Why we built Infosec Standards
If you have ever been handed a compliance requirement for the first time, you know the feeling. A customer asks for your SOC 2 report. A payment processor asks for your PCI attestation. A prime contractor asks about your CMMC level. You open a search engine, and an hour later you have twenty tabs open and still cannot answer the basic questions: who actually runs this standard, who is allowed to assess you against it, what document comes out the other end, who is going to read it, and what all of this is going to cost in money and in your team's time.
We built Infosec Standards to answer those questions in one place, in plain language.
Why the basics are hard to find
Some standards are reasonably tidy. PCI DSS is published by one council as one document, with a defined set of assessor types and a defined set of reporting forms. Once you know where to look, the shape of it is clear.
Others are not. SOC 2 is governed by an accounting body, not a security one. There is no certificate; there is an examination performed by a CPA firm, and the rules for that examination are spread across attestation standards, practitioner guides, and a description criteria document, with the criteria themselves in yet another publication. Someone starting from zero does not know which of those documents is authoritative, which is guidance, or which one they should read first. CMMC layers a certification program on top of a NIST publication that is itself a tailoring of a much larger NIST catalog. HIPAA is a federal regulation with no certification at all, enforced after the fact.
None of this is a secret. It is just scattered, written for people who already know the territory, and rarely accompanied by a straight answer on cost. We spend the first part of many introductory calls explaining exactly this, and we have watched capable people, including new practitioners, lose weeks trying to orient themselves. That is the gap the site fills.
What is on the site
A page for each standard that covers the practical questions in the same order every time: who manages the standard, who it applies to, what it requires, who can assess you, what report or attestation you receive and who its audience is, what the process looks like, and roughly what it costs. The cost figures are ranges from named public sources and follow one written methodology so the numbers stay comparable across standards. PCI DSS, SOC 2, HIPAA, and CMMC are live now, with more in progress.
Decision guides for the questions that come up once you know a standard applies. Which PCI SAQ do I fill out? Am I a covered entity or a business associate? CMMC Level 1 or Level 2? Does HIPAA require a penetration test? Each guide is a short, single-topic article with a clear answer.
A "what applies to me?" picker that asks a few questions about what your organization does and what data it handles, and returns a short list of standards worth reading about. Each standard page also has its own picker for that standard's main fork in the road.
A news feed that covers actual changes to the standards, with links to the official source, so you can follow the ones you care about without wading through vendor noise.
A free risk assessment tool that walks a first-timer through a NIST SP 800-30 style assessment entirely in the browser. Nothing you enter leaves your machine. That one deserves its own post, and it will get one shortly.
Who it is for
It is written for whoever in your organization got handed the compliance task: an IT lead, a founder, an office manager, someone in legal. It is also, we have found, useful to people newer to our own field who want the lay of the land before they dive into the primary documents. It is not written for auditors already deep in a framework, and it does not try to replace the primary sources. It links to them.
The pages are drafted for a first-time reader and edited by practitioners here at Aeris Secure. The site is a free resource, not a brochure. Where a page ends with an offer of help, that goes to the same people who edit the content, and you will find the site just as useful if you never take it.
Start with the standards catalog or the what-applies picker. If something on the site is wrong or unclear, the contact form reaches us so that we can fix the page.