Compliance isn't one law, one auditor, or one certificate. It's a stack of separate obligations that arrive from different directions and never announce themselves together.
Regulatory applicability is the question of which laws, rules, and contract terms actually bind your business. It's decided by five things: the data you handle, the industry you're in, where your customers live, who you sell to, and how you take money. It is not decided by your headcount, your revenue, or whether anyone has told you yet.
That last part is the problem. Nobody sends you a letter listing the rules you have to follow. You find out from an auditor, an insurance application, a customer's security questionnaire, or a breach.
Because no single agency owns the list.
American data regulation grew sideways, not top-down. Health data got its own law. Financial data got another. Card payments got a private contractual standard rather than a statute. Then states started writing privacy laws of their own, and defense contracts started carrying cybersecurity clauses down through the supply chain.
The result is that a fifteen-person business can be in scope for four or five separate regimes without ever having been notified by any of them. There's no registry, no annual notice, and no default. The obligation attaches the moment the triggering fact is true.
Five inputs, and they compound rather than compete.
The data you handle. This is the strongest signal. Health records pull in HIPAA. Cardholder data pulls in PCI DSS. Personal information about California residents pulls in CCPA/CPRA. Storing, processing, or transmitting it for someone else counts - you don't have to own the data for the rules to reach you.
Your industry. Sector rules follow the work. Healthcare, financial services, education, and defense each carry their own frameworks, and being a vendor to one of those sectors often carries the requirements to you by contract.
Where your customers are. Geography gates a whole category of law. CCPA/CPRA turns on California residents, BIPA on Illinois, NYDFS Part 500 on New York, GDPR on the EU and UK. Where your office sits is close to irrelevant.
Who you sell to. Government contracts carry cybersecurity clauses, and those clauses flow down. A machine shop that has never signed a prime contract can still inherit DFARS obligations through a subcontract.
How you take money. Accepting card payments brings PCI DSS into scope, and card-present environments add requirements that card-not-present ones don't.
Almost never, and the exception people cite is narrower than they think.
The FTC Safeguards Rule is the usual example. It does contain a small-entity provision, at 16 CFR 314.6, and here is its complete text: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."
Read what that leaves in place. Under five thousand consumers, you are still required to designate a Qualified Individual to run the program, encrypt customer information in transit and at rest, implement access controls and multi-factor authentication, train your staff, oversee your service providers, and notify the FTC within 30 days of a breach affecting 500 or more consumers. You're relieved of the written risk assessment, the penetration testing schedule, the written incident response plan, and the annual board report. That's four obligations lifted out of ten.
The second trap in that rule is the word "financial institution." Under 16 CFR 314.2, it reaches any business engaged in activities that are financial in nature - and the FTC's own enumerated examples include tax preparers, auto dealerships that lease vehicles, mortgage brokers, real estate appraisers, travel agencies arranging financial services, and check cashers. Most of those businesses do not think of themselves as financial institutions. The rule doesn't care what they think.
Three things, and all three are the kind of drift that quietly makes existing guidance wrong.
The CCPA revenue threshold is no longer $25 million. The figure in the statute is CPI-adjusted, and the California Privacy Protection Agency has it at $26,625,000 in annual gross revenue, effective January 1, 2025 (CPPA CPI adjustment). Revenue is only one of three independent triggers - buying, selling, or sharing the personal information of 100,000 or more California residents or households will do it, as would deriving 50 percent or more of annual revenue from selling or sharing that information. Any one of the three puts you in scope. Worth knowing: the California Attorney General's own CCPA page still shows the old $25 million figure and omits "sharing" from the third prong. Cite the CPPA.
CMMC Phase 2 is suspended. On July 13, 2026, the Department of War announced the immediate suspension of the transition to Phase II, which had been scheduled for November 10, 2026, along with pending and future implementation milestones, and stood up a CMMC Reform Task Force (DoD CIO). What that does not mean is that CMMC went away. The 32 CFR Part 170 program rule and the DFARS acquisition rule are both still on the books - no rulemaking rescinded either one. Phase 1 self-assessment requirements are unchanged, DFARS 252.204-7012 is unchanged, and per the DoD CIO's FAQ dated August 19, 2026, Level 2 self-assessments are due March 1, 2027. If you read somewhere that CMMC is dead, that's wrong. If you read that C3PAO certification is required this November, that's also wrong.
State privacy laws keep arriving. Indiana, Kentucky, and Rhode Island comprehensive privacy laws all took effect January 1, 2026. Vermont enacted one in 2026 that takes effect January 1, 2028. I'm deliberately not publishing a national count, because no government body maintains an authoritative one - the most defensible primary-source figure I can point to is a June 2026 multistate attorney general letter stating that twenty states have enacted comprehensive privacy laws since 2018. That letter doesn't separate enacted from in-effect, and I'm not going to pretend it does.
A list of applicable frameworks is a reading list, not a verdict. It tells you what to read; it doesn't tell you where you fall short.
The gap between those two is where the actual work lives. Knowing HIPAA applies to you is a five-minute realization. Knowing which of your systems touch electronic protected health information, whether your business associate agreements are in place, and whether your access controls would survive an audit is a different exercise entirely.
There's also a category that no applicability test will surface: the frameworks nobody mandates and everybody asks about. NIST CSF, ISO/IEC 27001, SOC 2, and COBIT aren't required by any regulator. They're how businesses prove security to customers, insurers, and auditors when no regulator is in the picture. Half the security questionnaires I see from our customers' customers are asking for one of those four.
If you have fewer than a hundred employees, you are almost certainly in scope for more than you think, and almost certainly for fewer things than a vendor trying to sell you a compliance platform will claim.
Here's the honest version. Most Treasure Coast businesses I talk to are in scope for two to four regimes. A dental practice: HIPAA, plus PCI DSS if they take cards at the counter. A CPA firm: the FTC Safeguards Rule, whether or not they've ever heard of it. A marine parts manufacturer with one defense subcontract: the CUI and DFARS stack, arriving through a flow-down clause nobody read closely.
None of those businesses got a letter. All of them found out some other way, and the ones who found out from an auditor or a carrier had a worse week than the ones who went looking.
The practical move is to find out on a Tuesday afternoon rather than during a claim. Our Compliance Finder asks five questions - industry, data types, locations, government contracts, card payments - and maps your answers against the published applicability criteria of 38 frameworks. It's free, it doesn't ask for your email, and the results are a shareable link you can hand to your attorney or your controller.
It's also honest about its limits. Five questions can't see thresholds, exemptions, or your actual contract terms. Every result carries a caveat for exactly that reason. What it gives you is the reading list, which is the thing most businesses have never had.
If you want the next layer - where you actually fall short against the rules that apply - that's what the Cyber Risk & Compliance Gap Assessment is for. It looks at your environment, not your answers.
Disclaimer. This article is provided for general information only. It is not legal, regulatory, or professional advice, and reading it does not create a client relationship with WOM Technology Management Group. Regulations, threats, and vendor products change; specific obligations depend on your industry, jurisdiction, contracts, and data. Verify anything you plan to rely on against the primary source and consult qualified counsel or a security professional before acting.
Sources are cited as of the last-reviewed date shown above. Where a linked source has moved or been withdrawn, the citation reflects what was verifiable at review time.