Services →](https://efros.com/compliance/soc-2-type-ii-for-financial-services/)
- [HealthcareSOC 2 Type II for Healthcare →](https://efros.com/compliance/soc-2-type-ii-for-healthcare/)
- [Professional ServicesSOC 2 Type II for Professional Services →](https://efros.com/compliance/soc-2-type-ii-for-professional-services/)

## NYDFS Part 500

23 NYCRR 500 (Second Amendment, November 2023) · Authority: the New York Department of Financial Services
- [Financial ServicesNYDFS Part 500 for Financial Services →](https://efros.com/compliance/nydfs-part-500-for-financial-services/)

## GLBA

Safeguards Rule (amended May 2024) · Authority: the FTC and federal banking agencies
- [Financial ServicesGLBA for Financial Services →](https://efros.com/compliance/glba-for-financial-services/)

## ISA/IEC 62443

62443 series (2-1, 2-4, 3-2, 3-3, 4-1, 4-2) · Authority: ISA and IEC
- [ManufacturingISA/IEC 62443 for Manufacturing →](https://efros.com/compliance/isa-iec-62443-for-manufacturing/)

## FFIEC

FFIEC IT Examination Handbook + Cybersecurity Assessment Tool · Authority: the FFIEC member agencies
- [Financial ServicesFFIEC for Financial Services →](https://efros.com/compliance/ffiec-for-financial-services/)

## Colorado AI Act

SB 26-189 (amended AI law; repealed and replaced SB 24-205, signed 2026-05-14, effective 2027-01-01) — a transparency/disclosure regime for automated decision systems · Authority: the Colorado Attorney General
- [HealthcareColorado AI Act for Healthcare →](https://efros.com/compliance/colorado-ai-act-for-healthcare/)
- [Financial ServicesColorado AI Act for Financial Services →](https://efros.com/compliance/colorado-ai-act-for-financial-services/)
- [Employment ServicesColorado AI Act for Employment Services →](https://efros.com/compliance/colorado-ai-act-for-employment-services/)
- [InsuranceColorado AI Act for Insurance →](https://efros.com/compliance/colorado-ai-act-for-insurance/)
- [EducationColorado AI Act for Education →](https://efros.com/compliance/colorado-ai-act-for-education/)

## NIST SP 800-171

Rev. 3 (May 2024) · Authority: NIST and DoD
- [Gov ContractorsNIST SP 800-171 for Gov Contractors →](https://efros.com/compliance/nist-sp-800-171-for-gov-contractor/)
- [ManufacturingNIST SP 800-171 for Manufacturing →](https://efros.com/compliance/nist-sp-800-171-for-manufacturing/)

## NYC Local Law 144

N.Y.C. Admin. Code §§ 20-870 to 20-874 (effective July 2023) · Authority: the NYC Department of Consumer and Worker Protection
- [Employment ServicesNYC Local Law 144 for Employment Services →](https://efros.com/compliance/nyc-local-law-144-for-employment-services/)

## PCI-DSS v4.0.1

v4.0.1 (June 2024, mandatory March 2025) · Authority: the PCI Security Standards Council
- [RetailPCI-DSS v4.0.1 for Retail →](https://efros.com/compliance/pci-dss-v4-for-retail/)
- [Professional ServicesPCI-DSS v4.0.1 for Professional Services →](https://efros.com/compliance/pci-dss-v4-for-professional-services/)

Disclaimer: these roadmaps are compliance research artifacts, not legal advice. Implementation decisions require analysis of specific facts and should be made with qualified legal counsel and an assessor appropriate to the framework.

Related EFROS resources

## Related EFROS compliance and research

[### EFROS Compliance Readiness service Compliance program design and operation across multiple frameworks.Open→](https://efros.com/services/compliance-readiness/) [### EFROS AI Governance service NIST AI RMF, Colorado SB 26-189, and state AI law overlays as an operating program.Open→](https://efros.com/services/ai-governance/) [### US State AI Law Tracker Citation-ready research on US state-level AI laws and compliance obligations.Open→](https://efros.com/research/state-ai-law-tracker/) [### US AI Vendor Governance Index 20 AI vendors scored on 12 US AI governance axes.Open→](https://efros.com/research/us-ai-vendor-governance-index/)
